Authorization method, first node, second node, first access network device, third node, second access network device, communication system, storage medium and program product
By using a collaborative authorization method, and leveraging authorization information and network function configuration files provided by the terminal UE or user, network security issues are resolved, enabling timely authorization and legitimate access to network entities.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2026-03-12
AI Technical Summary
Cybersecurity issues are becoming increasingly prominent in existing technologies, with frequent cyberattacks, fraud, and user information leaks. Network entity authorization technologies are insufficient to guarantee legitimate access and use.
By employing a collaborative authorization method among the first node, second node, first access network device, third node, and second access network device, and utilizing authorization information provided by the terminal UE or user and authorization information from the network function configuration file, timely authorization of network entities can be achieved.
It enables timely authorization of network entities, ensuring legitimate access and use, and reducing the risk of network attacks and information leaks.
Smart Images

Figure CN2024117830_12032026_PF_FP_ABST
Abstract
Description
Authorization method, first node, second node, first access network device, third node, second access network device, communication system, storage medium and program product TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to an authorization method, a first node, a second node, a first access network device, a third node, a second access network device, a communication system, a storage medium and a program product. BACKGROUND
[0002] With the rapid development of Internet technology and the continuous emergence of big data, network security problems are increasingly prominent. Network attacks, fraudulent behavior and user information leakage events occur from time to time, which has brought serious property and privacy security threats to users and enterprises. In order to better protect network security and ensure the legal access and use of network resources, network entity authorization technology has emerged as the times require.
[0003] SUMMARY
[0004] The present disclosure provides an authorization method, a first node, a second node, a first access network device, a third node, a second access network device, a communication system, a storage medium and a program product, which solves the technical problem of network entity authorization.
[0005] According to a first aspect of an embodiment of the present disclosure, an authorization method is provided, which is executed by a first node and includes:
[0006] receiving a first request sent by a second node or a first access network device, the first request being used to request first information;
[0007] if it is determined to authorize the second node or the first access network device according to first authorization information and second authorization information, sending the first information to the second node or the first access network device; the first authorization information includes authorization information provided by a terminal UE or a user, and the second authorization information is used to indicate authorization information corresponding to a network function configuration file.
[0008] According to a second aspect of an embodiment of the present disclosure, an authorization method is provided, which is executed by a second node or a first access network device and includes:
[0009] sending a first request to a first node, the first request being used to request first information;
[0010] receiving the first information sent by the first node, the first information being sent by the first node when it is determined to authorize the second node or the first access network device according to first authorization information and second authorization information, the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used to indicate authorization information corresponding to a network function configuration file.
[0011] According to a third aspect of embodiments of the present disclosure, a method for authorization is provided, performed by a third node, comprising:
[0012] receiving a second request sent by the first node, or receiving a third request sent by the second node or the first access network device;
[0013] sending, to the first node, second authorization information, the second authorization information being used to indicate authorization information corresponding to a network function profile, and the second authorization information being used for the first node to determine, according to the second authorization information and the first authorization information obtained, to send, to the second node or the first access network device, first information when the second node is authorized, the first authorization information comprising authorization information provided by a UE or a user.
[0014] According to a fourth aspect of embodiments of the present disclosure, a method for authorization is provided, performed by a second access network device, comprising:
[0015] sending, to the second node, a fourth request, the fourth request being used to request the first information, the fourth request being used for the second node to send, to the first node, the first request;
[0016] receiving first information sent by the second node, the first information being sent by the first node according to the first authorization information and the second authorization information when the second access network device is authorized, the first authorization information comprising authorization information provided by a UE or a user, and the second authorization information being used to indicate authorization information corresponding to a network function profile.
[0017] According to a fifth aspect of embodiments of the present disclosure, a first node is provided, comprising:
[0018] a transceiver, configured to receive a first request sent by a second node or a first access network device, the first request being used to request first information;
[0019] a processing module, configured to send, to the second node or the first access network device, the first information when the second node or the first access network device is authorized according to the first authorization information and the second authorization information, the first authorization information comprising authorization information provided by a UE or a user, and the second authorization information being used to indicate authorization information corresponding to a network function profile.
[0020] According to a sixth aspect of embodiments of the present disclosure, a second node or a first access network device is provided, comprising:
[0021] a transceiver, configured to send, to a first node, a first request, the first request being used to request first information;
[0022] The transceiver module is further configured to receive the first information sent by the first node, wherein the first information is sent by the first node according to first authorization information and second authorization information when the first node determines to authorize the second node or the first access network device, the first authorization information includes authorization information provided by a UE or a user, and the second authorization information is used to indicate authorization information corresponding to a network function profile.
[0023] According to a seventh aspect of an embodiment of the present disclosure, a third node is provided, comprising:
[0024] The transceiver module is configured to receive a second request sent by the first node or a third request sent by the second node or the first access network device.
[0025] The transceiver module is further configured to send second authorization information to the first node, wherein the second authorization information is used to indicate authorization information corresponding to a network function profile, and the second authorization information is used by the first node to send first information to the second node or the first access network device when the first node determines to authorize the second node according to the second authorization information and first authorization information obtained by the first node, and the first authorization information includes authorization information provided by a UE or a user.
[0026] According to an eighth aspect of an embodiment of the present disclosure, a second access network device is provided, comprising:
[0027] The transceiver module is configured to send a fourth request to the second node, wherein the fourth request is used to request first information, and the fourth request is used by the second node to send a first request to the first node.
[0028] The transceiver module is further configured to receive first information sent by the second node, wherein the first information is sent by the first node according to first authorization information and second authorization information when the first node determines to authorize the second access network device, the first authorization information includes authorization information provided by a UE or a user, and the second authorization information is used to indicate authorization information corresponding to a network function profile.
[0029] According to a ninth aspect of an embodiment of the present disclosure, a first node is provided, comprising:
[0030] One or more processors;
[0031] The first node is configured to perform the authorization method of the first aspect.
[0032] According to a tenth aspect of an embodiment of the present disclosure, a second node or a first access network device is provided, comprising:
[0033] One or more processors;
[0034] The second node or the first access network device is configured to perform the authorization method in the second aspect.
[0035] According to a first aspect of an embodiment of the present disclosure, a first node is provided, comprising:
[0036] one or more processors;
[0037] The first node is configured to perform the authorization method in the first aspect.
[0038] According to a second aspect of an embodiment of the present disclosure, a second node is provided, comprising:
[0039] one or more processors;
[0040] The second node is configured to perform the authorization method in the second aspect.
[0041] According to a third aspect of an embodiment of the present disclosure, a third node is provided, comprising:
[0042] According to a fourth aspect of an embodiment of the present disclosure, a second access network device is provided, comprising:
[0043] The third node is configured to perform the authorization method in the third aspect.
[0044] The fourth aspect is similar to the third aspect, and the second access network device is configured to perform the authorization method in the fourth aspect.
[0045] The fifth aspect is similar to the third aspect, and the second access network device is configured to perform the authorization method in the fifth aspect.
[0046] The present disclosure can timely authorize a network entity. BRIEF DESCRIPTION OF DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.
[0048] FIG. 1A is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0049] FIG. 1B is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0050] FIG. 1C is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0051] FIG. 2A is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0052] FIG. 2B is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0053] FIG. 2C is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0054] FIG. 2D is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0055] FIG. 2E is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0056] FIG. 2F is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0057] FIG. 2G is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0058] FIG. 2H is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0059] FIG. 3A is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0060] FIG. 3B is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0061] FIG. 3C is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0062] FIG. 3D is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0063] FIG. 3E is an example interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0064] FIG. 3F is an example interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0065] FIG. 3G is an example interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0066] FIG. 3H is an example interaction schematic diagram of an authorization method according to an embodiment of the present disclosure.
[0067] FIG. 4A is a structural schematic diagram of a terminal according to an embodiment of the present disclosure.
[0068] FIG. 4B is a structural schematic diagram of a first node according to an embodiment of the present disclosure.
[0069] FIG. 4C is a structural schematic diagram of a second node or a first access network device according to an embodiment of the present disclosure.
[0070] FIG. 4D is a structural schematic diagram of a third node according to an embodiment of the present disclosure.
[0071] FIG. 4E is a structural schematic diagram of a core network device according to an embodiment of the present disclosure.
[0072] FIG. 4F is a structural schematic diagram of a second access network device according to an embodiment of the present disclosure.
[0073] FIG. 5A is a structural schematic diagram of a communication device according to an embodiment of the present disclosure.
[0074] FIG. 5B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0075] Embodiments of the present disclosure provide an authorization method, a first node, a second node, a first access network device, a third node, a second access network device, a communication system, a storage medium and a program product.
[0076] In a first aspect, embodiments of the present disclosure provide an authorization method, performed by a first node, comprising:
[0077] receiving a first request sent by a second node or a first access network device, the first request being used to request first information;
[0078] if it is determined to authorize the second node or the first access network device according to first authorization information and second authorization information, sending the first information to the second node or the first access network device; the first authorization information comprises authorization information provided by a terminal UE or a user, and the second authorization information is used to indicate authorization information corresponding to a network function profile.
[0079] In the above embodiment, based on the authorization information provided by the UE or the user and the authorization information corresponding to the network function configuration file, the relevant authorization policy can be obtained, and then according to the authorization policy, the second node or the first access network device can be authorized in a timely manner in response to the request sent by the second node or the first access network device.
[0080] In combination with some embodiments of the first aspect, in some embodiments, the first authorization information is configured by the user to the first node or the third node, or the first authorization information is configured by the UE to the first node or the third node.
[0081] In the above embodiment, the authorization information provided by the UE or the user can be obtained in a timely manner through the user configuration or UE configuration, and then the authorization of the second node or the first access network device can be provided with relevant basis.
[0082] In combination with some embodiments of the first aspect, in some embodiments, the first authorization information includes at least one of the following: user information, data type, data processing purpose, and purpose of processing the data type.
[0083] In the above embodiment, the first authorization information indicates the user information, the data type, the data processing purpose, and the purpose of processing the data type, so that the authorization information related to the user can be determined, and then the authorization of the second node or the first access network device can be provided with relevant basis.
[0084] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:
[0085] Receiving second authorization information sent by the third node.
[0086] In the above embodiment, the second authorization information can be obtained by receiving the second authorization information sent by the third node, and the authorization of the second node or the first access network device can be provided with relevant basis by obtaining the authorization information corresponding to the network function configuration file.
[0087] In combination with some embodiments of the first aspect, in some embodiments, the second authorization information is used to indicate the authorization information of the fourth node.
[0088] In the above embodiment, the second authorization information indicates the authorization information related to the fourth node, so that the authorization information corresponding to the network function configuration file can be determined, and then the authorization of the second node or the first access network device can be provided with relevant basis.
[0089] In some embodiments of the first aspect, in some embodiments, the authorization information of the fourth node comprises at least one of: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service of the fourth node or a service operation of the fourth node.
[0090] In the above embodiments, the authorization information of the fourth node indicates the NF type of the fourth node or the NF instance ID of the fourth node, the service of the fourth node or the service operation of the fourth node, and the service-related authorization information can be determined, and then the authorization of the second node or the first access network device is provided as a basis.
[0091] In some embodiments of the first aspect, in some embodiments, the first information comprises at least one of: a data type, a data processing purpose, a purpose of processing the data type, and an NF instance ID of the first node.
[0092] In the above embodiments, based on the data type, the data processing purpose, and the purpose of processing the data type obtained, the data type, the data processing purpose, and the purpose of processing the data type that the second node or the first access network device is authorized to process can be determined, and then the corresponding network function service provider is requested to provide services according to the authorized content, and therefore, based on the authorization provided by the UE or the user and the authorization corresponding to the network function profile, the second node or the first access network device can be timely authorized to provide corresponding services when requesting services from the network function service provider; on this basis, the first information also indicates the NF instance ID of the first node (here, the issuer), and the authorization of the second node or the first access network device is implemented based on the issuer.
[0093] In some embodiments of the first aspect, in some embodiments, the first request comprises at least one of: user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing the data type, an NF type of the fourth node, and an NF instance ID of the fourth node.
[0094] In the above embodiments, based on one or more of the user information, the service or the service operation, the data type, the data processing purpose, the purpose of processing the data type, the NF type of the fourth node, and the NF instance ID of the fourth node included in the first request, it can be checked whether the requested service matches the first authorization information and the second authorization information obtained or whether it is within the authorized range, and then it can be determined whether to authorize the second node or the first access network device.
[0095] In some embodiments of the first aspect, in some embodiments, the method further comprises:
[0096] if it is determined, according to the first authorization information, that any of the following is true, sending a second request to the third node:
[0097] the data type in the first request is allowed and the purpose of processing the data type is allowed;
[0098] the data processing purpose in the first request is allowed.
[0099] In the above embodiment, before receiving the second authorization information sent by the third node, it can be determined, based on the first authorization information, whether the data type in the first request is allowed and whether the purpose of processing the data type is allowed, and it can be determined that the data processing purpose in the first request is allowed, and if so, the second request can be sent to the third node, thereby triggering the third node to send the second authorization information to the first node, so that the second authorization information is used as a basis for subsequent authorization of the second node or the first access network device.
[0100] In combination with some embodiments of the first aspect, in some embodiments, the second request is used by the third node to determine a corresponding network function profile according to an NF type of the fourth node or an NF instance ID of the fourth node provided by the first node.
[0101] In the above embodiment, after the third node obtains the second request, it can determine a corresponding network function profile according to an NF type of the fourth node or an NF instance ID of the fourth node, thereby providing a basis for subsequent sending of the second authorization information to the first node.
[0102] In combination with some embodiments of the first aspect, in some embodiments, the second request includes at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service or a service operation.
[0103] In the above embodiment, based on one or more of the NF type of the second node or the NF type of the first access network device, the NF type of the fourth node or the NF instance ID of the fourth node, the service or the service operation, etc. included in the second request, the third node is triggered to provide authorization information corresponding to the network function profile to the first node, thereby providing a basis for subsequent authorization of the second node or the first access network device.
[0104] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:
[0105] terminating the authorization procedure for the second node or the first access network device or sending third information to the second node or the first access network device, according to the first authorization information and the second authorization information, if the first condition is not met;
[0106] The first request includes a seventh request and an eighth request.
[0107] The seventh request is used to request UE or user authorization, and the eighth request is used to request network function authorization.
[0108] The first condition includes that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information.
[0109] The third information is used to indicate any of the following:
[0110] The second node or the first access network device is not authorized.
[0111] The second node or the first access network device fails to be authorized.
[0112] The second node or the first access network device fails to be authorized.
[0113] In the above embodiments, if the seventh request and / or the eighth request in the first request is not allowed, indicating that the second node or the first access network device fails to be authorized or the second node or the first access network device is not authorized, the authorization procedure for the second node or the first access network device can be terminated, or the third information can be sent to the second node or the first access network device in time to feed back any of not being authorized, authorization failure, and the reason for authorization failure.
[0114] In combination with some embodiments of the first aspect, in some embodiments, the method further includes:
[0115] terminating the authorization procedure for the second node or the first access network device or sending third information to the second node or the first access network device, according to the first authorization information and the second authorization information, if the first condition is not met;
[0116] The first condition includes that the data processing purpose in the first request is allowed and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node, or the data type in the first request and the purpose of processing the data type are allowed and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node; and the third information is used to indicate any of the following:
[0117] The second node or the first access network device is not authorized.
[0118] the second node or the first access network device fails in authorization;
[0119] a reason why the second node or the first access network device fails in authorization.
[0120] In the above embodiments, if the data type in the first request and the purpose of processing the data type are not allowed, and / or the service of the fourth node or the service operation of the fourth node in the first request is not authorized by the request, it is indicated that the second node or the first access network device fails in authorization or is not authorized by the second node or the first access network device. Therefore, the authorization process of the second node or the first access network device can be terminated, or the third information can be sent to the second node or the first access network device in time to feed back any one of the unauthorization, the authorization failure, and the reason for the authorization failure.
[0121] In some embodiments of the first aspect, the method further includes:
[0122] receiving second information sent by the UE, the second information being used to indicate whether the second node or the first access network device is authorized for the data processing purpose or is authorized for the purpose of processing the data type;
[0123] if the second node or the first access network device is authorized for the data processing purpose or is authorized for the purpose of processing the data type, sending the authorization identifier to the UE.
[0124] In the above embodiments, if the indication information that the second node or the first access network device is authorized for the data processing purpose or is authorized for the purpose of processing the data type is received by the UE, the authorization identifier can be provided to the UE. In order to obtain the first authorization information based on the authorization identifier, the authorization of the second node or the first access network device is provided.
[0125] In the second aspect, the disclosure embodiments propose an authorization method, which is executed by the second node or the first access network device, and includes:
[0126] sending a first request to a first node, the first request being used to request first information;
[0127] receiving the first information sent by the first node, the first information being sent by the first node according to first authorization information and second authorization information when determining to authorize the second node or the first access network device, the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used to indicate authorization information corresponding to a network function configuration file.
[0128] In the above embodiments, the first information is requested from the first node by sending a first request to the first node, and if the first information sent by the first node based on the first authorization information and the second authorization information is received, it indicates that the second node or the first access network device is authorized, so that the authorization of the second node or the first access network device can be realized in time, and then subsequent service requests can be realized.
[0129] In combination with some embodiments of the second aspect, in some embodiments, the first authorization information is configured by a user to the first node or the third node, or the first authorization information is configured by the UE to the first node or the third node.
[0130] In combination with some embodiments of the second aspect, in some embodiments, the first authorization information includes at least one of the following: user information, data type, data processing purpose, purpose of processing the data type.
[0131] In combination with some embodiments of the second aspect, in some embodiments, the first information includes at least one of the following: data type, data processing purpose, purpose of processing the data type, NF instance ID of the first node.
[0132] In combination with some embodiments of the second aspect, in some embodiments, the method further includes:
[0133] sending a third request to the third node, the third request being used to trigger the third node to send second authorization information to the first node.
[0134] In the above embodiments, by sending a third request to the third node, and then triggering the third node to send second authorization information to the first node, so that based on the second authorization information, relevant basis is provided for subsequent authorization of the second node or the first access network device.
[0135] In combination with some embodiments of the second aspect, in some embodiments, the second authorization information is used to indicate authorization information of the fourth node.
[0136] In combination with some embodiments of the second aspect, in some embodiments, the authorization information of the fourth node includes at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service of the fourth node or service operation of the fourth node.
[0137] In combination with some embodiments of the second aspect, in some embodiments, the first request includes at least one of the following: user information, service or service operation, data type, data processing purpose, purpose of processing the data type, NF type of the fourth node or NF instance ID of the fourth node.
[0138] In some embodiments in combination with the second aspect, the method further comprises:
[0139] receiving fourth information sent by the third node, the fourth information being used to indicate any of the following: the second node or the first access network device is allowed to request a service or a service operation of the fourth node, the second node or the first access network device is not allowed to request the service or the service operation of the fourth node.
[0140] In the above embodiments, by receiving the fourth information sent by the third node, a basis can be provided for whether to subsequently send the first request to the first node.
[0141] In some embodiments in combination with the second aspect, the sending of the first request to the first node comprises:
[0142] if the second node or the first access network device is authorized by the second authorization information, sending the first request to the first node.
[0143] In the above embodiments, if the second node or the first access network device is authorized by the second authorization information, the first request can be sent to the first node, and the first information can be requested from the first node to determine whether the second node or the first access network device is authorized.
[0144] In some embodiments in combination with the second aspect, the sending of the first request to the first node comprises:
[0145] if the second node or the first access network device is allowed to request the service or the service operation of the fourth node, sending the first request to the first node.
[0146] In the above embodiments, if the received fourth information is used to indicate that the second node or the first access network device is allowed to request the service or the service operation of the fourth node, the first request can be sent to the first node, and the first information can be requested from the first node to determine whether the second node or the first access network device is authorized.
[0147] In some embodiments in combination with the second aspect, the method further comprises:
[0148] if the second node or the first access network device is not authorized by the second authorization information, determining not to send the first request to the first node.
[0149] In the above embodiment, if the second node or the first access network device is not authorized by the second authorization information, the first node can not be sent the first request, thereby reducing invalid requests in the network and reducing resource waste.
[0150] In some embodiments in combination with the second aspect, in some embodiments, the method further comprises:
[0151] If the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node, it is determined that the first request is not sent to the first node.
[0152] In the above embodiment, if the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node, the first node is not sent the first request, thereby reducing invalid requests in the network and reducing resource waste.
[0153] In some embodiments in combination with the second aspect, in some embodiments, the method further comprises:
[0154] The address information of the first node is sent to the UE.
[0155] In the above embodiment, by sending the address information of the first node to the UE, the UE can find the first node based on the provided address information, and then interact with the first node to obtain authorization-related information, etc.
[0156] In some embodiments in combination with the second aspect, in some embodiments, the method further comprises:
[0157] The third information sent by the first node is received, and the third information is used to indicate any of the following:
[0158] The second node or the first access network device is not authorized;
[0159] The second node or the first access network device fails to be authorized;
[0160] The second node or the first access network device fails to be authorized;
[0161] The third information is sent by the first node when it is determined that the first condition is not met according to the first authorization information and the second authorization information, the first request includes a seventh request and an eighth request, the seventh request is used to request UE or user authorization, the eighth request is used to request network function authorization, and the first condition includes that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information.
[0162] In the above embodiment, if the third information sent by the first node is received, it is indicated that the second node or the first access network device fails to be authorized or the second node or the first access network device is not authorized or the reason why the second node or the first access network device fails to be authorized, and the second node or the first access network device can be fed back in time that it is not authorized.
[0163] With reference to the second aspect, in some embodiments, the method further includes:
[0164] receiving third information sent by the first node, the third information being used to indicate any of the following:
[0165] the second node or the first access network device is not authorized;
[0166] the second node or the first access network device fails to be authorized;
[0167] the reason why the second node or the first access network device fails to be authorized;
[0168] wherein the third information is sent by the first node according to the first authorization information and the second authorization information when it is determined that the first condition is not met, and the first condition includes that the data processing purpose in the first request is allowed and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node, or the data type in the first request and the purpose of processing the data type are allowed and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node.
[0169] In the above embodiment, if the third information sent by the first node is received, it is indicated that the second node or the first access network device fails to be authorized or the second node or the first access network device is not authorized or the reason why the second node or the first access network device fails to be authorized, and the second node or the first access network device can be fed back in time that it is not authorized.
[0170] In a third aspect, the embodiments of the present disclosure provide an authorization method, executed by a third node, including:
[0171] receiving a second request sent by a first node, or receiving a third request sent by a second node or a first access network device;
[0172] sending second authorization information to the first node, the second authorization information being used to indicate authorization information corresponding to a network function configuration file, and the second authorization information being used for the first node to determine to authorize the second node according to the second authorization information and acquired first authorization information, and send first information to the second node or the first access network device, the first authorization information including authorization information provided by a UE or a user.
[0173] In the above embodiments, the first node is provided with the second authorization information by receiving the second request sent by the first node when the data type in the first request, the data processing purpose and the purpose of processing the data type are allowed according to the first authorization information, or receiving the third request sent by the second node or the first access network device, thereby providing a basis for the authorization of the subsequent second node or the first access network device.
[0174] In combination with some embodiments of the third aspect, in some embodiments, the first authorization information is configured to the first node or the third node by the user, or the first authorization information is configured to the first node or the third node by the UE.
[0175] In combination with some embodiments of the third aspect, in some embodiments, the first authorization information includes at least one of the following: user information, data type, data processing purpose, and purpose of processing the data type.
[0176] In combination with some embodiments of the third aspect, in some embodiments, the second request includes at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service or service operation; and / or,
[0177] The third request includes at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service or service operation.
[0178] In combination with some embodiments of the third aspect, in some embodiments, the second authorization information is used to indicate the authorization information of the fourth node.
[0179] In combination with some embodiments of the third aspect, in some embodiments, the authorization information of the fourth node includes at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service of the fourth node or service operation of the fourth node.
[0180] In combination with some embodiments of the third aspect, in some embodiments, the first information includes at least one of the following: data type, data processing purpose, purpose of processing the data type, and NF instance ID of the first node.
[0181] In combination with some embodiments of the third aspect, in some embodiments, the method further includes:
[0182] According to the NF type of the fourth node in the second request, a network function profile of the fourth node is obtained; or according to the NF instance ID of the fourth node in the third request, a network function profile of the fourth node is obtained.
