Wireless communication method and communication device

By storing encrypted data in the data plane of the communication system and introducing blockchain and smart contract mechanisms, the problem of secure storage and retrieval of data plane is solved, ensuring the security and trustworthiness of data. It is applicable to various communication systems such as 5G, 6G, and satellite communication.

WO2026065298A1PCT designated stage Publication Date: 2026-04-02GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

In communication systems, how can we ensure secure data storage and retrieval at the data plane, especially in cross-domain storage and retrieval scenarios, to guarantee data security and non-repudiation?

Method used

By storing encrypted data in the data plane and introducing blockchain and smart contract mechanisms, the immutability and traceability of the data are ensured. At the same time, authentication and authorization are performed through the data plane access controller and data storage function network elements to ensure the secure storage and retrieval of the data.

Benefits of technology

It enables secure storage and retrieval of data on the data plane, improving data security and trustworthiness, and preventing data leakage and unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024122459_02042026_PF_FP_ABST
    Figure CN2024122459_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a wireless communication method and a communication device. The wireless communication method comprises: a first device receives a first message sent by a second device, wherein the first message is used for requesting to store first data; and the first device sends a second message to a third device, wherein the second message is used for requesting to store the first data, the first device is used for performing access authentication and / or access control on a data plane, the third device is used for providing a data storage function for the data plane, and the stored first data is encrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Method and communication device for wireless communication TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, and more particularly, to a method and a communication device for wireless communication. BACKGROUND

[0002] In some scenarios, a communication system needs to support collection, storage, processing, etc. of a large amount of data, and provide the data to internal functions of the network or external functions of the network efficiently and credibly. For this purpose, the related art proposes that data operations can be implemented based on a data plane. When data operations are performed in the data plane, how to implement secure storage and invocation of data is a problem to be solved urgently.

[0003] SUMMARY

[0004] The present application provides a method and a communication device for wireless communication. The following introduces each aspect of the present application.

[0005] In a first aspect, a method for wireless communication is provided, comprising: receiving, by a first device, a first message sent by a second device, the first message being used to request storage of first data; and sending, by the first device, a second message to a third device, the second message being used to request storage of the first data; wherein the first device is used for access authentication and / or access control of a data plane, the third device is used to provide a data storage function of the data plane, and the stored first data is encrypted data.

[0006] In a second aspect, a method for wireless communication is provided, comprising: receiving, by a first device, a first request sent by a fourth device, the first request being used to request invocation of first data; sending, by the first device, a second request to a second device, the second request being used to request the first data; receiving, by the first device, a response message of the second request sent by the second device, the response message of the second request comprising first data, the first data being encrypted by a key provided by the fourth device; wherein the first device is used for access authentication and / or access control of a data plane.

[0007] In a third aspect, a method for wireless communication is provided, comprising: sending, by a second device, a first message to a first device, the first message being used to request storage of first data; wherein the first device is used for access authentication and / or access control of a data plane, and the stored first data is encrypted data.

[0008] In a fourth aspect, a method of wireless communication is provided that includes receiving, by a second device, a second request transmitted by a first device, the second request being for requesting first data; transmitting, by the second device, a response message of the second request to the first device, the response message of the second request including the first data encrypted with a key provided by a fourth device; and wherein the first device is configured for access authentication and / or access control in a data plane, and the fourth device is a data consumer invoking the first data.

[0009] In a fifth aspect, a method of wireless communication is provided that includes transmitting, by a fourth device, a third message to a first device, the third message being for requesting invoking first data; and receiving, by the fourth device, a fourth message transmitted by the first device, the fourth message including the encrypted first data; and wherein the first device is configured for access authentication and / or access control in a data plane.

[0010] In a sixth aspect, a method of wireless communication is provided that includes transmitting, by a fourth device, a first request to a first device, the first request being for requesting invoking first data; and receiving, by the fourth device, the first data transmitted by the first device, the first data being encrypted with a key provided by the fourth device; and wherein the first device is configured for access authentication and / or access control in a data plane.

[0011] In a seventh aspect, a communication device is provided, the communication device being a first device, the communication device comprising: a first receiving module configured to receive a first message transmitted by a second device, the first message being for requesting storing first data; and a first transmitting module configured to transmit a second message to a third device, the second message being for requesting storing the first data; and wherein the first device is configured for access authentication and / or access control in a data plane, and the third device is configured to provide a data storage function in the data plane, and the stored first data is encrypted data.

[0012] In an eighth aspect, a communication device is provided, the communication device being a first device, the communication device comprising: a first receiving module configured to receive a first request transmitted by a fourth device, the first request being for requesting invoking first data; a transmitting module configured to transmit a second request to a second device, the second request being for requesting the first data; and a second receiving module configured to receive a response message of the second request transmitted by the second device, the response message of the second request including the first data encrypted with a key provided by the fourth device; and wherein the first device is configured for access authentication and / or access control in a data plane.

[0013] In a ninth aspect, a communication device is provided, the communication device being a second device, the communication device comprising: a first sending module configured to send a first message to a first device, the first message being used to request storing of first data; wherein the first device is configured to perform access authentication and / or access control in a data plane, and the first data to be stored is encrypted data.

[0014] In a tenth aspect, a communication device is provided, the communication device being a second device, the communication device comprising: a receiving module configured to receive a second request sent by a first device, the second request being used to request first data; and a sending module configured to send a response message of the second request to the first device, the response message of the second request comprising the first data encrypted by a key provided by a fourth device; wherein the first device is configured to perform access authentication and / or access control in a data plane, and the fourth device is a data consumer that invokes the first data.

[0015] In an eleventh aspect, a communication device is provided, the communication device being a fourth device, the communication device comprising: a first sending module configured to send a third message to a first device, the third message being used to request invoking first data; and a receiving module configured to receive a fourth message sent by the first device, the fourth message comprising encrypted first data; wherein the first device is configured to perform access authentication and / or access control in a data plane.

[0016] In a twelfth aspect, a communication device is provided, the communication device being a fourth device, the communication device comprising: a sending module configured to send a first request to a first device, the first request being used to request invoking first data; and a receiving module configured to receive the first data sent by the first device, the first data being encrypted by a key provided by the fourth device; wherein the first device is configured to perform access authentication and / or access control in a data plane.

[0017] In a thirteenth aspect, a communication device is provided, comprising a processor, a memory, and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer programs in the memory to cause the communication device to perform some or all of the steps in the method of any one of the first aspect to the sixth aspect.

[0018] In a fourteenth aspect, an embodiment of the present application provides a communication system, comprising the communication device described above. In another possible design, the system can further comprise other devices interacting with the communication device in the scheme provided by an embodiment of the present application.

[0019] In a fifteenth aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program. The computer program causes a computer to perform some or all of the steps of the method in each of the aspects.

[0020] In a sixteenth aspect, an embodiment of the present application provides a computer program product. The computer program product includes a non-transitory computer readable storage medium storing a computer program. The computer program is operable to cause a computer to perform some or all of the steps of the method in each of the aspects. In some implementations, the computer program product can be a software installation package.

[0021] In a seventeenth aspect, an embodiment of the present application provides a chip. The chip includes a memory and a processor. The processor can invoke and run a computer program from the memory to implement some or all of the steps described in the method of each of the aspects.

[0022] In an embodiment of the present application, the first data stored by the second device (i.e., the data source) to the data plane is encrypted data. In this way, when the data consumer wants to invoke the first data, the first data needs to be authorized by the first device (the control network element of the data plane) and / or the second device, which is beneficial to ensure the secure storage and invocation of the first data in the data plane. BRIEF DESCRIPTION OF DRAWINGS

[0023] FIG. 1 is an example diagram of a system architecture of a wireless communication system to which embodiments of the present application can be applied.

[0024] FIG. 2 is an example diagram of a security architecture of 3GPP.

[0025] FIG. 3 is an example diagram of a communication system architecture including a data plane according to an embodiment of the present application.

[0026] FIG. 4 is a flow diagram of data storage of a data plane according to an embodiment of the present application.

[0027] FIG. 5 is a flow diagram of a method of wireless communication according to an embodiment of the present application.

[0028] FIG. 6 is a flow diagram of a method of wireless communication according to another embodiment of the present application.

[0029] FIG. 7 is a flow diagram of a method of wireless communication according to yet another embodiment of the present application.

[0030] FIG. 8 is a flow diagram of a method of wireless communication according to yet another embodiment of the present application.

[0031] FIG. 9 is a flow diagram of a method of wireless communication according to yet another embodiment of the present application.

[0032] FIG. 10 is a flow diagram illustrating a method of wireless communication, according to another embodiment of the present disclosure.

[0033] FIG. 11 is a flow diagram illustrating a method of wireless communication, according to another embodiment of the present disclosure.

[0034] FIG. 12 is a flow diagram illustrating a method of wireless communication, according to another embodiment of the present disclosure.

[0035] FIG. 13 is a flow diagram illustrating a method of wireless communication, according to another embodiment of the present disclosure.

[0036] FIG. 14 is a schematic diagram illustrating a structure of a communication device, according to an embodiment of the present disclosure.

[0037] FIG. 15 is a schematic diagram illustrating a structure of a communication device, according to another embodiment of the present disclosure.

[0038] FIG. 16 is a schematic diagram illustrating a structure of a communication device, according to another embodiment of the present disclosure.

[0039] FIG. 17 is a schematic diagram illustrating a structure of a communication device, according to another embodiment of the present disclosure.

[0040] FIG. 18 is a schematic diagram illustrating a structure of a communication device, according to another embodiment of the present disclosure.

[0041] FIG. 19 is a schematic diagram illustrating a structure of a communication device, according to another embodiment of the present disclosure.

[0042] FIG. 20 is a schematic diagram illustrating a structure of a communication device, according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0043] Communication system architecture

[0044] FIG. 1 is an example of a system architecture of a communication system 100 to which embodiments of the present disclosure are applicable. The system architecture shown in FIG. 1 can include terminal devices, access network (AN) devices, and network elements in a core network.

[0045] It should be understood that the technical solutions of the embodiments of the present disclosure can be applied to various communication systems, for example, a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), and the like. The technical solutions provided by the present disclosure can also be applied to future communication systems, such as a 6th generation mobile communication system, a satellite communication system, and the like.

[0046] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), an MT, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless terminal, a user agent or a user apparatus. The terminal device in the embodiments of the present application can refer to a device providing voice and / or data connectivity for a user, and can be used to connect people, things and machines, such as handheld devices with wireless connection function, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a scheduling entity, which provides sidelink signals between terminal devices in vehicle-to-everything (V2X) or device to device (D2D), etc. For example, a cellular phone and a car communicate with each other using sidelink signals. The cellular phone and the smart home device communicate with each other without relaying the communication signals through the base station.

