Communication method and communication apparatus
By exchanging information and credentials between terminal devices and network devices, independent scheduling of heterogeneous network resources is achieved, solving the problem of low task execution efficiency in heterogeneous networks, improving task execution efficiency and enhancing security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2026-04-02
AI Technical Summary
When terminal devices perform tasks through heterogeneous networks, complex cross-network strategies are required, resulting in low efficiency.
The terminal device sends task information and credentials to the first network device. The network device independently schedules resources based on the task information. The terminal device then invokes network resources to execute the task based on the credentials, thus avoiding cross-network policies.
It improves the efficiency of terminal devices in performing tasks through heterogeneous networks, enhances network security, and prevents unauthorized use and abuse.
Smart Images

Figure CN2025121150_02042026_PF_FP_ABST
Abstract
Description
Communication method and communication apparatus
[0001] The present application claims priority from the Chinese patent application No. 202411398188.X filed on September 30, 2024, and entitled "Communication method and communication apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication, in particular to a communication method and a communication apparatus. BACKGROUND
[0003] With the development of communication technology, the types of networks providing services for terminal devices are constantly enriched, wherein the network providing services for the terminal device can be an access network, a partial access network, a core network, a partial core network, or a network composed of a partial access network and a partial core network, and the network providing services for the terminal device can also be a network provided by a third-party service provider. For example, the network can include one or more of a personal area network, a home network, an industrial field network, a near-field self-organizing network, a terrestrial wireless access network, a drone base station network, and a satellite network, and the terminal device can perform tasks such as perception, storage, calculation, artificial intelligence, and digital twin using one or more networks. Different types of networks constitute a heterogeneous network.
[0004] In order to meet the task requirements, the terminal device can need multiple networks in the heterogeneous network to perform tasks, but due to the differences in resource scheduling methods or processes of different networks, the terminal device often needs to perform tasks based on complex processes and cross-network strategies through the heterogeneous network, which is low in efficiency. SUMMARY
[0005] Embodiments of the present application provide a communication method and a communication apparatus to improve the efficiency of the terminal device performing tasks through a heterogeneous network.
[0006] In a first aspect, embodiments of the present application provide a communication method, which can be executed by a terminal device or a chip of the terminal device. The following takes the terminal device as an example to describe the method. The method comprises: sending information of a first task to a first network device, the information of the first task being used to determine N networks, N being a positive integer greater than 1; receiving a first task credential from the first network device; and sending a first task credential and a first task message, the first task credential being used for resource scheduling of the N networks respectively to process the first task message.
[0007] The information of the first task indicates a task and / or a service that needs to be performed by a user of the terminal device, and the first network device can determine N networks involved in performing the first task (i.e., processing a packet of the first task) according to the information of the first task. The first task credential is information associated with the first task. After receiving the first task credential from the first network device, the N networks can independently determine a resource scheduling strategy for performing the first task based on their own running conditions, and call resources to perform the first task based on the resource scheduling strategy and the first task credential received from the terminal device. After receiving the first task credential, the terminal device can call resources of the N networks to perform the first task based on the first task credential. Since the resource scheduling strategy for performing the first task is independently determined by each network, there is no need to formulate a cross-network strategy for performing the first task, thereby improving the efficiency of the terminal device in performing the task through the heterogeneous networks.
[0008] In an optional implementation of the first aspect, the method further includes: sending first information to the first network device, the first information being used to prove that the user of the terminal device has the right to use the N networks.
[0009] The first information can include right information provided by part or all of the N networks, and the first network device issues the first task credential to the terminal device based on the first information, so that the networks can be prevented from being illegally used or abused.
[0010] In an optional implementation of the first aspect, the first information includes identity information and / or right information of the user of the terminal device.
[0011] The identity information is used to prove that the user of the terminal device is a legal user, and the right information is used to prove that the user of the terminal device has the right to use one or more networks. The identity information can also be referred to as a user identifier or a user profile, and the right information can also be referred to as permission information, authorization information, subscription information, or proof information. The embodiments of the present application do not limit the specific names of the identity information and the right information. The terminal device can select different information as the first information based on actual conditions. For example, for some public service scenarios, the user of the terminal device only needs to provide the identity information to prove that he or she is a legal user to use the public service. For some confidential scenarios, the user of the terminal device only needs to provide the right information to prove that he or she has the right to use a certain service. For some paid service scenarios, the user of the terminal device needs to provide the identity information and the right information. Therefore, the embodiments can be flexibly applied to different scenarios.
[0012] In an optional implementation of the first aspect, the method further includes: sending first verification information to the first network device, the first verification information being used for verification of a signer of the first information.
[0013] The first check information is, for example, a signature of a signer of the first information. The first check information can or can not be in a same message as the first information. The terminal device sending the first check information can avoid an illegal user from invoking a network service, thereby improving network security.
[0014] In an optional implementation of the first aspect, the method further includes sending second check information to the first network device, the second check information being used to check that the first information is from the terminal device.
[0015] The second check information is, for example, a signature of a user of the terminal device. The second check information can or can not be in a same message as the first information. The terminal device sending the second check information can avoid an illegal user from invoking a network service, thereby improving network security.
[0016] In an optional implementation of the first aspect, the user of the terminal device is an individual, a family, an enterprise, or a government organization that owns the terminal device.
[0017] In an optional implementation of the first aspect, the method further includes deleting or revoking the first task credential in a case where message processing of the first task is completed, or in a case where it is determined that messages of the first task are no longer processed.
[0018] When the first task is completed, or when the terminal device determines to end the first task, the terminal device can actively delete or revoke the first task credential, so as to avoid a service subscribed by the user from being illegally used or abused.
[0019] In an optional implementation of the first aspect, the method further includes sending second information to the first network device, the second information indicating that the first task credential has been deleted or revoked.
[0020] After the terminal device deletes or revokes the first task credential, the terminal device can send the second information to the first network device, to request the first network device to delete or revoke the first task credential, so as to avoid a service subscribed by the user from being illegally used or abused.
[0021] In an optional implementation of the first aspect, the method further includes sending, to the first network device, task end information indicating that the first task has ended, in a case where message processing of the first task is completed, or in a case where it is determined that messages of the first task are no longer processed.
[0022] Some terminal devices can not actively delete or revoke the first task credential. These terminal devices can report the task end information, so that the first network device indicates the terminal device to timely delete or revoke the first task credential through the third information, to avoid a service subscribed by the user from being illegally used or abused.
[0023] In an optional implementation of the first aspect, the method further includes: receiving third information from the first network device, the third information indicating deletion or revocation of the first task credential; and deleting or revoking the first task credential according to the third information.
[0024] Some terminal devices can not actively delete or revoke the first task credential. The first network device can send the third information to the terminal device according to some mechanisms (such as a timeout mechanism, or receiving task end information from the second network device, or receiving information from the second network device indicating that the first task credential has been deleted or revoked), indicating the terminal device to delete or revoke the first task credential. Thereby, the user's subscribed service can be prevented from being illegally used or abused.
[0025] In an optional implementation of the first aspect, the information of the first task includes: information of a service required for executing the first task; and the N networks include a network providing the service.
[0026] In some cases, the terminal device has specific requirements for the service required for executing the first task, the terminal device can directly inform the first network device of the relevant information of the required service, so as to execute the first task using a suitable service.
[0027] In an optional implementation of the first aspect, the service includes at least one of the following: a communication service, a perception service, a computing service, a data service, an artificial intelligence service, or a digital twin service.
[0028] In a second aspect, embodiments of the present application provide a communication method, which is applied to a first network device. The first network device can be a software module and / or a hardware module in a core network. The first network device can be an integrated module or multiple discrete modules. The method includes: receiving information of a first task from a terminal device; determining N networks according to the information of the first task, N being a positive integer greater than 1; and sending a first task credential to the terminal device and the N networks, the first task credential being used for resource scheduling of the N networks respectively to process a packet of the first task.
[0029] The information of the first task indicates a task and / or a service to be invoked by a user of the terminal device, and the first network device can determine N networks involved in performing the first task according to the information of the first task. The first task credential is information associated with the first task, and after receiving the first task credential from the first network device, the N networks independently determine a resource scheduling strategy for performing the first task based on their own running conditions. After receiving the first task credential, the terminal device can invoke resources of the N networks to perform the first task based on the first task credential. Since the resource scheduling strategy for performing the first task is independently determined by each network, there is no need to formulate a cross-network strategy for performing the first task, thereby improving the efficiency of the terminal device in performing the task through the heterogeneous networks.
[0030] In an optional implementation of the second aspect, the method further includes: obtaining the first task credential in a case where the user of the terminal device has the right to use the N networks.
[0031] Obtaining the first task credential in a case where the user has the right can avoid the services of the N networks being illegally used or abused.
[0032] In an optional implementation of the second aspect, the method further includes: receiving the first information from the terminal device; and obtaining the first task credential in a case where the user of the terminal device has the right to use the N networks includes: determining (or generating) the first task credential in a case where the first information proves that the user of the terminal device has the right to use the N networks.
[0033] The first information can include right information issued by part or all of the N networks, and the first network device can generate the first task credential based on the first information, which can avoid the networks being illegally used or abused.
[0034] In an optional implementation of the second aspect, the method further includes: receiving the first information from the terminal device; and obtaining the first task credential in a case where the user of the terminal device has the right to use the N networks includes: sending the first information to a credential management network element in a case where the first information proves that the user of the terminal device has the right to use the N networks, the first information being used for generation of the first task credential; and receiving the first task credential from the credential management network element.
[0035] The first information can include right information issued by part or all of the N networks, and the first network device can generate the first task credential based on the first information, which can avoid the networks being illegally used or abused.
[0036] In an optional implementation of the second aspect, the first information includes identity information and / or right information of the user of the terminal device.
[0037] The identity information is used to prove that the user of the terminal device is a legal user, and the permission information is used to prove that the user of the terminal device has the permission to use one or more networks. The identity information can also be referred to as a user identification or a user portrait, and the permission information can also be referred to as permission information, authorization information, subscription information, or proof information. Embodiments of the present application do not limit the specific names of the identity information and the permission information. The terminal device can select different information as the first information based on actual conditions. For example, for some public service scenarios, the user of the terminal device only needs to provide identity information to prove that he or she is a legal user to use the public service. For some confidential scenarios, the user of the terminal device only needs to provide permission information to prove that he or she has the permission to use a certain service. For some paid service scenarios, the user of the terminal device needs to provide identity information and permission information. Therefore, the embodiments can be flexibly applied to different scenarios.
[0038] In an optional implementation of the second aspect, the method further includes: receiving first verification information from the terminal device; and the acquiring the first task credential in the case that the user of the terminal device has the permission to use the N networks includes: acquiring the first task credential in the case that the user of the terminal device has the permission to use the N networks, and the first verification information proves that the issuer of the first information is from the N networks.
[0039] The first verification information is, for example, a signature of the issuer of the first information. The first verification information and the first information can be located in one message or can not be located in one message. The first network device acquires the first task credential in the case that the first verification information is verified successfully, which can avoid an illegal user from invoking a network service, thereby improving network security.