[0183] According to the network function profile of the fourth node, the second authorization information is determined.
[0184] In the above embodiment, based on the network function profile of the fourth node, the second authorization information can be determined, and by providing the second authorization information to the first node, a basis for subsequent authorization of the second node or the first access network device is provided.
[0185] In combination with some embodiments of the third aspect, in some embodiments, the method further includes: sending fourth information to the second node or the first access network device, the fourth information being used to indicate any of the following: the second node or the first access network device is allowed to request a service or a service operation of the fourth node, the second node or the first access network device is not allowed to request a service or a service operation of the fourth node.
[0186] In the above embodiment, by sending the fourth information to the second node or the first access network device, it is indicated whether the second node or the first access network device is allowed to request a service or a service operation of the fourth node, thereby providing a basis for subsequent authorization of the second node or the first access network device.
[0187] In combination with some embodiments of the third aspect, in some embodiments, the second request is sent by the first node when it is determined according to the first authorization information that any of the following is allowed: a data type in the first request and a purpose of processing the data type, a purpose of data processing in the first request.
[0188] In a fourth aspect, the embodiments of the present disclosure propose an authorization method, executed by a terminal, including:
[0189] Sending first authorization information to a first node or a third node;
[0190] The first authorization information includes authorization information provided by a UE or a user, and the first authorization information is used for the first node to determine, according to the first authorization information and obtained second authorization information, to send first information to the second node or the first access network device when authorizing the second node or the first access network device, and the second authorization information is used to indicate authorization information corresponding to a network function profile.
[0191] In the above embodiment, by providing the first node or the third node with the first authorization information, the first node can determine whether to authorize the second node or the first access network device in time according to the first authorization information and the obtained second authorization information, and an authorization basis for the second node or the first access network device is provided.
[0192] In combination with some embodiments of the fourth aspect, in some embodiments, the first authorization information is configured by a user to the first node or the third node, or the first authorization information is configured by the UE to the first node or the third node.
[0193] In combination with some embodiments of the fourth aspect, in some embodiments, the first authorization information includes at least one of the following: user information, data type, data processing purpose, purpose of processing the data type.
[0194] In combination with some embodiments of the fourth aspect, in some embodiments, the method further includes:
[0195] receiving address information of the first node sent by the second node or the first access network device;
[0196] sending second information to the first node according to the address information, the second information being used to indicate whether the second node or the first access network device is authorized for the data processing purpose or for the purpose of processing the data type.
[0197] In the above embodiment, based on the address information of the first node, the first node located is sent the second information used to indicate whether the second node or the first access network device is authorized to process the data type under a given purpose or is authorized for the data processing purpose, and then whether to authorize the second node or the first access network device is determined.
[0198] In combination with some embodiments of the fourth aspect, in some embodiments, the method further includes:
[0199] determining whether the second node or the first access network device is authorized for the data processing purpose or for the purpose of processing the data type.
[0200] In the above embodiment, by determining whether the second node or the first access network device is authorized to process the data type under a given purpose or is authorized for the data processing purpose, whether to authorize the second node or the first access network device is determined.
[0201] In combination with some embodiments of the fourth aspect, in some embodiments, the second authorization information is used to indicate authorization information of the fourth node.
[0202] In combination with some embodiments of the fourth aspect, in some embodiments, the authorization information of the fourth node comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service of the fourth node or a service operation of the fourth node.
[0203] In combination with some embodiments of the fourth aspect, in some embodiments, the first information comprises at least one of the following: a data type, a data processing purpose, a purpose of processing the data type, an NF instance ID of the first node.
[0204] In the fifth aspect, the embodiments of the present disclosure propose an authorization method, executed by a core network device, comprising:
[0205] sending a first request to a first node, the first request being used to request first information;
[0206] if receiving a second request sent by the first node, sending second authorization information to the first node, the second authorization information being used to indicate authorization information corresponding to a network function profile;
[0207] receiving first information sent by the first node, the first information being sent by the first node when determining that the core network device is authorized according to the first authorization information and the second authorization information, the first authorization information comprising authorization information provided by a UE or a user.
[0208] In the above embodiments, by requesting the first information from the first node, triggering the provision of the second authorization information to the first node when receiving the second request sent by the first node, and based on receiving the first information sent by the first node when determining that the core network device is authorized according to the first authorization information and the second authorization information, the timely authorization of a network entity (here, the core network device) can be achieved.
[0209] In the sixth aspect, the embodiments of the present disclosure propose an authorization method, executed by a second access network device, comprising:
[0210] sending a fourth request to a second node, the fourth request being used to request fifth information, the fourth request being used for the second node to send a first request to a first node;
[0211] receiving fifth information sent by the second node, the fifth information being determined by the second node based on first information, the first information being sent by the first node to the second node when determining that the second access network device is authorized according to first authorization information and second authorization information, the first authorization information comprising authorization information provided by a UE or a user, the second authorization information being used to indicate authorization information corresponding to a network function profile.
[0212] In the above embodiment, by requesting the second node for the fifth information, if the fifth information sent by the second node is received, and the fifth information is determined by the first node according to the first authorization information and the second authorization information when it is determined that the access network device is authorized, the authorization of the second access network device is realized.
[0213] In combination with some embodiments of the sixth aspect, in some embodiments, the method further includes:
[0214] sending a fifth request to the second node, the fifth request being used for requesting a service or a service operation of the fourth node, the fifth request being used for the second node to send a sixth request to the fourth node, the sixth request being used for requesting the service or the service operation of the fourth node, and the fifth information being included in the fifth request and the sixth request.
[0215] In the above embodiment, by sending the fifth request to the second node, the second node is triggered to request the service or the service operation of the fourth node, and then the service response is obtained, so that the request process of the service or the service operation is realized.
[0216] In the seventh aspect, the embodiments of the present disclosure propose an authorization method, including:
[0217] The second node sends a third request to the third node;
[0218] The third node acquires second authorization information;
[0219] The second authorization information is used to indicate authorization information corresponding to a network function configuration file, and the second authorization information is used for the first node to determine to send first information to the second node according to the second authorization information and the acquired first authorization information when the second node is authorized, and the first authorization information includes authorization information provided by the UE or the user.
[0220] In the above embodiment, by sending the third request to the third node by the second node, the third node is triggered to provide the second authorization information to the first node, and then the third node acquires the second authorization information, which provides a basis for subsequent authorization of the second node or the first access network device.
[0221] In the eighth aspect, the embodiments of the present disclosure propose an authorization method, including:
[0222] The UE sends first authorization information to the first node; the first authorization information includes authorization information provided by the UE or the user;
[0223] The core network device sends a first request and second authorization information to the first node, the first request is used to request the first information, and the second authorization information is used to indicate authorization information corresponding to a network function profile;
[0224] The first node sends the first information to the core network device if it is determined that the core network device is authorized according to the first authorization information and the second authorization information.
[0225] In the above embodiment, through the interaction of the UE, the first node, and the core network device, the communication system can authorize the second node or the first access network device in a timely manner according to the authorization policy related to the UE or the user.
[0226] In a ninth aspect, the embodiments of the present disclosure provide an authorization method, including:
[0227] The UE sends first authorization information to the first node, and the first authorization information includes authorization information provided by the UE or the user;
[0228] The first access network device sends a first request to the first node, and the first request is used to request first information;
[0229] The first node receives second authorization information sent by the core network device, and the second authorization information is used to indicate authorization information corresponding to a network function profile;
[0230] The first node sends the first information to the first access network device if it is determined that the first access network device is authorized according to the first authorization information and the second authorization information.
[0231] In the above embodiment, through the interaction of the UE, the first node, the first access network device, and the core network device, the communication system can authorize the second node or the first access network device in a timely manner according to the authorization policy related to the UE or the user.
[0232] In a tenth aspect, the embodiments of the present disclosure provide an authorization method, including:
[0233] The UE sends first authorization information to the first node, and the first authorization information includes authorization information provided by the UE or the user;
[0234] The second access network device sends a fourth request to the core network device, and the fourth request is used to request fifth information;
[0235] The core network device sends a first request and second authorization information to the first node, and the second authorization information is used to indicate authorization information related to a service or a service operation;
[0236] The first node sends first information to the core network device if the first node determines that the second access network device is authorized according to the first authorization information and the second authorization information.
[0237] The core network device sends fifth information to the second access network device, where the fifth information is determined by the core network device based on the first information.
[0238] In the above embodiments, through the interaction of the UE, the first node, the second access network device, and the core network device, the communication system can authorize the second node or the first access network device in a timely manner according to the authorization policy related to the UE or the user.
[0239] In an eleventh aspect, the embodiments of the present disclosure provide a first node, which includes at least one of a transceiver module and a processing module; and the first node is configured to perform the first aspect and the optional implementation manners of the first aspect.
[0240] In a twelfth aspect, the embodiments of the present disclosure provide a second node or a first access network device, which includes a transceiver module; and the second node or the first access network device is configured to perform the second aspect and the optional implementation manners of the second aspect.
[0241] In a thirteenth aspect, the embodiments of the present disclosure provide a third node, which includes a transceiver module; and the third node is configured to perform the third aspect and the optional implementation manners of the third aspect.
[0242] In a fourteenth aspect, the embodiments of the present disclosure provide a terminal, which includes a transceiver module; and the terminal is configured to perform the fourth aspect and the optional implementation manners of the fourth aspect.
[0243] In a fifteenth aspect, the embodiments of the present disclosure provide a core network device, which includes a transceiver module; and the core network device is configured to perform the fifth aspect and the optional implementation manners of the fifth aspect.
[0244] In a sixteenth aspect, the embodiments of the present disclosure provide a second access network device, which includes a transceiver module; and the second access network device is configured to perform the sixth aspect and the optional implementation manners of the sixth aspect.
[0245] In a seventeenth aspect, the embodiments of the present disclosure provide a first node, which includes one or more processors; and the first node is configured to perform the first aspect and the optional implementation manners of the first aspect.
[0246] In an eighteenth aspect, the embodiments of the present disclosure provide a second node or a first access network device, comprising: one or more processors; wherein the second node or the first access network device is configured to perform the method described in the second aspect and the optional implementation manners of the second aspect.
[0247] In a nineteenth aspect, the embodiments of the present disclosure provide a third node, comprising: one or more processors; wherein the third node is configured to perform the method described in the third aspect and the optional implementation manners of the third aspect.
[0248] In a twentieth aspect, the embodiments of the present disclosure provide a terminal, comprising: one or more processors; wherein the terminal is configured to perform the method described in the fourth aspect and the optional implementation manners of the fourth aspect.
[0249] In a twenty-first aspect, the embodiments of the present disclosure provide a core network device, comprising: one or more processors; wherein the core network device is configured to perform the method described in the fifth aspect and the optional implementation manners of the fifth aspect.
[0250] In a twenty-second aspect, the embodiments of the present disclosure provide a second access network device, comprising: one or more processors; wherein the second access network device is configured to perform the method described in the sixth aspect and the optional implementation manners of the sixth aspect.
[0251] In a twenty-third aspect, the embodiments of the present disclosure provide a core network device, comprising: a second node and a third node.
[0252] The second node sends a third request to the third node.
[0253] The third node acquires second authorization information.
[0254] The second authorization information is used to indicate authorization information corresponding to a network function configuration file, and the second authorization information is used for the first node to send first information to the second node when the first node determines to authorize the second node according to the second authorization information and acquired first authorization information, wherein the first authorization information comprises authorization information provided by a UE or a user.
[0255] In a twenty-fourth aspect, the embodiments of the present disclosure provide a communication system, comprising: a first node, a core network device, and a terminal, wherein the first node is configured to perform the method described in the first aspect and the optional implementation manners of the first aspect, the terminal is configured to perform the method described in the fourth aspect and the optional implementation manners of the fourth aspect, and the core network device is configured to perform the method described in the second aspect and the optional implementation manners of the second aspect, the method described in the third aspect and the optional implementation manners of the third aspect, and the method described in the fifth aspect and the optional implementation manners of the fifth aspect.
[0256] In a twenty-fifth aspect, the embodiments of the present disclosure provide a communication system, the communication system comprising: a first node, a first access network device, a core network device, and a terminal, wherein the first node is configured to perform the method described in the first aspect and the optional implementation manners of the first aspect, the first access network device is configured to perform the method described in the second aspect and the optional implementation manners of the second aspect, the terminal is configured to perform the method described in the fourth aspect and the optional implementation manners of the fourth aspect, and the core network device is configured to perform the method described in the third aspect and the optional implementation manners of the third aspect, the method described in the fifth aspect and the optional implementation manners of the fifth aspect.
[0257] In a twenty-sixth aspect, the embodiments of the present disclosure provide a communication system, the communication system comprising: a first node, a second access network device, a core network device, and a terminal, wherein the first node is configured to perform the method described in the first aspect and the optional implementation manners of the first aspect, the terminal is configured to perform the method described in the fourth aspect and the optional implementation manners of the fourth aspect, the core network device is configured to perform the method described in the second aspect and the optional implementation manners of the second aspect, the method described in the third aspect and the optional implementation manners of the third aspect, the method described in the fifth aspect and the optional implementation manners of the fifth aspect, and the second access network device is configured to perform the method described in the sixth aspect and the optional implementation manners of the sixth aspect.
[0258] In a twenty-seventh aspect, the embodiments of the present disclosure provide a storage medium, the storage medium storing instructions, when the instructions are executed on a communication device, causing the communication device to perform the method described in the first aspect and the optional implementation manners of the first aspect, the method described in the second aspect and the optional implementation manners of the second aspect, the method described in the third aspect and the optional implementation manners of the third aspect, the method described in the fourth aspect and the optional implementation manners of the fourth aspect, the method described in the fifth aspect and the optional implementation manners of the fifth aspect, the method described in the sixth aspect and the optional implementation manners of the sixth aspect.
[0259] In a twenty-eighth aspect, the embodiments of the present disclosure provide a program product, comprising a program and / or instructions, when the program product is executed by a communication device, causing the communication device to perform the method described in the first aspect and the optional implementation manners of the first aspect, the method described in the second aspect and the optional implementation manners of the second aspect, the method described in the third aspect and the optional implementation manners of the third aspect, the method described in the fourth aspect and the optional implementation manners of the fourth aspect, the method described in the fifth aspect and the optional implementation manners of the fifth aspect, the method described in the sixth aspect and the optional implementation manners of the sixth aspect.
[0260] In a 29th aspect, the embodiments of the present disclosure provide a computer program which, when running on a computer, causes the computer to perform the method described in the first aspect and optional implementation manners of the first aspect, the method described in the second aspect and optional implementation manners of the second aspect, the method described in the third aspect and optional implementation manners of the third aspect, the method described in the fourth aspect and optional implementation manners of the fourth aspect, the method described in the fifth aspect and optional implementation manners of the fifth aspect, the method described in the sixth aspect and optional implementation manners of the sixth aspect.
[0261] In a 30th aspect, the embodiments of the present disclosure provide a chip system. The chip system comprises processing circuitry configured to perform the method described in the first aspect and optional implementation manners of the first aspect, the method described in the second aspect and optional implementation manners of the second aspect, the method described in the third aspect and optional implementation manners of the third aspect, the method described in the fourth aspect and optional implementation manners of the fourth aspect, the method described in the fifth aspect and optional implementation manners of the fifth aspect, the method described in the sixth aspect and optional implementation manners of the sixth aspect.
[0262] It can be understood that the terminal, the first node, the second node, the first access network device, the third node, the core network device, the second access network device, the communication system, the storage medium, the program product, the computer program, and the chip system are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved by them can refer to the beneficial effects in the corresponding method, which will not be described here.
[0263] The embodiments of the present disclosure propose an authorization method, a first node, a second node, a first access network device, a third node, a second access network device, a communication system, a storage medium, and a program product. In some embodiments, the authorization method and the information processing method, the communication method, and other terms can be replaced with each other, the authorization device and the information processing device, the communication device, and other terms can be replaced with each other, and the information processing system and the communication system can be replaced with each other.
[0264] The embodiments of the present disclosure are not exhaustive and are only a part of the embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, part or all steps of different embodiments can be combined arbitrarily, and an embodiment can be combined with optional implementation manners of other embodiments.
[0265] In the embodiments of the present disclosure, the terms and / or descriptions among the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0266] The terms used in the embodiments of the present disclosure are only for the purpose of describing particular embodiments and are not used as limitations of the present disclosure.
[0267] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "one", "the", "above", "above", "above", "this", etc., can represent "one and only one", and can also represent "one or more", "at least one", etc. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.
[0268] In the embodiments of the present disclosure, "plurality" refers to two or more.
[0269] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.
[0270] In some embodiments, the writing methods such as "at least one of A, B", "A and / or B", "A in one case, B in another case", "in response to a case A, in response to another case B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selected to be executed (A and B are selectively executed); in some embodiments, A and B (A and B are executed). When there are more branches such as A, B, C, etc., it is similar to the above.
[0271] In some embodiments, the writing methods such as "A or B" and the like can include the following technical solutions according to the case: in some embodiments A (A is executed regardless of B); in some embodiments B (B is executed regardless of A); in some embodiments, A and B are selected to be executed (A and B are selectively executed). When there are more branches such as A, B, C, etc., it is similar to the above.
[0272] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the contents thereof can be the same or different.
[0273] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0274] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0275] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0276] In some embodiments, the apparatuses and devices can be interpreted as entities, and also as virtual, whose names are not limited to the names described in the embodiments, and in some cases can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like.
[0277] In some embodiments, "network" can be interpreted as an apparatus contained in the network, for example, an access network device, a core network device, and the like.
[0278] In some embodiments, "access network device (AN device)" can also be referred to as "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", and in some embodiments can also be understood as "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)", and the like.
[0279] In some embodiments, a "terminal" or "terminal device" can be referred to as a "user equipment" (UE), a "user terminal," a "mobile station" (MS), a "mobile terminal" (MT), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, and the like.
[0280] In some embodiments, data, information, and the like can be acquired in compliance with laws and regulations of a country where a location is situated.
[0281] In some embodiments, data, information, and the like can be acquired after consent of a user is obtained.
[0282] In some embodiments, information, messages, and requests, and the like are not limited to names described in embodiments, that is, embodiments of the present disclosure are not limited to information names, message names, and request names.
[0283] In addition, each element, each row, or each column in a table of an embodiment of the present disclosure can be implemented as an independent embodiment, and a combination of any element, any row, or any column can be implemented as an independent embodiment.
[0284] FIG. 1A is one exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0285] As shown in FIG. 1A, the communication system 100 includes a terminal 101, a second access network device 102, a core network device 103, and a first node 104.
[0286] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet (Pad), a wireless-transmitting computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, or the like, but is not limited thereto.
[0287] In some embodiments, the second access network device 102 functions as a service consumer for a "consumption service", and the name is not limited thereto.
[0288] In some embodiments, the second access network device 102 is, for example, a node or device that accesses the terminal 101 to a wireless network, and the second access network device 102 can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in another communication system, an access node in a Wi-Fi system, or the like, but is not limited thereto.
[0289] In some embodiments, the technical solutions of the present disclosure can be applicable to an Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.
[0290] In some embodiments, the second access network device 102 can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers are controlled by the CU, and the rest or all of the protocol layers are distributed in the DU and controlled by the CU. However, the present disclosure is not limited thereto.
[0291] In some embodiments, the core network device 103 can be one device including the second node 1031, the third node 1032, etc., or can be multiple devices or device groups including all or part of the second node 1031, the third node 1032, etc. The network element can be virtual or physical. The core network includes at least one of an evolved packet core (EPC), a 5G core network (5GCN), and a next-generation core (NGC), for example.
[0292] In some embodiments, the second node 1031 is a network function (NF), for example. Alternatively, the second node 1031 is denoted as “NF1”, for example.
[0293] In some embodiments, the second node 1031 is an application (application) or an application function (AF), for example. Alternatively, the application or the AF can implement each step or part of the step with the second node as the execution subject.
[0294] In some embodiments, the second node 1031 is used for “consuming services” as a service consumer, and the name is not limited thereto.
[0295] In some embodiments, the third node 1032 is a network repository function (NRF), for example. Alternatively, the third node 1032 is denoted as “NF2”, for example.
[0296] In some embodiments, the third node 1032 is configured to "store information", without limitation of the name.
[0297] In some embodiments, the first node 104 is, for example, a Common API Framework (CAPIF) Core Functionality (CF), that is, a CCF.
[0298] In some embodiments, the first node 104 is configured to "authentication and / or authorization", without limitation of the name.
[0299] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be understood by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.
[0300] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subject, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, and the communication system 100 can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of each subject is arbitrary, each subject can be real or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0301] FIG. 1B is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0302] As shown in FIG. 1B, the communication system 200 includes a terminal 201, a first access network device 202, a core network device 203, and a first node 204.
[0303] In some embodiments, the terminal 201 is the same as or similar to the terminal 101, and details are not repeated here.
[0304] In some embodiments, the first node 204 is the same as or similar to the first node 104, and details are not repeated here.
[0305] In some embodiments, the first access network device 202 is the same as or similar to the second access network device 102, and details are not repeated here. Optionally, the first access network device 202 has the same or similar capability as the second node 1031 in the core network device 103, and details are not repeated here.
[0306] In some embodiments, the core network device 203 can be one device including the third node 2031, or a plurality of devices or device groups including all or part of the third node 2031, and the like. The network function can be virtual or physical. The core network includes at least one of an evolved packet core, a 5G core network, a next generation core, and the like.
[0307] In some embodiments, the core network device 203 is the same as or similar to the core network device 103, and details are not repeated here.
[0308] In some embodiments, the third node 2031 in the core network device 203 is the same as or similar to the third node 1032 in the core network device 103, and details are not repeated here.
[0309] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. Those skilled in the art can know that the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems as the system architecture evolves and new business scenarios appear.
[0310] The following embodiments of the present disclosure can be applied to the communication system 200 shown in FIG. 1B or part of the subject, but are not limited thereto. The subjects shown in FIG. 1B are exemplary, and the communication system 200 can include all or part of the subjects in FIG. 1B, or other subjects other than those in FIG. 1B. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, and the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0311] FIG. 1C is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0312] As shown in FIG. 1C, the communication system 300 includes a terminal 301, a core network device 302, and a first node 303.
[0313] In some embodiments, the terminal 301 is the same as or similar to the terminal 101 and the terminal 201, and details are not repeated here.
[0314] In some embodiments, the first node 303 is the same as or similar to the first node 104 and the first node 204, and details are not repeated here.
[0315] In some embodiments, the core network device 302 can be one device including the second node 3021, the third node 3022, and the like, or can be multiple devices or device groups including all or part of the second node 3021, the third node 3022, and the like, respectively. The network function can be virtual or physical. The core network includes at least one of an evolved packet core, a 5G core network, a next generation core, and the like.
[0316] In some embodiments, the second node 3021 in the core network device 302 is the same as or similar to the second node 1031 in the core network device 103, which is not repeated here.
[0317] In some embodiments, the core network device 302 is the same as or similar to the core network device 103, which is not repeated here.
[0318] In some embodiments, the third node 3022 in the core network device 302 is the same as or similar to the third node 1032 in the core network device 103, the third node 2031 in the core network device 203, which is not repeated here.
[0319] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the present disclosure. Those skilled in the art can know that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed in the present disclosure are also applicable to similar technical problems.
[0320] The following embodiments of the present disclosure can be applied to the communication system 300 shown in FIG. 1C or part of the subject, but are not limited thereto. The subjects shown in FIG. 1C are exemplary, and the communication system 300 can include all or part of the subjects in FIG. 1C, or include other subjects other than those in FIG. 1C. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, and the connection can be in any manner, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0321] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0322] According to embodiments of this disclosure, in future communication systems, network entities may obtain authorization from the relevant user in accordance with regulatory requirements and local policies before processing, operating, or using information related to a specific user.
[0323] Optionally, in order to enable the network function to obtain the authorization from the user in time, one possible method is to reuse the token-based authorization mechanism deployed in the communication system.
[0324] Optionally, for the OAuth2.0-based network function authorization mechanism, the scope part of the token contains the intended service (for example, the User Equipment Configuration Management (Nudm_UECM) service).
[0325] Optionally, the additional scope part of the token contains the intended resource and service operation (for example, the Nudm_UECM_Registration service operation).
[0326] The above-mentioned scope of the token and the additional scope of the token can be the key factor to express the user authorization.