[0047] The access network device can be an access device through which a terminal device accesses the network architecture wirelessly, and is mainly responsible for radio resource management, quality of service (QoS) management, data compression and encryption, and the like on the air interface side. The access network device can also be referred to as a radio access network (RAN) device, for example, the access network device can be a base station. The base station can broadly cover various names in the following or replace the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, and the like. The base station can be a macro base station, a micro base station, a relay node, a donor node, or the like, or a combination thereof. The base station can also refer to a communication module, modem, or chip used in the aforementioned device or apparatus. The base station can also be a mobile switching center and a device that performs the function of a base station in D2D, V2X, machine-to-machine (M2M) communication, a network side device in a 6G network, a device that performs the function of a base station in a future communication system, and the like. The base station can support networks of the same or different access technologies. Embodiments of the present application do not limit the specific technology and specific device form adopted by the access network device.

[0048] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, the helicopter or the drone can be configured to act as a device that communicates with another base station.

[0049] The type of the network element in the core network can include a user plane function (UPF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, a policy control function (PCF) network element, a data network (DN), a network slice selection function (NSSF), an authentication server function (AUSF), a unified data management (UDM), and the network exposure function (NEF). Among them, the UPF network element is mainly responsible for the transmission of user data, and other network elements can be referred to as control plane function network elements, which are mainly responsible for authentication, authorization, registration management, session management, mobility management, and policy control, etc., to ensure reliable and stable transmission of user data. For related introduction of UPF, AMF, SMF, PCF, NSSF, etc., please refer to related technologies, and for the sake of brevity, no longer description is given here.

[0050] In addition, some networks (for example, 5G networks) also add a network data analysis function (NWDAF) in the core network. The NWDAF can collect data from various network elements, network management systems, etc. in the core network, and perform big data statistics, analysis or intelligent data analysis, so as to obtain network side analysis or prediction data, and then assist various network elements to more effectively control terminal device access according to the data analysis result.

[0051] In some communication systems (for example, 5G systems, 6G systems, etc.), the network elements in the core network can also be referred to as network functions (NFs).

[0052] In the system architecture shown in FIG. 1, one of the most important features is that these system architectures include a service based architecture (SBA), that is, a service provider (such as a network element in the core network) can provide specific services, and other network elements (consumers) can call through defined API interfaces.

[0053] It should be noted that each network element in FIG. 1 can be a network element in a hardware device, a software function running on a dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). It should be noted that in the network architecture shown in FIG. 1, only the network elements included in the entire network architecture are exemplarily illustrated. In the embodiments of the present application, the network elements included in the entire network architecture are not limited.

[0054] Those skilled in the art can understand that the network architecture shown in FIG. 1 does not constitute a limitation on the network architecture, and in actual implementation, the network architecture can include more or fewer network elements than those shown, or some network elements are combined, etc. It should be understood that the AN or RAN is represented in the form of (R)AN in FIG. 1.

[0055] 3GPP trust domain

[0056] FIG. 2 is an example diagram of a 3GPP security architecture. As shown in FIG. 2, 3GPP divides the security domains in the security architecture into six categories (i.e., categories I-VI), and the following describes the six categories of security domains.

[0057] Category I: Network access security. Network access security includes a set of security functions that enable a terminal device to securely authenticate and access services through a network, including 3GPP access and non-3GPP access, and in particular, to prevent attacks on interfaces (such as wireless interfaces). In addition, network access security also includes secure context transfer from a service network (SN) to an access network (AN) to achieve access security.

[0058] Category II: Network domain security. Network domain security includes a set of security functions that enable network nodes to securely exchange signaling data and user plane data.

[0059] Category III: User domain security. User domain security includes a set of security functions that ensure the security of user access to mobile devices.

[0060] Category IV: Application domain security. Application domain security includes a set of security functions that enable applications in the user domain and the provider domain to securely exchange messages.

[0061] Category V: SBA domain security. SBA domain security includes a set of security functions that enable NFs of the SBA architecture to securely communicate within the service network domain and with other network domains. These functions include network function registration, discovery, and authorization security aspects, as well as protection of service-based interfaces.

[0062] Category VI: Visibility and configurability of security. Visibility and configurability of security include a set of functions that enable users to understand whether security functions are running.

[0063] Data plane (DP)

[0064] In some scenarios (for example, practical experience of 5G network intelligence), it is very difficult to obtain data, and the quality of data is difficult to guarantee. On the one hand, the data collection based on network management also has the problems of less data types, long collection period (15 min), non-uniform data format, naming and calculation method of different manufacturers, which leads to difficulty in opening network management data. On the other hand, it is more difficult to collect data from terminal devices, because collecting data from terminal devices may lead to leakage of private data and reduce the security of data. In addition, some communication systems (such as 6G system, future communication system) can provide support for artificial intelligence / machine learning (AI / ML) and integrated sensing and communication (ISAC) technologies. In this way, the communication system needs to support the collection, storage, processing, analysis and other operations of a large amount of data, and provide the data to the internal or external functions of the network conveniently and efficiently.

[0065] To solve the above problems, in some network architectures (for example, 6G network architecture), a scheme of adding a “data plane” is proposed. In some implementation modes, the data elements in the data plane will cover internal and external data of the network, including service data, user data, network data, sensing data, external data and the like.

[0066] In some implementation modes, the basic data service includes data collection, data preprocessing, data storage, data access, data sharing and collaboration and the like. The basic data service can have the following characteristics: supporting trusted authentication, authorization and access, efficient data storage and management, on-demand data collection and data preprocessing, and opening external data. That is, the data plane can include one or more network elements that provide basic data services for the above data elements, or in other words, the data plane includes one or more functions (or network elements) to support one or more of the following data services: trusted between data source and data consumer, flexible data collection, data opening, data preprocessing, data storage, data tracking.

[0067] To facilitate understanding, the data plane of the embodiments of the present application is introduced first.

[0068] In some embodiments, the data plane can be used to support one or more of the following functions: trusted data collection, trusted data storage, trusted data processing, trusted data access, trusted data sharing. It should be understood that the name of the data plane is not limited in the embodiments of the present application, for example, the data plane can also be referred to as a "data plane", a "data network element set", or a "data service plane", etc. In future communication architectures, the name can be replaced by the name of a network element with the same or similar function in a future communication system. For ease of description, the embodiments of the present application take the data plane as an example for introduction.

[0069] FIG. 3 shows an example diagram of a communication system architecture including a data plane according to an embodiment of the present application. As shown in FIG. 3, the data plane can include a network element 1 and / or a network element 2. In some implementations, the network element 1 is configured to provide data operation functions of the data plane, or in other words, the network element 1 is configured to operate data in the data plane. The embodiments of the present application do not limit the data operation functions of the data plane provided by the network element 1, and exemplary, the network element 1 can process data transaction requests, such as storing data, calling data, etc. In order to guarantee the non-tamperability, traceability and trustworthiness of data, the network element 1 can introduce related functions of a blockchain smart contract. For example, the network element 1 can cooperate with other peer nodes to verify the consistency of transaction data, and together with other nodes in the blockchain, provide distributed storage. For another example, the network element 1 can add a successfully verified data transaction (through a smart contract and a consensus algorithm) to a newly created block, and link the block to the blockchain. For another example, the network element 1 can update and maintain a data ledger corresponding to each node, thereby ensuring the tracking of each data transaction. For another example, the network element 1 can open an API interface, so that the network element 2 can call the interface and the network element 1 to perform a data service based on the blockchain. It should be noted that data provided by a data source or data called by a data consumer can be referred to as a data transaction, and the data transaction can be implemented through the network element (such as the network element 1 and / or the network element 2) of the data plane.

[0070] The embodiments of the present application do not limit the name of the network element 1. Exemplarily, the name of the network element 1 can include one or more of the following: a data plane operation network element, a data plane repository (DPR) network element, a data plane repository function (DPRF), a data plane operation infrastructure, a data plane repository infrastructure, etc. Of course, the network element 1 can also be other names, such as the name of a network element with the same or similar function as the network element 1 in a future communication system.

[0071] In some embodiments, the network element 2 is configured to authenticate and / or control data plane access, or in other words, the network element 2 can act as an interface between data in the communication system and data operation network elements (e.g., the network element 1) in the data plane. Thus, the network element 2 can also be referred to as a data plane access controller (DPAC). Of course, the network element 2 can also be referred to as one or more of the following in the embodiments of the present application: a data plane management network element, a data plane interface, a data plane control network element, and the embodiments of the present application are not limited in this regard.

[0072] In some embodiments, the network element 2 can be located in the core network, that is, the network element 2 can be a network element in the core network. However, the embodiments of the present application are not limited in this regard. For example, one or more network elements 2 can correspond to different domains to authenticate and / or control data plane access. As an example, one or more network elements 2 can correspond to a terminal device domain, one or more network elements 2 can correspond to an access network domain, and so on.

[0073] It should be noted that in the embodiments of the present application, the function corresponding to the network element 2 can be implemented by enhancing the data collection coordination function (DCCF). That is, the network element 2 can be one network element with the DCCF. Of course, in the embodiments of the present application, the network element 2 can be a separate network element in the core network.

[0074] Referring back to FIG. 3, the network element 2 in the data plane can communicate with the control plane (CP) through a service-based interface. Taking the network element 2 as a DPAC as an example, the service-based interface can be denoted as Ndpac. In some embodiments, the network element 2 and the network element 1 can be connected based on the service-based interface.

[0075] In some embodiments, the terminal device and / or the access network device can access the core network based on a reference point (e.g., N1, N2 interface), as shown in option 1 of FIG. 3. In some embodiments, the terminal device and / or the access network device can access the core network based on a service-based interface, as shown in option 2 of FIG. 3.

[0076] After introducing the data plane, the data plane can collect and store data of the data source. It should be noted that the data can also be referred to as metadata, for example, the data of the data source can be referred to as the metadata of the data source. The data storage process of the data plane will be introduced below in conjunction with FIG. 4. As shown in FIG. 4, the data storage process of the data plane can include steps S410 to S460.

[0077] At step S410, the data source sends a DPAC_MetaTrans_Create / Update_Request to the DPAC to request storing the metadata in the data plane. In some embodiments, the data source can be configured to proactively store the metadata in the data plane once a predefined condition is met.

[0078] At step S420, the DPAC verifies the legitimacy of the data source’s access.