[0040] In an optional implementation of the second aspect, the method further includes: receiving second verification information from the terminal device; and the acquiring the first task credential in the case that the user of the terminal device has the permission to use the N networks includes: acquiring the first task credential in the case that the user of the terminal device has the permission to use the N networks, and the second verification information proves that the first information is from the terminal device.
[0041] The second verification information is, for example, a signature of the user of the terminal device. The second verification information and the first information can be located in one message or can not be located in one message. The first network device acquires the first task credential in the case that the second verification information is verified successfully, which can avoid an illegal user from invoking a network service, thereby improving network security.
[0042] In an optional implementation of the second aspect, the user of the terminal device is an individual, a family, an enterprise, or a government organization that owns the terminal device.
[0043] In an optional implementation of the second aspect, the method further includes: sending, to the N networks, user information corresponding to the first task credential, the user information being used for resource scheduling of the N networks respectively to process the packets of the first task.
[0044] Different users have different execution requirements for tasks, for example, a paid user needs shorter latency, and a free user is insensitive to latency. The user information is used to indicate the execution requirement of the user for the first task, and sending the user information to the N networks helps the N networks to formulate appropriate resource scheduling strategies to meet the user's requirements while optimizing resource utilization.
[0045] In an optional implementation of the second aspect, the user information includes at least one of the following: a type of network service that the user can use, a maximum quota of network service that the user can use, a resource distribution area of network service that the user can use, a service level agreement of the user, a total amount of the first task, or a distribution area of the first task.
[0046] In an optional implementation of the second aspect, the method further includes: sending, to the N networks, time information corresponding to the first task credential, the time information indicating a maximum time interval of the packets of the first task.
[0047] Some terminal devices or networks can not actively request to delete or revoke the first task credential, and then the first network device can send time information corresponding to the first task credential to the N networks, and instruct the N networks to report task end information when the interval of the packets of the first task exceeds the maximum time interval, so that the first network device can timely delete or revoke the first task credential, and avoid that the service subscribed by the user is illegally used or abused.
[0048] In an optional implementation of the second aspect, the method further includes: receiving second information, the second information indicating that the first task credential has been deleted or revoked; and deleting or revoking the first task credential according to the second information.
[0049] After the terminal device and / or the N networks delete or revoke the first task credential, the terminal device and / or the N networks can send second information to the first network device to request the first network device to delete or revoke the first task credential. The terminal device and / or the N networks can send the second information to the first network device directly, or send the second information to the first network device through other network elements (such as a task management network element). The first network device deletes or revokes the local first task credential based on the second information, which can avoid that the service subscribed by the user is illegally used or abused.
[0050] In an optional implementation of the second aspect, the method further includes: sending, to the terminal device and / or the N networks, third information, the third information indicating to delete or revoke the first task credential.
[0051] In some cases, the terminal device and the N networks can not actively request to delete or revoke the first task credential, and the first network device can delete or revoke the first task credential based on its own mechanism (e.g., a timeout mechanism). After the first network device deletes or revokes the first task credential, the first network device can send third information to the terminal device and / or the N networks, instructing the terminal device and / or the N networks to delete or revoke the first task credential, so as to avoid illegal use or abuse of the service subscribed by the user. In other cases, only part of the terminal device and the N networks send the second information to the first network device. The first network device can delete or revoke the first task credential according to the second information sent by the part of the terminal device and the N networks. After the first network device deletes or revokes the first task credential, the first network device can send third information to the other part of the terminal device and the N networks that do not send the second information, instructing the other part of the terminal device and the N networks to delete or revoke the first task credential, so as to avoid illegal use or abuse of the service subscribed by the user.
[0052] In an optional implementation of the second aspect, the method further includes: receiving, from the terminal device and / or the N networks, task end information, the task end information indicating that the first task has ended; and the sending, to the terminal device and / or the N networks, of the third information includes: sending, to the terminal device and / or the N networks, the third information according to the task end information, the third information instructing to delete or revoke the first task credential.
[0053] Some terminal devices or networks can not actively delete or revoke the first task credential. These terminal devices can report the task end information, so that the first network device instructs the terminal devices to delete or revoke the first task credential in time through the third information, so as to avoid illegal use or abuse of the service subscribed by the user.
[0054] In an optional implementation of the second aspect, the information of the first task includes: information of a service required for executing the first task; and the N networks include a network providing the service.
[0055] In some cases, the terminal device has specific requirements for the service required for executing the first task. The terminal device can directly inform the first network device of the related information of the required service, and the first network device selects a suitable service to execute the first task based on the related information of the service, so as to ensure that the execution of the first task meets the user requirements.
[0056] In an optional implementation of the second aspect, the service includes at least one of the following: a communication service, a perception service, a computing service, a data service, an artificial intelligence service, or a digital twin service.
[0057] In a third aspect, embodiments of the present application provide a communication method applied to one or more network devices in a first network, which is exemplified below as being applied to a second network device in the first network. The second network device can be a software module and / or a hardware module in an access network, or the second network device can be a software module and / or a hardware module in a core network, or the second network device can be a software module and / or a hardware module in the Internet. The second network device can be an integrated module or multiple discrete modules. The method comprises: receiving, from a first network device, a first task credential, the first task credential being used for resource scheduling of N networks respectively to process a packet of a first task, N being a positive integer greater than 1, and the N networks including the first network; determining an association relationship between the first task credential and a resource scheduling policy; receiving, from a terminal device, the first task credential and the packet of the first task; determining the resource scheduling policy according to the first task credential received from the terminal device and the association relationship; and scheduling resources in the first network according to the resource scheduling policy to process the packet of the first task.
[0058] The steps of the above method can also be represented as: receiving, from a first network device, a first task credential, the first task credential being used for resource scheduling of N networks respectively to process a packet of a first task, N being a positive integer greater than 1, and the N networks including the first network; determining a resource scheduling policy according to the first task credential; receiving, from a terminal device, the first task credential and the packet of the first task; and processing the packet of the first task according to the first task credential received from the terminal device and the resource scheduling policy.
[0059] The first task credential is information associated with the first task. After receiving the first task credential from the first network device, the second network device independently determines a resource scheduling policy for executing the first task based on its own running condition. The resource scheduling policy associated with the first task credential can be generated according to the first task credential, or can be determined from a preset resource scheduling policy. The terminal device can invoke resources of N networks including the second network device to execute the first task based on the first task credential. Since the resource scheduling policy for executing the first task is independently determined by each network, there is no need to formulate a cross-network policy for executing the first task, thereby improving the efficiency of the terminal device in executing tasks through heterogeneous networks.
[0060] In an optional implementation of the third aspect, before determining the association relationship between the first task credential and the resource scheduling policy, the method further comprises: generating the resource scheduling policy according to the first task credential.
[0061] The resource scheduling strategy generated based on the first task credential is more in line with the current resource situation of the first network. For example, if the current resource of the first network is relatively sufficient, a resource scheduling strategy of scheduling more resources can be generated; if the current resource of the first network is relatively tight, a resource scheduling strategy of scheduling less resources can be generated. Therefore, the embodiment can improve the resource utilization efficiency of the first network.
[0062] In an optional implementation of the third aspect, the method further includes: receiving, from the first network device, user information corresponding to the first task credential; and generating the resource scheduling strategy based on the first task credential, including: generating the resource scheduling strategy based on the first task credential and the user information.
[0063] Different users have different execution requirements for tasks. For example, a paid user needs a shorter time delay, and a free user is not sensitive to the time delay. The user information is used to indicate the execution requirement of the user for the first task. The resource scheduling strategy formulated based on the user information can optimize the resource utilization rate while meeting the user requirement.
[0064] In an optional implementation of the third aspect, the user information includes at least one of the following information: a type of network service that the user can use, a maximum quota of network service that the user can use, a resource distribution area of network service that the user can use, a service level agreement of the user, a total amount of the first task, or a distribution area of the first task.
[0065] In an optional implementation of the third aspect, the method further includes: receiving, from the first network device, time information corresponding to the first task credential, the time information indicating a maximum time interval of the first task message; and deleting or revoking the first task credential when an interval between a current time and a time of last time of receiving the first task message is greater than or equal to the maximum time interval.
[0066] Based on the time information obtained from the first network device, the second network device can delete or revoke the first task credential in time when the interval of the first task message is greater than or equal to the maximum time interval, thereby avoiding that the subscribed service of the user is illegally used or abused.
[0067] In an optional implementation of the third aspect, the method further includes: sending, to the first network device, second information, the second information indicating that the first task credential has been deleted or revoked.
[0068] After the second network device deletes or revokes the first task credential, the second network device can send second information to the first network device, to request the first network device to delete or revoke the first task credential, so that the first network device informs other network devices and terminal devices to delete or revoke the first task credential, to avoid the service subscribed by the user being illegally used or abused. The second network device can directly send the second information to the first network device, or send the second information to the first network device through another network element (for example, a task management network element).
[0069] In an optional implementation of the third aspect, the method further includes: receiving third information from the first network device, the third information indicating to delete or revoke the first task credential; and deleting or revoking the first task credential according to the third information.
[0070] Some network devices can not actively delete or revoke the first task credential. The first network device can send third information to the second network device according to some mechanisms (for example, receiving task end information from the terminal device, or receiving information from the terminal device indicating that the first task credential has been deleted or revoked), to indicate the second network device to delete or revoke the first task credential. Thus, the service subscribed by the user can be avoided from being illegally used or abused.
[0071] In an optional implementation of the third aspect, the method further includes: receiving a packet of the first task; querying a task credential corresponding to the packet of the first task; and in a case where the task credential corresponding to the packet of the first task is not found, or in a case where the first task credential has been revoked, determining not to process the packet of the first task.
[0072] After the second network device deletes or revokes the first task credential, the user of the terminal device can no longer use the first task credential to schedule resources of the second network device. If the second network device receives the packet of the first task again, whether the packet carries the first task credential or not, and regardless of where the packet comes from, since the first task credential is not found or the first task credential has been revoked, the second network device can determine not to process the packet of the first task, thus avoiding the service subscribed by the user from being illegally used or abused.
[0073] In the fourth aspect, the embodiments of the present application provide a communication apparatus. The communication apparatus can include a processing unit and a communication unit, configured to perform: any one of the methods in the first aspect and the optional implementations thereof, or any one of the methods in the second aspect and the optional implementations thereof, or any one of the methods in the third aspect and the optional implementations thereof.
[0074] In a fifth aspect, an embodiment of the present application provides a communication apparatus, which can be a terminal device or a chip applied to a terminal device, or the communication apparatus can be a network device or a chip applied to a network device. The communication apparatus can include a processor. When the communication apparatus is a terminal device or a chip applied to a terminal device, the processor is configured to perform the method in any one of the first aspect and the optional implementation of the first aspect. When the communication apparatus is a network device or a chip applied to a network device, the processor is configured to perform the method in any one of the second aspect and the optional implementation of the second aspect, or the method in any one of the third aspect and the optional implementation of the third aspect.