[0327] Optionally, in order to enable the user / User Equipment (UE) to provide the authorization policy to the network function (NF) / base station in time, the communication system provides a mechanism.
[0328] Optionally, the mechanism can authorize the network function (NF) / access network device (for example, a base station) to process the user information in time based on the authorization policy related to the UE / user through the interaction with the UE / user.
[0329] Optionally, for the authorization mechanism based on the Common API Framework (CAPIF), that is, the Common API Framework, the CAPIF Core Functionality (that is, CCF) uses the authorization information related to the user and the authorization information related to the Network Exposure Function (NEF) (for example, whether the API of a certain NEF can be called by a specific application function or user equipment) to issue a token.
[0330] The embodiments of the present disclosure can be applied to any communication scenario, such as 4G, 5G, 6G, future communication systems, vehicle-to-everything, and improved versions thereof, without specific limitation here.
[0331] FIG. 2A is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2A, the present disclosure relates to an authorization method, and the method includes:
[0332] In step S2101, the second node 3021 or the first access network device 202 sends a first request to the first node 104.
[0333] In some embodiments, the first node 104 receives the first request.
[0334] In some embodiments, the first node 104 is for "authentication, authorization, logging, charging, etc."
[0335] In some embodiments, the name of the first node 104 is not limited, which is, for example, "CAPIF Core Function", "CCF", "a node for authentication and / or authorization", etc.
[0336] In some embodiments, the first request is for "requesting the first information".
[0337] In some embodiments, the name of the information, etc. is not limited to the name described in the embodiments, and the terms of "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "code point", "bit", "data", "program", "chip", etc. can be replaced with each other.
[0338] In some embodiments, the terms of "codebook", "codeword", "precoding matrix", etc. can be replaced with each other. For example, the codebook can be a collection of one or more codewords / precoding matrices.
[0339] In some embodiments, the name of the first request is not limited, which is, for example, "token request", "request for authentication and / or authorization", "Token request", etc.
[0340] In some embodiments, the first request includes at least one of user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing a data type, an NF type of the fourth node, or an NF instance ID of the fourth node.
[0341] In the above embodiments, based on one or more of the user information contained in the first request, the service or service operation, the data type, the data processing purpose, the purpose of processing the data type, the NF type of the fourth node, or the NF instance ID of the fourth node, etc., it can be checked whether the requested service matches the obtained first authorization information and second authorization information or is within the authorized range, and then it is determined whether to authorize the second node 3021 or the first access network device 202.
[0342] In some embodiments, the user information includes identification information of the terminal 101 (UE) or identification information of the user. Optionally, the identification information of the UE or the identification information of the user is the same. Optionally, the identification information of the UE or the identification information of the user has an association relationship.
[0343] In some embodiments, the identification information of the UE is used for “identifying the UE”.
[0344] In some embodiments, the identification information of the user is used for “identifying the user”.
[0345] In some embodiments, the identification information of the UE can be a generic public subscription permanent identifier (GPSI) or a subscription permanent identifier (SUPI).
[0346] In some embodiments, the identification information of the user can be a GPSI or a SUPI.
[0347] In some embodiments, the name of the identification information is not limited, which is, for example, “unique identification code, number, or identity”, “identifier for identifying identity”, etc.
[0348] In some embodiments, the fourth node 1033 is, for example, a network function (NF). Optionally, the fourth node 1033 is represented by, for example, “NF3”.
[0349] In some embodiments, the fourth node 1033 is used for “providing services”, and as a network function service provider, the name is not limited thereto.
[0350] In some embodiments, the first information includes at least one of the data type, the data processing purpose, the purpose of processing the data type, and the NF instance ID of the first node.
[0351] In some embodiments, the first information includes at least one of the data type, the data processing purpose, the purpose of processing the data type, and the ID of the first node.
[0352] In some embodiments, the ID of the first node can be an NF instance ID or an application layer ID or an instance ID.
[0353] In the above embodiments, based on the acquired data type, data processing purpose, and purpose of processing data type, the data type, data processing purpose, and purpose of processing data type authorized for the second node 3021 or the first access network device 202 can be determined, and then the corresponding network function service provider is requested for service according to the authorized content, so that based on the authorization provided by the UE or the user and the authorization corresponding to the network function profile, the second node 3021 or the first access network device 202 can timely acquire the authorization to request the corresponding service when requesting the service from the network function service provider.
[0354] In some embodiments, the first information further indicates the NF instance ID of the first node 104, and the NF instance ID corresponds to an issuer (or iss) claim.
[0355] In some embodiments, the name of the first information is not limited, and for example, is “token”, “information for identity verification and / or authorization”, “token”, etc.
[0356] In some embodiments, the first information includes at least one of the NF instance ID of the NF service consumer, the expected service name, the optional “additional scope” information, and the expire time.
[0357] In some embodiments, the token includes at least one of the NF instance ID of the NF service consumer, the expected service name, the optional “additional scope” information, and the expire time.
[0358] In some embodiments, the NF instance ID of the NF service consumer corresponds to a subject claim of the token.
[0359] In some embodiments, the expected service name corresponds to a scope of the token.
[0360] In some embodiments, the optional “additional scope” information includes a service or a service operation allowed to be exerted on a resource, and the service or the service operation allowed to be exerted on the resource corresponds to an additional scope claim of the token.
[0361] In some embodiments, the expire time corresponds to an expire time (exp) claim of the token.
[0362] In some embodiments, the first access network device 202 supports a service architecture with the same or similar capabilities as the second node 3022.
[0363] In some embodiments, the name of the first access network device 202 is not limited, for example, it is a “base station”.
[0364] In some embodiments, the terms “radio”, “wireless”, “radio access network (RAN)”, “access network (AN)”, “RAN-based”, and the like can be replaced with each other.
[0365] In some embodiments, the terms “wireless access scheme”, “waveform”, and the like can be replaced with each other.
[0366] In some embodiments, the second node 3021 (for example, represented by NF1) or the first access network device 202 sends a token request to the first node 104, and the token request is used to request the first information.
[0367] Optionally, based on the regulatory rules and local policies, if the requested service or service operation requires authorization of the UE or user, the second node 3021 or the first access network device 202 sends the token request to the CCF (the first node 104).
[0368] Optionally, the token request includes at least one of user information, services of the fourth node (which can be represented by NF3), or service operations of the fourth node. Optionally, the token request includes data type, data processing purpose, purpose of processing data type, identifier of UE / user, NF type of network function service provider (the fourth node, for example, represented by NF3), or NF instance ID, and service / service operation of NF3. Optionally, the first information includes a token. Optionally, the token includes at least one of data type, data processing purpose, purpose of processing data type, and parameter. Optionally, the token includes the NF instance ID of the first node 104. Optionally, the token includes the NF instance ID of the NF service consumer (subject), the expected service name (scope), optional “additional scope” information (allowed resources and allowed operations (service operations) on resources), and expiration time (validity period).
[0369] In some embodiments, if the NF type of the fourth node is included in the first request, the audience declaration is the NF type of the requested fourth node; if the NF instance ID of the fourth node is included in the first request, the audience declaration is the NF instance ID of the requested fourth node.
[0370] Optionally, for the audience declaration, if the NF type of the NF network function service provider (e.g., NF3) is contained in the token request, the audience declaration is the NF type of the requested NF network function service provider; if the NF instance ID of the NF network function service provider (e.g., NF3) is contained in the token request, the audience declaration is the NF instance ID of the requested NF network function service provider.
[0371] At step S2102, the first node 104 determines that the first request is allowed.
[0372] In some embodiments, the first node 104 determines, according to the first authorization information, that the data type in the first request and the purpose of processing the data type are allowed, or determines that the data processing purpose in the first request is allowed.
[0373] In some embodiments, the first authorization information includes authorization information provided by a terminal (UE) or a user.
[0374] In some embodiments, the first authorization information is used to indicate authorization information provided by a terminal (UE) or a user.
[0375] In some embodiments, the name of the first authorization information is not limited, which is, for example, “user-related authorization information”, “information used to indicate authorization related to a UE or a user”, etc.
[0376] In some embodiments, the user is a subscriber or a user of the terminal (i.e., a user who is using the terminal).
[0377] In some embodiments, the first authorization information includes at least one of user information, a data type, a data processing purpose, and a purpose of processing a data type.
[0378] In some embodiments, the first authorization information includes at least one of user information, an allowed data type, an allowed data processing purpose, and an allowed purpose of processing a data type.
[0379] In some embodiments, the user information includes identification information of a UE or identification information of a user. Optionally, the identification information of the UE or the identification information of the user is the same. Optionally, the identification information of the UE or the identification information of the user has an association relationship.
[0380] In some embodiments, the user information includes GPSI or SUPI.
[0381] In some embodiments, the identification information of the UE is used to “identify the UE”.
[0382] In some embodiments, the identification information of the user is used to "identify the user".
[0383] In some embodiments, the identification information of the UE can be a GPSI or a SUPI.
[0384] In some embodiments, the identification information of the user can be a GPSI or a SUPI.
[0385] In some embodiments, the user information includes at least one of basic information of the UE or the user, or an identifier of the UE or the user.
[0386] In the above embodiments, the first authorization information indicates the user information, the data type, the data processing purpose, and the purpose of processing the data type, and the authorization information related to the user can be determined, thereby providing a basis for subsequent authorization of the second node 3021 or the first access network device 202.
[0387] In some embodiments, the terminal sends the first authorization information to the first node 104. Optionally, the first node 104 receives the first authorization information.
[0388] In some embodiments, the first authorization information is configured by the user to the first node or the third node, or is configured by the terminal to the first node or the third node. Optionally, the first authorization information is pre-configured by the user to the first node or the third node.
[0389] In the above embodiments, the authorization information provided by the UE or the user can be obtained in a timely manner through user configuration or UE configuration, thereby providing a basis for subsequent authorization of the second node 3021 or the first access network device 202.
[0390] In some embodiments, the first node 104 checks whether the data type can be processed through the purpose in the token request according to the user information, the data type, the data processing purpose, and the purpose of processing the data type.
[0391] In some embodiments, the first node 104 determines that the first request is not allowed (or the first node 104 determines that the first request is not allowed).
[0392] In some embodiments, the first node 104 determines that the data type, the data processing purpose, and the purpose of processing the data type in the first request are not allowed according to the first authorization information, or determines that the data type, the data processing purpose, and the purpose of processing the data type in the first request are not allowed.
[0393] In some embodiments, the first node 104 determines that the first request is not allowed, and the first node 104 sends seventh information to the second node 3021 or the first access network device 202.
[0394] In some embodiments, the seventh information is used to "indicate that the data type in the first request and the purpose of processing the data type are not allowed" or "indicate that the purpose of data processing in the first request is not allowed".
[0395] In some embodiments, the name of the seventh information is not limited, which is, for example, "failure information", "failure message", "indication information used to indicate that the first request is not allowed", and the like.
[0396] In some embodiments, the terms "certain", "preseted", "preset", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced with each other, and "certain A", "preset A", "preset A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A predefined in a protocol or the like, can be interpreted as A obtained by setting, configuring, or indicating, and can be interpreted as certain A, certain A, arbitrary A, or first A, but are not limited thereto.
[0397] In some embodiments, the determination or judgment can be performed by a value (0 or 1) represented by 1 bit, can be performed by a true or false value (Boolean value) represented by true or false, or can be performed by comparison of numerical values (for example, comparison with a predetermined value), but is not limited thereto.
[0398] Step S2103, the first node 104 sends a second request to the third node 1032.
[0399] In some embodiments, the third node 1032 (for example, represented by NF2) receives the second request.
[0400] In some embodiments, the second request is used to "trigger the third node to send second authorization information to the first node".
[0401] In some embodiments, the second request is used to "request service authorization information delivery".
[0402] In some embodiments, the name of the second request is not limited, which is, for example, "service authorization information delivery request", "request used to represent service authorization information delivery", and the like.
[0403] In some embodiments, the second request includes at least one of an NF type of the second node 3021 or an NF type of the first access network device 202, an NF type of the fourth node or an NF instance ID of the fourth node, a service or a service operation.
[0404] In some embodiments, the second request is used for the third node to determine the corresponding network function profile according to the NF type of the fourth node or the NF instance ID of the fourth node provided by the first node. Optionally, the NF type of the NF1 or the first access network device 202 can access the NF3 (identified by the NF type or identified by the NF instance ID), and can request or access the service or service operation.
[0405] In the above embodiments, based on one or more of the NF type of the second node 3021 or the first access network device 202, the NF type of the fourth node or the NF instance ID of the fourth node, the service or service operation, etc. contained in the second request, the third node is triggered to provide the authorization information corresponding to the network function profile to the first node, thereby providing the relevant basis for subsequent authorization of the second node 3021 or the first access network device 202.
[0406] In some embodiments, the service in the second request is the service of the fourth node.
[0407] In some embodiments, the service operation in the second request is the service operation of the fourth node.
[0408] In some embodiments, the first node 104 sends the second request to the third node if it determines any of the following according to the first authorization information: the data type and the purpose of processing the data type in the first request are allowed; the data processing purpose in the first request is allowed.
[0409] In the above embodiments, before receiving the second authorization information sent by the third node, it can be determined whether the data type in the first request is allowed and whether the purpose of processing the data type is allowed based on the first authorization information, and it can be determined whether the data processing purpose in the first request is allowed. If allowed, the second request can be sent to the third node, thereby triggering the third node to send the second authorization information to the first node, so that the relevant basis is provided for subsequent authorization of the second node 3021 or the first access network device 202 based on the second authorization information.
[0410] In some embodiments, if the first node 104 determines that the data type, the purpose of processing the data type, or the data processing purpose is allowed according to the authorization information of the UE / user, the first node 104 sends a service authorization information delivery request to the third node 1032, and the service authorization information delivery request is used to trigger the third node 1032 to provide the authorization information corresponding to the network function profile to the first node 104.
[0411] Optionally, the service authorization information delivery request comprises at least one of the following: the NF type of the NF1 or the NF type of the first access network device, the NF type of the network function service provider (e.g., the NF3) or the NF instance ID of the NF3, and the service / service operation of the NF3.
[0412] Optionally, the name of the service authorization information delivery request is not limited, which is, for example, “authorization delivery request”, “service authorization information delivery request”, etc.
[0413] In step S2104, the third node 1032 obtains the second authorization information.
[0414] In some embodiments, the second authorization information is from a network function profile (NF profile).
[0415] In some embodiments, the second authorization information is used to “indicate the authorization information corresponding to the network function profile (NF profile)”.
[0416] In some embodiments, the name of the second authorization information is not limited, which is, for example, “service-related authorization information”, “used to indicate authorized services or service operations”, etc.
[0417] In some embodiments, the second authorization information is used to indicate the services or service operations of the network function service provider that the second node or the first access network device is allowed to access.
[0418] In some embodiments, the second authorization information is used to indicate the authorization information of the fourth node.
[0419] In the above embodiments, the second authorization information indicates the authorization information related to the fourth node, the authorization information corresponding to the network function profile can be determined, and then the relevant basis for subsequent authorization of the second node 3021 or the first access network device 202 is provided.
[0420] In some embodiments, the authorization information of the fourth node comprises at least one of the following: the NF type of the second node or the NF type of the first access network device, the NF type of the fourth node or the NF instance ID of the fourth node, and the service of the fourth node or the service operation of the fourth node.
[0421] In the above embodiments, the authorization information of the fourth node indicates the NF type of the fourth node or the NF instance ID of the fourth node, the service of the fourth node or the service operation of the fourth node, the service-related authorization information can be determined, and then the relevant basis for subsequent authorization of the second node 3021 or the first access network device 202 is provided.
[0422] In some embodiments, the third node 1032 obtains, according to the NF type of the fourth node in the second request, the network function profile of the fourth node, or obtains, according to the NF instance ID of the fourth node in the third request, the network function profile of the fourth node, and determines the second authorization information according to the network function profile of the fourth node.
[0423] In some embodiments, NF2 locates the NF profile of NF3 through the NF type or the NF instance ID of NF3. Optionally, NRF (for example, NF2) finds the corresponding NF profile (that is, the NF profile) according to the NF type (that is, the NF type) or the NF instance ID (that is, the NF instance ID) of NF3 provided by CCF. Optionally, the corresponding NF profile is the network function profile of NF3.
[0424] In the above embodiments, based on the network function profile of the fourth node, the second authorization information can be determined, and the basis for subsequent authorization of the second node 3021 or the first access network device 202 is provided by providing the second authorization information to the first node.
[0425] In some embodiments, NF2 obtains the authorization information (for example, service-related information, including the authorization information of the fourth node) of NF3 according to the NF profile of NF3.
[0426] In some embodiments, the second request is used for the third node to determine the corresponding network function profile according to the NF type of the fourth node or the NF instance ID of the fourth node provided by the first node.
[0427] In the above embodiments, after the third node obtains the second request, the corresponding network function profile can be determined according to the NF type of the fourth node or the NF instance ID of the fourth node, thereby providing the relevant basis for subsequent transmission of the second authorization information to the first node.
[0428] In some embodiments, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive” can be replaced with each other, which can be interpreted as receiving from other subjects, obtaining from protocols, obtaining from high layers, obtaining by self-processing, independently implementing, and various meanings.
[0429] In some embodiments, the terms “send”, “transmit”, “report”, “issue”, “transfer”, “bidirectional transfer”, “send and / or receive”, and the like can be replaced by each other.
[0430] Step S2105, the third node 1032 sends the second authorization information to the first node 104.
[0431] In some embodiments, the first node 104 receives the second authorization information.
[0432] In the above embodiments, the manner in which the first node 104 obtains the second authorization information can be that the third node sends the authorization information corresponding to the obtained network function configuration file, so as to provide a basis for subsequent authorization of the second node 3021 or the first access network device 202.
[0433] In some embodiments, the third node 1032 sends the second authorization information to the first node 104 according to the NF configuration file of the fourth node.
[0434] In some embodiments, the third node 1032 sends a service authorization delivery response to the first node 104.
[0435] In some embodiments, the first node 104 receives the service authorization delivery response.
[0436] In some embodiments, the second authorization information is included in the service authorization delivery response. In some embodiments, NF2 sends authorization information (e.g., service-related information, including authorization information related to the fourth node) related to NF3 to CCF according to the NF configuration file of NF3.
[0437] Optionally, NF2 sends service-related authorization information to CCF. These information indicates the NF type of NF1, the NF type of NF3 or the NF instance ID of NF3, and the service (e.g., NF service) of NF3.
[0438] Optionally, NF2 sends service-related authorization information to CCF. These information indicates the NF type of NF1, the NF type of NF3 or the NF instance ID of NF3, and the service (e.g., NF service) of NF3.
[0439] Step S2106, the first node 104 determines authorization of the second node 3021 or the first access network device 202.
[0440] In some embodiments, the first node 104 determines authorization of the second node 3021 or the first access network device 202 according to the first authorization information and the second authorization information.
[0441] In some embodiments, the first node 104 determines to authorize the second node 3021 or the first access network device 202 according to the first authorization information and the second authorization information if the first condition is met.
[0442] In some embodiments, the first request comprises a seventh request and an eighth request, the seventh request is used to request UE or user authorization, and the eighth request is used to request network function authorization.
[0443] In some embodiments, the name of the seventh request is not limited, which is, for example, “UE or user authorization related request” and the like.
[0444] In some embodiments, the name of the eighth request is not limited, which is, for example, “network function authorization related request” and the like.
[0445] In some embodiments, the first condition comprises that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information. Optionally, if the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information, it is determined to authorize the second node 3021 or the first access network device 202. Optionally, if it is determined that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information, it is determined to authorize the second node 3021 or the first access network device 202.
[0446] In some embodiments, the first condition comprises that the data type in the first request and the purpose of processing the data type are allowed, and the second node 3021 or the first access network device 202 is allowed to request the service of the fourth node or the service operation of the fourth node. Optionally, if the data type in the first request and the purpose of processing the data type are allowed, and the second node 3021 or the first access network device 202 is allowed to request the service of the fourth node or the service operation of the fourth node, it is determined to authorize the second node 3021 or the first access network device 202.
[0447] In some embodiments, the CCF checks whether the NF type of the received NF3 or the NF instance ID of the NF3 and the service / service operation match the service-related authorization information received in step S2105.
[0448] In some embodiments, the CCF sends a token to the NF1 (or the first access network device) when both of the following conditions are met: according to the UE / user authorization information, the data type and its corresponding use are allowed; the NF1 (or the first access network device) is authorized to request the service / service operation of the NF3.
[0449] In some embodiments, according to the first authorization information and the second authorization information, if the first condition is not met, the authorization procedure to the second node or the first access network device is terminated or the third information is sent to the second node or the first access network device.
[0450] In some embodiments, the second node 3021 or the first access network device 202 receives the third information.
[0451] In some embodiments, the third information is used to indicate at least one of the following: the second node or the first access network device is not authorized, the authorization of the second node or the first access network device fails, and the reason for the authorization failure of the second node or the first access network device.
[0452] In some embodiments, the name of the third information is not limited, which is, for example, “failure message”, “failure information”, “information used to indicate that the second node 3021 or the first access network device 202 is not authorized”, “information indicating that the authorization of the second node 3021 or the first access network device 202 fails”, and the like.
[0453] In some embodiments, the failure message can indicate that the UE / user is not allowed to process the data type for such purpose, or the NF1 (or the first access network device) is not allowed to request the service / service operation of the NF3.
[0454] In some embodiments, the first condition is not met if the seventh request is not allowed and / or the eighth request is not allowed. Alternatively, if the seventh request is not allowed and / or the eighth request is not allowed, the authorization procedure to the second node or the first access network device is terminated or the third information is sent to the second node or the first access network device.
[0455] In some embodiments, the first condition is not met if the seventh request is not allowed by the first authorization information and / or the eighth request is not allowed by the second authorization information. Alternatively, if the seventh request is not allowed and / or the eighth request is not allowed, the authorization procedure to the second node or the first access network device is terminated or the third information is sent to the second node or the first access network device.
[0456] In the above embodiments, if the seventh request and / or the eighth request in the first request is not allowed, indicating that the authorization of the second node or the first access network device fails or the second node or the first access network device is not authorized, the authorization procedure to the second node or the first access network device can be terminated, or the third information can be sent to the second node or the first access network device in time to feed back any one of the following: not authorized, authorization failure, and the reason for the authorization failure.
[0457] In some embodiments, the first condition is not met when: the data processing purpose in the first request is not allowed and / or the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node, or the data type in the first request and the purpose of processing the data type are not allowed and / or the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node.
[0458] In the above embodiments, if the data type in the first request and the purpose of processing the data type are not allowed, and / or the service of the fourth node or the service operation of the fourth node in the first request is not authorized to be requested, it indicates that the authorization of the second node 3021 or the first access network device 202 fails or the second node 3021 or the first access network device 202 is not authorized, and then the authorization process of the second node 3021 or the first access network device 202 can be terminated, or the third information can be sent to the second node 3021 or the first access network device 202 in time to feed back any one of not being authorized, authorization failure, and the reason for authorization failure.
[0459] In some embodiments, the CCF sends the third information to the NF1 (or the first access network device) when at least one of the following two conditions is not met: according to the authorization information of the UE / user, the data type and its corresponding use are not allowed or the data processing purpose is allowed; the NF1 (or the first access network device) is not authorized to request the service / service operation of the NF3.
[0460] In the above embodiments, if the second node 3021 or the first access network device 202 receives the third information sent by the first node 104, it indicates that the authorization of the second node 3021 or the first access network device 202 fails or the second node 3021 or the first access network device 202 is not authorized or the reason for the authorization failure of the second node 3021 or the first access network device 202, and the second node 3021 or the first access network device 202 can feed back that it is not authorized in time.
[0461] Step S2107, the first node 104 sends the first information to the second node 3021 or the first access network device 202.
[0462] In some embodiments, the second node 3021 or the first access network device 202 receives the first information.
[0463] In some embodiments, the second node 3021 or the first access network device 202 obtains the first information specified by the protocol, and in this case, step S2107 can be omitted.
[0464] In some embodiments, the second node 3021 or the first access network device 202 processes to obtain the first information, in which case step S2107 can be omitted.
[0465] In some embodiments, the second node 3021 or the first access network device 202 autonomously implements the function indicated by the first information, or the function is default or default, in which case step S2107 can be omitted.
[0466] In some embodiments, if it is determined that the authorization, the CCF sends a token response (e.g., Token response) to the NF1 or the first access network device.