[0079] At step S431, if the data source’s verification is passed, the DPAC can send a DPAC_MetaTrans_Create / Update_Response to the data source to indicate that the access is legitimate.

[0080] At step S432, if the data source’s verification is failed, the DPAC can send a DPAC_MetaTrans_response to the data source to indicate that the access is not legitimate.

[0081] In some embodiments, if the data source’s verification is passed, the DPAC can detect the metadata profile based on the Metadata Catalogue to confirm whether the metadata has been stored in the DPRF. In some embodiments, if the DPAC confirms that the metadata is not stored in the DPRF, the DPAC can perform step S441.

[0082] At step S441, the DPAC sends a DPRF_MetaTrans_Create / Update_Request to the DPRF to request storing the metadata in the data plane. In some embodiments, the second message can include the metadata profile and the metadata.

[0083] At step S442, the DPRF performs integrity processing on the metadata to ensure the integrity of the metadata on the blockchain.

[0084] At step S443, the DPRF sends a DPRF_MetaTrans_Create / Update_Response to the DPAC to indicate the storage of the metadata. In some embodiments, after the DPRF stores the metadata in the data plane, the DPRF can update the Metadata Catalogue and send the DPRF_MetaTrans_Create / Update_Response to the DPAC.

[0085] At step S450, the DPAC processes the status of the transaction. For example, the DPAC can update the Metadata Catalogue.

[0086] At step S460, the DPAC sends a DPAC_MetaTrans_Create / Update_Response to the data source to indicate that the metadata storage is successful.

[0087] On one hand, the data collected by the data plane from the data source can contain private data (such as perception measurement results, perception results) or high-value data (such as AI / ML models, algorithms, and other vendor private data) of the data source. The network element (such as network element 1) in the data plane can store such data, but it cannot be considered as a fully trusted entity for storing the above-mentioned data itself. On the other hand, in the scenario where the blockchain and the smart contract are deployed in the data plane, the deployment of the blockchain and the smart contract can guarantee the data trustworthiness in the data plane, the traceability and non-repudiation of data transactions, but there is still a need for secure storage and secure invocation of data. In addition, there are many scenarios of cross-domain storage and cross-domain invocation in the data plane, and in the cross-domain scenario, there is a need for secure storage and secure invocation of data. For example, the data source is a terminal device, and the terminal device can store perception measurement data, AI / ML models, AI algorithm information, and the like in the data plane. The terminal device and the network element in the data plane belong to different domains. For another example, the data source is a perception node (such as a terminal device, a base station, a perception network element, an NWDAF, and the like), and the perception node can store perception data related to a single terminal device or multiple terminal devices in the data plane. The perception node and the network element in the data plane can belong to different domains. For another example, the data source, the network element in the data plane, and the data consumer can belong to different vendors and operators (such as PLMNs), such as the data source is a network element (such as an AI / ML model production function) in the core network. The network element 1 and the data consumer can belong to different vendors or operators than the data source.

[0088] As can be seen from the above description, after introducing the data plane, how to realize the secure storage and invocation of data when operating in the data plane is a problem to be solved urgently.

[0089] To solve the above problem, embodiments 1 and 2 are provided, which can ensure that the first data stored from the data source to the data plane is encrypted data, thereby facilitating the secure storage and invocation of the first data in the data plane. Embodiments 1 and 2 are introduced as follows.

[0090] Embodiment 1:

[0091] FIG. 5 is a flow diagram of a method of wireless communication provided by an embodiment of the present application. The method shown in FIG. 5 is introduced from the perspective of the interaction of the first device, the second device, and the third device.

[0092] In some embodiments, the first device can be used for access authentication and / or access control in the data plane. For example, the first device can be the network element 2 described above, and the introduction of the first device can refer to the introduction of the network element 2 described above, which will not be repeated here.

[0093] In some embodiments, the second device is a data source, which can provide data. The second device (i.e., the data source) can be any mobile communication system entity. For example, the second device can include one or more of the following: a terminal device, an access network device, a network element in a core network, an operation administration and maintenance (OAM) device, a third-party server, and the like.

[0094] In some embodiments, the data of the second device can be data generated by the second device. However, the embodiments of the present application are not limited thereto, for example, the data of the second device can be data perceived or acquired by the second device.

[0095] In some embodiments, the third device can be used to provide data storage function in the data plane. For example, the third device can be the network element 1 described above, and the introduction of the third device can refer to the introduction of the network element 1 described above, which will not be repeated here.

[0096] The method shown in FIG. 5 can include steps S510 and S520, which will be introduced below.

[0097] In step S510, the second device sends a first message to the first device. The first message can be used to request to store first data. For example, the first message can be used to request to store the first data in the data plane.

[0098] As an implementation manner, the first message can be DPAC_MetaTrans_Create / Update_Request.

[0099] In some embodiments, the first data contained in the first message is encrypted data. That is, the second device can first encrypt the data to be stored, and then send the encrypted data to the first device to store the encrypted data to the data plane.

[0100] In some embodiments, the first data contained in the first message is not encrypted. In this case, the first device can encrypt the first data after receiving the first data, and store the encrypted data to the data plane.

[0101] In some embodiments, the first message can comprise first information, the first information being used to decrypt the first data. Thus, in some embodiments, the first information can also be referred to or understood as a security parameter of the first data. For example, in a case where the first data comprised in the first message is encrypted data, the first information can be comprised in the first message.

[0102] The present embodiments do not make a specific limitation on the first information, as long as it can be used to decrypt the first data. Exemplarily, the first information can comprise one or more of the following: a first key, a first parameter, a first identifier. As an example, the first information comprises the first key. As another example, the first information comprises the first parameter. As yet another example, the first information comprises the first identifier. As yet another example, the first information comprises the first key and the first parameter. As yet another example, the first information comprises the first identifier and the first parameter.

[0103] The first key can be used to decrypt the first data, i.e., the first key is a decryption key of the first data. In some embodiments, the first key can be the same as a key used to encrypt the first data, i.e., the encryption key of the first data and the decryption key of the first data are symmetric keys, so as to ensure the efficiency of encryption and / or decryption. For example, in a case where the data amount of the first data is large, in order to ensure the efficiency of encryption and / or decryption, the encryption key of the first data and the decryption key of the first data can be symmetric keys. However, the present embodiments are not limited thereto, for example, the first key and the key used to encrypt the first data can be asymmetric keys. Or, the first key and the key used to encrypt the first data can be a key pair, the key pair comprising a public key and a private key, the private key being used for encryption and the public key being used for decryption.

[0104] In some embodiments, the first key can be a key provided by the second device. For example, in a case where the first data comprised in the first message is encrypted data, the first key can be a key provided by the second device.

[0105] In some embodiments, the first key can be a key provided by the first device. For example, in a case where the first data comprised in the first message is not encrypted, and the first data is stored to the data plane after being encrypted by the first device, the first key can be a key provided by the first device. However, the present embodiments are not limited thereto, for example, in a case where the first data comprised in the first message is not encrypted, the first device can also encrypt the first data by using a key provided by the second device.

[0106] The embodiments of the present application do not limit the generation manner of the first key. As an implementation manner, the first key can be generated by the second device. As another implementation manner, the first key can be generated by the first device. As still another implementation manner, the first key can be a shared key between the first device and the second device. As still another implementation manner, the first key can be a shared key between the second device and the terminal device. It should be noted that the first key can be a shared key between the second device and the terminal device because, in some application scenarios, the data generated by the second device can be related to one or more terminal devices. In this scenario, although the first data is not generated by the terminal device, such data is related to the terminal device, and therefore a security parameter related to the terminal device (for example, the second device uses a shared key between the terminal device as the first key) can be used. The embodiments of the present application do not limit the data related to the terminal device, and exemplarily, the data related to the terminal device can include one or more of the following: perception measurement data generated by a perception node, a model (such as an AI-based positioning accuracy enhancement model, a beam model, a CSI model, etc.) generated by training channel measurement data of the terminal device, and inference generated by using data of the terminal device.

[0107] For example, in the case where the first data included in the first message is encrypted data, the first key can be generated by the second device, or can be a shared key between the first device and the second device, or can be a shared key between the second device and the terminal device.

[0108] For another example, in the case where the first data included in the first message is not encrypted, the first key can be generated by the first device, or can be generated by the second device, or can be a shared key between the first device and the second device.

[0109] In some embodiments, the first key can be generated based on a related parameter of the data stored to the data plane by the second device. The embodiments of the present application do not limit the related parameter of the data for generating the first key. Exemplarily, the related parameter of the data for generating the first key can include one or more of the following: a type of the data stored to the data plane, a service type corresponding to the data stored to the data plane. That is, in some embodiments, the first key can be generated based on the type of the data stored to the data plane by the second device and / or the service type corresponding to the data. As an implementation manner, the first key can be generated based on one or more of the following parameters: a first parameter, a second parameter, and a third parameter. The second parameter refers to a key (i.e., a seed key) held by the first device or the second device. The third parameter refers to a related parameter of the data stored to the data plane by the second device, such as a type of the data, a service type corresponding to the data, etc.

[0110] In some embodiments, the first key can be generated based on a key generation function. Exemplarily, assuming the first key is denoted as K, the first key can be denoted as K = F (the second parameter, the third parameter, the first parameter), F denoting the key generation function.

[0111] It should be noted that one device (e.g., the second device, the first device) can encrypt different data with the same key, including data with different content, data generated at different times. Alternatively, one device can also encrypt different data with different keys. As an example, different types of data are encrypted using different keys, and as another example, data generated at different times is encrypted using different keys.

[0112] The first parameter can be used to indicate the freshness of the first data, and thus the first parameter can also be referred to as a freshness parameter or a freshness value. For example, the first parameter can be used to indicate the freshness of the encrypted first data.

[0113] Embodiments of the present application do not make specific limitations on the first parameter. Exemplarily, the first parameter can include one or more of the following: a nonce, a count value, a sequence number, etc.

[0114] The first identifier can be used to indicate the first key for decrypting the first data. Alternatively, the first identifier can be used by the recipient (e.g., the first device, the data consumer) to identify the first key for decrypting the first data. Subsequently, the first device or the data consumer can request the first key from the second device (or the terminal device) by using the first identifier. Alternatively, the first device can find the first key by using the first identifier, etc. For example, in the case of encryption of the first data carried in the first message, the second device can send the first identifier to the first device, so that the first device or the data consumer can use the first identifier to request the first key from the second device (or the terminal device).

[0115] In some embodiments, when the first message includes the first information, the first device can store the first information.