[0075] Optionally, the communication apparatus can further include a transceiver. When the communication apparatus is a terminal device or a network device, the transceiver can be a transceiver circuit or an antenna, etc. When the communication apparatus is a chip applied to a terminal device or a network device, the transceiver can be an input / output interface, a pin, or a circuit, etc.
[0076] Optionally, the communication apparatus can further include a memory configured to store a computer program or an instruction. The processor executes the computer program or the instruction stored in the memory, so that the communication apparatus performs the method in any one of the first aspect and the optional implementation of the first aspect, or the method in any one of the second aspect and the optional implementation of the second aspect, or the method in any one of the third aspect and the optional implementation of the third aspect. When the communication apparatus is a terminal device or a network device, the memory can be a read-only memory or a random access memory, etc. When the communication apparatus is a chip applied to a terminal device or a network device, the memory can be a register or a cache, etc.
[0077] In a sixth aspect, an embodiment of the present application provides a communication system, which includes at least two of the communication apparatuses for performing the method in any one of the first aspect and the optional implementation of the first aspect, the communication apparatuses for performing the method in any one of the second aspect and the optional implementation of the second aspect, and the communication apparatuses for performing the method in any one of the third aspect and the optional implementation of the third aspect. Alternatively, the communication system includes at least two of the communication apparatuses for performing the method in any one of the first aspect and the optional implementation of the first aspect, the communication apparatuses for performing the method in any one of the second aspect and the optional implementation of the second aspect, and the communication apparatuses for performing the method in any one of the third aspect and the optional implementation of the third aspect.
[0078] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium storing a computer program or instructions, which, when executed on a communication apparatus, cause the communication apparatus to perform any one of the methods in the first aspect and the optional implementation thereof, or any one of the methods in the second aspect and the optional implementation thereof, or any one of the methods in the third aspect and the optional implementation thereof.
[0079] In an eighth aspect, an embodiment of the present application provides a computer program product comprising a computer program or instructions, which, when executed on a communication apparatus, cause the communication apparatus to perform any one of the methods in the first aspect and the optional implementation thereof, or any one of the methods in the second aspect and the optional implementation thereof, or any one of the methods in the third aspect and the optional implementation thereof. BRIEF DESCRIPTION OF DRAWINGS
[0080] FIG. 1 is a schematic diagram of an architecture of a communication system to which embodiments of the present application are applied;
[0081] FIG. 2 is a schematic diagram of an architecture of a core network to which embodiments of the present application are applied;
[0082] FIG. 3 is a schematic diagram of an architecture of a heterogeneous network to which embodiments of the present application are applied;
[0083] FIG. 4 is a schematic diagram of another architecture of a heterogeneous network to which embodiments of the present application are applied;
[0084] FIG. 5 is a schematic diagram of a communication method provided by an embodiment of the present application;
[0085] FIG. 6 is a schematic diagram of a method for deleting or revoking a first task credential provided by an embodiment of the present application;
[0086] FIG. 7 is a schematic diagram of another method for deleting or revoking a first task credential provided by an embodiment of the present application;
[0087] FIG. 8 is a schematic diagram of another communication method provided by an embodiment of the present application;
[0088] FIG. 9 is a schematic diagram of still another communication method provided by an embodiment of the present application;
[0089] FIG. 10 is a schematic diagram of a structure of a communication apparatus provided by an embodiment of the present application;
[0090] FIG. 11 is a schematic diagram of another structure of a communication apparatus provided by an embodiment of the present application. DETAILED DESCRIPTION
[0091] The technical solutions in the present application will be described below with reference to the accompanying drawings.
[0092] FIG. 1 is a schematic diagram of an architecture of a communication system 1000 to which embodiments of the present application are applied. As shown in FIG. 1, the communication system includes a radio access network (RAN) 100, wherein the RAN 100 includes at least one RAN node (e.g., 110a-110b, collectively referred to as 110 in FIG. 1), and can further include at least one terminal device (e.g., 120a-120j, collectively referred to as 120 in FIG. 1). The RAN 100 can further include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in FIG. 1). The terminal devices 120 are connected to the RAN nodes 110 wirelessly. The terminal devices and the terminal devices, and the RAN nodes and the RAN nodes can be connected to each other by wireline or wirelessly. The communication system 1000 can further include a core network (CN) 200. The RAN nodes 110 are connected to the core network 200 wirelessly or by wire. The core network devices in the core network 200 and the RAN nodes 110 in the RAN 100 can be independent and different physical devices, or can be the same physical device integrated with the logical functions of the core network devices and the logical functions of the RAN nodes. The communication system 1000 can further include an Internet 300.
[0093] The RAN 100 can be an evolved universal terrestrial radio access (E-UTRA) system, a new radio (NR) system, or a future wireless access system defined in the 3rd generation partnership project (3GPP), or a Wi-Fi system. The RAN 100 can also include two or more different wireless access systems described above. The RAN 100 can also be an open RAN (O-RAN).
[0094] The RAN node, also referred to as a network device, an access network device, a radio access network device, a RAN entity, or an access node, is used to help the terminal device access the communication system wirelessly. Optionally, the RAN node can also be referred to simply as a RAN.
[0095] In one application scenario, the RAN node can be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a 5th generation (5G) mobile communication system, a base station in a future mobile communication system, an access node (AP) in a Wi-Fi system, an AP in a long range radio (LoRa) system, or an AP in a vehicle-to-everything (V2X) system. The RAN node can be a macro base station (e.g., 110a in FIG. 1), a micro base station or an indoor station (e.g., 110b in FIG. 1), or a relay node or a donor node.
[0096] In another application scenario, a terminal device can access a wireless network through cooperation of a plurality of RAN nodes, and different RAN nodes implement part of functions of a base station. For example, a RAN node can be a central unit (CU), a distributed unit (DU), or a radio unit (RU). The CU here implements functions of a radio resource control (RRC) protocol and a packet data convergence protocol (PDCP) of the base station, and can also implement a function of a service data adaptation protocol (SDAP); the DU implements functions of a radio link control (RLC) layer and a medium access control (MAC) layer of the base station, and can also implement part or all of functions of a physical (PHY) layer; for descriptions of the above protocol layers, refer to relevant technical specifications of the 3GPP. The RU can be used to implement functions of transceiving radio frequency signals. The CU and the DU can be arranged as two independent RAN nodes, or integrated in the same RAN node, for example, integrated in a baseband unit (BBU). The RU can be included in a radio frequency device, for example, included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH). The CU can be further divided into two types of RAN nodes: a central unit control plane (CU-CP) and a central unit user plane (CU-UP).
[0097] In different systems, the RAN node can have different names, for example, in an O-RAN system, the CU can be referred to as an open CU (O-CU), the DU can be referred to as an open DU (O-DU), and the RU can be referred to as an open RU (O-RU). The RAN node in the embodiments of the present application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module, for example, the RAN node can be a server loaded with a corresponding software module. The embodiments of the present application do not limit the specific technology and specific equipment form adopted by the RAN node. For ease of description, a base station is described as an example of the RAN node in the following.
[0098] The terminal device is a device with wireless transceiving function, which can send signals to the base station or receive signals from the base station. The terminal device can also be referred to as a terminal, user equipment (UE), mobile station or mobile terminal, etc. The terminal device can be widely applied in various scenarios, such as device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), internet of things (IoT), virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, remote medical treatment, smart grid, smart furniture, smart office, smart wear, smart transportation and smart city, etc. The terminal device can be a mobile phone (such as 120a, 120e, 120f and 120j in FIG. 1), a notebook computer (such as 120g in FIG. 1), a printer with wireless transceiving function (such as 120h in FIG. 1), a wearable device, a vehicle (such as 120b in FIG. 1), a charging pile (such as 120c in FIG. 1), an airplane (such as 120i in FIG. 1), a ship, a robot, a mechanical arm or a smart home device, etc. The embodiments of the present application do not limit the specific technology and specific equipment form adopted by the terminal device.
[0099] By way of example, and without limitation, a wearable device is a portable device that can be directly worn on the body or integrated into a user's clothing or accessories. A wearable device is not only a hardware device, but also can achieve powerful functions through software support, data interaction, and cloud interaction. A wearable device can include electronic devices with full functions, large sizes, and complete functions that can be achieved without relying on a smart phone, such as smart watches and smart glasses; a wearable device can also include electronic devices that focus on a certain type of application function and need to be used in cooperation with other devices (such as a smart phone), such as smart bracelets and smart jewelry for measuring physical signs.
[0100] By way of example, and without limitation, a vehicle can be a smart car or an intelligent car, a digital car, an unmanned car, a driverless car, a pilotless car, or an automobile, a self-driving car or an autonomous car, or an electric vehicle (EV), where the EV can be a pure EV or a battery EV, a hybrid electric vehicle (HEV), a range extended EV (REEV), a plug-in HEV (PHEV), or a new energy vehicle. The various terminal devices described above can be considered as vehicle-mounted terminal devices if they are located on a vehicle (for example, placed in or installed in a vehicle), and the vehicle-mounted terminal device can also be referred to as a vehicle-mounted module, a vehicle-mounted chip, or an on-board unit (OBU).
[0101] A base station and a terminal device can be in a fixed location or can be movable. A base station and a terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can be deployed on the water surface; or can be deployed on an airplane, a balloon, or a man-made satellite. Embodiments of the present application do not limit the application scenarios of base stations and terminal devices.
[0102] The roles of the base station and the terminal device can be relative, for example, 120i in FIG. 1 (which can be a helicopter or a drone) can be configured as a mobile base station, and for 120j that accesses the wireless access network 100 through 120i, 120i is a base station; but for 110a, 120i is a terminal device, that is, 110a communicates with 120i through a wireless air interface protocol. Of course, 110a and 120i can also communicate through a base station-to-base station interface protocol, and in this case, 120i is also a base station relative to 110a. Therefore, the base station and the terminal device can be collectively referred to as a communication device, and 110a and 110b in FIG. 1 can be referred to as a communication device with a base station function, and 120a-120j in FIG. 1 can be referred to as a communication device with a terminal device function.
[0103] The base station and the terminal device, the base station and the base station, and the terminal device and the terminal device can communicate through a licensed spectrum, an unlicensed spectrum, or both the licensed spectrum and the unlicensed spectrum; can communicate through a spectrum below 6 gigahertz (GHz), a spectrum above 6 GHz, or both the spectrum below 6 GHz and the spectrum above 6 GHz. The embodiments of the present application do not limit the spectrum resources used for wireless communication.
[0104] In the embodiments of the present application, the functions of the base station can also be performed by a module (such as a chip) in the base station, or by a control subsystem containing base station functions. The control subsystem containing base station functions herein can be a control center in the application scenarios described above, such as smart grids, industrial control, intelligent transportation, and smart cities. The functions of the terminal device can also be performed by a module (such as a chip or a modem) in the terminal device, or by a device containing terminal device functions.
[0105] The functions of the core network 200 mainly include providing user connection, user management, and service bearing, and providing an interface to an external network (such as the Internet 300) as a bearing network. The core network 200 is briefly introduced below by taking the service-based architecture (SBA) shown in FIG. 2 as an example. It should be noted that the UE, RAN, and DN shown in FIG. 2 are used to facilitate the description of the interface between the core network 200 and external devices or external networks, and the UE, RAN, and DN do not belong to the core network 200.