[0467] Step S2108, the second node 3021 or the first access network device 202 sends a sixth request to the fourth node 1033.
[0468] In some embodiments, the fourth node 1033 receives the sixth request.
[0469] In some embodiments, the sixth request is used for "requesting a service or service operation" or for "requesting a service or service operation of the fourth node" or for "requesting a service or service operation provided by the fourth node".
[0470] In some embodiments, the name of the sixth request is not limited, which is, for example, "service request", "service request".
[0471] In some embodiments, the name of the service request is not limited, which is, for example, "Service request".
[0472] In some embodiments, the NF1 (or the first access network device) uses the token to request the service of the NF3.
[0473] Step S2109, the fourth node 1033 determines that the sixth request is authorized.
[0474] In some embodiments, the NF3 determines that the token in the sixth request is valid, and at the same time the sixth request meets the authorized scope of the token.
[0475] Step S2110, the fourth node 1033 sends sixth information to the second node 3021 or the first access network device 202.
[0476] In some embodiments, the second node 3021 or the first access network device 202 receives the sixth information.
[0477] In some embodiments, the second node 3021 or the first access network device 202 obtains the sixth information specified by the protocol, in which case step S2110 can be omitted.
[0478] In some embodiments, the second node 3021 or the first access network device 202 processes to obtain the sixth information, and step S2110 can be omitted.
[0479] In some embodiments, the second node 3021 or the first access network device 202 autonomously implements the function indicated by the sixth information, or the function is default or default, and step S2110 can be omitted.
[0480] In some embodiments, the name of the sixth information is not limited, which is, for example, “service response”, “information valid for token pair request”, “response valid for token pair request”, etc.
[0481] In some embodiments, if the token is valid and the content requested by the sixth request conforms to the authorized range agreed by the token, the NF3 sends a service response to the NF1 (or the first access network device).
[0482] In some embodiments, the NF3 sends a service response to the NF1 (or the first access network device).
[0483] The authorization method related to the embodiments of the present disclosure can include at least one of steps S2101-S2110. For example, step S2102 can be implemented as an independent embodiment, step S2104 can be implemented as an independent embodiment, step S2106 can be implemented as an independent embodiment, step S2109 can be implemented as an independent embodiment, steps S2101+S2102 can be implemented as an independent embodiment, steps S2101+S2107 can be implemented as an independent embodiment, steps S2103+S2104+S2105 can be implemented as an independent embodiment, steps S2101+S2102+S2103+S2104+S2105+S2106+S2107 can be implemented as an independent embodiment, steps S2108+S2109+S2110 can be implemented as an independent embodiment, but not limited thereto.
[0484] In some embodiments, steps S2101 and S2107 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0485] In some embodiments, steps S2103, S2104, and S2105 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0486] In some embodiments, the embodiments do not limit the form of the messages involved. Alternatively, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, the communication device A requests the communication device B, and the communication device B sends the corresponding response message to the communication device A, or the communication device A subscribes to the communication device B, and the communication device B sends the corresponding notification message to the communication device A. In both ways, the communication device A can obtain the message from the communication device B.
[0487] In some embodiments, the steps of the embodiment of FIG. 2A can be implemented independently, or can be combined and implemented in any order without contradiction.
[0488] In some embodiments, reference can be made to other optional implementations described before or after the description of the embodiment of FIG. 2A.
[0489] FIG. 2B is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2B, the embodiment of the present disclosure relates to an authorization method, and the method includes:
[0490] In step S2201, the second node 3021 or the first access network device 202 sends a third request to the third node 1032.
[0491] In some embodiments, the third node 1032 receives the third request.
[0492] In some embodiments, the third request is used to “trigger the third node to send the second authorization information to the first node”.
[0493] In some embodiments, the third request is used for the third node to determine the corresponding network function configuration file according to the NF type of the fourth node or the NF instance ID of the fourth node provided by the first node.
[0494] In some embodiments, the name of the third request is not limited, which is, for example, “service authorization information delivery request”, “request for indicating service authorization information delivery”, etc.
[0495] In the above embodiment, by sending the third request to the third node, the third node is triggered to send the second authorization information to the first node, so that the second authorization information is used as the basis for subsequent authorization of the second node 3021 or the first access network device 202.
[0496] In some embodiments, if the requested service or service operation requires authorization of the UE or user, the second node (e.g., NF1) or the first access network device delivers a service authorization information transfer request to the third node (e.g., NF2, such as NRF) according to the regulatory rules and local policies. This request is used to trigger the third node to provide the authorization information of the service / service operation provided by the fourth node (NF3) to the first node (e.g., CCF).
[0497] Optionally, since the NF profile of NF3 stored in NF2 includes the allowed NF types of NF service consumers that can request its service / service operation, the service authorization information transfer request includes at least one of the NF type of NF1, the NF type of the first access network device, the NF type of NF3, the NF instance ID of NF3, and the NF service / service operation of NF3.
[0498] At step S2202, the third node 1032 obtains the second authorization information.
[0499] In some embodiments, the third node obtains the second authorization information according to the configuration file of the fourth node.
[0500] In some embodiments, the second authorization information indicates whether the second node 3021 or the first access network device 202 is authorized to request the service or service operation of the fourth node.
[0501] In some embodiments, the second authorization information indicates the network function types allowed to access the service or service operation of the fourth node.
[0502] In some embodiments, the third node stores the NF profile of the fourth node.
[0503] In some embodiments, the third node obtains the second authorization information according to the stored NF profile of the fourth node, and determines whether the second node 3021 or the first access network device 202 is authorized to request the service or service operation of the fourth node.
[0504] In some embodiments, if the third node is authorized to request the service / service operation of the fourth node, the third node obtains the second authorization information according to the stored configuration file, and determines whether the second node 3021 or the first access network device 202 is authorized to request the service or service operation of the fourth node.
[0505] At step S2203, the third node 1032 sends the second authorization information to the first node 104.
[0506] In some embodiments, the second authorization information is transmitted between the third node 1032 and the first node 104.
[0507] In some embodiments, the first node 104 receives the second authorization information.
[0508] In some embodiments, the first node 104 obtains the second authorization information as specified by a protocol, in which case step S2203 can be omitted.
[0509] In some embodiments, the first node 104 processes to obtain the second authorization information, in which case step S2203 can be omitted.
[0510] In some embodiments, the first node 104 autonomously implements the function indicated by the second authorization information, or the above function is default or default, in which case step S2203 can be omitted.
[0511] In some embodiments, if the third node (such as NF2) is not authorized to request the service / service operation of the fourth node (NF3), step S2202 is skipped. Optionally, NF2 sends authorization information related to NF3 to CCF in a manner similar to that defined in FIG. 2A (such as step S2104).
[0512] Step S2204, the third node 1032 sends the fourth information to the second node 3021 or the first access network device 202.
[0513] In some embodiments, the second node 3021 or the first access network device 202 receives the fourth information.
[0514] In some embodiments, the second node 3021 or the first access network device 202 obtains the fourth information as specified by a protocol, in which case step S2204 can be omitted.
[0515] In some embodiments, the second node 3021 or the first access network device 202 processes to obtain the fourth information, in which case step S2204 can be omitted.
[0516] In some embodiments, the second node 3021 or the first access network device 202 autonomously implements the function indicated by the fourth information, or the above function is default or default, in which case step S2204 can be omitted.
[0517] In some embodiments, the fourth information is used to indicate any of the following: the second node 3021 or the first access network device 202 is allowed to request the service of the fourth node or the service operation of the fourth node, the second node 3021 or the first access network device 202 is not allowed to request the service of the fourth node or the service operation of the fourth node.
[0518] In some embodiments, the name of the fourth information is not limited, which is, for example, “authorization information delivery response”, “service authorization information delivery response”, “authorization information delivery response information”, etc.
[0519] In the above embodiments, the fourth information is sent to the second node 3021 or the first access network device 202 to indicate whether the second node 3021 or the first access network device 202 is allowed to request the service or the service operation of the fourth node, thereby providing a basis for subsequent authorization of the second node 3021 or the first access network device 202.
[0520] In the above embodiments, by receiving the fourth information sent by the third node, a relevant basis can be provided for subsequent sending of the first request to the first node.
[0521] In some embodiments, the third node 1032 sends an authorization information delivery response (or service authorization information delivery response) to the second node 3021 or the first access network device 202.
[0522] In some embodiments, the second node 3021 or the first access network device 202 receives the authorization information delivery response.
[0523] In some embodiments, the authorization information delivery response is used to “indicate whether the second node 3021 or the first access network device 202 is authorized to request the service or the service operation of the fourth node”.
[0524] In some embodiments, the fourth information is included in the authorization information delivery response.
[0525] In some embodiments, the NF2 indicates to the NF1 (or the first access network device) that the NF1 (or the first access network device) is not allowed to request the service / service operation of the NF3.
[0526] In some embodiments, the NF2 indicates to the NF1 (or the first access network device) that the NF1 (or the first access network device) is allowed to request the service / service operation of the NF3.
[0527] Step S2205, the second node 3021 or the first access network device 202 sends the first request to the first node 104.
[0528] In some embodiments, the first node 104 receives the first request.
[0529] In some embodiments, the second node 3021 or the first access network device 202 sends the first request to the first node after determining that the second node or the first access network device is authorized by the second authorization information.
[0530] In some embodiments, the second node 3021 or the first access network device 202 sends the first request to the first node after determining that the second node or the first access network device is allowed to request the service or the service operation of the fourth node.
[0531] In the above embodiments, the first request can be sent to the first node, and the first information can be requested from the first node, to determine whether the second node or the first access network device is authorized, if the second node or the first access network device is authorized by the second authorization information.
[0532] In some embodiments, the second node 3021 or the first access network device 202 sends the first request to the first node 104 after receiving the fourth information indicating that the second node 3021 or the first access network device 202 is allowed to request the service or the service operation of the fourth node.
[0533] In the above embodiments, the first request can be sent to the first node, and the first information can be requested from the first node, to determine whether the second node 3021 or the first access network device 202 is authorized, if the second node or the first access network device is allowed to request the service or the service operation of the fourth node, as indicated by the received fourth information.
[0534] In some embodiments, the NF1 (or the first access network device) sends a token request to the CCF to obtain a token for processing specific user data by the service of the NF3, after receiving the fourth information indicating that the second node 3021 or the first access network device 202 is authorized to request the service or the service operation of the fourth node.
[0535] Step S2206, the first node 104 determines the authorization to the second node 3021 or the first access network device 202.
[0536] Step S2207, the first node 104 sends the first information to the second node 3021 or the first access network device 202.
[0537] Step S2208, the second node 3021 or the first access network device 202 sends a sixth request to the fourth node 1033.
[0538] Step S2209, the fourth node 1033 determines that the sixth request is authorized.
[0539] Step S2210, the fourth node 1033 sends the sixth information to the second node 3021 or the first access network device 202.
[0540] In some embodiments, the second node 3021 or the first access network device 202 determines not to send the first request to the first node if the second node or the first access network device is not authorized by the second authorization information, and step S2205 can be omitted.
[0541] In the above embodiment, if the second node or the first access network device is not authorized by the second authorization information, the first request can not be sent to the first node, thereby reducing invalid requests in the network and reducing resource waste.
[0542] In some embodiments, the second node 3021 or the first access network device 202 determines not to send the first request to the first node if it is determined that the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node, in which case step S2205 can be omitted.
[0543] In the above embodiment, if the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node, the first request is not sent to the first node, thereby reducing invalid requests in the network and reducing resource waste.
[0544] In some embodiments, steps S2206 to S2210 are the same as steps S2106 to S2110 (for example, step S2206 is the same as step S2106, step S2207 is the same as step S2107, step S2208 is the same as step S2108, step S2209 is the same as step S2109, step S2210 is the same as step S2110, and so on), which will not be repeated here.
[0545] In some embodiments, the embodiments shown in FIG. 2A and FIG. 2B, network entity authorization is performed through a client credential flow of the first node (for example, CAPIF core function).
[0546] Optionally, assuming that the UE / user has configured authorization information related to data usage to the first node, for example, CAPIF core function (CCF), wherein the preconfigured authorization information (for example, the first authorization information) indicates that the CCF works in a classic client credential flow mode, which is not limited here.
[0547] The authorization method related to the embodiments of the present disclosure can include at least one of steps S2201 to S2210. For example, step S2202 can be implemented as an independent embodiment, step S2206 can be implemented as an independent embodiment, step S2209 can be implemented as an independent embodiment, steps S2201+S2202+S2203+S2204 can be implemented as an independent embodiment, steps S2205+S2206+S2207 can be implemented as an independent embodiment, but not limited thereto, steps S2208+S2209+S2210 can be implemented as an independent embodiment, but not limited thereto.
[0548] In some embodiments, steps S2201, S2202, S2203, and S2204 are optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0549] In some embodiments, the embodiments do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, the communication device A requests the communication device B, and the communication device B sends a corresponding response message to the communication device A, or the communication device A subscribes to the communication device B, and the communication device B sends a corresponding notification message to the communication device A. In both ways, the communication device A can obtain the message from the communication device B.
[0550] In some embodiments, the steps of the embodiment of FIG. 2B can be implemented independently, or can be combined and implemented in any order without contradiction.
[0551] In some embodiments, reference can be made to the other optional implementations described before or after the description of FIG. 2B.
[0552] FIG. 2C is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2C, the embodiment of the present disclosure relates to an authorization method, and the method includes:
[0553] In step S2301, the second node 3021 or the first access network device 202 sends a ninth request to the terminal 101.
[0554] In some embodiments, the terminal 101 receives the ninth request.
[0555] In some embodiments, the ninth request is used to “request information related to authorization”.
[0556] In some embodiments, the name of the ninth request is not limited, and it is, for example, “request related to authorization” and the like.
[0557] In some embodiments, the ninth request includes address information of the first node.
[0558] In some embodiments, the address information of the first node includes at least one of a Fully qualified domain name (FQDN) of the first node and an Internet Protocol (IP) address of the first node.
[0559] In some embodiments, the address information of the first node comprises a Fully qualified domain name (FQDN) of the first node, and the UE needs to obtain the IP address of the first node through a DNS server and the FQDN, and then interacts with the first node based on the IP address of the first node to obtain the authorization-related information.
[0560] In some embodiments, the ninth request comprises a data type, a data processing purpose, and a purpose of processing the data type (e.g., collection, exposure).
[0561] In the above embodiments, by sending the address information of the first node to the UE, the UE can find the first node based on the provided address information, and then can interact with the first node to obtain the authorization-related information, etc.
[0562] Step S2302, the terminal 101 determines whether the data type can be processed under a given purpose.
[0563] In some embodiments, the terminal 101 determines whether the second node 3021 or the first access network device 202 is authorized for the data processing purpose or is authorized for the purpose of processing the data type.
[0564] In the above embodiments, by determining whether the second node 3021 or the first access network device 202 is authorized for the purpose of processing the data type or is authorized for the data processing purpose, the authorization of the second node 3021 or the first access network device 202 is determined.
[0565] Step S2303, the terminal 101 sends second information to the first node 104.
[0566] In some embodiments, the first node receives the second information.
[0567] In some embodiments, the first node 104 obtains the second information specified by the protocol, and step S2303 can be omitted.
[0568] In some embodiments, the first node 104 processes to obtain the second information, and step S2303 can be omitted.
[0569] In some embodiments, the first node 104 autonomously implements the function indicated by the second information, or the above function is default or default, and step S2303 can be omitted.
[0570] In some embodiments, the second information is used to "indicate whether the second node 3021 or the first access network device 202 is authorized for the data processing purpose or is authorized for the purpose of processing the data type".
[0571] In some embodiments, the second information comprises an identity of the second node or an identity of the first access network device.
[0572] In some embodiments, the second information comprises at least one of the following: allowed data processing purpose, allowed data type, allowed data type processing purpose.
[0573] In some embodiments, the name of the second information is not limited, for example, "authorization result", "authorization information delivery response", "authorization information delivery", "authorization result related to the ninth request", "authorization result of the request related to authorization", and the like.
[0574] In the above embodiments, if the indication information that the second node 3021 or the first access network device 202 is authorized for the data processing purpose or the purpose of processing the data type is received, the authorized identity can be provided to the UE, so that the first authorization information can be obtained based on the authorized identity, and further, the authorization of the second node 3021 or the first access network device 202 is provided.
[0575] In some embodiments, the terminal 101 sends the second information to the first node 104 according to the address information of the first node 104.
[0576] In the above embodiments, based on the address information of the first node, the indication information for indicating whether the second node 3021 or the first access network device 202 is authorized for the purpose of processing the data type or is authorized for the data processing purpose is sent to the located first node, and further, the authorization of the second node 3021 or the first access network device 202 is determined.
[0577] In some embodiments, the UE / user sends the authorization result to the CCF through the FQDN / IP address provided by the NF1 (or the first access network device).
[0578] In step S2304, the first node 104 sends the authorized identity to the terminal 101.
[0579] In some embodiments, the terminal 101 receives the authorized identity.
[0580] In some embodiments, the terminal 101 obtains the authorized identity specified by the protocol, and in this case, step S2304 can be omitted.
[0581] In some embodiments, the terminal 101 processes to obtain the authorized identity, and in this case, step S2304 can be omitted.
[0582] In some embodiments, the terminal 101 autonomously implements the function indicated by the authorized identity, or the above function is default or default, and in this case, step S2304 can be omitted.
[0583] In some embodiments, the authorization identifier is used for "identity authorization".
[0584] In some embodiments, the name of the authorization identifier is not limited, which is, for example, "authorization code", "authorization identifier", "identifier for indicating authorization", and the like.
[0585] In some embodiments, the composition or form of the authorization code is not limited, which is, for example, a specific code or string, used for verifying the identity and authority of the user.
[0586] In some embodiments, the first node 104 sends the authorization identifier to the terminal 101 if the second node 3021 or the first access network device 202 is authorized for data processing purposes or is authorized for processing data types.
[0587] In some embodiments, the CCF sends the authorization code to the UE if the NF1 or the first access network device is authorized.
[0588] Step S2305: The terminal 101 sends the authorization identifier to the second node 3021 or the first access network device 202.
[0589] In some embodiments, the second node 3021 or the first access network device 202 receives the authorization identifier.
[0590] In some embodiments, the second node 3021 or the first access network device 202 obtains the authorization identifier specified by the protocol, and in this case, step S2305 can be omitted.
[0591] In some embodiments, the second node 3021 or the first access network device 202 processes to obtain the authorization identifier, and in this case, step S2305 can be omitted.
[0592] In some embodiments, the second node 3021 or the first access network device 202 autonomously implements the function indicated by the authorization identifier, or the above function is default or default, and in this case, step S2305 can be omitted.
[0593] In some embodiments, the UE sends the authorization code to the NF1 (or the first access network device).
[0594] Step S2306: The second node 3021 or the first access network device 202 sends a first request to the first node 104.
[0595] In some embodiments, the first request includes the authorization identifier or the authorization code.
[0596] In some embodiments, the NF1 (or the first access network device) sends a token request to the CCF. The token request includes, in addition to the authorization code, the NF type or NF instance ID of the NF3 and the service / service operation of the NF3.
[0597] Step S2307, the first node 104 determines that the first request is allowed.
[0598] Step S2308, the first node 104 sends a second request to the third node 1032.
[0599] Step S2309, the third node 1032 obtains second authorization information.
[0600] Step S2310, the third node 1032 sends the second authorization information to the first node 104.
[0601] Step S2311, the first node 104 determines that the second node 3021 or the first access network device 202 is authorized.
[0602] Step S2312, the first node 104 sends first information to the second node 3021 or the first access network device 202.
[0603] Step S2313, the second node 3021 or the first access network device 202 sends a sixth request to the fourth node 1033.
[0604] Step S2314, the fourth node 1033 determines that the sixth request is authorized.
[0605] Step S2315, the fourth node 1033 sends sixth information to the second node 3021 or the first access network device 202.
[0606] In some embodiments, steps S2307 to S2315 are the same as steps S2102 to S2110 (for example, step S2307 is the same as step S2106, step S2312 is the same as step S2107, and so on), which will not be repeated here.
[0607] The authorization method related by the embodiments of the present disclosure can include at least one of steps S2301-S2315. For example, step S2302 can be implemented as an independent embodiment, step S2307 can be implemented as an independent embodiment, step S2309 can be implemented as an independent embodiment, step S2311 can be implemented as an independent embodiment, step S2314 can be implemented as an independent embodiment, steps S2301+S2302 can be implemented as an independent embodiment, steps S2301+S2302+S2303+S2304+S2305 can be implemented as an independent embodiment, steps S2306+S2307+S2308+S2309+S2310+S2311+S2312 can be implemented as an independent embodiment, and steps S2313+S2314+S2315 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.
[0608] In some embodiments, steps S2301, S2302, S2303, S2304, and S2305 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0609] In some embodiments, the present embodiments do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[0610] In some embodiments, the steps of the embodiment of FIG. 2C can be implemented independently, or can be combined and implemented in any order without contradiction.
[0611] In some embodiments, reference can be made to other optional implementations described before or after the description corresponding to FIG. 2C.
[0612] FIG. 2D is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2D, the present embodiment relates to an authorization method, and the above method includes:
[0613] In step S2401, the second node 3021 or the first access network device 202 sends a third request to the third node 1032.
[0614] In step S2402, the third node 1032 obtains second authorization information.
[0615] In step S2403, the third node 1032 sends the second authorization information to the first node 104.
[0616] Step S2404: The third node 1032 sends fourth information to the second node 3021 or the first access network device 202.
[0617] In some embodiments, steps S2401 to S2404 are the same as steps S2201 to S2204 (for example, step S2401 is the same as step S2201, step S2402 is the same as step S2202, and so on), which will not be repeated here.
[0618] Step S2405: The second node 3021 or the first access network device 202 sends a ninth request to the terminal 101.
[0619] In some embodiments, the terminal 101 receives the ninth request.
[0620] In some embodiments, the ninth request is used to “request information related to authorization”.
[0621] In some embodiments, the name of the ninth request is not limited, which is, for example, “request related to authorization” and the like.
[0622] In some embodiments, the ninth request includes address information of the first node.
[0623] In some embodiments, the address information of the first node includes at least one of a Fully qualified domain name (FQDN) of the first node, an Internet Protocol (IP) address of the first node.
[0624] In some embodiments, the ninth request includes a data type, a data processing purpose, and a purpose of processing the data type (for example, collection, exposure).
[0625] Step S2406: The terminal 101 determines whether the data type can be processed under a given purpose.
[0626] In some embodiments, the terminal 101 determines whether the second node 3021 or the first access network device 202 is authorized to process the purpose of the data type or is authorized the data processing purpose.
[0627] Step S2407: The terminal 101 sends second information to the first node 104.
[0628] In some embodiments, the first node receives the second information.
[0629] In some embodiments, the second information is used to "indicate whether the second node 3021 or the first access network device 202 is authorized for data processing purposes or for processing data of a certain type".
[0630] In some embodiments, the name of the second information is not limited, which is, for example, "authorization result", "authorization information delivery response", "authorization information delivery", "authorization result related to the ninth request", "authorization result of the request related to authorization", and the like.
[0631] In some embodiments, the UE / user sends the authorization result to the CCF through the FQDN / IP address provided by the NF1 (or the first access network device).
[0632] Step S2408, the first node 104 sends the authorization identifier to the terminal 101.
[0633] In some embodiments, the terminal 101 receives the authorization identifier.
[0634] In some embodiments, the authorization identifier is used to "identify authorization".
[0635] In some embodiments, the name of the authorization identifier is not limited, which is, for example, "authorization code", "authorization identifier", "identifier for indicating authorization", and the like.
[0636] In some embodiments, the composition or form of the authorization code is not limited, which is, for example, a specific code or string, used to verify the identity and authority of the user.
[0637] In some embodiments, if the NF1 (or the first access network device) is authorized, the CCF sends the authorization code to the UE.
[0638] Step S2409, the terminal 101 sends the authorization identifier to the second node 3021 or the first access network device 202.
[0639] In some embodiments, the second node 3021 or the first access network device 202 receives the authorization identifier.
[0640] In some embodiments, the UE sends the authorization code to the NF1 (or the first access network device).
[0641] In some embodiments, steps S2405 to S2409 are the same as steps S2301 to S2305 (for example, step S2405 is the same as step S2301, step S2406 is the same as step S2302, and so on), which will not be repeated here.