[0116] In some embodiments, the first message can include a profile of the first data. The profile of the first data will be described below and will not be described here in detail.

[0117] In step S520, the first device sends a second message to the third device. The second message can be used to request storage of the first data. As an implementation, the second message can be DPRF_MetaTrans_Create / Update_Request.

[0118] In some embodiments, the second message can comprise the first data and / or a profile of the first data.

[0119] In the embodiments of the present application, the first data contained in the second message is encrypted data, which can be encrypted by the first device or the second device. That is, in the embodiments of the present application, the first data stored by the third device (or the data plane) is encrypted data. In this way, when a subsequent data consumer initiates a data plane service request to the first device, only the data consumer who obtains the authorization of the first device and / or the second device can obtain the first data and the corresponding decryption method, thereby improving the security of the data.

[0120] In some embodiments, before the first device sends the second message to the third device, the first device can authenticate the second device, for example, authenticate the legality of the second device.

[0121] In some embodiments, after the first device authenticates the second device, the first device can send an authentication result to the second device. For example, the first device sends a first response to the second device to indicate that the authentication is successful. Alternatively, the first device sends a second response to the second device to indicate that the authentication fails.

[0122] In some embodiments, after the first device authenticates the second device, the first device can determine whether the first data has been stored in the third device. In the case that the first data is not stored in the third device, the first device can send the second message to the third device. As an implementation manner, the first device can detect the profile of the first data based on a metadata directory to determine whether the first data is stored in the third device. The metadata directory can be used to record the data stored in the third device.

[0123] In some embodiments, after the third device receives the second message, the third device can store the first data carried in the second message. In some embodiments, after the third device stores the first data, the third device can also update the metadata directory.

[0124] In some embodiments, after the third device stores the first data, the third device can send a response message of the second message to the first device. The response message can be used to indicate the storage result of the first data. In some embodiments, the response message can contain the updated metadata directory. As an implementation manner, the response message can be DPRF_MetaTrans_Create / Update_Response.

[0125] In some embodiments, after the first device receives the response message of the second message sent by the third device, the first device stores the updated metadata directory.

[0126] In some embodiments, after receiving the response message of the second message sent by the third device, the first device can send a response message of the first message to the second device to indicate the storage result of the first data.

[0127] The above describes how the second device stores the first data. The following describes how the data consumer invokes the first data in combination with FIG. 6.

[0128] FIG. 6 is a flow diagram of a method of wireless communication provided by another embodiment of the present application. The method shown in FIG. 6 includes step S610 and step S620.

[0129] In step S610, the fourth device sends a third message to the first device. The third message is used to request invocation of the first data.

[0130] In some embodiments, the fourth device is a data consumer, which can obtain and / or use the data of the data source. The fourth device can be any mobile communication system entity. For example, the fourth device can include one or more of the following: a terminal device, an access network device, a network element in a core network, a network management device (such as OAM), a third-party server, and the like.

[0131] In some embodiments, the third message can be DPAC_MetaTrans_Subscribe_Request. In some embodiments, DPAC_MetaTrans_Subscribe_Request can be used to request one or more metadata from one or more data sources.

[0132] In some embodiments, the third message can include a profile of the first data.

[0133] In some embodiments, the first data requested to be invoked by the third message can include one or more metadata. For example, the first data requested to be invoked by the third message can include metadata of one or more data sources. Alternatively, the first data requested to be invoked by the third message can include metadata generated at one or more times.

[0134] In step S620, the first device sends a fourth message to the fourth device in response to the authorization of the fourth device being passed.

[0135] In some embodiments, the fourth message includes the decrypted first data. In some embodiments, the first device can decrypt the first data before sending the fourth message to the fourth device. In this way, the first device can carry the decrypted first data in the fourth message.

[0136] In some embodiments, the fourth message comprises the encrypted first data. That is, the second device does not provide the first information for the first device to decrypt the first data, so as to further improve the security of data storage and invocation.

[0137] In some embodiments, in the case that the fourth message comprises the encrypted first data, the fourth message can further comprise third information, the third information being used by the fourth device to obtain the first key.

[0138] Embodiments of the present application do not limit the third information. Exemplarily, the third information can comprise one or more of the following: address information of the second device, an identifier of the second device, address information of the terminal device, an identifier of the terminal device, and an authorization token. The authorization token can be used by the fourth device to obtain the first key for decrypting the first data from the second device or the terminal device. As an example, the third information can comprise the address information of the second device or the identifier of the second device, so that the fourth device obtains the first key from the second device. As another example, the third information can comprise the address information of the terminal device or the identifier of the terminal device, so that the fourth device obtains the first key from the terminal device. As yet another example, the third information can comprise the address information of the second device and the authorization token, or the third information can comprise the identifier of the second device and the authorization token, or the third information can comprise the address information of the second device, the identifier of the second device and the authorization token, so that the fourth device obtains the first key from the second device. As yet another example, the third information can comprise the address information of the terminal device and the authorization token, or the third information can comprise the identifier of the terminal device and the authorization token, or the third information can comprise the address information of the terminal device, the identifier of the terminal device and the authorization token, so that the fourth device obtains the first key from the terminal device.

[0139] In this way, the fourth device can establish a connection with the second device based on the third information, request the first key using the authorization token, and thus obtain the decrypted first data. Exemplarily, the fourth device can send a seventh message to the second device (or the terminal device), i.e., the fourth device can send the seventh message to the second device (or the terminal device) based on the third information, to request the first key for decrypting the first data.

[0140] In some embodiments, the seventh message is sent by the fourth device to the second device through the data plane. That is, the seventh message is sent by the first device to the second device.

[0141] In some embodiments, the seventh message is not sent by the fourth device to the second device through the data plane. For example, the fourth device can directly establish a communication connection with the second device and send the seventh message to the second device.

[0142] In some embodiments, the authorization of the fourth device can comprise one or more of the following: the authorization of the fourth device by the first device, the authorization of the fourth device by the second device. As an example, the authorization of the fourth device can comprise the authorization of the fourth device by the first device. As another example, the authorization of the fourth device can comprise the authorization of the fourth device by the first device and the authorization of the fourth device by the second device. The authorization of the fourth device by the second device is beneficial to improve the security of the data invocation. For example, when the first data requested by the fourth device comprises privacy-related data or high-value data, the authorization of the fourth device can comprise the authorization of the fourth device by the second device.

[0143] In some embodiments, the authorization of the fourth device by the first device can be a service authorization, i.e., the authorization of the fourth device by the first device can be used to determine the legitimacy of the fourth device. Alternatively, the authorization of the fourth device by the first device can mean that the first device can perform access authentication and / or access control on the fourth device to determine the legitimacy of the fourth device. As an implementation manner, the first device can perform access authentication and / or access control on the fourth device based on operator policies, relevant laws and regulations of data protection in the location, and the profile of the first data.

[0144] In some embodiments, after the authorization of the fourth device by the first device is passed, the first device can send a subscription response to the fourth device to indicate that the authorization is passed.

[0145] In some embodiments, the authorization of the fourth device by the second device can be used to determine whether the fourth device can obtain the first data. The authorization of the fourth device by the second device is described below.

[0146] In some embodiments, after the fourth device sends the third message to the first device to request to invoke the first data, the first device needs to request the authorization of the second device, and only when the authorization of the second device is passed, the first device can send the first data to the fourth device. This is described below in combination with FIG. 6.

[0147] In some embodiments, the method shown in FIG. 6 can further comprise step S612 and step S614.

[0148] In step S612, the first device sends a fifth message to the second device. The fifth message can be used to request the second device to determine whether to send the first data to the fourth device. Alternatively, the fifth message can be used to inform the second device that the fourth device requests to invoke the first data, so that the second device determines whether to agree to this invocation. In some embodiments, the fifth message can be DPAC_Notification_Invoke_Request.

[0149] In some embodiments, the fifth message can comprise one or more of the following information: an identity of the fourth device, a data type requested by the fourth device, the first identity, a profile of the first data.

[0150] The application embodiments do not limit the data type requested by the fourth device. Exemplarily, the data type requested by the fourth device can comprise one or more of the following: positioning information, perception information, AI / ML model for model training, algorithm information, etc. In some embodiments, the data type requested by the fourth device can also be understood as a data service type requested by the fourth device.

[0151] In some embodiments, if the second device does not carry the first key in the first message above but carries the first identity, the first device can carry the first identity in the fifth message so as to obtain the first key from the second device.

[0152] In step S614, the second device sends a response message of the fifth message to the first device.

[0153] In some embodiments, the second device can determine whether to send (expose) the first data to the fourth device based on the content carried in the fifth message, and indicate the result of the determination in the response message of the fifth message.

[0154] In some embodiments, the response message of the fifth message can comprise the first key for decrypting the first data. For example, if the second device authorizes the fourth device to invoke the first data, and the second device has not previously provided the first key to the first device, the second device can carry the first key in the response message of the fifth message.

[0155] In some embodiments, whether the first key is carried in the response message of the fifth message is determined according to whether the first identity is carried in the fifth message. For example, in the case where the first identity is carried in the fifth message and the second device determines to authorize the fourth device to invoke the first data, the first key can be carried in the response message of the fifth message. For another example, in the case where the first identity is not carried in the fifth message and the second device determines to authorize the fourth device to invoke the first data, the first key can not be carried in the response message of the fifth message.

[0156] In some embodiments, whether the first key is carried in the response message of the fifth message is determined according to whether the second device carries the first key in the first message. For example, the first key is carried in the first message, and the first key does not need to be carried in the response message of the fifth message. For another example, the first key is not carried in the first message, and the first key can be carried in the response message of the fifth message.

[0157] In the case that the authorization of the fourth device includes the authorization of the second device to the fourth device, the step S620 can include that, in response to the determination of the second device to send the first data to the fourth device, the first device sends a fourth message to the fourth device. The first data carried in the fourth message can be encrypted data or decrypted data.

[0158] In some embodiments, after the authorization of the first device to the fourth device is passed, the first device can determine whether the first data is stored in the data plane, so as to send the first data to the fourth device when the first data is stored in the data plane. As an implementation manner, the first device can check the configuration file of the first data based on the metadata directory to determine whether the first data has been stored in the data plane.

[0159] In some embodiments, if the first data has been stored in the data plane, the first device can request the first data from the third device, and the third device can send the encrypted first data to the first device based on the request. In some embodiments, the method shown in FIG. 6 can be applied to the scenario that the first data has been stored in the data plane.

[0160] In some embodiments, if the first data is not stored in the data plane, the first device can request the first data from the second device. This will be introduced below in combination with FIG. 7.