[0106] SBA is mainly embodied in the control plane, and the essence of SBA is to define network functions as a number of "service" modules that can be flexibly invoked according to the three principles of "self-contained, reusable and independent management". Based on this, the operator can flexibly customize networking according to business needs. The interaction between network functions is realized by service invocation, and each network function presents a common service interface to the outside, which can be authorized by network functions or service invocation.
[0107] As shown in FIG. 2, the core network 200 includes a user plane function (UPF), an access and mobility management function (AMF), a session management function (SMF), a unified data management function (UDM), and an authentication server function (AUSF).
[0108] The above-mentioned UPF, AMF, SMF, UDM and AUSF can be referred to as core network elements or core network devices. These network elements can be independent hardware devices, or modules integrated in the same hardware device to implement different functions, or software functions running on a dedicated hardware or virtualized functions instantiated on a cloud platform. The embodiments of the present application do not limit the specific form of the core network elements.
[0109] The core network elements in FIG. 2 are briefly introduced as follows.
[0110] The UPF, which can also be referred to as a user plane device, a user plane function network element, a user plane network element or a user plane function entity, can be understood as the naming of the user plane function network element in 5G. The user plane function network element mainly includes the following functions: data packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, uplink packet detection and downlink data packet storage, and other user plane related functions.
[0111] Optionally, the UPF can be divided into a protocol data unit (PDU) session anchor UPF (PSA-UPF) and an intermediate UPF (I-UPF), wherein the PSA-UPF is a UPF supporting a PDU session anchor function, is a UPF connected with a data network (DN) through an N6 interface, and is responsible for data transmission between a core network and the DN; all UPFs between the RAN and the PSA-UPF can be referred to as I-UPFs, the I-UPFs can be connected with the RAN through an N3 interface, and the I-UPFs can be connected with the PSA-UPF through an N9 interface.
[0112] The AMF, which can also be referred to as a mobility management device, can be understood as the naming of a mobility management network element in the 5G architecture. The mobility management network element mainly includes the following functions: connection management, mobility management, registration management, access authentication and authorization, reachability management, security context management, and other access and mobility related functions.
[0113] The SMF, which can be understood as the naming of a session management function network element in the 5G architecture. The session management function network element mainly performs session management, execution of a control policy issued by a policy control function (PCF), selection of a UPF, and UE internet protocol (IP) address allocation.
[0114] The UDM, which can also be referred to as a unified data management network element, a unified data management entity, or a data management device, can be understood as the naming of a unified data management network element in the 5G architecture. It is mainly used for processing terminal device identification, access authentication, registration, and mobility management.
[0115] The AUSF, which can also be referred to as an authentication service function network element, an authentication service function entity, an authentication service device, or an authentication device, can be understood as the naming of an authentication service function network element in the 5G architecture. The authentication service function network element is mainly used for user authentication. For example, after the authentication service function network element receives an authentication request initiated by a subscription user, the authentication service function network element can authenticate and / or authorize the subscription user through authentication information and / or authorization information stored in the unified data management network element, or generate authentication and / or authorization information of the subscription user through the unified data management network element. The authentication service function network element can feed back the authentication information and / or authorization information to the subscription user. In one possible implementation manner, the authentication service function network element can also be combined with the unified data management network element.
[0116] The DN is a network outside the operator network, such as the Internet 300. The operator network (for example, the core network 200) can access multiple DNs, and multiple services can be deployed on one DN to provide data, voice, communication, sensing, computing, digital twin, artificial intelligence and other services for terminal devices. For example, the DN is a private network of a certain intelligent factory, sensors installed in the workshop of the intelligent factory are terminal devices, a control server of the sensors is deployed in the DN, the sensors can communicate with the control server, obtain instructions from the control server, and transmit collected sensor data to the control server according to the instructions, and the control server provides computing services for the sensors based on the sensor data. For another example, the DN is an internal office network of a certain company, and the mobile phones or computers of employees of the company are terminal devices, and the mobile phones or computers of the employees can access data on the internal office network of the company, and the internal office network provides data services for the mobile phones or computers.
[0117] In FIG. 2, Uu, N1, N2, N3, N4, N6 and N9 are interface numbers, wherein the dashed line corresponding to N9 indicates that this interface is an optional interface. Namf is a service interface corresponding to the AMF, Nsmf is a service interface corresponding to the SMF, Nausf is a service interface corresponding to the AUSF, and Nudm is a service interface corresponding to the UDM. The meanings of the interfaces shown in FIG. 2 can be referred to the related definitions in the 3GPP standard protocol, which are not limited herein.
[0118] The above network architecture is only illustrative, and the network architecture to which the embodiments of the present application are applicable is not limited thereto. Any network architecture including the functions of the above-mentioned network elements is applicable to the embodiments of the present application.
[0119] The above naming is only defined for the purpose of distinguishing different functions, and should not constitute any limitation on the present application. The present application does not exclude the possibility of using other names in the 5G network and future other networks. For example, in future communication networks, part or all of the above-mentioned network elements can use the terms in 5G, or other names, etc. The above interface name is only an example, and the name of the interface in the specific implementation can be other names, which are not limited in the present application.
[0120] As described above, the DN can provide data, voice, communication, sensing, computing, digital twin, artificial intelligence and other services for terminal devices, and the terminal devices need to transmit data to at least one DN using these services, which usually needs to pass through the access network and the core network to reach the at least one DN. In some cases, data also needs to be transmitted from one DN to another DN. The architectures of these networks through which the data passes are different, forming a heterogeneous network.
[0121] FIG. 3 is a schematic diagram of a heterogeneous network to which the embodiments of the present application are applied.
[0122] With the development of communication technology, the types of networks providing services for terminal devices are constantly enriched, wherein the network providing services for the terminal device can be an access network, a partial access network, a core network, a partial core network, or a network composed of a partial access network and a partial core network, and the network providing services for the terminal device can also be a network provided by a third-party service provider. Different types of networks constitute a heterogeneous network, and each network (such as an access network, a core network, and a network provided by a third-party service provider) constituting the heterogeneous network can also be referred to as a subnet.
[0123] As shown in FIG. 3, each subnet can be connected to a service bus of the core network, and the core network can further include one or more of the following network elements: an identity management network element, a tenant management network element, a task management network element, a credential management network element, or a user plane gateway, which are all connected to the service bus of the core network and can interact with each subnet in signaling and / or data. The dashed line in FIG. 3 represents the service bus, and the solid line represents the actual transmission path of signaling and / or data (example, not limitation).
[0124] The identity management network element is responsible for identity authentication and access management of users of terminal devices, which can be implemented by an AMF or can be a separate network element.
[0125] The tenant management network element is responsible for user management, generation and issuance of task credentials, and user context management, etc.
[0126] The task management network element is responsible for assisting terminal devices to obtain task credentials, establishing session connections for tasks, controlling messages of traffic flows using credentials, and invoking subnet services using credentials, etc. The task management network element can be implemented by an SMF or can be a separate network element.
[0127] The credential management network element is responsible for management of task credentials, such as generation, sending, revoking, and deleting of task credentials, etc.
[0128] The user plane gateway is responsible for data transmission between the core network and the DN, which can be implemented by a PSA-UPF or can be a separate network element.
[0129] The subnet 1 and the subnet 2 can be user plane network elements of the core network or can be DNs independent of the core network. Each subnet including the access network provides services for users according to task credentials invoking resources.
[0130] FIG. 4 is a schematic diagram of another heterogeneous network to which embodiments of the present application are applied.
[0131] A physical network can be logically divided into several virtual subnets by technologies such as virtualization to provide services to users, where the subnets can be networks providing communication, sensing, computing, data, digital twin, or artificial intelligence (AI) services, and the users can be individuals, families, enterprises, or government organizations.
[0132] As shown in FIG. 4, the physical network is logically divided into access network 1, access network 2, access network 3, and service network, where access network 1, access network 2, and access network 3 can be considered as three subnets, and the service network can be considered as six subnets, where the access network 1, access network 2, and access network 3 can be wireless access networks or wired access networks.
[0133] Terminal devices such as drones, cars, cameras, robots, and cars call one or more services in the service network through the access network 1; terminal devices such as mobile phones, laptops, and desktop computers call one or more services in the service network through the access network 2; and terminal devices such as smart glasses, smart watches, and smart earphones call one or more services in the service network through the access network 3.
[0134] For example, a mobile phone can call a communication service for satellite communication, a car can call a sensing service for surrounding environment and object sensing, a laptop can call a computing service to offload computing tasks to a network computing unit, smart glasses can call a data service for data collection, processing, and analysis, a robot can call a network AI capability for wisdom empowerment, and a desktop computer can call a digital twin service for network simulation.
[0135] The functions and architectures of the above subnets are different, and there are differences between them in terms of resource scheduling methods and protocol processes, forming a complex heterogeneous network. In order to meet the business needs of terminal devices, complex processes and cross-network strategies often need to be developed.
[0136] For example, a ground base station access network uses a network registration process defined by an NR access network protocol, a home wireless access network uses a fixed wireless access protocol process, and a satellite access network uses a non-terrestrial network (NTN) defined protocol process. When a terminal device accesses a network through different access networks, the specific processing method of each 5G quality of service identifier (5G quality of service identifier, 5QI) corresponding to the message flow in different access networks needs to be specified in detail. With the development of communication technology, the types of service-providing subnets are constantly enriched, and the above business processing process needs to develop complex cross-network strategies for each newly added subnet, resulting in a decrease in the efficiency of terminal devices performing tasks through heterogeneous networks, thus failing to adapt to the development trend of future networks.
[0137] The communication method provided by the embodiment of the present application is described below.
[0138] As shown in FIG. 5, the method 500 includes the following.
[0139] S510, the terminal device sends information of a first task to a first network device.
[0140] Correspondingly, the first network device receives the information of the first task from the terminal device.
[0141] The information of the first task is information for the first network device to determine N networks for executing the first task (i.e., processing messages of the first task), where N is a positive integer greater than 1. The first task can be a satellite communication task, a perception task for perceiving surrounding environment and objects, a computing task for offloading computing tasks to a network computing unit, a data task for collecting, processing and analyzing data, an AI task for intelligent empowerment, or a digital twin task for network simulation and simulation, etc. The first task can also be a combination of multiple tasks, and the embodiments of the present application do not limit the specific content of the first task.
[0142] The information of the first task can include information of at least one service required for executing the first task; and the N networks include a network providing the at least one service.
[0143] In some cases, the terminal device has specific requirements for the service required for executing the first task, and the terminal device can directly inform the first network device of the related information of the required service, so as to facilitate the first network device to determine the network capable of providing the required service of the terminal device. Optionally, the service required for executing the first task can include at least one of the following services: a communication service, a perception service, a computing service, a data service, an artificial intelligence service, or a digital twin service.
[0144] The following gives several examples of the information of the first task.