[0642] Step S2410, the second node 3021 or the first access network device 202 sends the first request to the first node.
[0643] In some embodiments, the first request comprises an authorization identity or an authorization code.
[0644] In some embodiments, the NF1 (or the first access network device) sends a token request to the CCF. The token request comprises, in addition to the authorization code, the NF type or NF instance ID of the NF3 and the service / service operation of the NF3.
[0645] In some embodiments, the first node obtains the first authorization information.
[0646] In some embodiments, the CCF locates the authorization information of the UE / user by the authorization code.
[0647] Optionally, the CCF locates the authorization information of the UE / user by the authorization code to check whether the data type can be processed by the requested purpose. Then, the CCF also checks whether the NF type or NF instance ID of the NF3 and the service / service operation received match the service-related authorization information received in step S2303.
[0648] Step S2411, the first node 104 determines authorization to the second node 3021 or the first access network device 202.
[0649] Step S2412, the first node 104 sends the first information to the second node 3021 or the first access network device 202.
[0650] Step S2413, the second node 3021 or the first access network device 202 sends a sixth request to the fourth node 1033.
[0651] Step S2414, the fourth node 1033 determines that the sixth request is authorized.
[0652] Step S2415, the fourth node 1033 sends the sixth information to the second node 3021 or the first access network device 202.
[0653] In some embodiments, steps S2410 to S2415 are the same as steps S2205 to S2210 (such as step S2410 is the same as step S2205, step S2411 is the same as step S2206, and so on), which will not be repeated here.
[0654] In some embodiments, the embodiments shown in FIG. 2C, FIG. 2D, the network entity authorization is performed by the authorization code flow of the first node (for example, the CAPIF core function).
[0655] In some embodiments, FIGS. 2A-2D can enable the first node (e.g., CAPIF or CCF) to authorize the first access network device, i.e., the access network device supporting the service-based architecture, where the first access network device can be regarded as a second node (e.g., NF1).
[0656] The authorization method related to the embodiments of the present disclosure can include at least one of steps S2401-S2415. For example, step S2402 can be implemented as an independent embodiment, step S2406 can be implemented as an independent embodiment, step S2411 can be implemented as an independent embodiment, step S2414 can be implemented as an independent embodiment, steps S2401+S2402+S2403+S2404 can be implemented as an independent embodiment, steps S2405+S2406+S2407+S2408+S2409 can be implemented as an independent embodiment, steps S2410+S2411+S2412 can be implemented as an independent embodiment, steps S2413+S2414+S2415 can be implemented as an independent embodiment, but are not limited thereto.
[0657] In some embodiments, steps S2401, S2402, S2403, S2404 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0658] In some embodiments, steps S2405, S2406, S2407, S2408, S2409 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0659] In some embodiments, the embodiments of the present disclosure do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In both ways, communication device A can obtain messages from communication device B.
[0660] In some embodiments, the steps of the embodiment of FIG. 2D can be implemented independently, or can be combined and implemented in any order without contradiction.
[0661] In some embodiments, reference can be made to other optional implementations described before or after the description corresponding to FIG. 2D.
[0662] FIG. 2E is an exemplary interaction diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2E, the present disclosure relates to an authorization method, and the above method includes:
[0663] At step S2501, the second access network device 102 sends a fourth request to the second node 1031.
[0664] In some embodiments, the second node 1031 receives the fourth request.
[0665] In some embodiments, the fourth request is used to request fifth information.
[0666] In some embodiments, the fourth request is used to request the second node to send the first request to the first node.
[0667] In some embodiments, the name of the fourth request is not limited, which is, for example, “token request”, “request for identity verification and / or authorization”, “Token request”, etc.
[0668] In some embodiments, the fourth request includes at least one of user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing a data type, an NF type of the fourth node, or an NF instance ID of the fourth node.
[0669] In some embodiments, the fourth request includes an identity of the second access network device 102.
[0670] In some embodiments, the identity of the second access network device or the type of the second access network device is included in the fourth request.
[0671] In some embodiments, the user information includes identity information of the terminal 101 (UE) or identity information of a user. Optionally, the identity information of the UE or the identity information of the user is the same. Optionally, the identity information of the UE or the identity information of the user is in an association relationship.
[0672] In some embodiments, the identity information of the UE is used to “identify the UE”.
[0673] In some embodiments, the identity information of the user is used to “identify the user”.
[0674] In some embodiments, the name of the identity information is not limited, which is, for example, “unique identification code, number, or identity”, “identifier for identifying identity”, etc.
[0675] In some embodiments, the fourth node 1033 is, for example, an NF. Optionally, the fourth node 1033 is, for example, represented by “NF3”.
[0676] In some embodiments, the fourth node 1033 is used to “provide a service” as a network function service provider, and the name is not limited thereto.
[0677] In some embodiments, the fifth information includes at least one of a data type, a data processing purpose, a purpose of processing the data type, and an NF instance ID of the first node.
[0678] In some embodiments, the name of the fifth information is not limited, which is, for example, “token”, “information for identity authentication and / or authorization”, “token”, and the like.
[0679] In some embodiments, the fifth information includes an NF instance ID of an NF service consumer (subject), an expected service name (scope), optional “additional scope” information (resources allowed on resources and allowed operations (service operations)), and an expiration time (validity period).
[0680] In some embodiments, the fifth information includes a subject declaration (claim) of the token. Optionally, the content of the subject declaration is the identity of the second access network device 102.
[0681] In some embodiments, the fifth information includes the identity of the second access network device or the type of the second access network device.
[0682] In some embodiments, the second access network device 102 does not support a service architecture.
[0683] In some embodiments, the name of the second access network device 102 is not limited, which is, for example, “base station”.
[0684] In some embodiments, the second access network device 102 sends a token request to the first node 104, and the token request is used to request the fifth information. Optionally, the token request includes at least one of user information, a service of the fourth node (which can be represented using NF3), or a service operation of the fourth node. Optionally, the token request includes at least one of a data type, a data processing purpose, a purpose of processing the data type, an identifier of a UE / user, an NF type or an NF instance ID of a network function service provider (the fourth node, for example, represented using NF3), and a service / service operation of NF3. Optionally, the fifth information includes a token. Optionally, the token includes at least one of a data type, a data processing purpose, a purpose of processing the data type, and a parameter. Optionally, the token includes an NF instance ID of the first node 104. Optionally, the token includes at least one of an NF instance ID of an NF service consumer (subject), an expected service name, optional “additional scope” information, and an expiration time.
[0685] Step S2502, the second node 1031 sends a first request to the first node 104.
[0686] Step S2503, the first node 104 determines that the first request is allowed.
[0687] Step S2504, the first node 104 sends a second request to the third node 1032.
[0688] Step S2505, the third node 1032 acquires second authorization information.
[0689] Step S2506, the third node 1032 sends the second authorization information to the first node 104.
[0690] In some embodiments, steps S2502 to S2506 are the same as steps S2101 to S2105 (for example, step S2502 is the same as step S2101, step S2503 is the same as step S2102, and so on), which will not be repeated here.
[0691] Step S2507, the first node 104 determines to authorize the second access network device 102.
[0692] In some embodiments, the first node 104 determines to authorize the second access network device 102 according to the first authorization information and the second authorization information.
[0693] In some embodiments, the first node 104 determines to authorize the second access network device 102 according to the first authorization information and the second authorization information, if a first condition is met.
[0694] In some embodiments, the first request includes a seventh request and an eighth request, the seventh request is used to request UE or user authorization, and the eighth request is used to request network function authorization.
[0695] In some embodiments, the name of the seventh request is not limited, which is, for example, “UE or user authorization related request” and the like.
[0696] In some embodiments, the name of the eighth request is not limited, which is, for example, “network function authorization related request” and the like.
[0697] In some embodiments, the first condition includes that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information. Optionally, if the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information, it is determined to authorize the second access network device 102.
[0698] In some embodiments, the first condition includes that the data type in the first request and the purpose of processing the data type are allowed, and the second access network device 102 is allowed to request the service of the fourth node or the service operation of the fourth node. Optionally, if the data type in the first request and the purpose of processing the data type are allowed, and the second access network device 102 is allowed to request the service of the fourth node or the service operation of the fourth node, it is determined to authorize the second access network device 102.
[0699] In some embodiments, the CCF sends the token to the second access network device when both of the following conditions are met: according to the authorization information of the UE / user, the data type and its corresponding usage are allowed; the second access network device is authorized to request the service / service operation of the NF3.
[0700] In some embodiments, according to the first authorization information and the second authorization information, if the first condition is not met, the authorization process for the second access network device is terminated or the third information is sent to the second access network device.
[0701] In some embodiments, the second access network device receives the third information.
[0702] In some embodiments, the third information is used to indicate at least one of the following: the second access network device is not authorized, the authorization of the second access network device fails, the reason for the authorization failure of the second access network device.
[0703] In some embodiments, the name of the third information is not limited, which is, for example, “failure message”, “failure information”, “information used to indicate that the second access network device 102 is not authorized”, “information indicating that the authorization of the second access network device 102 fails”, etc.
[0704] In some embodiments, the failure message can indicate that the UE / user is not allowed to process the data type for such purpose, or the second access network device is not allowed to request the service / service operation of the NF3.
[0705] In some embodiments, the first condition is not met if the seventh request is not allowed, and / or the eighth request is not allowed. Optionally, if the seventh request is not allowed, and / or the eighth request is not allowed, the authorization process for the second access network device is terminated or the third information is sent to the second access network device.
[0706] In some embodiments, the first condition is not met if the seventh request is not allowed by the first authorization information, and / or the eighth request is not allowed by the second authorization information. Optionally, if the seventh request is not allowed, and / or the eighth request is not allowed, the authorization process for the second access network device is terminated or the third information is sent to the second access network device.
[0707] In the above embodiments, if the seventh request and / or the eighth request in the first request is not allowed, indicating that the authorization of the second access network device fails or the second access network device is not authorized, the authorization process for the second access network device can be terminated, or the third information can be sent to the second access network device in time to feed back any one of the following: not authorized, authorization failure, reason for authorization failure.
[0708] In some embodiments, the first condition is not met when: the data processing purpose in the first request is not allowed and / or the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node, or the data type and the purpose of processing the data type in the first request are allowed and / or the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node.
[0709] In the above embodiments, if the data type and the purpose of processing the data type in the first request are not allowed, and / or the service of the fourth node or the service operation of the fourth node in the first request is not authorized to be requested, it indicates that the authorization of the second access network device 102 fails or the second access network device 102 is not authorized, and the authorization process of the second access network device 102 can be terminated, or the third information can be sent to the second access network device 102 in time to feedback any one of unauthorized, authorization failure, and reason for authorization failure.
[0710] In the above embodiments, if the data processing purpose in the first request is not allowed, and / or the service of the fourth node or the service operation of the fourth node in the first request is not authorized to be requested, it indicates that the authorization of the second access network device 102 fails or the second access network device 102 is not authorized, and the authorization process of the second access network device 102 can be terminated, or the third information can be sent to the second access network device 102 in time to feedback any one of unauthorized, authorization failure, and reason for authorization failure.
[0711] In some embodiments, the CCF sends the third information to the second access network device when at least one of the following two conditions is not met: according to the authorization information of the UE / user, the data type and its corresponding use are not allowed; the second access network device is not authorized to request the service / service operation of NF3.
[0712] In some embodiments, the CCF sends the third information to the second access network device when at least one of the following two conditions is not met: according to the authorization information of the UE / user, the data processing purpose is not allowed; the second access network device is not authorized to request the service / service operation of NF3.
[0713] In the above embodiments, if the second access network device receives the third information sent by the first node 104, it indicates that the second node access network device authorization fails or the second access network device is not authorized or the reason for the authorization failure of the second access network device, and the second access network device can feedback that it is not authorized in time.
[0714] Step S2508, the first node 104 sends the first information to the second node 1031.
[0715] In some embodiments, step S2508 is the same as step S2107, and is not described herein again.
[0716] In some embodiments, the first information comprises at least one of a data type, a data processing purpose, a purpose of processing the data type, an NF instance ID of the first node, an identifier of the second access network device, and an identifier of the first node.
[0717] In some embodiments, the first information is used to indicate that the second access network device is authorized to request a service or a service operation of the fourth node.
[0718] In step S2509, the second node 1031 sends fifth information to the second access network device 102.
[0719] In some embodiments, the second access network device 102 receives the fifth information.
[0720] In some embodiments, the second access network device 102 obtains the fifth information specified by a protocol, and in this case, step S2509 can be omitted.
[0721] In some embodiments, the second access network device 102 processes to obtain the fifth information, and in this case, step S2509 can be omitted.
[0722] In some embodiments, the second access network device 102 autonomously implements the function indicated by the fifth information, or the above function is default or default, and in this case, step S2509 can be omitted.
[0723] In some embodiments, the fifth information is determined based on the first information.
[0724] In some embodiments, the fifth information comprises at least one of a data type, a data processing purpose, a purpose of processing the data type, and an NF instance ID of the first node.
[0725] In some embodiments, the fifth information comprises at least one of an identifier of the second access network device and an identifier of the first node.
[0726] In some embodiments, the fifth information is used to indicate that the second access network device is authorized to request a service or a service operation of the fourth node.
[0727] In the above embodiments, based on the acquired data type, data processing purpose, and purpose of processing data type, the data type, data processing purpose, and purpose of processing data type authorized for the second access network device can be determined, and then the corresponding network function service provider is requested for service according to the authorized content, so that based on the authorization provided by the UE or user and the authorization corresponding to the network function configuration file, the corresponding service can be timely provided when the second access network device requests the service from the network function service provider; on this basis, the fifth information also indicates the NF instance ID of the first node 104 (here, the first node as the issuer of the token, i.e., issuer or iss).
[0728] In some embodiments, the name of the fifth information is not limited, which is, for example, "token", "information for identity verification and / or authorization", "token", etc.
[0729] In some embodiments, the fifth information includes the NF instance ID of the NF service consumer (subject), the expected service name (scope), the optional "additional scope" information (allowed resources and allowed operations (service operations) on resources), and the expiration time (validity period).
[0730] Step S2510: The second access network device 102 sends a fifth request to the second node 1031.
[0731] In some embodiments, the second node 1031 receives the fifth request.
[0732] In some embodiments, the fifth request is used for "requesting a service or a service operation" or for "requesting a service or a service operation of the fourth node" or for "requesting a service or a service operation provided by the fourth node".
[0733] In some embodiments, the name of the fifth request is not limited, which is, for example, "service request", "service request"
[0734] In some embodiments, the name of the service request is not limited, which is, for example, "Service request".
[0735] In some embodiments, the fifth request is used for the second node to send a sixth request to the fourth node.
[0736] In some embodiments, the fifth request contains a token, and the token contains the identity of the second access network device or the type of the second access network device.
[0737] In some embodiments, the fifth request contains the identity of the second access network device or the type of the second access network device.
[0738] Step S2511, the second node 1031 sends a sixth request to the fourth node 1033.
[0739] In some embodiments, the sixth request contains a token, and the token contains an identity of the second access network device or a type of the second access network device.
[0740] Step S2512, the fourth node 1033 determines that the sixth request is authorized.
[0741] Step S2513, the fourth node 1033 sends sixth information to the second node 1031.
[0742] In some embodiments, steps S2511 to S2513 are the same as steps S2108 to S2110 (for example, step S2511 is the same as step S2108, step S2512 is the same as step S2109, and so on), which will not be repeated here.
[0743] Step S2514, the second node 1031 sends eighth information to the second access network device 102.
[0744] In some embodiments, the second access network device 102 receives the eighth information.
[0745] In some embodiments, the second access network device 102 obtains the eighth information as specified by a protocol, and in this case, step S2514 can be omitted.
[0746] In some embodiments, the second access network device 102 processes to obtain the eighth information, and in this case, step S2514 can be omitted.
[0747] In some embodiments, the second access network device 102 autonomously implements a function indicated by the eighth information, or the above function is default or default, and in this case, step S2514 can be omitted.
[0748] In some embodiments, the eighth information is the same as or similar to the content of the sixth information.
[0749] In some embodiments, the eighth information contains an identity of the second access network device or a type of the second access network device.
[0750] The authorization method related by the embodiments of the present disclosure can include at least one of steps S2501-S2514. For example, step S2503 can be implemented as an independent embodiment, step S2505 can be implemented as an independent embodiment, step S2507 can be implemented as an independent embodiment, step S2512 can be implemented as an independent embodiment, steps S2502+S2503+S2504+S2505+S2506+S2507+S2508 can be implemented as an independent embodiment, steps S2501+S2507 can be implemented as an independent embodiment, steps S2503+S2504+S2505 can be implemented as an independent embodiment, steps S2511+S2512+S2513 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.
[0751] In some embodiments, steps S2501, S2509, S2510, S2514 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0752] In some embodiments, the present embodiment does not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[0753] In some embodiments, the steps of the embodiment of FIG. 2E can be implemented independently, or can be combined and implemented in any order without contradiction.
[0754] In some embodiments, reference can be made to other optional implementations described before or after the description corresponding to FIG. 2E.
[0755] FIG. 2F is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2F, the present embodiment relates to an authorization method, and the above method includes:
[0756] Step S2601: The second access network device 102 sends a tenth request to the second node 1031.
[0757] In some embodiments, the second node 1031 receives the tenth request.
[0758] In some embodiments, the tenth request is used to request fourth information.
[0759] In some embodiments, the tenth request is used for the second node to send a third request to the third node.
[0760] In some embodiments, the tenth request contains an identity of the second access network device or a type of the second access network device.
[0761] In some embodiments, the name of the tenth request is not limited, which is, for example, "fourth information acquisition request", "service authorization information delivery request", "request for indicating service authorization information delivery", and the like.
[0762] Step S2602, the second node 1031 sends a third request to the third node 1032.
[0763] Step S2603, the third node 1032 acquires the second authorization information.
[0764] Step S2604, the third node 1032 sends the second authorization information to the first node 104.
[0765] Step S2605, the third node 1032 sends fourth information to the second node 1031.
[0766] In some embodiments, steps S2602 to S2605 are the same as steps S2201 to S2204 (for example, step S2602 is the same as step S2201, step S2603 is the same as step S2202, and so on), which will not be repeated here.
[0767] Step S2606, the second node 1031 sends ninth information to the second access network device 102.
[0768] In some embodiments, the second access network device 102 receives the ninth information.
[0769] In some embodiments, the second access network device 102 acquires the ninth information specified by the protocol, and at this time, step S2606 can be omitted.
[0770] In some embodiments, the second access network device 102 processes to obtain the ninth information, and at this time, step S2606 can be omitted.
[0771] In some embodiments, the second access network device 102 autonomously implements the function indicated by the ninth information, or the above function is default or default, and at this time, step S2606 can be omitted.
[0772] In some embodiments, the content of the ninth information and the fourth information is the same or similar.
[0773] In some embodiments, the ninth information contains an identity of the second access network device or a type of the second access network device.
[0774] Step S2607, the second access network device 102 sends a fourth request to the second node 1031.
[0775] Step S2608. The second node 1031 sends the first request to the first node 104.
[0776] In some embodiments, steps S2607-S2608 are the same as steps S2501-S2502 (e.g., step S2607 is the same as step S2501, step S2608 is the same as step S2502, and so on), which will not be repeated here.
[0777] Step S2609. The first node 104 determines that the second access network device 102 is authorized.
[0778] Step S2610. The first node 104 sends the first information to the second node 1031.
[0779] In some embodiments, steps S2609-S2610 are the same as steps S2507-S2508 (e.g., step S2609 is the same as step S2507, step S2610 is the same as step S2508, and so on), which will not be repeated here.
[0780] Step S2611. The second node 1031 sends the fifth information to the second access network device 102.
[0781] Step S2612. The second access network device 102 sends a fifth request to the second node 1031.
[0782] Step S2603. The second node 1031 sends a sixth request to the fourth node 1033.
[0783] Step S2614. The fourth node 1033 determines that the sixth request is authorized.
[0784] Step S2615. The fourth node 1033 sends the sixth information to the second node 1031.
[0785] Step S2616. The second node 1031 sends the eighth information to the second access network device 102.
[0786] In some embodiments, steps S2611-S2616 are the same as steps S2509-S2514 (e.g., step S2611 is the same as step S2509, step S2612 is the same as step S2510, and so on), which will not be repeated here.
[0787] The authorization method related by the embodiments of the present disclosure can include at least one of steps S2601-S2616. For example, step S2603 can be implemented as an independent embodiment, step S2609 can be implemented as an independent embodiment, step S2614 can be implemented as an independent embodiment, steps S2601+S2602+S2603+S2604+S2605+S2606 can be implemented as an independent embodiment, steps S2607+S2608+S2609+S2610+S2611 can be implemented as an independent embodiment, steps S2612+S2613+S2614+S2615+S2616 can be implemented as an independent embodiment, but the present disclosure is not limited thereto.
[0788] In some embodiments, steps S2601, S2606, S2607, S2611, S2612, S2616 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0789] In some embodiments, the embodiments of the present disclosure do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[0790] In some embodiments, the steps of the embodiment of FIG. 2F can be implemented independently, or can be combined and implemented in any order without contradiction.
[0791] In some embodiments, reference can be made to other optional implementations described before or after the description corresponding to FIG. 2F.
[0792] FIG. 2G is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2G, the embodiments of the present disclosure relate to an authorization method, and the method includes:
[0793] In step S2701, the second access network device 102 sends an eleventh request to the second node 1031.
[0794] In some embodiments, the eleventh request is used to request information related to authorization.
[0795] In some embodiments, the eleventh request is used to request the second node to send a ninth request to the terminal.
[0796] In some embodiments, the name of the eleventh request is not limited, and it is, for example, “request related to authorization” and the like.
[0797] In some embodiments, the eleventh request comprises address information of the first node.
[0798] In some embodiments, the address information of the first node comprises at least one of a Fully qualified domain name (FQDN) of the first node, an Internet Protocol (IP) address of the first node.
[0799] In some embodiments, the eleventh request comprises a data type, a data processing purpose, and a purpose of processing the data type (e.g., collection, exposure).
[0800] In some embodiments, the eleventh request comprises an identity of the second access network device or a type of the second access network device.
[0801] At step S2702, the second node 1031 sends a ninth request to the terminal 101.
[0802] At step S2703, the terminal 101 determines whether the data type can be processed under the given purpose.
[0803] In some embodiments, the terminal 101 determines whether the data processing purpose can be agreed to.
[0804] At step S2704, the terminal 101 sends second information to the first node 104.
[0805] At step S2705, the first node 104 sends an authorization identity to the terminal 101.
[0806] At step S2706, the terminal 101 sends the authorization identity to the second node 1031.
[0807] In some embodiments, steps S2702 to S2706 are the same as steps S2301 to S2305 (for example, step S2702 is the same as step S2301, step S2703 is the same as step S2302, and so on), which will not be described here.
[0808] At step S2707, the second node 1031 sends the authorization identity to the second access network device 102.
[0809] In some embodiments, the second access network device 102 receives the authorization identity.
[0810] In some embodiments, the second access network device 102 obtains the authorization identity specified by the protocol, and at this time, step S2707 can be omitted.
[0811] In some embodiments, the second access network device 102 performs processing to obtain the authorization identity, and step S2707 can be omitted.
[0812] In some embodiments, the second access network device 102 autonomously implements the function indicated by the authorization information, or the function is default or default, and step S2707 can be omitted.
[0813] Step S2708, the second access network device 102 sends a fourth request to the second node 1031.
[0814] Step S2709, the second node 1031 sends the first request to the first node 104.
[0815] Step S2710, the first node 104 determines that the first request is allowed.
[0816] Step S2711, the first node 104 sends a second request to the third node 1032.
[0817] Step S2712, the third node 1032 obtains second authorization information.
[0818] Step S2713, the third node 1032 sends the second authorization information to the first node 104.
[0819] Step S2714, the first node 104 determines to authorize the second access network device 102.
[0820] Step S2715, the first node 104 sends first information to the second node 1031.
[0821] In some embodiments, the first information includes authorization information for the second access network device.
[0822] In some embodiments, the first information includes an identity of the second access network device or a type of the second access network device.
[0823] Step S2716, the second node 1031 sends fifth information to the second access network device 102.
[0824] In some embodiments, the fifth information includes authorization information for the second access network device.
[0825] In some embodiments, the fifth information includes an identity of the second access network device or a type of the second access network device.