[0161] FIG. 7 is a flow diagram of a method of wireless communication provided by another embodiment of the present application. The method shown in FIG. 7 includes steps S710 to S750.

[0162] In step S710, the fourth device sends a third message to the first device. The third message is used to request to invoke the first data.

[0163] The introduction of step S710 can refer to the introduction of step S610 above, and for brevity, will not be repeated here.

[0164] In some embodiments, after the first device receives the third message sent by the fourth device, the first device can perform the authorization check of the first device to the fourth device to perform subsequent processing in the case that the authorization of the fourth device is passed. The authorization check of the first device to the fourth device can refer to the related introduction of the authorization check of the first device to the fourth device above, and will not be repeated here.

[0165] In step S720, if the first device determines that the third device does not store the first data, the first device sends a sixth message to the second device. The sixth message is used to request the first data.

[0166] In some embodiments, the sixth message can include one or more of the following information: the identity of the fourth device, the data type requested by the fourth device, and the configuration file of the first data.

[0167] In some embodiments, the sixth message can be a DSx_MetaTrans_Subscribe_Request.

[0168] At step S730, the second device performs authorization check on the fourth device. For introduction about step S730, please refer to the introduction about the authorization check of the second device on the fourth device above, which will not be repeated here.

[0169] At step S740, in response to the authorization pass of the fourth device, the second device can send the first data to the first device. The first data can be encrypted first data. In some embodiments, when the second device sends the first data to the first device, the first information can be carried.

[0170] At step S750, after receiving the first data sent by the second device, the first device can send the first data to the fourth device. In some embodiments, after receiving the first data sent by the second device, the first device can also store the first data in the data plane.

[0171] It should be noted that the method shown in FIG. 6 and the method shown in FIG. 7 can be used alone or in combination. For example, part of the first data requested by the third message sent by the fourth device is stored in the data plane, and the other part of the data is not stored in the data plane. In this case, the first device can obtain the complete first data through the methods shown in FIG. 6 and FIG. 7, and send the first data to the fourth device after merging and processing the first data.

[0172] Embodiment 2:

[0173] FIG. 8 is a flow diagram of a method of wireless communication according to another embodiment of the present application. The method shown in FIG. 8 is introduced from the perspective of the interaction of various devices. For the introduction of various devices, please refer to the above. The method shown in FIG. 8 includes steps S810 to S830.

[0174] At step S810, the fourth device sends a first request to the first device, and the first request is used to request to invoke the first data.

[0175] In some embodiments, the first request is similar to the third message above, so for the introduction of step S810, please refer to the introduction of step S610 above.

[0176] At step S820, the first device sends a second request to the second device, and the second request is used to request to invoke the first data.

[0177] In some embodiments, the second request can include one or more of the following information: the identifier of the fourth device, the data type requested by the fourth device, and the configuration file of the first data.

[0178] In some embodiments, the second request is similar to the sixth message above, and thus the description of step S820 can refer to the description of step S720 above.

[0179] In step S830, the second device sends a response message of the second request to the first device.

[0180] In some embodiments, the response message of the second request includes the first data. For example, the second device agrees to send the first data to the fourth device, and the response message of the second request can include the first data. However, the embodiments of the present application are not limited thereto, for example, the second device does not agree to send the first data to the fourth device, and the response message of the second request can include an indication information of refusing to send the first data.

[0181] In some embodiments, the first data included in the response message of the second request is encrypted by the key provided by the fourth device. For example, the first data can be encrypted by the key generated by the fourth device.

[0182] As an implementation manner, the fourth device can provide the key through the communication process of the data plane. For example, the fourth device can provide the key through the first request and / or the second request, so as to encrypt the first data by the key provided by the fourth device. That is, in some embodiments, the first request and / or the second request can include the key for encrypting the first data.

[0183] As another implementation manner, the fourth device can not provide the key through the communication process of the data plane. For example, the fourth device can establish a communication connection with the second device, and provide the key for encrypting the first data to the second device.

[0184] In some embodiments, the key provided by the fourth device can be the public key of the fourth device. In this way, the encrypted data can only be decrypted by the fourth device using its own private key.

[0185] In some embodiments, after receiving the first data sent by the second device, the first device can send the first data to the fourth device. The first data sent by the first device to the fourth device is encrypted data.

[0186] In some embodiments, after receiving the first data sent by the second device, the first device can also store the first data in the data plane.

[0187] In embodiment 2, the second device cannot obtain the first information for encrypting the first data, or cannot obtain the unencrypted first data, which can provide better security and privacy protection.

[0188] As mentioned above, the profile of the first data can be carried in the message transmitted between devices. The profile of the first data is described below in combination with Table 1.

[0189] In some embodiments, the profile of the first data can be used to determine the operation performed on the first data. For example, the first device can determine the operation performed on the first data according to the profile of the first data, such as determining whether the first data needs to be stored, determining whether the first data needs to be encrypted, etc. For example, the first device can determine the operation performed on the first data according to the profile of the first data, such as determining whether the first data needs to be invoked, determining the data type of the first data that needs to be invoked, etc.

[0190] In some embodiments, the profile of the first data can include second information. The second information can be used to indicate whether the first data is encrypted.

[0191] In some embodiments, the second information can be used to indicate one or more of the following: whether the first data is encrypted, whether the privacy data contained in the first data is encrypted. As an implementation manner, the second information can include first indication information and / or second indication information, wherein the first indication information is used to indicate whether the data is encrypted; the second indication information is used to indicate whether the privacy data contained in the first data is encrypted. That is, when the first data includes privacy data, whether the privacy data in the first data is encrypted can be determined based on the second indication information.

[0192] In some embodiments, the second information is applicable to the data source. In some embodiments, the second information is not applicable to the data consumer.

[0193] Table 1

[0194] For ease of understanding, the following describes several examples of Embodiment 1 and Embodiment 2 with the first device as DPAC, the second device as the data source, the third device as DPRF, and the fourth device as the data consumer. It should be noted that the steps indicated by the dashed line in the examples below are optional steps.

[0195] Example 1: Data plane stores the first data and the first information

[0196] FIG. 9 is a flow diagram of a method of wireless communication, according to another embodiment of the present application. The method shown in FIG. 9 includes steps S910 to S980.

[0197] At step S910, the data source sends a DPAC_MetaTrans_Create / Update_Request to the DPAC. In this example, the DPAC_MetaTrans_Create / Update_Request can include the first data, the first key, and the profile of the first data. However, embodiments of the present application are not limited thereto, and the DPAC_MetaTrans_Create / Update_Request can also include the first parameter. In this example, the first data included in the DPAC_MetaTrans_Create / Update_Request can be encrypted data or unencrypted data.

[0198] At step S920, the DPAC performs an authorization check on the data source and stores the first key. In some embodiments, after the DPAC authorizes the data source, the DPAC can detect the profile of the first data based on the metadata directory to determine whether the first data has already been stored in the data plane.

[0199] At step S931, the DPAC sends a DPAC_MetaTrans_Create / Update_Response to the data source to indicate that the access is legal.

[0200] At step S932, the DPAC sends a DPAC_MetaTrans_response to the data source to indicate that the access is not legal.

[0201] At step S940, the DPAC sends a DPRF_MetaTrans_Create / Update_Request to the DPRF. In this example, the DPRF_MetaTrans_Create / Update_Request can include the encrypted first data and the profile of the first data.

[0202] At step S950, the DPRF stores the encrypted first data and updates the metadata directory.

[0203] At step S960, the DPRF sends a DPRF_MetaTrans_Create / Update_Response to the DPAC. In this example, the response message of the second message can include the updated metadata directory.

[0204] At step S970, the DPAC stores the updated metadata directory.

[0205] At step S980, the DPAC sends a DPAC_MetaTrans_Create / Update_Response to the data source.

[0206] Example 2: First data of data plane storage encryption

[0207] FIG. 10 is a flow diagram illustrating a method of wireless communication according to another embodiment of the present application. The method shown in FIG. 10 includes steps S1010 to S1080.

[0208] At step S1010, the data source sends a DPAC_MetaTrans_Create / Update_Request to the DPAC. In this example, the DPAC_MetaTrans_Create / Update_Request can include the first data, the profile of the first data. In this example, the DPAC_MetaTrans_Create / Update_Request can include the first parameter and / or the first identity, but does not include the first key. In this example, the first data can be encrypted data or unencrypted data.

[0209] At step S1020, the DPAC performs authorization check on the data source.

[0210] At step S1031, the DPAC sends a DPAC_MetaTrans_Create / Update_Response to the data source to indicate that the access is legal.

[0211] At step S1032, the DPAC sends a DPAC_MetaTrans_response to the data source to indicate that the access is not legal.

[0212] At step S1040, the DPAC sends a DPRF_MetaTrans_Create / Update_Request to the DPRF. In this example, the DPRF_MetaTrans_Create / Update_Request can include the encrypted first data, the profile of the first data.

[0213] At step S1050, the DPRF stores the encrypted first data and updates the metadata directory.

[0214] At step S1060, the DPRF sends a DPRF_MetaTrans_Create / Update_Response to the DPAC. In this example, the response message of the second message can include the updated metadata directory.

[0215] At step S1070, the DPAC stores the updated metadata directory.

[0216] At step S1080, the DPAC sends a DPAC_MetaTrans_Create / Update_Response to the data source.

[0217] Example 2 differs from example 1 in that the data source does not provide the first key to the data plane when storing the first data to the DPAC, but can provide the first identity, so that the DPAC and the data consumer use the first identity to obtain the key from the data source or the terminal device.

[0218] Example 3: Data consumer obtains decrypted first data

[0219] FIG. 11 is a flow diagram of a method of wireless communication, according to another embodiment of the present application. The method shown in FIG. 11 includes steps S1101 to S1116.

[0220] At step S1101, the data consumer sends a DPAC_MetaTrans_Subscribe_Request to the DPAC to request invoking the first data. In some embodiments, the DPAC_MetaTrans_Subscribe_Request can include the profile of the first data.

[0221] At step S1102, the DPAC performs an authorization check on the data consumer.

[0222] At step S1103, the DPAC sends a DPAC_MetaTrans_Subscribe_Response to the data consumer to indicate that the authorization is passed.

[0223] In some embodiments, the DPAC can check the profile of the first data based on the metadata directory to determine whether the first data is stored in the data plane. If the first data has been stored in the data plane, the DPAC can request the first data from the DPRF (see steps S1104 to S1109).

[0224] At step S1104, the DPAC sends a DPRF_MetaTrans_Query_Request to the DPRF to request the first data.