[0145] Optionally, the information of the first task can be a profile of the first task. For example, when the terminal device is a camera, the profile of the first task can be that the video taken by the camera counts the types and quantities of goods in a store, and the first network device can determine that the service required for performing the first task is computer vision based on the profile, and select a network providing the computer vision service from a plurality of networks providing the computer vision service as the subnet for performing the first task.
[0146] Optionally, the information of the first task can also be the type of the service required for performing the first task. For example, the camera can send the computer vision as the information of the first task to the first network device, and the first network device can select a network providing the computer vision service from a plurality of networks providing the computer vision service as the subnet for performing the first task. When the user needs a value-added service (for example, reminding the user to restock when the quantity of goods is below a threshold), the camera can send the computer vision and data analysis as the information of the first task to the first network device, and the first network device can select a network providing the computer vision service from a plurality of networks providing the computer vision service as the subnet for performing the first task, and select a network providing the data analysis service from a plurality of networks providing the data analysis service as the subnet for performing the first task.
[0147] Optionally, the information of the first task can also be the identity of the service required for performing the first task. Still taking the camera as an example, the vendor of the camera provides the computer vision service and the data analysis service, and the camera can send the identity (for example, the IP address) of the computer vision service and the identity of the data analysis service as the information of the first task to the first network device, and the first network device can select the network corresponding to the identity from a plurality of networks providing the computer vision service and a plurality of networks providing the data analysis service as the subnet for performing the first task.
[0148] The information of the first task can also be other information for determining the N networks for performing the first task, and embodiments of the present application do not limit the specific content of the information of the first task.
[0149] The terminal device can send the information of the first task to the first network device through a wireless network such as a cellular network, or send the information of the first task to the first network device through a wired network such as an optical fiber, and embodiments of the present application do not limit the sending manner of the information of the first task.
[0150] After receiving the information of the first task, the first network device can perform the following steps.
[0151] S520, the first network device determines the N networks according to the information of the first task.
[0152] After determining the service required for performing the first task, the first network device determines N networks for performing the first task.
[0153] For example, the first network device determines that the service required for performing the first task is a computer vision service, and the N networks include a network A providing the computer vision service, a core network connected with the network A, and an access network connecting the core network and the terminal device.
[0154] For another example, the first network device determines that the service required for performing the first task is a computer vision service and a data analysis service, and the N networks include a network A providing the computer vision service, a network B providing the data analysis service, a core network connected with the network A and the network B, and an access network connecting the core network and the terminal device.
[0155] After determining the N networks for performing the first task, the first network device can perform the following steps.
[0156] S530, the first network device obtains a first task credential for resource scheduling of the N networks respectively to process the packet of the first task.
[0157] The first task credential is a credential of the terminal device using the resources of the N networks to perform the first task, and is also a credential of the N networks formulating a resource scheduling strategy related to the first task. In other words, the first task credential is proof information of the terminal device proving that it has the permission to use the resources of the N networks to perform the first task.
[0158] The first task credential can be a string uniquely identifying the first task within a limited time. For example, the "within a limited time" means that the first task credential is valid before the end of the first task, and the first task credential is invalid after the end of the first task.
[0159] The first task credential can be randomly generated, or can be generated based on the information of the first task or the permission information provided by the service related to the first task (such as a verifiable credential (VC) or a verifiable presentation (VP) described below). Embodiments of the present application do not limit the generation method of the first task credential.
[0160] For example, a string can be generated by using a secret key to hash calculate the information of the first task or the permission information provided by the service related to the first task, which is an example of the first task credential.
[0161] The first network device can generate the first task credential by itself, or can obtain the first task credential from other network elements.
[0162] For example, the first network device can send the information of the first task or the permission information of the service related to the first task to the credential management network element. Correspondingly, the credential management network element receives the information of the first task or the permission information of the service related to the first task from the first network device, generates the first task credential according to the information of the first task or the permission information of the service related to the first task, and sends the first task credential to the first network device.
[0163] In some scenarios, the user of the terminal device does not need to provide any information to prove that he or she has the permission to use the N networks. For example, in the earthquake prediction scenario, the first network device can issue the first task credential for obtaining the earthquake prediction information to the user without the user providing the identity information and / or the permission information. In other scenarios, the user of the terminal device needs to prove that he or she has the permission to use the N networks to obtain the first task credential from the first network device.
[0164] The following describes an embodiment in which the user of the terminal device proves that he or she has the permission to use the N networks.
[0165] Optionally, before obtaining the first task credential, the first network device can receive first information from the terminal device, the first information being used to prove that the user of the terminal device has the permission to use the N networks. The user of the terminal device can be an individual, a family, an enterprise, or a government organization that owns the terminal device.
[0166] As an optional example, the first information can include the permission information issued by some or all of the N networks.
[0167] For example, the first information can include the permission information (e.g., the identity of the server) issued by the server providing the AI service, which proves that the user of the terminal device has the permission to use the AI service. Generally, the AI server verifies whether the user is a legal user when issuing the permission information. Therefore, the user who has the permission to use the AI service is generally a legal user and has the permission to use the access network and the core network. The first network device can issue the first task credential to the user of the terminal device based on the permission information issued by the AI server, proving that the user of the terminal device has the permission to use the access network, the core network, and the AI service, so as to avoid the network being used illegally or being abused.
[0168] Of course, the first information can include the permission information issued by all of the N networks, such as the permission information issued by the server providing the AI service, the permission information issued by the access network, and the permission information issued by the core network, to prove that the user of the terminal device has the permission to use the access network, the core network, and the AI service.
[0169] As another optional example, the first information can include identity information and / or permission information of the user of the terminal device, where the identity information is used to prove that the user of the terminal device is a legal user, and the permission information is used to prove that the user of the terminal device has the permission to use one or more subnets, the identity information can also be referred to as a user identifier or a user profile, and the permission information can also be referred to as permission information, authorization information, subscription information, or proof information, and embodiments of the present application do not limit the specific names of the identity information and the permission information.
[0170] For example, the first information can include identity information of the user of the terminal device, which proves that the user of the terminal device is a very important person (VIP) user of the operator and has the permission to use the access network and the core network; based on the identity information, the first network device determines that the user of the terminal device has the permission to use the N networks, and can send the first task credential to the terminal device.
[0171] The terminal device can select different information as the first information based on actual conditions, for example, for some public service scenarios, the user of the terminal device only needs to provide identity information to prove that he or she is a legal user to use the public service, and does not need to prove that he or she has the permission to use the public service; for some confidential scenarios, the user of the terminal device only needs to provide permission information to prove that he or she has the permission to use a certain service, and does not need to provide identity information; for some paid service scenarios, the user of the terminal device can provide identity information and permission information to prove that the user of the terminal device is a legal user and has the permission to use the paid service. Therefore, the embodiments based on the identity information and / or the permission information to prove that the user of the terminal device has the permission to use the N networks can be flexibly applied to different scenarios.
[0172] After receiving the first information, the first network device can verify the first information based on the locally stored identity information and / or permission information, or initiate online verification to the issuer of the first information. If the verification is passed, the first network device can issue the first task credential to the user of the terminal device; if the verification fails, the first network device determines not to issue the first task credential.
[0173] In order to improve the security of the first information, the verification of the first information by the first network device can be divided into two aspects, one aspect is to verify whether the first information itself is legal, and the other aspect is to verify whether the sender of the first information is legal, and the two aspects can exist at the same time or only one of them can exist.
[0174] First, embodiments for verifying whether the first information itself is legal are introduced.
[0175] Optionally, the first information comprises first verification information, and the first verification information is used for verification of a signer (or, a provider, or a generator) of the first information.
[0176] The first verification information is, for example, a signature of the signer of the first information, and the first information carrying the first verification information can avoid an illegal user from invoking the network service, thereby improving network security.
[0177] For example, the first information comprises permission information signed by a server providing an AI service, and the signer of the first information is the AI server. The AI server can use a private key of the AI server to sign the permission information to obtain the first verification information, and the first verification information is carried in the first information, so that a device (for example, the first network device) that needs to verify the first information can verify the first information based on a public key of the AI server. If the first verification information passes the verification, it indicates that the signer of the first information has a legal identity, and the first network device can issue the first task credential; if the first verification information fails the verification, it indicates that the signer of the first information does not have a legal identity, and the first network device can not issue the first task credential.
[0178] The following describes an embodiment of verifying whether the sender of the first information is legal.
[0179] Optionally, the terminal device can send second verification information to the first network device when sending the first information to the first network device, and the second verification information is used for verifying that the first information comes from the terminal device.
[0180] The second verification information is, for example, a signature of a user of the terminal device. The terminal device sending the second verification information can avoid an illegal user from invoking the network service, thereby improving network security.
[0181] For example, the terminal device can use a private key of the user to sign the first information to obtain the second verification information, so that a device (for example, the first network device) that needs to verify the first information can verify the first information based on a public key of the user. If the second verification information passes the verification, it indicates that the sender of the first information has a legal identity, and the first network device can issue the first task credential; if the second verification information fails the verification, it indicates that the sender of the first information does not have a legal identity, and the first network device can not issue the first task credential.
[0182] The second verification information can also be other information that can verify the sender of the first information, for example, a time stamp of the terminal device sending the first information, or challenge information received by the terminal device from the core network. Embodiments of the present application do not limit the specific content of the second verification information.
[0183] After obtaining the first task credential, the first network device can perform the following steps.
[0184] S540a, the first network device sends the first task credential to the terminal device.
[0185] S540b, the first network device sends the first task credential to the N networks.
[0186] The first task credential is information associated with the first task. After receiving the first task credential from the first network device, the N networks determine a resource scheduling policy of the first task according to the first credential. Optionally, the N networks can independently determine the resource scheduling policy of executing the first task based on their own running conditions. After receiving the first task credential, the terminal device can invoke the resources of the N networks to execute the first task based on the first task credential.
[0187] S540a and S540b can be executed simultaneously or sequentially, and the execution order of S540a and S540b is not limited in the embodiments of the present application. The N networks include a network provided by the second network device. The operations performed by the N networks are described below with the second network device as an example.
[0188] It should be noted that the network can be considered as a logical level concept of the network device. In some examples that are biased towards the logical level, the concept of "network" is often used, and in some examples that are biased towards the physical level, the concept of "network device" is often used. In various embodiments of the present application, if not specifically stated, the two concepts of network and network device are equivalent.
[0189] S550, the second network device determines an association relationship between the first task credential and the resource scheduling policy.
[0190] The second network device can generate a resource scheduling policy according to the first task credential, and record the association relationship between the first task credential and the resource scheduling policy. Alternatively, the second network device can select a resource scheduling policy matching the first task credential from one or more preset resource scheduling policies, and record the association relationship between the first task credential and the resource scheduling policy.
[0191] For example, when the second network device is a base station, the base station can determine, based on the first task credential, an air interface resource scheduling policy for performing the first task, which describes time domain resources and / or frequency domain resources that can be used by the first task, so that messages of the first task can be timely delivered to the core network. When the second network device is a core network device, the core network device can determine, based on the first task credential, a QoS policy for performing the first task, which describes a bearer resource that can be used by the first task, such as a guaranteed flow bit rate (GBR) bearer, a non-GBR (non-GBR) bearer, or a delay critical GBR bearer, so that messages of the first task can be timely delivered to the core network. When the second network device is a third-party network device (such as an AI server), the resource scheduling policy determined by the third-party network device based on the first task credential can be a computing power resource scheduling policy, a storage resource scheduling policy, or a delay guarantee policy, so that messages of the first task can be processed according to user demand.