[0826] Step S2717, the second access network device 102 sends a fifth request to the second node 1031.
[0827] Step S2718, the second node 1031 sends a sixth request to the fourth node 1033.
[0828] Step S2719, the fourth node 1033 determines that the sixth request is authorized.
[0829] Step S2720, the fourth node 1033 sends the sixth information to the second node 1031.
[0830] Step S2721, the second node 1031 sends the eighth information to the second access network device 102.
[0831] In some embodiments, steps S2708 to S2721 are the same as steps S2501 to S2514 (for example, step S2708 is the same as step S2501, step S2709 is the same as step S2502, and so on), which will not be repeated here.
[0832] The authorization method involved in the embodiments of the present disclosure can include at least one of steps S2701 to S2721. For example, step S2703 can be implemented as an independent embodiment, step S2710 can be implemented as an independent embodiment, step S2712 can be implemented as an independent embodiment, step S2714 can be implemented as an independent embodiment, step S2719 can be implemented as an independent embodiment, steps S2702+S2703+S2705+S2705+S2706 can be implemented as an independent embodiment, steps S2709+S2710+S2711+S2712+S2713+S2714+S2715 can be implemented as an independent embodiment, and steps S2718+S2719+S2720 can be implemented as an independent embodiment, but are not limited thereto.
[0833] In some embodiments, steps S2701, S2707, S2708, S2716, S2717, and S2721 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0834] In some embodiments, the embodiments do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In both ways, communication device A can obtain messages from communication device B.
[0835] In some embodiments, the steps of the embodiment of FIG. 2G can be implemented independently, or can be combined and implemented in any order without contradiction.
[0836] In some embodiments, reference can be made to other optional implementations described before or after the description corresponding to FIG. 2G.
[0837] FIG. 2H is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 2H, the embodiment of the present disclosure relates to an authorization method, and the method comprises:
[0838] Step S2801, the second access network device 102 sends a tenth request to the second node 1031.
[0839] Step S2802, the second node 1031 sends a third request to the third node 1032.
[0840] Step S2803, the third node 1032 acquires second authorization information.
[0841] Step S2804, the third node 1032 sends the second authorization information to the first node 104.
[0842] Step S2805, the third node 1032 sends fourth information to the second node 1031.
[0843] Step S2806, the second node 1031 sends ninth information to the second access network device 102.
[0844] In some embodiments, steps S2801 to S2806 are the same as steps S2601 to S2606 (for example, step S2801 is the same as step S2601, step S2802 is the same as step S2602, and so on), which will not be described here.
[0845] Step S2807, the second access network device 102 sends an eleventh request to the second node 1031.
[0846] Step S2808, the second node 1031 sends a ninth request to the terminal 101.
[0847] Step S2809, the terminal 101 determines whether the data type can be processed under a given purpose.
[0848] In some embodiments, the terminal 101 determines whether the data processing purpose can be agreed.
[0849] Step S2810, the terminal 101 sends second information to the first node 104.
[0850] In some embodiments, the second information contains authorization information for the second access network device.
[0851] In some embodiments, the second information contains an identity of the second access network device or a type of the second access network device.
[0852] Step S2811, the first node 104 sends the authorization identity to the terminal 101.
[0853] Step S2812, the terminal 101 sends the authorization identity to the second node 1031.
[0854] Step S2813, the second node 1031 sends the authorization identity to the second access network device 102.
[0855] In some embodiments, the steps S2807 to S2813 are the same as the steps S2701 to S2707 (for example, the step S2807 is the same as the step S2701, the step S2808 is the same as the step S2702, and so on), which will not be repeated here.
[0856] Step S2814, the second access network device 102 sends a fourth request to the second node 1031.
[0857] Step S2815, the second node 1031 sends a first request to the first node 104.
[0858] Step S2816, the first node 104 determines to authorize the second access network device 102.
[0859] Step S2817, the first node 104 sends first information to the second node 1031.
[0860] In some embodiments, the first information contains the identity of the second access network device or the type of the second access network device.
[0861] In some embodiments, the first information contains authorization information for the second access network device.
[0862] Step S2818, the second node 1031 sends fifth information to the second access network device 102.
[0863] In some embodiments, the fifth information contains the identity of the second access network device or the type of the second access network device.
[0864] In some embodiments, the fifth information contains authorization information for the second access network device.
[0865] Step S2819, the second access network device 102 sends a fifth request to the second node 1031.
[0866] Step S2820, the second node 1031 sends a sixth request to the fourth node 1033.
[0867] Step S2821, the fourth node 1033 determines that the sixth request is authorized.
[0868] Step S2822: The fourth node 1033 sends sixth information to the second node 1031.
[0869] Step S2823: The second node 1031 sends eighth information to the second access network device 102.
[0870] In some embodiments, steps S2814 to S2823 are the same as steps S2607 to S2616 (for example, step S2814 is the same as step S2607, step S2815 is the same as step S2608, and so on), which will not be repeated here.
[0871] In some embodiments, FIGS. 2E to 2H can enable the first node to authorize the second access network device which does not support the service-based architecture. Alternatively, the second access network device (or access network device) implements each of the embodiments shown in FIGS. 2E to 2H through the second node, which will not be repeated here. Alternatively, the second node forwards the request or information sent by the second access network device.
[0872] Alternatively, in this case, the second access network device actively triggers the NF1 to request the token, and the NF1 is, for example, a network function related to access and mobility management. The NF1 also needs to send the received token to the second access network device. After receiving the token, the second access network device sends a service request to the NF3 through the NF1 and receives the response of the NF3.
[0873] The authorization method related to the embodiments of the present disclosure can include at least one of steps S2801 to S2823. For example, step S2803 can be implemented as an independent embodiment, step S2809 can be implemented as an independent embodiment, step S2816 can be implemented as an independent embodiment, step S2822 can be implemented as an independent embodiment, steps S2802+S2803+S2805+S2805 can be implemented as an independent embodiment, steps S2808+S2809+S2810+S2811+S2812 can be implemented as an independent embodiment, steps S2815+S2816+S2817 can be implemented as an independent embodiment, steps S2820+S2821+S2822 can be implemented as an independent embodiment, but are not limited thereto.
[0874] In some embodiments, steps S2801, S2806, S2807, S2813, S2814, S2818, S2819, S2823 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0875] In some embodiments, the embodiments do not limit the form of the messages involved. Alternatively, the request and response messages can be replaced by subscription and notification messages in specific implementations. For example, the communication device A requests the communication device B, and the communication device B sends the corresponding response message to the communication device A, or the communication device A subscribes to the communication device B, and the communication device B sends the corresponding notification message to the communication device A. In both ways, the communication device A can obtain the message from the communication device B.
[0876] In some embodiments, the steps of the embodiment of FIG. 2H can be implemented independently, or can be combined in any order without contradiction.
[0877] In some embodiments, reference can be made to other optional implementations described before or after the description corresponding to FIG. 2H.
[0878] [According to Rule 91 Correction 29.09.2024] The authorization method provided by the embodiments of the present disclosure provides a CAPIF-involved network entity authorization mechanism (in combination with FIGS. 4A-4F):
[0879] In some embodiments, the network function NF authorization based on client credential flow (Client Credentials Flow based NF Authorization). Alternatively, 1) in the client credential flow, the CCF (for example, CAPIF core function) actively requests the NF2 to provide service authorization information. 2) In the client credential flow, the NF1 actively requests the NF2 to provide service authorization information.
[0880] In some embodiments, the NF authorization based on authorization code flow (Authorization Code Flow based NF Authorization). Alternatively, 3) in the authorization code flow, the NF1 actively requests the NF2 to provide service authorization information. 4) In the authorization code flow, the CCF actively requests the NF2 to provide service authorization information.
[0881] In some embodiments, the CAPIF-based access network authorization (Access Network Authorization). Alternatively, the above 1) to 4) are modified to support the CAPIF-based access network authorization.
[0882] FIG. 3A is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiments of the present disclosure relate to an authorization method, and the above method comprises:
[0883] Step S3101, the NF1 sends a token request to the CCF.
[0884] In some embodiments, the NF1 is the second node 3021, the CCF is the first node 104, and the token request is the first request.
[0885] In some embodiments, the token request includes an identifier of the UE / user, a data type, a data processing purpose, a purpose of processing the data type, an NF type or NF instance ID of a network function service provider (e.g., the NF3), or a service or service operation of the NF3. Optionally, the NF3 is the fourth node 1033.
[0886] In some embodiments, based on the regulatory rules and the local policy, if the requested service / service operation requires authorization of the UE or the user, the NF1 (the service consumer) sends the token request to the CCF.
[0887] In some embodiments, the optional implementation of step S3101 can be referred to step S2101 of FIG. 2A and other associated parts in the embodiments involved by FIG. 2A, which will not be repeated here.
[0888] In step S3102, the CCF sends a service authorization information delivery request to the NF2.
[0889] In some embodiments, the service authorization information delivery request is the second request.
[0890] In some embodiments, the CCF sends the service authorization information delivery request to the NF2 if it determines that the data type and the corresponding processing purpose are allowed according to the authorization information provided by the UE or the user. Optionally, the authorization information of the UE or the user is the first authorization information, and the corresponding purpose includes any one of the purpose of processing the data type or the data processing purpose.
[0891] In some embodiments, the service authorization information delivery request is used to trigger the NF2 to provide the authorization information related to the service or the service operation to the CCF. Optionally, the authorization information related to the service or the service operation is the second authorization information.
[0892] In some embodiments, the service authorization information delivery request includes the NF type of the NF1, the NF type or NF instance ID of a network function service provider (e.g., the NF3), and the NF service or service operation of the NF3. Optionally, the NF3 is the fourth node 1033.
[0893] In some embodiments, the optional implementation of step S3102 can be referred to step S2103 of FIG. 2A and other associated parts in the embodiments involved by FIG. 2A, which will not be repeated here.
[0894] Step S3103. NF2 sends a service authorization information delivery response to CCF.
[0895] In some embodiments, the service authorization information delivery response is the second authorization information. Optionally, the service authorization information delivery response comprises authorization information related to NF3 and NF1.
[0896] In some embodiments, the authorization information related to NF3 and NF1 comprises NF type of NF1, NF type or NF instance ID of NF3, authorized NF service or service operation.
[0897] In some embodiments, NF2 locates the NF profile of NF3 by the NF type or NF instance ID of NF3, and according to the NF profile of NF3, if it is determined that NF1 is authorized to request the service or service operation of NF3, it sends the service authorization information delivery response to CCF.
[0898] In some embodiments, if it is determined that NF1 is not authorized to request the service or service operation of NF3, it indicates to CCF that NF1 is not authorized to request the service or service operation of NF3.
[0899] In some embodiments, the optional implementation of step S4103 can refer to step S2104 of FIG. 2A and other related parts in the embodiments involved by FIG. 2A, which will not be repeated here.
[0900] Step S3104. CCF sends a token to NF1.
[0901] In some embodiments, the token is the first information.
[0902] In some embodiments, the token comprises data type, data processing purpose, purpose of processing data type, NF instance ID (issuer) of CCF, NF instance ID of NF service consumer (subject), expected service name (scope), optional “additional scope” information (resources allowed on resources and allowed operations (service operations)), and expiration time (validity period).
[0903] In some embodiments, the issuer (issuer or iss) in the token claims the NF instance ID (issuer) of CCF.
[0904] In some embodiments, the subject (subject or sub) in the token claims the identity of the base station device.
[0905] In some embodiments, CCF sends the token to NF1 when both of the following conditions are met: according to the authorization information of UE / user, the data type and its corresponding use are allowed; NF1 is authorized to request the service / service operation of NF3.
[0906] In some embodiments, the CCF sends a failure message to the NF1 when any of the above conditions is not met. Optionally, the failure message is the third information.
[0907] In some embodiments, the failure message can indicate that the UE / user is not allowed to handle the data type for such purpose, or the NF1 is not allowed to request the service / service operation of the NF3.
[0908] In some embodiments, the optional implementation of step S3104 can refer to step S2107 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0909] Step S3105, the NF1 sends a service request to the NF3.
[0910] In some embodiments, the service request is the sixth request, and the NF1 requests the service of the NF3 using the token.
[0911] In some embodiments, the optional implementation of step S3105 can refer to step S2108 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0912] Step S3106, the NF3 sends a service response to the NF1.
[0913] In some embodiments, the service response is the sixth information.
[0914] In some embodiments, the NF3 sends the service response to the NF1 if the token is valid for the request.
[0915] In some embodiments, the optional implementation of step S3106 can refer to steps S2109-S2110 of FIG. 2A and other associated parts in the embodiments related to FIG. 2A, which will not be repeated here.
[0916] The authorization method related to the embodiments of the present disclosure can include at least one of steps S3101-S3106.
[0917] In some embodiments, steps S3102 and S3103 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0918] In some embodiments, steps S3105 and S3106 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0919] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.
[0920] In some embodiments, the present embodiments do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, the communication device A requests the communication device B, and the communication device B sends a corresponding response message to the communication device A, or the communication device A subscribes to the communication device B, and the communication device B sends a corresponding notification message to the communication device A. In both ways, the communication device A can obtain the message from the communication device B.
[0921] In some embodiments, the steps in the embodiment of FIG. 3A can be independently implemented, or combined and implemented in any order without contradiction.
[0922] FIG. 3B is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3B, the present embodiment relates to an authorization method, and the above method comprises:
[0923] In step S3201, the NF1 sends a service authorization information delivery request to the NF2.
[0924] In some embodiments, the NF1 is a second node, the NF3 is a third node, and the service authorization information delivery request is a third request.
[0925] In some embodiments, according to the regulatory rules and local policies, if the requested service or service operation requires authorization of the UE or user, the NF1 sends the service authorization information delivery request to the NF2 (for example, the NRF). This request is used to trigger the NF2 to provide the authorization information of the service / service operation provided by the NF3 to the CAPIF core function (CCF).
[0926] Optionally, since the NF profile of the NF3 stored in the NF2 includes the NF type of the NF service consumer that can request its service / service operation, the service authorization information delivery request includes the NF type of the NF1, the NF type of the NF3 or the NF instance ID, and the NF service / service operation.
[0927] In some embodiments, the optional implementation manner of step S3201 can refer to step S2201 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be described here.
[0928] In step S3202, the NF2 sends a service authorization information delivery response to the NF1.
[0929] In some embodiments, the service authorization information delivery response is the second authorization information.
[0930] In some embodiments, the NF2 indicates authorization information of the NF3 to the NF1.
[0931] In some embodiments, the NF2 indicates an NF profile of the NF3 to the NF1.
[0932] In some embodiments, the NF2 indicates to the NF1 that the NF1 is authorized to request services / service operations of the NF3.
[0933] In some embodiments, the NF2 indicates to the NF1 that the NF1 is not authorized to request services / service operations of the NF3.
[0934] In some embodiments, if the NF2 is authorized to request services / service operations of the NF3, the NF2 obtains second authorization information according to the stored profile, and determines whether the NF1 is authorized to request services / service operations of the NF3.
[0935] In some embodiments, if the NF2 is not authorized to request services / service operations of the NF3, the NF2 sends authorization information related to the NF3 to the CCF in a manner similar to that defined in FIG. 2A (such as step S2104).
[0936] In some embodiments, the optional implementation of step S3202 can be referred to step S2203 of FIG. 2B and other associated parts of the embodiments involved in FIG. 2B, which will not be repeated here.
[0937] Step S3203, the NF1 sends a token request to the CCF.
[0938] In some embodiments, the optional implementation of step S3203 can be referred to step S2205 of FIG. 2B, step S3101 of FIG. 3A, and other associated parts of the embodiments involved in FIG. 2B and FIG. 3A, which will not be repeated here.
[0939] Step S3204, the CCF sends a token to the NF1.
[0940] In some embodiments, the optional implementation of step S3204 can be referred to step S2207 of FIG. 2B, step S3105 of FIG. 3A, and other associated parts of the embodiments involved in FIG. 2B and FIG. 3A, which will not be repeated here.
[0941] Step S3205, the NF1 sends a service request to the NF3.
[0942] In some embodiments, the optional implementation of step S3205 can be referred to step S2208 of FIG. 2B, step S3106 of FIG. 3A, and other associated parts of the embodiments involved in FIG. 2B and FIG. 3A, which will not be repeated here.
[0943] Step S3206, NF3 sends a service response to NF1.
[0944] In some embodiments, optional implementation of step S3206 can refer to step S2210 in FIG. 2B, step S3107 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2B and FIG. 3A, which are not described herein.
[0945] The authorization method related to the embodiments of the present disclosure can include at least one of steps S3201-S3206.
[0946] In some embodiments, steps S3201 and S3202 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0947] In some embodiments, steps S3205 and S3206 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0948] In the embodiments of the present disclosure, part or all of the steps and their optional implementations can be combined with part or all of the steps in other embodiments, or combined with optional implementations of other embodiments.
[0949] In some embodiments, the present embodiment does not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[0950] In some embodiments, the steps of the embodiment of FIG. 3B can be implemented independently, or can be combined and implemented in any order without contradiction.
[0951] FIG. 3C is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3C, the present embodiment relates to an authorization method, and the method includes:
[0952] Step S3301, NF1 sends a service authorization information delivery request to NF2.
[0953] In some embodiments, optional implementation of step S3301 can refer to step S2401 in FIG. 2D, step S3201 in FIG. 3B, and other associated parts in the embodiments related to FIG. 2D and FIG. 3B, which are not described herein.
[0954] In step S3302, NF2 sends a service authorization information delivery response to NF1.
[0955] In some embodiments, optional implementations of step S3302 can be found in step S2403 of FIG2D, step S3202 of FIG3B, and other related parts in the embodiments involved in FIG2D and FIG3B, which will not be repeated here.
[0956] In step S3303, NF1 sends an authorization-related request to the UE.
[0957] In some embodiments, the authorization-related request is a ninth request. Optionally, the authorization-related request includes the CCF's FQDN / IP address. Optionally, the authorization-related request also includes the data type, the purpose of data processing, and the purpose of processing the data type (e.g., collection, exposure).
[0958] In some embodiments, the UE or the user determines whether a data type can be processed for a given purpose.
[0959] In some embodiments, the UE or the user determines whether the requested data processing purpose is permitted.
[0960] In some embodiments, optional implementations of step S3303 can be found in step S2405 of FIG2D and other related parts in the embodiments involved in FIG2D, which will not be repeated here.
[0961] In step S3304, the UE sends the authorization result to the CCF.
[0962] In some embodiments, the authorization result is second information.
[0963] In some embodiments, the UE sends the authorization result to the CCF via the FQDN / IP address provided by NF1.
[0964] In some embodiments, optional implementations of step S3304 can be found in step S2407 of FIG2D and other related parts in the embodiments involved in FIG2D, which will not be repeated here.
[0965] In step S3305, the CCF sends an authorization code to the UE.
[0966] In some embodiments, the authorization code is an authorization identifier.
[0967] In some embodiments, if NF1 is authorized, CCF sends an authorization code to UE.
[0968] In some embodiments, optional implementations of step S3305 can be found in step S2408 of FIG2D and other related parts in the embodiments involved in FIG2D, which will not be repeated here.
[0969] Step S3306, the UE sends the authorization code to the NF1.
[0970] In some embodiments, the optional implementation of step S3306 can refer to step S2409 in FIG. 2D and other associated parts in the embodiments involved in FIG. 2D, which will not be repeated here.
[0971] Step S3307, the NF1 sends a token request to the CCF.
[0972] In some embodiments, the token request includes the authorization code. Optionally, in addition to the authorization code, the token request also includes the NF type or NF instance ID of the NF3 and the service / service operation.
[0973] In some embodiments, the CCF locates the authorization information of the UE / user through the authorization code to check whether the data type can be processed through the requested purpose. Then, the CCF also checks whether the received NF type or NF instance ID of the NF3 and the service / service operation match the authorization information related to the NF3.
[0974] In some embodiments, the optional implementation of step S3307 can refer to step S2410 in FIG. 2D and other associated parts in the embodiments involved in FIG. 2D, which will not be repeated here.
[0975] Step S3308, the CCF sends a token to the NF1.
[0976] In some embodiments, the optional implementation of step S3308 can refer to step S3204 in FIG. 3B and other associated parts in the embodiments involved in FIG. 3B, which will not be repeated here.
[0977] Step S3309, the NF1 sends a service request to the NF3.
[0978] In some embodiments, the optional implementation of step S3309 can refer to step S3205 in FIG. 3B and other associated parts in the embodiments involved in FIG. 3B, which will not be repeated here.
[0979] Step S3310, the NF3 sends a service response to the NF1.
[0980] In some embodiments, the optional implementation of step S3310 can refer to step S3206 in FIG. 3B and other associated parts in the embodiments involved in FIG. 3B, which will not be repeated here.
[0981] The authorization method involved in the embodiments of the present disclosure can include at least one of steps S3301-S3310.
[0982] In some embodiments, steps S3301 and S3302 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0983] In some embodiments, steps S3303, S3304, S3305, and S3306 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0984] In some embodiments, steps S3309 and S3310 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0985] In the embodiments of the present disclosure, part or all of the steps, or optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.
[0986] In some embodiments, the present embodiment does not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[0987] In some embodiments, the steps in the embodiment of FIG. 3C can be implemented independently, or can be combined and implemented in any order without contradiction.
[0988] FIG. 3D is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3D, the present embodiment relates to an authorization method, and the above method comprises:
[0989] In step S3401, NF1 sends a request related to authorization to UE.
[0990] In some embodiments, the request related to authorization is a ninth request. Optionally, the request related to authorization comprises the FQDN / IP address of CCF. Optionally, the request related to authorization further comprises the data type, the data processing purpose, and the purpose of processing the data type (for example, collection, exposure).
[0991] In some embodiments, the UE or the user determines whether the data type can be processed under a given purpose.
[0992] In some embodiments, the UE or the user determines whether the requested data processing purpose is allowed.
[0993] In some embodiments, the optional implementation of step S3401 can refer to step S2301 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be repeated here.
[0994] In step S3402, the UE sends the authorization result to the CCF.
[0995] In some embodiments, the authorization result is the second information.
[0996] In some embodiments, the UE sends the authorization result to the CCF through the FQDN / IP address provided by the NF1.
[0997] In some embodiments, the optional implementation of step S3402 can refer to step S2303 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be repeated here.
[0998] In step S3403, the CCF sends the authorization code to the UE.
[0999] In some embodiments, the authorization code is the authorization identifier.
[1000] In some embodiments, the CCF sends the authorization code to the UE if the NF1 is authorized.
[1001] In some embodiments, the optional implementation of step S3403 can refer to step S2304 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be repeated here.
[1002] In step S3404, the UE sends the authorization code to the NF1.
[1003] In some embodiments, the optional implementation of step S3404 can refer to step S2305 in FIG. 2C and other associated parts in the embodiments related to FIG. 2C, which will not be repeated here.
[1004] In step S3405, the NF1 sends a token request to the CCF.
[1005] In some embodiments, the token request includes the authorization code. Optionally, in addition to the authorization code, the token request also includes the NF type or NF instance ID of the NF3 and the service / service operation.
[1006] In some embodiments, the CCF locates the authorization information of the UE / user through the authorization code to check whether the data type can be processed through the requested purpose. Then, the CCF also checks whether the received NF type or NF instance ID of the NF3 and the service / service operation match the authorization information related to the NF3.
[1007] In some embodiments, the optional implementation of step S3405 can refer to step S2306 in FIG. 2C, step S3101 in FIG. 3A, and other associated parts in the embodiments involved by FIG. 2C and FIG. 3A, which are not described here again.
[1008] In step S3406, the CCF sends a service authorization information delivery request to the NF2.
[1009] In some embodiments, the optional implementation of step S3406 can refer to step S2308 in FIG. 2C, step S3102 in FIG. 3A, and other associated parts in the embodiments involved by FIG. 2C and FIG. 3A, which are not described here again.
[1010] In step S3407, the NF2 sends a service authorization information delivery response to the CCF.
[1011] In some embodiments, the optional implementation of step S3407 can refer to step S2310 in FIG. 2C, step S3103 in FIG. 3A, and other associated parts in the embodiments involved by FIG. 2C and FIG. 3A, which are not described here again.
[1012] In step S3408, the CCF sends a token to the NF1.
[1013] In some embodiments, the optional implementation of step S3401 can refer to step S2312 in FIG. 2C, step S3104 in FIG. 3A, and other associated parts in the embodiments involved by FIG. 2C and FIG. 3A, which are not described here again.