[0225] At step S1105, the DPRF processes the request sent by the DPAC and retrieves the requested first data.

[0226] At step S1106, the DPRF sends a DPRF_MetaTrans_Query_Response to the DPAC to carry the first data. In this example, the first data sent by the DPRF to the DPAC is encrypted data. In some embodiments, the DPRF sends the first data to the DPAC with a profile of the first data.

[0227] At step S1107, the DPAC sends a DPAC_Notification_Invoke_Request to the data source to request the data source to determine whether to send the first data to the data consumer. In this example, the DPAC_Notification_Invoke_Request can include an identity of the data consumer, a data type requested by the data consumer, and a profile of the first data. In some embodiments, the DPAC_Notification_Invoke_Request can also include the first identity.

[0228] At step S1108, the data source sends a DPAC_Notification_Result to the DPAC to indicate the result of the authorization check. In some embodiments, if the data source determines that the data consumer can invoke the first data, the data source can carry the first key in the DPAC_Notification_Result.

[0229] At step S1109, the DPAC decrypts the first data.

[0230] In some embodiments, the DPAC can check the profile of the first data based on the metadata directory to determine whether the first data is stored in the data plane. If the first data is not stored in the data plane, the DPAC can request the first data from the data source (see steps S1110 to S1113).

[0231] At step S1110, the DPAC sends a DSx_MetaTrans_Subscribe_Request to the data source to request the first data. In some embodiments, the DPAC can determine the data source corresponding to the first data according to the profile of the first data carried in the third message sent by the data consumer, and request the first data from the data source.

[0232] At step S1111, the data source performs an authorization check on the data consumer. In some embodiments, if the authorization of the data consumer by the data source is passed, the data source can obtain the first data and encrypt the first data.

[0233] At step S1112, the data source sends a DSx_MetaTrans_Subscribe_Response to the DPAC to send the first data. In some embodiments, the data source can send the first information at the same time when sending the first data to the DPAC.

[0234] At step S1113, the data source stores the first data. In some embodiments, the data source can also store the first information when storing the first data.

[0235] At step S1114, the DPAC decrypts and merges the data obtained from the DPRF and the data obtained from the data source to obtain the first data requested by the data consumer.

[0236] At step S1115, the DPAC sends a DPAC_MetaTrans_Subscribe_Response to the data consumer to send the decrypted first data.

[0237] At step S1116, the DPAC sends a DSx_MetaTrans_Subscribe_Notify to the data source to indicate that the data call is completed.

[0238] Example 4: Data consumer obtains encrypted first data and first information

[0239] FIG. 12 is a flow diagram of a method of wireless communication, according to another embodiment of the present application. The method shown in FIG. 12 includes steps S1201 to S1217.

[0240] The description of steps S1201 to S1208 can be referred to the description of steps S1101 to S1108.

[0241] In some embodiments, the DPAC can check the configuration file of the first data based on the metadata directory to determine whether the first data is stored in the data plane. If the first data is not stored in the data plane, the DPAC can request the first data from the data source (see steps S1209 to S1212).

[0242] At step S1209, the DPAC sends a DSx_MetaTrans_Subscribe_Request to the data source to request the first data. In some embodiments, the DPAC can determine the data source corresponding to the first data according to the configuration file of the first data carried in the third message sent by the data consumer, and request the first data from the data source.

[0243] At step S1210, the data source performs authorization check on the data consumer. In some embodiments, in case that the data source passes the authorization check on the data consumer, the data source can acquire the first data and encrypt the first data.

[0244] At step S1211, the data source sends a DSx_MetaTrans_Subscribe_Response to the DPAC to send the first data. In this example, the first data sent by the data source to the DPAC is the encrypted data.

[0245] At step S1212, the data source stores the first data.

[0246] At step S1213, the DPAC merges the data acquired from the DPRF and the data acquired from the data source to obtain the first data requested by the data consumer.

[0247] At step S1214, the DPAC sends a DPAC_MetaTrans_Subscribe_Response to the data consumer to send the encrypted first data. In this example, the DPAC_MetaTrans_Subscribe_Response can also include one or more of the following: address information of the data source, identity of the data source, address information of the terminal device, identity of the terminal device, authorization token. In this way, the data consumer can acquire the first key from the data source or the terminal device based on the above information.

[0248] At step S1215, the DPAC sends a DSx_MetaTrans_Subscribe_Notify to the data source to indicate that the data call is completed.

[0249] At step S1216, the data consumer sends a seventh message to the data source to acquire the first key. Of course, in step S1216, the data consumer can also send the seventh message to the terminal device to acquire the first key, which is not limited in the present application.

[0250] At step S1217, the data consumer decrypts the first data using the first key to obtain the decrypted first data.

[0251] Example 4 differs from example 3 in that not only the data plane stores the encrypted first data, and the data source will not provide the first information to the data plane. When the data consumer acquires the encrypted first data stored by the data plane or when the data consumer acquires the encrypted first data collected by the data plane from the data source, the DPAC can provide the data source or the terminal device related information to the data consumer, so that the data consumer establishes a connection with the data source or the terminal device to acquire the first key, thereby acquiring the decrypted first data.

[0252] Example 5: Data consumer provides a first key to encrypt the first data

[0253] FIG. 13 is a flow diagram of a method of wireless communication, provided by another embodiment of the present application. The method shown in FIG. 13 includes steps S1301 to S1313.

[0254] At step S1301, the data consumer sends a DPAC_MetaTrans_Subscribe_Request to the DPAC to request invoking the first data. In this example, the DPAC_MetaTrans_Subscribe_Request includes a key to encrypt the first data. For example, the first request can include a public key of the data consumer.

[0255] The description of steps S1302 to S1306 can be referred to the description of steps S1102 to S1106.

[0256] In some embodiments, the DPAC can check the configuration file of the first data based on the metadata directory to determine whether the first data is stored in the data plane. If the first data is not stored in the data plane, the DPAC can request the first data from the data source (see steps S1307 to S1309).

[0257] At step S1307, the DPAC sends a DSx_MetaTrans_Subscribe_Request to the data source to request the first data. In this example, the DSx_MetaTrans_Subscribe_Request can include the key to encrypt the first data.

[0258] At step S1308, the data source performs an authorization check on the data consumer. In some embodiments, if the data source passes the authorization check on the data consumer, the data source can obtain the first data and encrypt the first data using the key provided by the data consumer.

[0259] At step S1309, the data source sends a DSx_MetaTrans_Subscribe_Response to the DPAC to carry the first data. In this example, the first data sent by the data source to the DPAC is encrypted data, and the first data is encrypted using the key provided by the data consumer.

[0260] At step S1310, the data source stores the first data. It is noted that the data source can also not store the first data, which is not limited in the embodiments of the present application.

[0261] At step S1311, the DPAC sends a DPAC_MetaTrans_Subscribe_Response to the data consumer to carry the encrypted first data, and the first data is encrypted using a key provided by the data consumer.

[0262] At step S1312, the DPAC sends a DSx_MetaTrans_Subscribe_Notify to the data source to indicate that the data call is completed.

[0263] At step S1313, the data consumer decrypts the first data to obtain decrypted first data. For example, the first data is encrypted using a public key of the data consumer, and the data consumer can use a private key of the data consumer to decrypt at step S1313.

[0264] In Example 5, the data source or the DPAC can encrypt the first data using a key provided by the data consumer. In this way, a network element on the data plane cannot obtain the decrypted first data, and cannot obtain a security parameter for decrypting the first data, which is beneficial to improving the security and privacy protection of data storage and call. It should be noted that in Example 5, the data consumer provides the key for encrypting the first data through a communication process on the data plane, but the embodiments of the present application are not limited thereto. For example, the data consumer can directly communicate with the data source to provide the key for encrypting the first data.

[0265] The method embodiments of the present application are described in detail above in combination with FIGS. 1 to 13, and the device embodiments of the present application are described in detail below in combination with FIGS. 14 to 20. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.

[0266] FIG. 14 is a structural schematic diagram of a communication device according to an embodiment of the present application. The communication device 1400 shown in FIG. 14 is a first device. The communication device 1400 includes a first receiving module 1410 and a first sending module 1420. The first receiving module 1410 is configured to receive a first message sent by a second device, and the first message is used to request to store first data. The first sending module 1420 is configured to send a second message to a third device, and the second message is used to request to store the first data. Wherein, the first device is used for access authentication and / or access control on a data plane, the third device is used to provide a data storage function on the data plane, and the stored first data is encrypted data.

[0267] In some embodiments, the first message includes first information, and the first information is used to decrypt the first data.

[0268] In some embodiments, the first information comprises one or more of: a first key for decrypting the first data; a first parameter for indicating freshness of the first data; a first identifier for indicating the first key for decrypting the first data.

[0269] In some embodiments, the first key is generated by the second device; or, the first key is generated by the first device; or, the first key is a shared key between the first device and the second device; or, the first key is a shared key between the second device and a terminal device.

[0270] In some embodiments, the first key is the same as a key for encrypting the first data.

[0271] In some embodiments, the first key is generated based on a relevant parameter of data stored to a data plane by the second device.

[0272] In some embodiments, the relevant parameter of data stored to a data plane by the second device comprises one or more of: a type of data stored to a data plane, a service type corresponding to data stored to a data plane.

[0273] In some embodiments, the communication device further comprises a storage module configured to store the first information.

[0274] In some embodiments, the communication device further comprises: a second receiving module configured to receive a third message sent by a fourth device, the third message being used to request invoking the first data; and a second sending module configured to, in response to authorization of the fourth device, decrypt the first data and send a fourth message to the fourth device, the fourth message comprising the decrypted first data.

[0275] In some embodiments, the communication device further comprises: a second receiving module configured to receive a third message sent by a fourth device, the third message being used to request invoking the first data; and a second sending module configured to, in response to authorization of the fourth device, send a fourth message to the fourth device, the fourth message comprising the encrypted first data.

[0276] In some embodiments, the fourth message further comprises one or more of: address information of the second device; an identifier of the second device; address information of a terminal device; an identifier of the terminal device; an authorization token, the authorization token being used by the fourth device to obtain the first key for decrypting the first data from the second device or the terminal device.

[0277] In some embodiments, the communication device further includes: a third sending module, configured to send a fifth message to the second device, the fifth message being used to request the second device to determine whether to send the first data to the fourth device; a third receiving module, configured to receive a response message of the fifth message sent by the second device; and the second sending module is configured to: in response to the second device determining to send the first data to the fourth device, send the fourth message to the fourth device.