[0192] Since the resource scheduling policy for performing the first task is independently determined by each network according to its own running condition, each network only needs to ensure the normal execution of the first task in the network, and does not need to transmit uniform policy information between networks, nor does it need to formulate a cross-network policy for performing the first task, thereby improving the efficiency of the terminal device in performing tasks through heterogeneous networks.
[0193] In actual application, different users have different execution requirements for tasks, for example, a paid user needs shorter delay, and a free user is not sensitive to delay. Therefore, the first network device can send user information to the N networks, the user information indicating the execution requirement of the first task, so that the resource scheduling policy formulated by the N networks based on the user information can optimize resource utilization while meeting user demand.
[0194] The following describes an embodiment in which the second network device determines a resource scheduling policy based on user information.
[0195] Optionally, the second network device can receive, from the first network device, user information corresponding to the first task credential, and determine the resource scheduling policy according to the first task credential and the user information.
[0196] The user information can include at least one of the following information:
[0197] a type of network service that can be used by the user, a maximum quota of network service that can be used by the user, a resource distribution area of network service that can be used by the user, a service level agreement (SLA) of the user, a total amount of the first task, or a distribution area of the first task.
[0198] The type of network service available to the user can be a communication service, a computing service, a data service, an artificial intelligence service, or a digital twin service, etc.
[0199] The maximum quota of the network service available to the user can be a bandwidth quota and a computing power quota specified in the agreement between the user and the operator, etc.
[0200] The resource distribution area of the network service available to the user can be a city, a province, a country, or the world, etc.
[0201] The SLA of the user can include the resource type of the service or the business rate of the user, etc., wherein the resource type can be a traffic quota, a latency requirement of each subnet, an experience level, a computing power quota, and a storage capacity, etc.
[0202] The total amount of the first task can be the data amount of the first task, or the computing power resource, the storage resource, and the communication resource required to execute the first task, etc.
[0203] The distribution area of the first task can be some business areas in a geographical range, for example, a factory area, and the business areas can be a restaurant and a factory, etc.
[0204] The user information and the first task credential can be sent simultaneously or not. The following takes the case of sending the user information and the first task credential simultaneously as an example.
[0205] The first network device can send the user information and the first task credential to N networks through the user context, and the N networks generate a resource scheduling strategy of the first task based on the user context. The resource scheduling control strategy can include one or more of the following: the type of service called by the first task credential, whether the service called by the first task credential can recursively call other types of services, the type of recursively called service, the maximum depth of recursively called service, the priority of the first task credential scheduling resources, the minimum amount of available resources, and the maximum amount of available resources, etc.
[0206] The above recursive call refers to: in the case that the granularity of the service called by the first task credential is large, the second network device can call a service with fine granularity to meet the service demand of the first task according to the actual situation.
[0207] For example, the first task credential invokes a QoS service of the core network, but does not specify the specific content of the QoS service, and the resource scheduling strategy formulated by the core network can include a QoS class identifier (QCI), an allocation and retention priority (ARP), and reflective QoS attributes (RQA), wherein the QCI indicates that the bearer type is GBR or non-GBR, and for GBR, a flow bit rate can be further defined, such as a guaranteed flow bit rate (GFBR) and a maximum flow bit rate (MFBR).
[0208] The following are several examples of resource scheduling control strategies:
[0209] For example, according to the type of network service that the user can use, the resource distribution area of the network service that the user can use, and the predicted distribution area of the first task, the second network device can determine which network elements can provide services for the first task, the content of the services provided by the network elements, and whether a service chain needs to be formed between the network elements. In the service chain, the maximum number of recursive invocations of services provided by other network elements by a certain network element is the maximum depth of the recursive invocation of services.
[0210] For another example, according to the user SLA and the total amount of the first task, the satellite network determines the parameters of the satellite channel when providing network access services for the terminal device, or the terrestrial mobile network base station determines the parameters of the logical channel and the physical channel allocated for the terminal device. The user plane of the core network can determine the traffic quota and the delay requirement of the first task according to the user SLA and the total amount of the first task.
[0211] For another example, according to the maximum quota of AI services that the user can use and the total amount of the first task, the AI server can determine the priority of the resource scheduled by the first task credential. When the resources of the AI service scheduled by the first task credential reach or exceed the maximum quota, if the AI server has a large amount of idle resources, the AI server can continue to schedule resources for the first task, but the priority of the scheduled resources is the lowest, that is, other tasks are allowed to preempt the resources of the first task.
[0212] Returning to S540a, after the terminal device receives the first task credential, the terminal device can perform the following steps.
[0213] S560, the terminal device sends the first task credential and the message (or, data packet) of the first task.
[0214] The terminal device can carry the first task credential in each packet of the first task. Alternatively, the terminal device can first send the first task credential to establish a connection, and the packets sent subsequently through the link no longer carry the first task credential.
[0215] For example, the terminal device can package the first task credential and the data of the first task to generate a user datagram protocol (UDP) packet, each of which contains the first task credential. Alternatively, the terminal device can carry the first task credential in a transmission control protocol (TCP) request, and after the TCP connection is established, send the data packet of the first task through the TCP connection, which no longer carries the first task credential.
[0216] Embodiments of the present application do not limit the specific way in which the terminal device sends the first task credential and the packet of the first task.
[0217] After receiving the packet of the first task, the second network device can perform the following steps.
[0218] S570, the second network device determines a resource scheduling strategy according to the first task credential received from the terminal device and the association relationship.
[0219] S580, the second network device schedules resources in the first network to process the packet of the first task according to the resource scheduling strategy.
[0220] The second network device can save the association relationship between the first task credential and the resource scheduling strategy when generating the resource scheduling strategy, so that when the second network device receives the first task credential from the terminal device, it can determine the resource scheduling strategy according to the locally saved association relationship, and then schedule resources to process the packet of the first task according to the resource scheduling strategy.
[0221] If the terminal device uses a TCP connection to send the packet, the second network device can receive a packet that does not carry the first task credential. The second network device can determine whether the received packet belongs to the packet of the first task based on the relevant information of the TCP connection carried by the packet.
[0222] For example, the terminal device transmits the message of the first task by using a TCP connection, and the terminal device can send the first task credential and a TCP connection identifier to the second network device in the process of establishing the TCP connection, and the second network device records the association between the first task credential and the TCP connection identifier. After the second network receives the message without the first task credential through the TCP connection, the second network searches for the corresponding task credential based on the TCP connection identifier carried in the message. If the query result is the first task credential, it can be determined that the message is the message of the first task, and then the resources in the first network can be scheduled by the resource scheduling strategy associated with the first task credential to process the message of the first task.
[0223] The association between the first task credential and the resource scheduling strategy can also be saved on other devices, and the second network device queries the association from the other devices when needed.
[0224] For example, the association between the first task credential and the resource scheduling strategy can be saved in the control plane network element of the core network. After the user plane network element of the core network receives the first task credential from the terminal device, the user plane network element of the core network can query the resource scheduling strategy corresponding to the first task credential from the control plane network element of the core network. After the control plane network element of the core network determines the resource scheduling strategy corresponding to the first task credential based on the previously saved association, the control plane network element of the core network sends the identifier of the resource scheduling strategy to the user plane network element of the core network. The user plane network element of the core network determines the resource scheduling strategy corresponding to the first task credential based on the identifier of the resource scheduling strategy, and schedules resources to process the message of the first task based on the resource scheduling strategy.
[0225] The embodiments of the present application do not limit the specific way in which the second network device determines the resource scheduling strategy.
[0226] The way in which the second network device processes the message of the first task can be one or more of sending, receiving, encrypting, decrypting, storing, and calculating.
[0227] The embodiments of the present application do not limit the specific way in which the second network device processes the message of the first task.
[0228] In summary, in the method 500, the information of the first task indicates a task that needs to be performed by a user of the terminal device and / or a service that needs to be invoked, and the first network device can determine the N networks involved in performing the first task according to the information of the first task. The first task credential is information associated with the first task, and after receiving the first task credential from the first network device, the N networks independently determine a resource scheduling strategy for performing the first task based on their own running conditions. After receiving the first task credential, the terminal device can invoke the resources of the N networks to perform the first task based on the first task credential. Since the resource scheduling strategy for performing the first task is independently determined by each network, there is no need to develop a cross-network strategy for performing the first task, thereby improving the efficiency of the terminal device in performing the task through the heterogeneous network.
[0229] After the first task is performed, the terminal device or the second network device can request the first network device to delete or revoke the first task credential.
[0230] For example, the terminal device or the second network device can send a request message to the first network device, where the request message carries the first task credential and requests to delete or revoke the first task credential. Deleting the first task credential means no longer saving the first task credential (or no longer saving the association between the first task credential and the resource scheduling strategy), and revoking the first credential means recording the state of the saved first task credential as revoked or deactivated. The first task credential in the revoked or deactivated state can no longer be used to schedule the resources of the N networks.
[0231] In some scenarios, the terminal device or the second network device can not actively request to delete or revoke the first task credential, and the first network device can use some mechanisms (such as a timeout mechanism) to prevent the user-subscribed service from being illegally used or abused.
[0232] As shown in FIG. 6, the method 500 further includes:
[0233] S590, the first network device sends time information corresponding to the first task credential to the N networks, where the time information indicates a maximum time interval of packets of the first task.
[0234] The maximum time interval can also be referred to as: a maximum value of a time interval at which two adjacent packets of the first task arrive at the second network device, or a maximum value of a time interval at which the second network device receives two adjacent packets of the first task. The maximum time interval can be an absolute time, such as 1 second, 10 seconds, or 1 minute. Alternatively, the maximum time interval can be a multiple of a preset time period, such as 3 times of a task keep-alive time period (i.e., a time period for keeping the first task alive).
[0235] S591, when the interval between the current time and the time when the first message is last received is greater than or equal to the maximum time interval, the second network device deletes or revokes the first task credential.
[0236] After the second network device receives a message of the first task, if the next message of the first task is not received after reaching or exceeding the maximum time interval, the second network device can consider that the first task has ended, and the second network device can delete or revoke the local first task credential.
[0237] It should be noted that deleting or revoking the first task credential based on time information is not the only choice of the second network device, and the second network device can also delete or revoke the first task credential based on other mechanisms (for example, the resource usage of the second network device exceeds a threshold).
[0238] S592, the second network device sends second information to the first network device, indicating that the first task credential has been deleted or revoked.
[0239] The second network device can directly send the second information to the first network device, or can send the second information to the first network device through other network elements (for example, a task management network element).
[0240] After the first network device receives the second information, the following steps can be performed.
[0241] S593, the first network device deletes or revokes the first task credential according to the second information.
[0242] S594, the first network device sends third information to the terminal device, indicating that the first task credential is deleted or revoked.