[1014] In step S3409, the NF1 sends a service request to the NF3.
[1015] In some embodiments, the optional implementation of step S3409 can refer to step S2313 in FIG. 2C, step S3105 in FIG. 3A, and other associated parts in the embodiments involved by FIG. 2C and FIG. 3A, which are not described here again.
[1016] In step S3410, the NF3 sends a service response to the NF1.
[1017] In some embodiments, the optional implementation of step S3410 can refer to step S2315 in FIG. 2C, step S3106 in FIG. 3A, and other associated parts in the embodiments involved by FIG. 2C and FIG. 3A, which are not described here again.
[1018] The authorization method involved in the embodiments of the present disclosure can include at least one of steps S3401-S3410.
[1019] In some embodiments, steps S3401, S3402, S3403, S3404 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1020] In some embodiments, steps S3406, S3407 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1021] In some embodiments, steps S3409, S3410 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1022] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.
[1023] In some embodiments, the present embodiment does not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[1024] In some embodiments, the steps of the embodiment of FIG. 3D can be independently implemented, or can be combined and implemented in any order without contradiction.
[1025] FIG. 3E is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3E, the embodiment of the present disclosure relates to an authorization method, and the above method comprises:
[1026] In step S3501, the base station sends a token request to NF1.
[1027] In some embodiments, the base station is a second access network device, and NF1 is a second node.
[1028] In some embodiments, the token request comprises an identifier of the base station or a type of the base station.
[1029] In some embodiments, the optional implementation manner of step S3501 can refer to step S2501 of FIG. 2E and other associated parts in the embodiments related by FIG. 2E, which will not be repeated here.
[1030] In step S3502, NF1 sends a token request to CCF.
[1031] In some embodiments, CCF is a first node.
[1032] In some embodiments, the token request comprises an identity of the base station or a type of the base station.
[1033] In some embodiments, the optional implementation of step S3502 can be referred to step S3101 of FIG. 2E and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1034] Step S3503, the CCF sends a service authorization information delivery request to the NF2.
[1035] In some embodiments, the NF2 is a third node.
[1036] In some embodiments, the service authorization information delivery request comprises an identity of the base station or a type of the base station.
[1037] In some embodiments, the optional implementation of step S3503 can be referred to step S3102 of FIG. 3A and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1038] Step S3504, the NF2 sends a service authorization information delivery response to the CCF.
[1039] In some embodiments, the service authorization information delivery response comprises an identity of the base station or a type of the base station.
[1040] In some embodiments, the optional implementation of step S3504 can be referred to step S3103 of FIG. 3A and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1041] Step S3505, the CCF sends a token to the NF1.
[1042] In some embodiments, the token comprises an identity of the base station or a type of the base station.
[1043] In some embodiments, the optional implementation of step S3505 can be referred to step S3104 of FIG. 3A and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1044] Step S3506, the NF1 sends the token to the base station.
[1045] In some embodiments, the token comprises an identity of the base station or a type of the base station.
[1046] In some embodiments, the optional implementation of step S3506 can be referred to step S2509 of FIG. 2E and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1047] Step S3507, the base station sends a service request to the NF1.
[1048] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1049] In some embodiments, the optional implementation of step S3507 can be referred to step S2510 of FIG. 2E and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1050] Step S3508, the NF1 sends a service response to the NF3.
[1051] In some embodiments, the NF3 is a fourth node.
[1052] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1053] In some embodiments, the optional implementation of step S3508 can be referred to step S3105 of FIG. 3A and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1054] Step S3509, the NF3 sends a service response to the NF1.
[1055] In some embodiments, the service response comprises an identity of the base station or a type of the base station.
[1056] In some embodiments, the optional implementation of step S3509 can be referred to step S3106 of FIG. 3A and other associated parts of the embodiments related to FIG. 3A, which will not be repeated here.
[1057] Step S3510, the NF1 sends a service response to the base station.
[1058] In some embodiments, the service response comprises an identity of the base station or a type of the base station.
[1059] In some embodiments, the optional implementation of step S3510 can be referred to step S32514 of FIG. 2E and other associated parts of the embodiments related to FIG. 2E, which will not be repeated here.
[1060] The authorization method related to the embodiments of the present disclosure can comprise at least one of steps S3501-S3510.
[1061] In some embodiments, steps S3503 and S3504 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1062] In some embodiments, steps S3508 and S3509 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1063] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.
[1064] In some embodiments, the present embodiments do not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, the communication device A requests the communication device B, and the communication device B sends a corresponding response message to the communication device A, or the communication device A subscribes to the communication device B, and the communication device B sends a corresponding notification message to the communication device A. In both ways, the communication device A can obtain the message from the communication device B.
[1065] In some embodiments, the steps in the embodiment of FIG. 3E can be independently implemented, or can be combined and implemented in any order without contradiction.
[1066] FIG. 3F is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3F, the embodiment of the present disclosure relates to an authorization method, and the above method comprises:
[1067] In step S3601, the base station sends a service authorization information delivery request to the NF1.
[1068] In some embodiments, the base station is a second access network device, and the NF1 is a second node.
[1069] In some embodiments, the service authorization information delivery request comprises an identifier of the base station or a type of the base station.
[1070] In some embodiments, the optional implementation manner of step S3601 can refer to step S2601 in FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1071] In step S3602, the NF1 sends a service authorization information delivery request to the NF2.
[1072] In some embodiments, the NF2 is a third node.
[1073] In some embodiments, the service authorization information delivery request comprises an identifier of the base station or a type of the base station.
[1074] In some embodiments, the optional implementation manner of step S3602 can refer to step S2602 in FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1075] In step S3603, the NF2 sends a service authorization information delivery response to the NF1.
[1076] In some embodiments, the service authorization information delivery response comprises an identity of the base station or a type of the base station.
[1077] In some embodiments, the optional implementation of step S3603 can be referred to step S2605 of FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1078] Step S3604, the NF1 sends a service authorization information delivery response to the base station.
[1079] In some embodiments, the service authorization information delivery response comprises an identity of the base station or a type of the base station.
[1080] In some embodiments, the optional implementation of step S3604 can be referred to step S2606 of FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1081] Step S3605, the base station sends a token request to the NF1.
[1082] In some embodiments, the token request comprises an identity of the base station or a type of the base station.
[1083] In some embodiments, the optional implementation of step S3605 can be referred to step S2607 of FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1084] Step S3606, the NF1 sends a token request to the CCF.
[1085] In some embodiments, the CCF is a first node.
[1086] In some embodiments, the token request comprises an identity of the base station or a type of the base station.
[1087] In some embodiments, the optional implementation of step S3606 can be referred to step S2608 of FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1088] Step S3607, the CCF sends a token to the NF1.
[1089] In some embodiments, the token comprises an identity of the base station or a type of the base station.
[1090] In some embodiments, the optional implementation of step S3607 can be referred to step S2610 of FIG. 2F and other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1091] Step S3608, the NF1 sends the token to the base station.
[1092] In some embodiments, the token comprises an identity of the base station or a type of the base station.
[1093] In some embodiments, the optional implementation of step S3608 can be referred to step S2611 of FIG. 2F, other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1094] Step S3609, the base station sends a service request to NF1.
[1095] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1096] In some embodiments, the optional implementation of step S3609 can be referred to step S2612 of FIG. 2F, other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1097] Step S3610, NF1 sends a service request to NF3.
[1098] In some embodiments, the NF3 is a fourth node.
[1099] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1100] In some embodiments, the optional implementation of step S3610 can be referred to step S2613 of FIG. 2F, other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1101] Step S3611, NF3 sends a service response to NF1.
[1102] In some embodiments, the service response comprises an identity of the base station or a type of the base station.
[1103] In some embodiments, the optional implementation of step S3611 can be referred to step S2615 of FIG. 2F, other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1104] Step S3612, NF1 sends a service response to the base station.
[1105] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1106] In some embodiments, the optional implementation of step S3612 can be referred to step S2616 of FIG. 2F, other associated parts in the embodiments related to FIG. 2F, which will not be repeated here.
[1107] The authorization method related to the embodiments of the present disclosure can comprise at least one of steps S3601-S3612.
[1108] In some embodiments, steps S3601, S3602, S3603, S3604 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1109] In some embodiments, steps S3609, S3610, S3611, S3612 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1110] In the embodiments of the present disclosure, part or all of the steps and their optional implementation manners can be combined with part or all of the steps in other embodiments, or combined with the optional implementation manners of other embodiments.
[1111] In some embodiments, the present embodiment does not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[1112] In some embodiments, the steps of the embodiment of FIG. 3F can be implemented independently, or can be combined and implemented in any order without contradiction.
[1113] FIG. 3G is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3G, the embodiment of the present disclosure relates to an authorization method, and the above method comprises:
[1114] Step S3701, the base station sends a service authorization information delivery request to NF1.
[1115] In some embodiments, the base station is a second access network device, and the NF1 is a second node.
[1116] In some embodiments, the service authorization information delivery request comprises an identifier of the base station or a type of the base station.
[1117] In some embodiments, the optional implementation manner of step S3701 can refer to step S2801 in FIG. 2H and other related parts in the embodiments involved in FIG. 2H, which will not be repeated here.
[1118] Step S3702, the NF1 sends a service authorization information delivery request to NF2.
[1119] In some embodiments, the NF2 is a third node.
[1120] In some embodiments, the service authorization information delivery request comprises an identity of the base station or a type of the base station.
[1121] In some embodiments, the optional implementation of step S3702 can be referred to step S2802 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1122] Step S3703, NF2 sends a service authorization information delivery response to NF1.
[1123] In some embodiments, the service authorization information delivery response comprises an identity of the base station or a type of the base station.
[1124] In some embodiments, the optional implementation of step S3702 can be referred to step S2805 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1125] Step S3704, NF1 sends a service authorization information delivery response to the base station.
[1126] In some embodiments, the service authorization information delivery response comprises an identity of the base station or a type of the base station.
[1127] In some embodiments, the optional implementation of step S3704 can be referred to step S2806 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1128] Step S3705, the base station sends a request related to authorization to NF1.
[1129] In some embodiments, the request related to authorization is the ninth request. Optionally, the request related to authorization comprises a FQDN / IP address of the CCF. Optionally, the request related to authorization further comprises a data type, a data processing purpose, and a purpose of processing the data type (e.g., collection, exposure).
[1130] In some embodiments, the UE or the user determines whether the data type can be processed under the given purpose.
[1131] In some embodiments, the UE or the user determines whether the requested data processing purpose is allowed.
[1132] In some embodiments, the request related to authorization comprises an identity of the base station or a type of the base station.
[1133] In some embodiments, the optional implementation of step S3705 can be referred to step S2807 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1134] Step S3706, the NF1 sends a request related to authorization to the UE.
[1135] In some embodiments, the request related to authorization comprises an identification of the base station or a type of the base station.
[1136] In some embodiments, the optional implementation of step S3706 can be referred to step S2808 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1137] Step S3707, the UE sends an authorization result to the CCF.
[1138] In some embodiments, the CCF is the first node.
[1139] In some embodiments, the authorization result is the second information.
[1140] In some embodiments, the UE sends the authorization result to the CCF through the FQDN / IP address provided by the NF1.
[1141] In some embodiments, the optional implementation of step S3707 can be referred to step S2810 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1142] Step S3708, the CCF sends an authorization code to the UE.
[1143] In some embodiments, the authorization code is an authorization identification.
[1144] In some embodiments, the CCF sends the authorization code to the UE if the NF1 is authorized.
[1145] In some embodiments, the optional implementation of step S3708 can be referred to step S2811 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1146] Step S3709, the UE sends the authorization code to the NF1.
[1147] In some embodiments, the optional implementation of step S3709 can be referred to step S2812 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1148] Step S3710, the NF1 sends the authorization code to the base station.
[1149] In some embodiments, the optional implementation of step S3710 can be referred to step S2813 of FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1150] Step S3711, the base station sends a token request to NF1.
[1151] In some embodiments, the token request includes an authorization code. Optionally, in addition to the authorization code, the token request further includes the NF type or NF instance ID of NF3 and the service / service operation.
[1152] In some embodiments, the token request includes the identity of the base station or the type of the base station.
[1153] In some embodiments, the optional implementation of step S3711 can refer to step S2814 in FIG. 2H and other associated parts in the embodiments involved in FIG. 2H, which will not be repeated here.
[1154] Step S3712, NF1 sends a token request to CCF.
[1155] In some embodiments, the token request includes an authorization code. Optionally, in addition to the authorization code, the token request further includes the NF type or NF instance ID of NF3 and the service / service operation.
[1156] In some embodiments, the token request includes the identity of the base station or the type of the base station.
[1157] In some embodiments, the CCF locates the authorization information of the UE / user through the authorization code to check whether the data type can be processed through the requested purpose. Then, the CCF further checks whether the received NF type or NF instance ID of NF3 and the service / service operation match the authorization information related to NF3.
[1158] In some embodiments, the optional implementation of step S3712 can refer to step S2815 in FIG. 2H and other associated parts in the embodiments involved in FIG. 2H, which will not be repeated here.
[1159] Step S3713, CCF sends a token to NF1.
[1160] In some embodiments, the token includes the identity of the base station or the type of the base station.
[1161] In some embodiments, the optional implementation of step S3713 can refer to step S2817 in FIG. 2H and other associated parts in the embodiments involved in FIG. 2H, which will not be repeated here.
[1162] Step S3714, NF1 sends a token to the base station.
[1163] In some embodiments, the token includes the identity of the base station or the type of the base station.
[1164] In some embodiments, the optional implementation of step S3714 can be referred to step S2818 in FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1165] In step S3715, the base station sends a service request to NF1.
[1166] In some embodiments, the service request includes the identity of the base station or the type of the base station.
[1167] In some embodiments, the optional implementation of step S3715 can be referred to step S2819 in FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1168] In step S3716, NF1 sends a service request to NF3.
[1169] In some embodiments, NF3 is a fourth node.
[1170] In some embodiments, the service request includes the identity of the base station or the type of the base station.
[1171] In some embodiments, the optional implementation of step S3716 can be referred to step S2820 in FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1172] In step S3717, NF3 sends a service response to NF1.
[1173] In some embodiments, the service response includes the identity of the base station or the type of the base station.
[1174] In some embodiments, the optional implementation of step S3717 can be referred to step S2822 in FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1175] In step S3718, NF1 sends a service response to the base station.
[1176] In some embodiments, the service response includes the identity of the base station or the type of the base station.
[1177] In some embodiments, the optional implementation of step S3718 can be referred to step S2823 in FIG. 2H and other associated parts in the embodiments related to FIG. 2H, which will not be repeated here.
[1178] The authorization method related to the embodiments of the present disclosure can include at least one of steps S3701-S3718.
[1179] In some embodiments, steps S3701, S3702, S3703, S3704 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1180] In some embodiments, steps S3705, S3706, S3707, S3708, S3709, S3710 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1181] In some embodiments, steps S3715, S3716, S3717, S3718 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1182] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or combined with optional implementation manners of other embodiments.
[1183] In some embodiments, the present embodiment does not limit the form of the messages involved. Optionally, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, communication device A requests communication device B, and communication device B sends a corresponding response message to communication device A, or communication device A subscribes to communication device B, and communication device B sends a corresponding notification message to communication device A. In these two ways, communication device A can obtain messages from communication device B.
[1184] In some embodiments, the steps in the embodiment of FIG. 3G can be independently implemented, or can be combined and implemented in any order without contradiction.
[1185] FIG. 3H is an exemplary interaction schematic diagram of an authorization method according to an embodiment of the present disclosure. As shown in FIG. 3H, the embodiment of the present disclosure relates to an authorization method, and the above method comprises:
[1186] In step S3801, the base station sends a request related to authorization to NF1.
[1187] In some embodiments, the base station is a second access network device, and NF1 is a second node.
[1188] In some embodiments, the request related to authorization comprises an identifier of the base station or a type of the base station.
[1189] In some embodiments, the request related to authorization is an eleventh request. Optionally, the request related to authorization comprises an FQDN / IP address of the CCF. Optionally, the request related to authorization further comprises a data type, a data processing purpose, and a purpose of processing the data type (for example, collection, exposure).
[1190] In some embodiments, the UE or user determines whether the data type can be processed under the given purpose.
[1191] In some embodiments, the UE or user determines whether the requested data processing purpose is allowed.
[1192] In some embodiments, the optional implementation of step S3801 can be referred to step S2701 of FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1193] Step S3802, NF1 sends a request related to authorization to the UE.
[1194] In some embodiments, the request related to authorization includes an identification of the base station or a type of the base station.
[1195] In some embodiments, the optional implementation of step S3802 can be referred to step S2702 of FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1196] Step S3803, the UE sends an authorization result to the CCF.
[1197] In some embodiments, the CCF is a first node.
[1198] In some embodiments, the authorization result is second information.
[1199] In some embodiments, the UE sends the authorization result to the CCF through the FQDN / IP address provided by the NF1.
[1200] In some embodiments, the optional implementation of step S3803 can be referred to step S2704 of FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1201] Step S3804, the CCF sends an authorization code to the UE.
[1202] In some embodiments, the authorization code is an authorization identification.
[1203] In some embodiments, if the NF1 is authorized, the CCF sends the authorization code to the UE.
[1204] In some embodiments, the optional implementation of step S3804 can be referred to step S2705 of FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1205] Step S3805, the UE sends the authorization code to the NF1.
[1206] In some embodiments, the optional implementation of step S3805 can be referred to step S2706 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1207] Step S3806, the NF1 sends the authorization code to the base station.
[1208] In some embodiments, the optional implementation of step S3806 can be referred to step S2707 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1209] Step S3807, the base station sends a token request to the NF1.
[1210] In some embodiments, the token request includes the authorization code. Optionally, in addition to the authorization code, the token request further includes the NF type or NF instance ID of the NF3 and the service / service operation.
[1211] In some embodiments, the token request includes the identity of the base station or the type of the base station.
[1212] In some embodiments, the optional implementation of step S3807 can be referred to step S2708 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1213] Step S3808, the NF1 sends a token request to the CCF.
[1214] In some embodiments, the token request includes the authorization code. Optionally, in addition to the authorization code, the token request further includes the NF type or NF instance ID of the NF3 and the service / service operation.
[1215] In some embodiments, the token request includes the identity of the base station or the type of the base station.
[1216] In some embodiments, the CCF locates the authorization information of the UE / user through the authorization code to check whether the data type can be processed through the requested purpose. Then, the CCF further checks whether the received NF type or NF instance ID of the NF3 and the service / service operation match the authorization information related to the NF3.
[1217] In some embodiments, the optional implementation of step S3808 can be referred to step S2709 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1218] Step S3809, the CCF sends a service authorization information delivery request to the NF2.
[1219] In some embodiments, the NF2 is a third node.
[1220] In some embodiments, the service authorization information delivery request comprises an identity of the base station or a type of the base station.
[1221] In some embodiments, the optional implementation of step S3809 can be referred to step S2711 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1222] Step S3810, NF2 sends a service authorization information delivery response to CCF.
[1223] In some embodiments, the service authorization information delivery response comprises an identity of the base station or a type of the base station.
[1224] In some embodiments, the optional implementation of step S3810 can be referred to step S2713 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1225] Step S3811, CCF sends a token to NF1.
[1226] In some embodiments, the token comprises an identity of the base station or a type of the base station.
[1227] In some embodiments, the optional implementation of step S3811 can be referred to step S2715 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1228] Step S3812, NF1 sends the token to the base station.
[1229] In some embodiments, the token comprises an identity of the base station or a type of the base station.
[1230] In some embodiments, the optional implementation of step S3812 can be referred to step S2716 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1231] Step S3813, the base station sends a service request to NF1.
[1232] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1233] In some embodiments, the optional implementation of step S3813 can be referred to step S2717 in FIG. 2G and other associated parts in the embodiments related to FIG. 2G, which will not be repeated here.
[1234] Step S3814, NF1 sends the service request to NF3.
[1235] In some embodiments, NF3 is a fourth node.
[1236] In some embodiments, the service request comprises an identity of the base station or a type of the base station.
[1237] In some embodiments, the optional implementation of step S3814 can refer to step S2718 of FIG. 2G and other associated parts in the embodiments involved by FIG. 2G, which will not be repeated here.
[1238] Step S3815, NF3 sends a service response to NF1.
[1239] In some embodiments, the service response comprises an identity of the base station or a type of the base station.
[1240] In some embodiments, the optional implementation of step S3815 can refer to step S2720 of FIG. 2G and other associated parts in the embodiments involved by FIG. 2G, which will not be repeated here.
[1241] Step S3816, NF1 sends a service response to the base station.
[1242] In some embodiments, the service response comprises an identity of the base station or a type of the base station.
[1243] In some embodiments, the optional implementation of step S3816 can refer to step S2721 of FIG. 2G and other associated parts in the embodiments involved by FIG. 2G, which will not be repeated here.
[1244] The authorization method involved in the embodiments of the present disclosure can comprise at least one of steps S3801-S3816.
[1245] In some embodiments, steps S3801, S3802, S3803, S3804, S3805, S3806 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1246] In some embodiments, steps S3813, S3814, S3815, S3816 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1247] In some embodiments, steps S3809, S3810 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[1248] In the embodiments of the present disclosure, part or all of the steps and their optional implementations can be combined with part or all of the steps in other embodiments, or combined with the optional implementations of other embodiments.
[1249] In some embodiments, the embodiments do not limit the form of the messages involved. Alternatively, the request and response messages can be replaced by subscription and notification messages in specific implementation. For example, the communication device A requests the communication device B, and the communication device B sends a corresponding response message to the communication device A, or the communication device A subscribes to the communication device B, and the communication device B sends a corresponding notification message to the communication device A. In both ways, the communication device A can obtain the message from the communication device B.
[1250] In some embodiments, the steps of the embodiment of FIG. 3H can be implemented independently, or can be combined and implemented in any order without contradiction.
[1251] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device comprising units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another device is proposed, comprising units or modules for implementing the steps performed by the communication device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[1252] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize the functions of any of the above methods or the units or modules of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.
[1253] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the hardware circuit configuration. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[1254] FIG. 4A is a schematic diagram of a structure of a terminal according to an embodiment of the present disclosure. As shown in FIG. 4A, the terminal can include a transceiver 4101. In some embodiments, the transceiver 4101 is configured to send first authorization information to a first node or a third node, wherein the first authorization information includes authorization information provided by a user or a UE, and the first authorization information is used by the first node to determine whether to send first information to a second node or a first access network device according to the first authorization information and second authorization information obtained by the first node, and the second authorization information is used to indicate authorization information corresponding to a network function profile. Optionally, the transceiver is configured to perform at least one of the communication steps (for example, steps S2303, S2305, S2407, S2409, S2704, S2706, S2810, and S2812, but not limited thereto) of sending and / or receiving performed by the terminal in any of the above methods, details of which are not described herein again. Optionally, the terminal further includes a processing module, and the processing module is configured to perform at least one of the other steps (for example, steps S2302, S2406, S2703, and S2809, but not limited thereto) performed by the terminal 41 in any of the above methods, details of which are not described herein again.
[1255] In some embodiments, the first authorization information is configured by the user to the first node or the third node, or the first authorization information is configured by the UE to the first node or the third node.
[1256] In some embodiments, the first authorization information includes at least one of the following: user information, data type, data processing purpose, and purpose of processing data type.
[1257] In some embodiments,
[1258] The transceiver 4101 is configured to receive address information of the first node sent by the second node or the first access network device.
[1259] The transceiver 4101 is configured to send second information to the first node according to the address information, and the second information is used to indicate whether the second node or the first access network device is authorized for a data processing purpose or a purpose of processing data type.
[1260] In some embodiments, the terminal further includes a processing module.
[1261] The processing module is configured to determine whether the second node or the first access network device is authorized for a data processing purpose or a purpose of processing data type.
[1262] In some embodiments, the second authorization information is used to indicate authorization information of a fourth node.
[1263] In some embodiments, the authorization information of the fourth node comprises at least one of the following: the NF type of the second node or the NF type of the first access network device, the NF type of the fourth node or the NF instance ID of the fourth node, the service of the fourth node or the service operation of the fourth node.
[1264] In some embodiments, the first information comprises at least one of the following: a data type, a data processing purpose, a purpose of processing the data type, an NF instance ID of the first node.