[0278] In some embodiments, the fifth message includes one or more of the following information: an identifier of the fourth device; a type of data requested by the fourth device; a first identifier used to indicate a first key for decrypting the first data; a profile of the first data, the profile being used to determine an operation performed on the first data.

[0279] In some embodiments, the response message of the fifth message includes the first key used to decrypt the first data.

[0280] In some embodiments, the communication device further includes: a fourth sending module, configured to send a sixth message to the second device if the first device determines that the third device does not store the first data, the sixth message being used to request the first data.

[0281] In some embodiments, the sixth message includes one or more of the following information: an identifier of the fourth device; a type of data requested by the fourth device; a profile of the first data, the profile being used to determine an operation performed on the first data.

[0282] In some embodiments, the first message and / or the second message includes a profile of the first data, the profile being used to determine an operation performed on the first data.

[0283] In some embodiments, the profile of the first data includes second information used to indicate whether the first data is encrypted.

[0284] In some embodiments, the first receiving module 1410 and the first sending module 1420 can be a transceiver 2030. The communication device 1400 can further include a processor 2010 and a memory 2020, as shown in FIG. 20.

[0285] FIG. 15 is a structure diagram of a communication device according to another embodiment of the present application. The communication device 1500 shown in FIG. 15 is a first device. The communication device 1500 comprises a first receiving module 1510, a sending module 1520 and a second receiving module 1530. The first receiving module 1510 is configured to receive a first request sent by a fourth device, the first request being used to request invoking first data. The sending module 1520 is configured to send a second request to a second device, the second request being used to request the first data. The second receiving module 1530 is configured to receive a response message of the second request sent by the second device, the response message of the second request comprising the first data encrypted by a key provided by the fourth device. The first device is configured to perform access authentication and / or access control in a data plane.

[0286] In some embodiments, the first request and / or the second request comprises the key used to encrypt the first data.

[0287] In some embodiments, the second request comprises one or more of the following information: an identity of the fourth device; a data type requested by the fourth device; a configuration file of the first data, the configuration file being used to determine an operation performed on the first data.

[0288] In some embodiments, the configuration file comprises second information, the second information being used to indicate whether the first data is encrypted.

[0289] In some embodiments, the key provided by the fourth device is a public key of the fourth device.

[0290] In some embodiments, the first receiving module 1510, the sending module 1520 and the second receiving module 1530 can be a transceiver 2030. The communication device 1500 can further comprise a processor 2010 and a memory 2020, as shown in FIG. 20.

[0291] FIG. 16 is a structure diagram of a communication device according to another embodiment of the present application. The communication device 1600 shown in FIG. 16 is a second device. The communication device 1600 comprises a first sending module 1610. The first sending module 1610 is configured to send a first message to a first device, the first message being used to request storing first data. The first device is configured to perform access authentication and / or access control in a data plane, and the first data to be stored is encrypted data.

[0292] In some embodiments, the first message comprises first information, the first information being used to decrypt the first data.

[0293] In some embodiments, the first information comprises one or more of: a first key for decrypting the first data; a first parameter for indicating freshness of the first data; a first identifier for indicating the first key for decrypting the first data.

[0294] In some embodiments, the first key is generated by the second device; or, the first key is generated by the first device; or, the first key is a shared key between the first device and the second device; or, the first key is a shared key between the second device and a terminal device.

[0295] In some embodiments, the first key is the same as a key for encrypting the first data.

[0296] In some embodiments, the first key is generated based on a related parameter of data stored to a data plane by the second device.

[0297] In some embodiments, the related parameter of data stored to a data plane by the second device comprises one or more of: a type of data stored to a data plane, a service type corresponding to data stored to a data plane.

[0298] In some embodiments, the communication device further comprises: a first receiving module, configured to receive a fifth message sent by the first device, the fifth message being used for requesting the second device to determine whether to send the first data to the fourth device; and a second sending module, configured to send a response message of the fifth message to the first device.

[0299] In some embodiments, the fifth message comprises one or more of the following information: an identifier of the fourth device; a type of data requested by the fourth device; a first identifier for indicating a first key for decrypting the first data; a profile of the first data, the profile being used for determining an operation performed on the first data.

[0300] In some embodiments, the response message of the fifth message comprises the first key for decrypting the first data.

[0301] In some embodiments, the communication device further comprises: a second receiving module, configured to receive a sixth message sent by the first device, the sixth message being used for requesting the first data.

[0302] In some embodiments, the sixth message comprises one or more of the following information: an identifier of the fourth device; a type of data requested by the fourth device; a profile of the first data, the profile being used for determining an operation performed on the first data.

[0303] In some embodiments, the first message comprises a profile of the first data, the profile being used to determine an operation performed on the first data.

[0304] In some embodiments, the profile of the first data comprises second information, the second information being used to indicate whether the first data is encrypted.

[0305] In some embodiments, the first sending module 1610 can be a transceiver 2030. The communication device 1600 can further comprise a processor 2010 and a memory 2020, as shown in FIG. 20.

[0306] FIG. 17 is a structural diagram of a communication device according to another embodiment of the present application. The communication device 1700 shown in FIG. 17 is a second device. The communication device 1700 comprises a receiving module 1710 and a sending module 1720. The receiving module 1710 is configured to receive a second request sent by a first device, the second request being used to request first data. The sending module 1720 is configured to send a response message of the second request to the first device, the response message of the second request comprising the first data encrypted by a key provided by a fourth device. The first device is used for access authentication and / or access control in a data plane, and the fourth device is a data consumer invoking the first data.

[0307] In some embodiments, the second request comprises the key used to encrypt the first data.

[0308] In some embodiments, the second request comprises one or more of the following information: an identity of the fourth device; a data type requested by the fourth device; a profile of the first data, the profile being used to determine an operation performed on the first data.

[0309] In some embodiments, the profile comprises second information, the second information being used to indicate whether the first data is encrypted.

[0310] In some embodiments, the key provided by the fourth device is a public key of the fourth device.

[0311] In some embodiments, the receiving module 1710 and the sending module 1720 can be a transceiver 2030. The communication device 1700 can further comprise a processor 2010 and a memory 2020, as shown in FIG. 20.

[0312] FIG. 18 is a structural diagram of a communication device according to another embodiment of the present application. The communication device 1800 shown in FIG. 18 is a fourth device. The communication device 1800 includes a first sending module 1810 and a receiving module 1820. The first sending module 1810 is configured to send a third message to a first device, where the third message is used to request invoking first data. The receiving module 1820 is configured to receive a fourth message sent by the first device, where the fourth message includes encrypted first data. The first device is configured to perform access authentication and / or access control on a data plane.

[0313] In some embodiments, the fourth message further includes one or more of the following: address information of the second device; an identifier of the second device; address information of a terminal device; an identifier of the terminal device; and an authorization token, where the authorization token is used by the fourth device to obtain a first key for decrypting the first data from the second device or the terminal device.

[0314] In some embodiments, the communication device further includes a second sending module configured to send a seventh message to a second device, where the seventh message is used to request a first key for decrypting the first data.

[0315] In some embodiments, the seventh message is sent by the first device to the second device.

[0316] In some embodiments, the first sending module 1810 and the receiving module 1820 can be a transceiver 2030. The communication device 1800 can further include a processor 2010 and a memory 2020, as shown in FIG. 20.

[0317] FIG. 19 is a structural diagram of a communication device according to another embodiment of the present application. The communication device 1900 shown in FIG. 19 is a fourth device. The communication device 1900 includes a sending module 1910 and a receiving module 1920. The sending module 1910 is configured to send a first request to a first device, where the first request is used to request invoking first data. The receiving module 1920 is configured to receive the first data sent by the first device, where the first data is encrypted by a key provided by the fourth device. The first device is configured to perform access authentication and / or access control on a data plane.

[0318] In some embodiments, the first request includes a key used to encrypt the first data.

[0319] In some embodiments, the key provided by the fourth device is a public key of the fourth device.

[0320] In some embodiments, the sending module 1910 and the receiving module 1920 can be transceiver 2030. The communication device 1900 can further include a processor 2010 and a memory 2020, as shown in FIG. 20.

[0321] FIG. 20 is a schematic structural diagram of a communication device according to an embodiment of the present application. The dashed line in FIG. 20 indicates that the unit or module is optional. The device 2000 can be used to implement the method described in the above method embodiments. The device 2000 can be a chip, a terminal device, or a network device.

[0322] The device 2000 can include one or more processors 2010. The processor 2010 can support the device 2000 to implement the method described in the above method embodiments. The processor 2010 can be a general purpose processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic components, discrete hardware components, etc. The general purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0323] The device 2000 can further include one or more memories 2020. The memory 2020 stores a program, which can be executed by the processor 2010, so that the processor 2010 performs the method described in the above method embodiments. The memory 2020 can be independent of the processor 2010 or integrated in the processor 2010.

[0324] The device 2000 can further include a transceiver 2030. The processor 2010 can communicate with other devices or chips through the transceiver 2030. For example, the processor 2010 can perform data transceiving with other devices or chips through the transceiver 2030.

[0325] The embodiments of the present application further provide a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal device or the network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0326] The embodiment of the present application further provides a computer program product. The computer program product comprises a program. The computer program product can be applied to the terminal device or the network device provided by the embodiment of the present application, and the program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0327] The embodiment of the present application further provides a computer program. The computer program can be applied to the terminal device or the network device provided by the embodiment of the present application, and the computer program causes the computer to execute the method performed by the terminal device or the network device in the various embodiments of the present application.

[0328] It should be understood that the terms "system" and "network" can be used interchangeably in the present application. In addition, the terms used in the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.

[0329] In the embodiments of the present application, the "indication" mentioned can be direct indication, or indirect indication, or can be an indication with an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.

[0330] In the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0331] In the embodiments of the present application, the term "corresponding" can mean that there is a direct or indirect corresponding relationship between the two, or can mean that there is an associated relationship between the two, or can mean an indication and being indicated, configuration and being configured, and the like.

[0332] In the embodiments of the present application, "including" can mean direct inclusion, or indirect inclusion. Alternatively, "including" mentioned in the embodiments of the present application can be replaced by "indicating" or "used to determine". For example, A includes B can be replaced by A indicates B, or A is used to determine B.

[0333] In the embodiments of the present application, the "predefined" or "preconfigured" can be implemented by pre-storing corresponding codes, tables or other manners that can be used to indicate relevant information in devices (for example, including terminal devices and network devices), and the specific implementation manners are not limited in the present application. For example, the predefinition can refer to the definition in a protocol.