[0243] After the terminal device receives the third information, the following steps are performed based on the indication of the third information.
[0244] S595, the terminal device deletes or revokes the first task credential according to the third information.
[0245] After the second network device deletes or revokes the first task credential, the user of the terminal device cannot use the first task credential to schedule the resources of the second network device. If the second network device receives the message of the first task again, whether the message carries the first task credential or not, the second network device can not process (for example, delete or discard) the message of the first task, thereby avoiding that the service subscribed by the user is illegally used or abused.
[0246] In the example shown in S590-S595, the second network device notifies the first network device of the result after deleting or revoking the first task credential. Alternatively, the second network device can also request the first network device to send a command for deleting or revoking the first task credential, and delete or revoke the first task credential after receiving the command.
[0247] For example, the second network device can send task end information to the first network device, the task end information indicating that the first task has ended. After receiving the task end information, the first network device deletes or revokes the first task credential according to the task end information. Alternatively, after deleting or revoking the first task credential, the first network device can also send third information to the terminal device and / or the N network devices, the third information indicating that the first task credential is deleted or revoked. In this way, the service subscribed by the user can be prevented from being illegally used or abused.
[0248] In some scenarios, the terminal device needs to delete or revoke the first task credential, and the terminal device can perform the following steps:
[0249] As shown in FIG. 7, the method 500 further includes:
[0250] S5110, in a case where the packet processing of the first task is completed, or in a case where it is determined that the packet of the first task is no longer processed, the terminal device deletes or revokes the first task credential.
[0251] The terminal device is the initiator of the first task, and the terminal device can determine when the first task is completed. Therefore, when the packet processing of the first task is completed, the terminal device can delete or revoke the local first task credential.
[0252] In some cases, the terminal device can delete or revoke the first task credential even though the packet processing of the first task is not completed.
[0253] For example, when the user indicates to terminate the first task, the terminal device can delete or revoke the first task credential even though the packet processing of the first task is not completed.
[0254] Subsequently, the terminal device can perform the following steps.
[0255] S5111, the terminal device sends second information to the first network device, the second information indicating that the first task credential has been deleted or revoked.
[0256] After receiving the second information, the first network device can perform the following steps.
[0257] S5112, the first network device deletes or revokes the first task credential according to the second information.
[0258] After the first network device deletes or revokes the local first task credential, the first network device can also instruct the N networks to delete or revoke the first task credential, so that some devices in the N networks do not delete or revoke the first task credential, and the service subscribed by the user is not illegally used or abused.
[0259] S5113, the first network device sends third information to the second network device, and instructs to delete or revoke the first task credential.
[0260] After the terminal device receives the third information, the terminal device performs the following steps based on the instruction of the third information.
[0261] S5114, the second network device deletes or revokes the first task credential according to the third information.
[0262] After the second network device receives the third information, the second network device deletes or revokes the first task credential according to the instruction of the third information. After the second network device deletes or revokes the first task credential, the user of the terminal device cannot use the first task credential to schedule the resources of the second network device.
[0263] For the second network device in FIG. 6 and FIG. 7, after the first task credential is deleted or revoked, the second network device can also receive the first task message (the message can come from the terminal device in the method 500, or can come from other devices), and the second network device can perform the following optional steps:
[0264] The second network device receives the first task message.
[0265] The second network device queries the task credential corresponding to the first task message.
[0266] In a case where the task credential corresponding to the first task message cannot be queried, or in a case where the first task credential has been revoked, it is determined that the first task message is not processed.
[0267] If the second network device receives the first task message again, whether the first task message carries the first task credential or not, since the first task credential cannot be found, or since the first task credential has been revoked, the second network device does not process (such as deleting or discarding) the first task message, so that the service subscribed by the user is not illegally used or abused.
[0268] The method 500 is described in detail above, and in the following, the first network device is taken as a tenant management network element, and the second network device is taken as a base station, a UPF or a server, and the communication method 800 provided by the embodiment of the application is introduced in combination with FIG. 8.
[0269] Before the method 800 is performed, the user of the terminal device can first complete identity verification.
[0270] For example, the user can send identity information to the core network, which can be a user identifier or terminal device identifier in a subscriber identity module (SIM) or a user identity module (UIM), or a unique identifier issued by an operator for a user without a SIM or UIM.
[0271] After receiving the identity information, the core network can send a challenge question to the terminal device. The terminal device calculates the challenge question based on the shared key stored in the SIM or UIM, and sends the calculation result to the core network. If the calculation result is correct, the core network confirms that the user is a legitimate user, and indicates to the access network that the user is a legitimate user.
[0272] The terminal device can also sign a request message with a private key associated with the identity information, which requests the core network to verify the identity of the user. The core network can verify the signature using the public key associated with the identity information, and if the verification is passed, the core network confirms that the user is a legitimate user, and indicates to the access network that the user is a legitimate user. In this process, the terminal device can also carry a timestamp of the sending time in the request message, or carry challenge information received by the terminal device from the core network, so that the core network confirms that the request message comes from the current operation of the legitimate user.
[0273] Subsequently, the terminal device can perform steps 1 to 6 shown in FIG. 8.
[0274] Step 1: The terminal device obtains a verifiable credential (VC).
[0275] The VC is an example of the first information in method 500, which can be a proof that the user of the terminal device can use a certain service, or a proof that the user of the terminal device subscribes to a certain service. The access network, the core network, and the subnetwork of the Internet service provider can verify the VC to ensure its authenticity.
[0276] For example, the terminal device can send a request message to the AI server through the task management network element (as shown in step 1a in FIG. 8), which can carry the identity information of the user and request to obtain the VC corresponding to the AI service. After receiving the request message, the AI server determines that the user has purchased the AI service based on the identity information, and can issue a VC to the user, which is used to prove that the user of the terminal device has the right to use the AI service.
[0277] Optionally, the VC issued by the AI server can include the following contents:
[0278] Identity information of the user of the terminal device;
[0279] an identity of the VC issuer (e.g., an identity of the AI server);
[0280] selectively disclosed content (e.g., the user of the terminal device is using the AI service);
[0281] a signature of the above content by the VC issuer using a private key of the VC issuer.
[0282] For another example, the terminal device can send a request message to the UDM through the task management network element (as shown in step 1b in FIG. 8), which can carry the identity information of the user and request to obtain the VC corresponding to the satellite communication service. The UDM records part or all of the services subscribed by the user of the terminal device. After receiving the request, the UDM determines that the user has subscribed to the satellite communication service based on the identity information, and can then issue a VC to the user, which is used to prove that the user of the terminal device has the right to use the satellite communication service.
[0283] Optionally, the VC issued by the UDM can include the following content:
[0284] the identity information of the user of the terminal device;
[0285] an identity of the VC issuer (e.g., an identity of the UDM);
[0286] selectively disclosed content (e.g., the user of the terminal device has subscribed to the satellite communication service);
[0287] a signature of the above content by the VC issuer using a private key of the VC issuer.
[0288] Step 2: The terminal device applies for a first task credential to the core network.
[0289] The terminal device can send a request message to the tenant management network element through the task management network element, which carries the above-mentioned VC and the information of the first task, and requests to obtain the first task credential. The information of the first task is used by the tenant management network element to determine the communication service and the Internet service that need to be used by the first task. For example, the information of the first task can be to use the satellite communication service to transmit data to the AI server and receive the processing result of the data from the AI server.
[0290] In the request message sent by the terminal device to the tenant management network element, the VC can also be replaced by a verifiable presentation (VP), which is another example of the first information in the method 500.
[0291] Optionally, the VP can include the following content:
[0292] the VC issued by the AI server;
[0293] the VC issued by the UDM;
[0294] a timestamp of the request message sent by the terminal device to the tenant management network element, and / or challenge information received by the terminal device from the core network;
[0295] a signature of the above content based on a private key of the user of the terminal device.
[0296] The VP contains the signature of the above VC based on the private key of the user, as well as the timestamp and / or challenge information, so as to prove that the request message carrying the two VCs comes from a user who has the right to use the AI service and satellite communication service, and to avoid the AI service and satellite communication service of the user being used by other users.
[0297] Step 3: issue the first task credential.
[0298] The tenant management network element checks the VCs received in step 2, and issues the first task credential after the check is passed.
[0299] For example, the tenant management network element can parse the VC issued by the UDM, and verify the VC signature provided by the UDM to determine that the user subscribes to the satellite communication service; the tenant management network element also parses the VC issued by the AI server to determine that the user has the right to use the AI service. The tenant management network element can also determine that the user subscribes to the satellite communication service and has the right to use the AI service by checking the VP, and confirm that the request message carrying the two VCs comes from a user who has the right to use the AI service and satellite communication service.
[0300] Subsequently, the tenant management network element can generate the first task credential through the credential management network element, record the association between the first task and the first task credential, and issue the first task credential to the terminal device. The credential management network element can be integrated with the tenant management network element, or can be integrated with other network elements, or can be a separate network element.
[0301] The first task credential can be a string that is valid within a limited time and uniquely identifies the first task, wherein "valid within a limited time" means that the first task credential is valid before the end of the first task, and the first task credential is invalid after the end of the first task.
[0302] The first task credential can be randomly generated, or can be generated based on the information of the first task or the VC corresponding to the first task, for example, the credential management network element can use a secret key to perform hash calculation on the information of the first task or the VC to generate a string, which is an example of the first task credential.
[0303] Step 4: The tenant management network element sends the user context carrying the first task credential to the base station, the UPF (an example of the user plane of the core network), and the server.
[0304] The user context is information describing how the user uses the network resources, and how the user isolates the resources and services from each other. For example, the user context includes the first task credential, and the association between the first task credential and the user. The user context can also include one or more of the following information:
[0305] The type of network service that the user can use;
[0306] The maximum quota of network service that the user can use;
[0307] The resource distribution area of the network service that the user can use, such as a geographical range or a geographical location;
[0308] The SLA of the user, including the resource type of various services, such as the traffic quota, latency requirement, and experience level of a communication service, the computing power quota of a computing service, and the data storage capacity of a data service; the SLA can also include the business rate of the user, and the like;
[0309] The total amount of the first task;
[0310] The prediction result of the distribution area of the first task.
[0311] It should be noted that the user context sent to different subnets can be different. For example, the user context sent to the base station is the content related to the access network (as shown in step 4a in FIG. 8), the user context sent to the UPF is the content related to the core network user plane (as shown in step 4b in FIG. 8), and the user context sent to the server is the content related to the server (as shown in step 4c in FIG. 8).
[0312] Step 5: generating a resource scheduling strategy based on the user context.
[0313] After receiving the user context, the base station, the UPF, and the server generate their respective resource scheduling strategies based on their respective user contexts, for executing the first task.
[0314] The resource scheduling control strategy can include one or more of the following: the type of service called by the first task credential, whether the service called by the first task credential can recursively call other types of services, the type of recursively called service, the maximum depth of recursively called service, the priority of the first task credential in scheduling resources, the minimum amount of available resources, and the maximum amount of available resources, and the like.
[0315] Examples of the resource scheduling control strategy can refer to the method 500, which will not be described here.