[1265] FIG. 4B is a structural schematic diagram of the first node according to an embodiment of the present disclosure. As shown in FIG. 4B, the first node can comprise a transceiver module 4201 and a processing module 4202. In some embodiments, the transceiver module 4201 is configured to receive a first request sent by the second node or the first access network device, the first request being used to request first information; and the processing module 4202 is configured to send the first information to the second node or the first access network device when it is determined that the second node or the first access network device is authorized according to first authorization information and second authorization information, wherein the first authorization information comprises authorization information provided by a UE or a user, and the second authorization information is used to indicate authorization information corresponding to a network function profile.
[1266] Optionally, the transceiver module is configured to perform at least one of the communication steps (for example, steps S2103, S2107, S2207, S2304, S2308, S2308, S2312, S2408, S2412, S2504, S2508, S2610, S2705, S2711, S2715, but not limited thereto) of the sending and / or receiving performed by the first node in any of the above methods. Details are not described herein again. Optionally, the processing module is configured to perform at least one of the other steps (for example, steps S2102, S2106, S2206, S2311, S2411, S2503, S2507, S2609, S2710, S2714, but not limited thereto) performed by the first node in any of the above methods. Details are not described herein again.
[1267] In some embodiments, the first information comprises at least one of the following: a data type, a data processing purpose, a purpose of processing the data type, an NF instance ID of the first node.
[1268] In some embodiments, the first request comprises at least one of the following: user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing the data type, an NF type of the fourth node or an NF instance ID of the fourth node.
[1269] In some embodiments, the first authorization information is configured by a user to the first node or the third node, or the first authorization information is configured by the UE to the first node or the third node.
[1270] In some embodiments, the first authorization information comprises at least one of the following: user information, data type, data processing purpose, purpose of processing data type.
[1271] In some embodiments, the transceiver 4201 is configured to receive second authorization information sent by the third node.
[1272] In some embodiments, the second authorization information is used to indicate authorization information of the fourth node.
[1273] In some embodiments, the authorization information of the fourth node comprises at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service of the fourth node or service operation of the fourth node.
[1274] In some embodiments, the transceiver 4201 is configured to send a second request to the third node if any of the following is determined according to the first authorization information:
[1275] The data type in the first request and the purpose of processing data type are allowed;
[1276] The data processing purpose in the first request is allowed.
[1277] In some embodiments, the second request is used for the third node to determine the corresponding network function configuration file according to the NF type of the fourth node or the NF instance ID of the fourth node provided by the first node.
[1278] In some embodiments, the second request comprises at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service or service operation.
[1279] In some embodiments, the processing module 4202 is configured to:
[1280] According to the first authorization information and the second authorization information, if the first condition is not met, terminate the authorization process for the second node or the first access network device or send third information to the second node or the first access network device;
[1281] Wherein, the first request comprises a seventh request and an eighth request, the seventh request is used to request UE or user authorization, the eighth request is used to request network function authorization, the first condition comprises: the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information; the third information is used to indicate any of the following:
[1282] The second node or the first access network device is not authorized;
[1283] The second node or the first access network device fails in authorization;
[1284] A reason why the second node or the first access network device fails in authorization.
[1285] In some embodiments, the processing module 4202 is configured to:
[1286] According to the first authorization information and the second authorization information, if the first condition is not met, terminate the authorization procedure for the second node or the first access network device or send third information to the second node or the first access network device.
[1287] The first condition includes that a data processing purpose in the first request is allowed and the second node or the first access network device is allowed to request a service of the fourth node or a service operation of the fourth node, or a data type in the first request and a purpose of processing the data type are allowed and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node; and the third information is used to indicate any of the following:
[1288] The second node or the first access network device is not authorized;
[1289] The second node or the first access network device fails in authorization;
[1290] A reason why the second node or the first access network device fails in authorization.
[1291] In some embodiments, the transceiver module 4201 is configured to:
[1292] Receive second information sent by the UE, the second information being used to indicate whether the second node or the first access network device is authorized for a data processing purpose or for a purpose of processing a data type;
[1293] If the second node or the first access network device is authorized for the data processing purpose or for the purpose of processing the data type, send an authorization identifier to the UE.
[1294] FIG. 4C is a structural schematic diagram of the second node or the first access network device according to an embodiment of the present disclosure. As shown in FIG. 4C, the second node (3021) or the first access network device (202) can include a transceiver module 4301. In some embodiments, the transceiver module 4301 is configured to send a first request to the first node, the first request being used to request first information; and the transceiver module 4301 is configured to receive the first information sent by the first node, the first information being sent by the first node according to first authorization information and second authorization information, the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used to indicate authorization information corresponding to a network function profile.
[1295] Optionally, the transceiver module is configured to perform at least one of the communication steps (for example, steps S2101, S2108, S2201, S2205, S2208, S2301, S2306, S2313, S2401, S2405, S2410, S2413, but not limited thereto) of sending and / or receiving performed by the second node 3021 or the first access network device 202 in any of the above methods. Details are not described herein again.
[1296] In some embodiments, the first request includes at least one of the following: user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing the data type, an NF type of the fourth node, or an NF instance ID of the fourth node.
[1297] In some embodiments, the first authorization information is configured by a user to the first node or the third node, or the first authorization information is configured by the UE to the first node or the third node.
[1298] In some embodiments, the first authorization information includes at least one of the following: user information, a data type, a data processing purpose, or a purpose of processing the data type.
[1299] In some embodiments, the first information includes at least one of the following: a data type, a data processing purpose, a purpose of processing the data type, or an NF instance ID of the first node.
[1300] In some embodiments, the transceiver module 4301 is configured to send a third request to the third node, the third request being used to trigger the third node to send the second authorization information to the first node.
[1301] In some embodiments, the second authorization information is used to indicate authorization information of the fourth node.
[1302] In some embodiments, the authorization information of the fourth node comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service of the fourth node or a service operation of the fourth node.
[1303] In some embodiments, the transceiver 4301 is configured to: receive fourth information sent by the third node, the fourth information being used to indicate any one of the following: the second node or the first access network device is allowed to request a service or a service operation of the fourth node, or the second node or the first access network device is not allowed to request the service or the service operation of the fourth node.
[1304] In some embodiments, the transceiver 4301 is configured to: if the second node or the first access network device is authorized by the second authorization information, send the first request to the first node.
[1305] In some embodiments, the transceiver 4301 is configured to: if the second node or the first access network device is allowed to request the service or the service operation of the fourth node, send the first request to the first node.
[1306] In some embodiments, the processing module is further configured to: if the second node or the first access network device is not authorized by the second authorization information, determine not to send the first request to the first node.
[1307] In some embodiments, the processing module is further configured to: if the second node or the first access network device is not allowed to request the service or the service operation of the fourth node, determine not to send the first request to the first node.
[1308] In some embodiments, the transceiver 4301 is configured to: send address information of the first node to the UE.
[1309] In some embodiments, the transceiver 4301 is configured to: receive third information sent by the first node, the third information being used to indicate any one of the following:
[1310] The second node or the first access network device is not authorized;
[1311] The second node or the first access network device fails in authorization;
[1312] A reason why the second node or the first access network device fails in authorization;
[1313] The third information is sent by the first node when it is determined that the first condition is not met according to the first authorization information and the second authorization information, the first request includes a seventh request and an eighth request, the seventh request is used to request UE or user authorization, and the eighth request is used to request network function authorization, and the first condition includes that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information.
[1314] In some embodiments, the transceiver module 4301 is configured to:
[1315] receive third information sent by the first node, the third information being used to indicate any of the following:
[1316] the second node or the first access network device is not authorized;
[1317] the second node or the first access network device fails in authorization;
[1318] a reason why the second node or the first access network device fails in authorization;
[1319] The third information is sent by the first node when it is determined that the first condition is not met according to the first authorization information and the second authorization information, the first condition includes that a data type in the first request and a purpose of processing the data type are allowed, and the second node or the first access network device is allowed to request a service of the fourth node or a service operation of the fourth node.
[1320] FIG. 4D is a structural schematic diagram of a third node according to an embodiment of the present disclosure. As shown in FIG. 4D, the third node can include a transceiver module 4401. In some embodiments, the transceiver module 4401 is configured to receive a second request sent by the first node, or receive a third request sent by the second node or the first access network device; and the transceiver module 4401 is configured to send, to the first node, second authorization information used to indicate authorization information corresponding to a network function profile, and the second authorization information is used for the first node to determine to send first information to the second node or the first access network device according to the second authorization information and the obtained first authorization information, and the first authorization information includes authorization information provided by a UE or a user.
[1321] Optionally, the transceiver module is configured to perform at least one of the communication steps (for example, steps S2105, S2203, S2204, S2310, S2403, and S2404, but not limited thereto) of the sending and / or receiving performed by the third node in any of the methods described above. Optionally, the third node further includes a processing module configured to perform at least one of the other steps (for example, steps S2104, S2202, S2309, and S2402, but not limited thereto) of the third node in any of the methods described above.
[1322] In some embodiments, the first authorization information is configured to the first node or the third node by a user, or the first authorization information is configured to the first node or the third node by the UE.
[1323] In some embodiments, the first authorization information comprises at least one of the following: user information, data type, data processing purpose, purpose of processing data type.
[1324] In some embodiments, the second request is sent by the first node when any of the following is determined according to the first authorization information: the data type in the first request and the purpose of processing data type are allowed, the data processing purpose in the first request is allowed.
[1325] In some embodiments, the first information comprises at least one of the following: data type, data processing purpose, purpose of processing data type, NF instance ID of the first node.
[1326] In some embodiments, the second request comprises at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service or service operation; and / or, the third request comprises at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service or service operation.
[1327] In some embodiments, the second authorization information is used to indicate authorization information of the fourth node.
[1328] In some embodiments, the authorization information of the fourth node comprises at least one of the following: NF type of the second node or NF type of the first access network device, NF type of the fourth node or NF instance ID of the fourth node, service of the fourth node or service operation of the fourth node.
[1329] In some embodiments, further comprising a processing module, the processing module is configured to:
[1330] According to the NF type of the fourth node in the second request, obtain the network function configuration file of the fourth node; or, according to the NF instance ID of the fourth node in the third request, obtain the network function configuration file of the fourth node;
[1331] According to the network function configuration file of the fourth node, determine the second authorization information.
[1332] In some embodiments, the transceiver 4401 is configured to: send, to the second node or the first access network device, fourth information, the fourth information being used to indicate any of the following: the second node or the first access network device is allowed to request the service or the service operation of the fourth node, or the second node or the first access network device is not allowed to request the service or the service operation of the fourth node.
[1333] Figure 4E is a schematic diagram of a structure of a core network device according to an embodiment of the present disclosure. As shown in Figure 4E, the core network device can include a transceiver 4501. In some embodiments, the transceiver 4501 is configured to send, to the first node, a first request for first information, and send, to the first node, second authorization information for indicating authorization information corresponding to a network function profile when receiving a second request sent by the first node, and receive first information sent by the first node, the first information being sent by the first node according to the obtained first authorization information and the second authorization information, the first authorization information including authorization information provided by a UE or a user.
[1334] Optionally, the transceiver is configured to perform at least one of the communication steps, such as sending and / or receiving, of the core network device in any of the above methods, which will not be described herein.
[1335] Figure 4F is a schematic diagram of a structure of a second access network device according to an embodiment of the present disclosure. As shown in Figure 4F, the second access network device can include a transceiver 4601. In some embodiments, the transceiver 4601 is configured to send, to the second node, a fourth request for fifth information, the fourth request being used for the second node to send a first request to the first node, and receive the fifth information sent by the second node, the fifth information being dete...
Claims
1. An authorization method, characterized by, The method is performed by a first node, and the method comprises: receiving a first request sent by a second node or a first access network device, the first request being used for requesting first information; if it is determined that the second node or the first access network device is authorized according to first authorization information and second authorization information, sending the first information to the second node or the first access network device; the first authorization information comprises authorization information provided by a terminal UE or a user, and the second authorization information is used for indicating authorization information corresponding to a network function profile.
2. The method of claim 1, wherein, The first authorization information is configured to the first node or a third node by the user, or the first authorization information is configured to the first node or the third node by the UE.
3. The method according to claim 1 or 2, characterized in that, The first authorization information comprises at least one of the following: user information, a data type, a data processing purpose, and a purpose of processing the data type.
4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: receiving second authorization information sent by a third node.
5. The method of claim 4, wherein, The second authorization information is used for indicating authorization information of a fourth node.
6. The method of claim 5, wherein, The authorization information of the fourth node comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance identifier ID of the fourth node, a service of the fourth node, or a service operation of the fourth node.
7. The method according to any one of claims 1 to 6, characterized in that, The first information comprises at least one of the following: a data type, a data processing purpose, a purpose of processing the data type, and an NF instance ID of the first node.
8. The method according to claim 5 or 6, characterized in that, The first request comprises at least one of the following: user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing the data type, an NF type of the fourth node, or an NF instance ID of the fourth node.
9. The method according to any one of claims 4-8, characterized in that, The method further comprises: if any of the following is determined according to the first authorization information, sending a second request to the third node: a data type and a purpose of processing the data type in the first request are allowed; a data processing purpose in the first request is allowed.
10. The method of claim 9, wherein, The second request is used for the third node to determine a corresponding network function profile according to an NF type of the fourth node or an NF instance ID of the fourth node provided by the first node.
11. The method according to claim 9 or 10, characterized in that, The second request comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service or a service operation.
12. The method according to any one of claims 1 to 11, characterized in that, The method further comprises: if a first condition is not met according to the first authorization information and the second authorization information, terminating an authorization process for the second node or the first access network device or sending third information to the second node or the first access network device; The first request comprises a seventh request and an eighth request; The seventh request is used for requesting UE or user authorization, and the eighth request is used for requesting network function authorization; The first condition comprises that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information; The third information is used for indicating any of the following: the second node or the first access network device is not authorized; The second node or the first access network device fails in authorization; The second node or the first access network device fails in authorization.
13. The method according to any one of claims 1 to 11, characterized in that, The method further comprises: According to the first authorization information and the second authorization information, if the first condition is not met, terminating the authorization process of the second node or the first access network device or sending third information to the second node or the first access network device; The first condition comprises: the data processing purpose in the first request is allowed, and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node, or the data type in the first request and the purpose of processing the data type are allowed, and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node. The third information is used to indicate any of the following: The second node or the first access network device is not authorized; The second node or the first access network device fails in authorization; The second node or the first access network device fails in authorization.
14. The method of claim 3, wherein, The method further comprises: Receiving second information sent by the UE, the second information being used to indicate whether the second node or the first access network device is authorized for the data processing purpose or the purpose of processing the data type; If the second node or the first access network device is authorized for the data processing purpose or the purpose of processing the data type, sending the authorization identifier to the UE.
15. An authorization method, characterized by, The method is performed by the second node or the first access network device, and comprises: Sending a first request to a first node, the first request being used to request first information; Receiving the first information sent by the first node; The first information is sent by the first node according to first authorization information and second authorization information when determining to authorize the second node or the first access network device; the first authorization information comprises authorization information provided by a UE or a user, and the second authorization information is used to indicate authorization information corresponding to a network function profile.
16. The method of claim 15, wherein, The first authorization information is configured to the first node or a third node by the user, or the first authorization information is configured to the first node or the third node by the UE.
17. The method according to claim 15 or 16, characterized in that The first authorization information comprises at least one of the following: user information, data type, data processing purpose, and purpose of processing the data type.
18. The method according to any one of claims 15-17, characterized by, The first information comprises at least one of the following: data type, data processing purpose, purpose of processing the data type, and NF instance ID of the first node.
19. The method of claim 15 or 16, wherein, The method further comprises: Sending a third request to a third node, the third request being used for the third node to determine a corresponding network function profile according to an NF type of a fourth node or an NF instance ID of the fourth node provided by the first node.
20. The method according to any one of claims 15-19, characterized by, The second authorization information is used to indicate authorization information of the fourth node.
21. The method of claim 20, wherein, The authorization information of the fourth node includes at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service of the fourth node, or a service operation of the fourth node.
22. The method according to any one of claims 15-21, characterized in that, The first request includes at least one of the following: user information, a service or a service operation, a data type, a data processing purpose, a purpose of processing the data type, an NF type of the fourth node, and an NF instance ID of the fourth node.
23. The method according to any one of claims 15-22, characterized by, The method further includes: receiving fourth information sent by the third node, the fourth information being used to indicate any of the following: the second node or the first access network device is allowed to request a service of the fourth node or a service operation of the fourth node, or the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node.
24. The method according to any one of claims 15-23, characterized by, The sending of the first request to the first node includes: If the second node or the first access network device is authorized by the second authorization information, the first request is sent to the first node.
25. The method of claim 24, wherein, The sending of the first request to the first node includes: If the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node, the first request is sent to the first node.
26. The method of any one of claims 15-25, wherein, The method further includes: sending address information of the first node to the UE.
27. The method of any one of claims 15-26, wherein, The method further includes: receiving third information sent by the first node, the third information being used to indicate any of the following: the second node or the first access network device is not authorized; authorization of the second node or the first access network device fails; a reason for the authorization failure of the second node or the first access network device; The third information is sent by the first node when it is determined that a first condition is not met according to first authorization information and second authorization information, the first request includes a seventh request and an eighth request, the seventh request is used to request UE or user authorization, the eighth request is used to request network function authorization, and the first condition includes that the seventh request is allowed based on the first authorization information and the eighth request is allowed based on the second authorization information.
28. The method of any one of claims 15-27, wherein, The method further includes: receiving third information sent by the first node, the third information being used to indicate any of the following: the second node or the first access network device is not authorized; authorization of the second node or the first access network device fails; a reason for the authorization failure of the second node or the first access network device; The third information is sent by the first node when it is determined that a first condition is not met according to first authorization information and second authorization information, the first condition includes that a data processing purpose in the first request is allowed and the second node or the first access network device is allowed to request a service of the fourth node or a service operation of the fourth node, or a data type in the first request and a purpose of processing the data type are allowed and the second node or the first access network device is allowed to request the service of the fourth node or the service operation of the fourth node.
29. An authorization method, characterized by The method is performed by a third node, and the method comprises: receiving a second request sent by the first node, or receiving a third request sent by the second node or the first access network device; sending, to the first node, second authorization information, the second authorization information being used to indicate authorization information corresponding to a network function profile, and the second authorization information being used for the first node to send, to the second node or the first access network device, first information according to the second authorization information and first authorization information obtained by the first node, the first authorization information comprising authorization information provided by a user or a UE.
30. The method of claim 29, wherein, The first authorization information is configured to the first node or the third node by the user, or the first authorization information is configured to the first node or the third node by the UE.
31. The method of claim 29 or 30, wherein, The first authorization information comprises at least one of the following: user information, a data type, a data processing purpose, and a purpose of processing the data type.
32. The method of any one of claims 29-31, wherein, The second request comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service or a service operation; and / or The third request comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service or a service operation.
33. The method of any one of claims 29-32, wherein, The second authorization information is used to indicate authorization information of the fourth node.
34. The method of claim 33, wherein The authorization information of the fourth node comprises at least one of the following: an NF type of the second node or an NF type of the first access network device, an NF type of the fourth node or an NF instance ID of the fourth node, a service of the fourth node or a service operation of the fourth node.
35. The method of any one of claims 29-34, wherein, The first information comprises at least one of the following: a data type, a data processing purpose, a purpose of processing the data type, and an NF instance ID of the first node.
36. The method of any one of claims 29-35, wherein, The method further comprises: obtaining a network function profile of the fourth node according to the NF type of the fourth node in the second request, or obtaining a network function profile of the fourth node according to the NF instance ID of the fourth node in the third request; determining the second authorization information according to the network function profile of the fourth node.
37. The method of any one of claims 29-36, wherein, The method further comprises: sending, to the second node or the first access network device, fourth information used to indicate that the second node or the first access network device is allowed to request a service of the fourth node or a service operation of the fourth node, or the second node or the first access network device is not allowed to request the service of the fourth node or the service operation of the fourth node.
38. The method of any one of claims 29-37, wherein, The second request is sent by the first node when the first node determines that at least one of the following is allowed: the data type and the purpose of processing the data type in the first request, and the data processing purpose in the first request.
39. An authorization method, characterized by The method is performed by a second access network device, and the method comprises: sending a fourth request to the second node, the fourth request being used for requesting fifth information, the fourth request being used for the second node to send the first request to the first node; receiving fifth information sent by the second node, the fifth information being determined by the second node based on first information, the first information being sent by the first node to the second node when the first node determines to authorize the second access network device based on first authorization information and second authorization information, the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used for indicating authorization information corresponding to a network function profile.
40. The method of claim 39, wherein, The method further includes: sending a fifth request to the second node, the fifth request being used for requesting a service of the fourth node or a service operation of the fourth node, the fifth request being used for the second node to send a sixth request to the fourth node, the sixth request being used for requesting the service of the fourth node or the service operation of the fourth node, and the fifth information being included in both the fifth request and the sixth request. comprising:
41. A first node, the first node comprising: a transceiver, configured to receive a first request sent by a second node or a first access network device, the first request being used for requesting first information; a processing module, configured to send the first information to the second node or the first access network device when determining to authorize the second node or the first access network device based on first authorization information and second authorization information; the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used for indicating authorization information corresponding to a network function profile. comprising:
42. A second node or a first access network device, characterized by, a transceiver, configured to send a first request to a first node, the first request being used for requesting first information; the transceiver is further configured to receive the first information sent by the first node, the first information being sent by the first node when determining to authorize the second node or the first access network device based on first authorization information and second authorization information, the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used for indicating authorization information corresponding to a network function profile. comprising:
43. A third node, characterized in that, a transceiver, configured to receive a second request sent by a first node, or receive a third request sent by a second node or a first access network device; the transceiver is further configured to send second authorization information to the first node, the second authorization information being used for indicating authorization information corresponding to a network function profile, and the second authorization information being used for the first node to send first information to the second node or the first access network device when determining to authorize the second node based on the second authorization information and acquired first authorization information, the first authorization information including authorization information provided by a UE or a user. comprising:
44. A second access network device, comprising: a transceiver, configured to send a fourth request to a second node, the fourth request being used for requesting fifth information, the fourth request being used for the second node to send a first request to a first node; The transceiving module is further configured to receive fifth information sent by the second node, the fifth information being determined by the second node based on the first information, the first information being sent by the first node to the second node when determining to authorize the second access network device based on first authorization information and second authorization information, the first authorization information including authorization information provided by a UE or a user, and the second authorization information being used to indicate authorization information corresponding to a network function profile.
45. A first node, the first node comprising: Comprising: one or more processors; wherein the first node is configured to perform the authorization method of any one of claims 1-14.
46. A second node or a first access network device, characterized by, Comprising: one or more processors; wherein the second node or the first access network device is configured to perform the authorization method of any one of claims 15-28.
47. A third node, characterized in that, Comprising: one or more processors; wherein the third node is configured to perform the authorization method of any one of claims 29-38.
48. A second access network device, comprising: Comprising: one or more processors; wherein the second access network device is configured to perform the authorization method of claim 39 or 40.
49. A communication system, characterized by Comprising a first node and a core network device, wherein the first node is configured to implement the authorization method of any one of claims 1-14, and the core network device is configured to implement the authorization method of claims 15-28 or 29-38.
50. A communication system, characterized by Comprising a first node, a first access network device, and a core network device, wherein the first node is configured to implement the authorization method of any one of claims 1-14, the first access network device is configured to implement the authorization method of any one of claims 15-28, and the core network device is configured to implement the authorization method of claims 29-38.
51. A communication system, characterized by Comprising a first node, a second access network device, and a core network device, wherein the first node is configured to implement the authorization method of any one of claims 1-14, the core network device is configured to implement the authorization method of claims 15-28 or 29-38, and the second access network device is configured to implement the authorization method of claim 39 or 40.
52. A storage medium, the storage medium storing instructions, wherein, When the instructions are run on a communication device, the communication device is caused to perform the authorization method of any one of claims 1-14 or 15-28 or 29-38 or 39 or 40.
53. A program product, characterized by Comprising programs and / or instructions, which, when executed by a communication device, cause the communication device to perform the authorization method of any one of claims 1-14 or 15-28 or 29-38 or 39 or 40.
Citation Information
Patent Citations
Method, device and system for calling network function services
CN109587187A
Equipment association method and device
CN117633851A
Communication method and communication device
CN118118906A
Authorization method and device
WO2024103356A1