[0334] In the embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, for example, can include the LTE protocol, the NR protocol and the related protocol applied to the future communication system, and the present application is not limited to this.

[0335] In the embodiments of the present application, the term "and / or" is only used to describe the association relationship of the associated objects, that is, there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents that the front and rear associated objects are in an "or" relationship.

[0336] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0337] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented by other manners. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can be in another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed mutual objects can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0338] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiments of the present application.

[0339] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0340] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.

[0341] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of wireless communication, comprising: The method comprises: a first device receiving a first message sent by a second device, the first message being used for requesting storage of first data; the first device sending a second message to a third device, the second message being used for requesting storage of the first data; wherein the first device is used for access authentication and / or access control of a data plane, the third device is used for providing a data storage function of the data plane, and the stored first data is encrypted data.

2. The method of claim 1, wherein, The first message comprises first information used for decrypting the first data.

3. The method of claim 2, wherein, The first information comprises one or more of the following: a first key used for decrypting the first data; a first parameter used for indicating freshness of the first data; a first identifier used for indicating the first key for decrypting the first data.

4. The method of claim 3, wherein: the first key is generated by the second device; or the first key is generated by the first device; or the first key is a shared key between the first device and the second device; or the first key is a shared key between the second device and a terminal device.

5. The method according to claim 3 or 4, characterized in that, The first key is the same as a key used for encrypting the first data.

6. The method according to any one of claims 3-5, characterized in that, The first key is generated based on a related parameter of data stored to the data plane by the second device.

7. The method according to any one of claims 2-6, characterized in that, The method further comprises: the first device storing the first information.

8. The method according to any one of claims 1-7, characterized in that, The method further comprises: the first device receiving a third message sent by a fourth device, the third message being used for requesting invocation of the first data; in response to authorization pass of the fourth device, the first device decrypts the first data and sends a fourth message to the fourth device, the fourth message comprising the decrypted first data.

9. The method according to any one of claims 1-7, characterized in that, The method further comprises: the first device receiving a third message sent by a fourth device, the third message being used for requesting invocation of the first data; in response to authorization pass of the fourth device, the first device sends a fourth message to the fourth device, the fourth message comprising encrypted first data.

10. The method of claim 9, wherein, The fourth message further comprises one or more of the following: address information of the second device; an identifier of the second device; address information of a terminal device; an identifier of the terminal device; an authorization token used for the fourth device to obtain a first key for decrypting the first data from the second device or the terminal device.

11. The method according to any one of claims 8-10, characterized in that, The method further comprises: the first device sending a fifth message to the second device, the fifth message being used for requesting the second device to determine whether to send the first data to the fourth device; the first device receiving a response message of the fifth message sent by the second device; in response to authorization pass of the fourth device, the first device sending a fourth message to the fourth device comprises: in response to the second device determining to send the first data to the fourth device, the first device sending the fourth message to the fourth device.

12. The method of claim 11, wherein, The fifth message comprises one or more of the following information: an identifier of the fourth device; a data type requested by the fourth device; The first identifier is used to indicate a first key for decrypting the first data. The profile of the first data is used to determine an operation performed on the first data.

13. The method according to claim 11 or 12, characterized in that, The response message of the fifth message includes a first key for decrypting the first data.

14. The method of any one of claims 1-13, wherein, The method further includes: If the first device determines that the third device does not store the first data, the first device sends a sixth message to the second device, and the sixth message is used to request the first data.

15. The method of claim 14, wherein, The sixth message includes one or more of the following information: an identifier of the fourth device; a data type requested by the fourth device; and a profile of the first data, which is used to determine an operation performed on the first data.

16. The method of any one of claims 1-15, wherein, The first message and / or the second message includes a profile of the first data, which is used to determine an operation performed on the first data.

17. The method of any one of claims 1-16, wherein, The profile of the first data includes second information used to indicate whether the first data is encrypted.

18. A method of wireless communication, comprising: It includes: A first device receives a first request sent by a fourth device, and the first request is used to request to invoke first data. The first device sends a second request to a second device, and the second request is used to request the first data. The first device receives a response message of the second request sent by the second device, and the response message of the second request includes the first data encrypted by a key provided by the fourth device. The first device is used for access authentication and / or access control of a data plane.

19. The method of claim 18, wherein, The first request and / or the second request includes a key for encrypting the first data.

20. The method of claim 18 or 19, wherein, The second request includes one or more of the following information: an identifier of the fourth device; a data type requested by the fourth device; and a profile of the first data, which is used to determine an operation performed on the first data.

21. The method of claim 20, wherein, The profile includes second information used to indicate whether the first data is encrypted.

22. The method of any one of claims 18-21, wherein, The key provided by the fourth device is a public key of the fourth device.

23. A method of wireless communication, comprising: It includes: A second device sends a first message to a first device, and the first message is used to request to store first data. The first device is used for access authentication and / or access control of a data plane, and the stored first data is encrypted data.

24. The method of claim 23, wherein, The first message includes first information used to decrypt the first data.

25. The method of claim 24, wherein, The first information includes one or more of the following: A first key used to decrypt the first data; A first parameter used to indicate freshness of the first data; A first identifier used to indicate a first key for decrypting the first data.

26. The method of claim 25, wherein: The first key is generated by the second device; or The first key is generated by the first device; or The first key is a shared key between the first device and the second device; or The first key is a shared key between the second device and a terminal device.

27. The method of claim 25 or 26, wherein, The first key is the same as a key used to encrypt the first data.

28. The method of any one of claims 25-27, wherein, The first key is generated based on a related parameter of data stored by the second device to a data plane.

29. The method of any one of claims 23-28, wherein, The method further comprises: The second device receives a fifth message sent by the first device, and the fifth message is used to request the second device to determine whether to send the first data to the fourth device. The second device sends a response message of the fifth message to the first device.

30. The method of claim 29, wherein, The fifth message comprises one or more of the following information: an identifier of the fourth device; a data type requested by the fourth device; A first identifier for indicating a first key for decrypting the first data; A profile of the first data, the profile being used to determine an operation performed on the first data.

31. The method of claim 29 or 30, wherein, The response message of the fifth message comprises the first key for decrypting the first data.

32. The method of any one of claims 23-31, wherein, The method further comprises: The second device receives a sixth message sent by the first device, and the sixth message is used to request the first data.

33. The method of claim 32, wherein, The sixth message comprises one or more of the following information: an identifier of the fourth device; a data type requested by the fourth device; a profile of the first data, the profile being used to determine an operation performed on the first data.

34. The method of any one of claims 23-33, wherein, The first message comprises a profile of the first data, the profile being used to determine an operation performed on the first data.

35. The method of any one of claims 23-34, wherein, The profile of the first data comprises second information for indicating whether the first data is encrypted.

36. A method of wireless communication, the method comprising: Comprise: The second device receives a second request sent by the first device, and the second request is used to request first data; The second device sends a response message of the second request to the first device, and the response message of the second request comprises first data encrypted by a key provided by a fourth device; The first device is used for access authentication and / or access control of a data plane, and the fourth device is a data consumer that invokes the first data.

37. The method of claim 36, wherein, The second request comprises a key for encrypting the first data.

38. The method of claim 36 or 37, wherein, The second request comprises one or more of the following information: an identifier of the fourth device; a data type requested by the fourth device; a profile of the first data, the profile being used to determine an operation performed on the first data.

39. The method of claim 38, wherein, The profile comprises second information for indicating whether the first data is encrypted.

40. The method of any one of claims 36-39, wherein, The key provided by the fourth device is a public key of the fourth device.

41. A method of wireless communication, the method comprising: Comprise: The fourth device sends a third message to the first device, and the third message is used to request to invoke first data; The fourth device receives a fourth message sent by the first device, and the fourth message comprises encrypted first data; The first device is used for access authentication and / or access control of a data plane.

42. The method of claim 41, wherein, The fourth message further comprises one or more of the following: address information of the second device; an identifier of the second device; address information of a terminal device; an identifier of the terminal device; an authorization token, the authorization token being used for the fourth device to obtain a first key for decrypting the first data from the second device or the terminal device.

43. The method of claim 41 or 42, wherein, The method further comprises: The fourth device sends a seventh message to the second device, the seventh message being used to request a first key for decrypting the first data.

44. The method of claim 43, wherein, The seventh message is sent to the second device by the first device.

45. A method of wireless communication, the method comprising: Comprising: The fourth device sends a first request to the first device, the first request being used to request invoking first data; The fourth device receives the first data sent by the first device, the first data being encrypted by a key provided by the fourth device; The first device is used for access authentication and / or access control of a data plane.

46. The method of claim 45, wherein, The first request comprises a key for encrypting the first data.

47. The method of claim 45 or 46, wherein, The key provided by the fourth device is a public key of the fourth device.

48. A communications device, characterized by The communication device is the first device, and the communication device comprises a module for performing the method of any one of claims 1-17.

49. A communications device, characterized by The communication device is the first device, and the communication device comprises a module for performing the method of any one of claims 18-22.

50. A communications device, characterized by The communication device is the second device, and the communication device comprises a module for performing the method of any one of claims 23-35.

51. A communications device, characterized by The communication device is the second device, and the communication device comprises a module for performing the method of any one of claims 36-40.

52. A communications device, comprising: The communication device is the fourth device, and the communication device comprises a module for performing the method of any one of claims 41-44.

53. A communications device, characterized by The communication device is the fourth device, and the communication device comprises a module for performing the method of any one of claims 45-47.

54. A communications device, characterized by The communication device comprises a transceiver, a memory, and a processor, the memory being used to store a program, the processor being used to invoke the program in the memory and control the transceiver to receive or send a signal, so that the communication device performs the method of any one of claims 1-47.

55. An apparatus comprising: The apparatus comprises a processor configured to invoke a program from a memory to cause the apparatus to perform the method of any one of claims 1-47.

56. A chip, comprising: The chip comprises a processor configured to invoke a program from a memory to cause the apparatus to perform the method of any one of claims 1-47.

57. A computer-readable storage medium, characterized in that, The computer program product comprises a program configured to cause a computer to perform the method of any one of claims 1-47.

58. A computer program product, characterised in that, The computer program product comprises a program configured to cause a computer to perform the method of any one of claims 1-47.

59. A computer program characterised in that, The computer program product comprises a program configured to cause a computer to perform the method of any one of claims 1-47.

Citation Information

Patent Citations

  • Communication method and device

    CN115484598A

  • User-related data service processing method, device and network element

    CN115915127A

  • Communication method, communication device and communication system

    CN116193441A

  • Communication method, apparatus and system

    WO2024092697A1