[0316] It should be noted that the resource scheduling strategies generated by different subnets are different. For example, the resource invocation strategy generated by the base station is a strategy for scheduling access network resources (as shown in step 5a in FIG. 8), the resource invocation strategy generated by the UPF is a strategy for scheduling core network resources (as shown in step 5b in FIG. 8), and the resource invocation strategy generated by the server is a strategy for scheduling server resources (as shown in step 5c in FIG. 8).
[0317] Since the resource scheduling strategy for executing the first task is independently determined by each network according to its own running condition, each network only needs to ensure the normal execution of the first task in the network, and does not need to transmit uniform policy information between networks, nor does it need to formulate a cross-network policy for executing the first task, thereby improving the efficiency of the terminal device in executing tasks through heterogeneous networks.
[0318] Step 6: Schedule resources to execute the first task.
[0319] The application of the terminal device generates data related to the first task, encapsulates the data in an uplink message, and the terminal device can carry the first task credential when sending the uplink message of the first task. After the base station receives the uplink message, it determines to execute the first task using the resource scheduling strategy in step 5a based on the first task credential, for example, the base station forwards the uplink message to the UPF based on the resource scheduling strategy (as shown in step 6a in FIG. 8). After the UPF receives the uplink message, it determines to execute the first task using the resource scheduling strategy in step 5b based on the first task credential, for example, the UPF forwards the uplink message to the server using a suitable bandwidth based on the resource scheduling strategy (as shown in step 6b in FIG. 8). After the server receives the uplink message, it determines to execute the first task using the resource scheduling strategy in step 5c based on the first task credential, for example, the application of the server configures a proper number of analysis models and computing resources to process the uplink message based on the resource scheduling strategy (as shown in step 6c in FIG. 6).
[0320] In some cases, the server needs to return the processing result of the uplink packet to the user, and the server can encapsulate the processing result in a downlink packet and send the downlink packet based on the resource scheduling strategy in step 5c, for example, the application of the server sends the downlink packet based on the resource scheduling strategy using appropriate bandwidth (as shown in step 6c in FIG. 8), wherein the downlink packet can carry the first task credential. After the UPF receives the downlink packet, it determines to execute the first task based on the resource scheduling strategy in step 5b using the first task credential, for example, the UPF forwards the downlink packet to the base station based on the resource scheduling strategy using appropriate bandwidth (as shown in step 6b in FIG. 8). After the base station receives the downlink packet, it determines to execute the first task based on the resource scheduling strategy in step 5a using the first task credential, for example, the base station forwards the downlink packet to the terminal device based on the resource scheduling strategy by invoking the SDAP module (as shown in step 6a in FIG. 8).
[0321] After the first task is executed, the user of the terminal device can actively send a task end message to the task management network element, wherein the first task credential is carried. After the task management network element receives the task end message, it sends a message to the tenant management network element to revoke the first task credential, and the tenant management network element finds the user context corresponding to the first task credential, and then sends a message to the base station, the UPF and the server to delete the user context corresponding to the first task credential. After receiving the message, the base station, the UPF and the server delete the user context and release the resources used by the first task. Only when the base station, the UPF and the server have the user context containing the first task credential, the first task credential received by the base station, the UPF and the server is valid. If the base station, the UPF and the server receive a packet carrying the first task credential after deleting the user context, the base station, the UPF and the server will discard it as illegal packet and no longer invoke resources for processing.
[0322] Next, taking a camera as an example of a terminal device, taking a task management network element as an example of a first network device, and taking an access network, subnet 1 or subnet 2 as an example of a second network device, the communication method 900 provided by the embodiment of the application is introduced in combination with FIG. 9.
[0323] S901, identity verification.
[0324] The camera is connected to the core network through a wired network (i.e., a fixed access network). The camera presents identity information when connecting to the access network, and encrypts a challenge question of the access network with a private key associated with the identity information. The access network sends the encrypted result of the challenge question and the identity information to an identity management network element of the core network. The identity management network element decrypts the encrypted result using a public key associated with the identity information, and if the decrypted result matches the challenge question, the identity verification is passed, and the identity management network element can indicate to the access network that the user of the camera is a legal user. Subsequently, the access network and the core network can process the subsequent signaling of the camera.
[0325] S902, the camera sends a first request message to the task management network element, and the first request message carries identity information and information of the first task.
[0326] For example, the first task is to count the types and quantities of goods in a store through a video shot, so as to facilitate the enterprise to master the sales situation of the goods and replenish the goods in time. The task management network element determines that the AI service of the subnetwork 1 and the data processing service of the subnetwork 2 need to be called to execute the first task based on the above description.
[0327] The task management network element determines that the first request message is a message of a legal user based on the identity information, and can apply for a VC from the subnetwork 1 and the subnetwork 2.
[0328] S903, the task management network element obtains the VC of the subnetwork 1 from the subnetwork 1.
[0329] The task management network element can send the identity information to the subnetwork 1, and the subnetwork 1 sends the VC of the subnetwork 1 to the task management network element after determining that the user corresponding to the identity information subscribes to the AI service. The VC can include the identity information of the user, the information that the user can call the AI service, and the signature of the above contents using a private key of the subnetwork 1.
[0330] S904, the task management network element obtains the VC of the subnetwork 2 from the subnetwork 2.
[0331] The task management network element can send the identity information to the subnetwork 2, and the subnetwork 2 sends the VC of the subnetwork 2 to the task management network element after determining that the user corresponding to the identity information subscribes to the data processing service. The VC can include the identity information of the user, the information that the user can call the data processing service, and the signature of the above contents using a private key of the subnetwork 2.
[0332] S903 and S904 can be executed simultaneously or not simultaneously.
[0333] S905, the task management network element sends a first response message to the camera, and the first response message carries the VC of the subnetwork 1 and the VC of the subnetwork 2.
[0334] Optionally, the VC of the subnet 1 and the VC of the subnet 2 can also be sent separately.
[0335] S906, the camera sends a second request message to the tenant management network element, and the second request message carries the VC of the subnet 1, the VC of the subnet 2 and the information of the first task.
[0336] The second request message is used to obtain the first task credential required for executing the first task. After receiving the second request message, the tenant management network element checks the VC of the subnet 1 and the VC of the subnet 2, and in the case of passing the check, generates the first task credential or obtains the first task credential from the credential management network element, and then executes the following steps.
[0337] S907, the tenant management network element sends a second response message to the camera, and the second response message carries the first task credential.
[0338] S908a-S908d, the tenant management network element sends the user context to the access network, the task management network element, the subnet 1 and the subnet 2 respectively.
[0339] The user context includes the first task credential and the association relationship between the first task credential and the camera user.
[0340] S907, S908a, S908b, S908c and S908d can be executed simultaneously or not simultaneously.
[0341] S909a-S909d, the access network, the task management network element, the subnet 1 and the subnet 2 generate respective resource scheduling strategies according to respective user contexts.
[0342] For example, the access network prepares air interface resources according to the user context for forwarding the message of the first task; the task management network element prepares core network transmission resources according to the user context for forwarding the message of the first task; the subnet 1 prepares AI algorithm model and AI computing power resources according to the user context to facilitate object recognition based on the message of the first task; and the subnet 2 prepares data storage space and externally open server link for providing data processing services according to the user context.
[0343] S909a, S909b, S909c and S909d can be executed simultaneously or not simultaneously.
[0344] S910a, the camera sends the message of the first task to the access network.
[0345] The data encapsulated in the message of the first task includes video data shot by the camera, and the message of the first task can also carry the first task credential.
[0346] S910b, the access network forwards the message of the first task to the user plane gateway.
[0347] The access network determines a corresponding resource scheduling strategy according to the first task credential carried in the message of the first task, and forwards the message of the first task to the user plane gateway according to the resource scheduling strategy.
[0348] S910c, the user plane gateway forwards the message of the first task to the subnet 1.
[0349] The user plane gateway determines a corresponding resource scheduling strategy according to the first task credential carried in the message of the first task, and forwards the message of the first task to the subnet 1 according to the resource scheduling strategy. The user plane gateway can obtain the resource scheduling strategy from the task management network element.
[0350] After the subnet 1 obtains the message of the first task, it parses the message, obtains the video data, and calls the AI algorithm model and AI computing resource based on the resource scheduling strategy generated in S909c to process the video data and generate an identification result. Subsequently, the subnet 1 can encapsulate the identification result into a message and perform the following steps.
[0351] S910d, the subnet 1 forwards the message of the first task to the subnet 2.
[0352] The message carries the identification result and the first task credential. After the subnet 2 obtains the message, it parses the message and calls the storage resource based on the resource scheduling strategy generated in S909d to store the identification result in the storage space. The subnet 2 can also generate a server link that is open to the outside and send it to the user of the camera, so that the user of the camera can know the sales and inventory of the goods. The message transmission between the subnet 1 and the subnet 2 can pass through the user plane gateway or not.
[0353] The user context in S908a-S908d can also carry a task keep-alive time interval. After the goods inventory is completed, the camera no longer sends messages carrying the first task credential. The access network, the user plane of the core network, the subnet 1 and the subnet 2 have not received the message carrying the first task credential for a certain number of task keep-alive time intervals (for example, greater than or equal to 3), and send a notification message to the task management network element that the first task is detected to be completed. The notification message carries the first task credential. After receiving the notification message, the task management network element sends a message to the tenant management network element to revoke the first task credential. The tenant management network element finds the user context corresponding to the first task credential, and then sends a message to the access network, the user plane of the core network, the subnet 1 and the subnet 2 to delete the user context corresponding to the first task credential. After receiving the message, the access network, the user plane of the core network, the subnet 1 and the subnet 2 delete the user context and release the resources used by the first task.
[0354] The first task credential received by the access network, the user plane of the core network, the subnet 1 and the subnet 2 is valid only when the user context containing the first task credential exists in the access network, the user plane of the core network, the subnet 1 and the subnet 2. If the access network, the user plane of the core network, the subnet 1 and the subnet 2 receive the message carrying the first task credential after deleting the user context, the access network, the user plane of the core network, the subnet 1 and the subnet 2 will discard it as an illegal message and no longer call resources for processing.
[0355] The above describes the method examples provided by the embodiments of the present application in detail. It can be understood that the corresponding device contains the corresponding hardware structure and / or software module for implementing the above functions. Those skilled in the art should easily realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0356] FIGS. 10 and 11 are structural schematic diagrams of two devices provided by the embodiments of the present application, which can be used to implement the functions of the terminal device, the first network device or the second network device in the above method embodiments, and thus also have the beneficial effects possessed by the above method embodiments.
[0357] As shown in FIG. 10, the device 1000 includes a processing unit 1010 and a transceiver unit 1020. The transceiver unit 1020 performs the receiving step and / or the output step under the control of the processing unit 1010, wherein the transceiver unit 1020 is a transmitting unit when performing the output step (or, the sending step), and the transceiver unit 1020 is a receiving unit when performing the receiving step. The device 1000 is used to implement the functions of the terminal device, the first network device or the second network device in the method embodiments described in FIG. 5.
[0358] When the device 1000 is used to implement the functions of the terminal device in the method embodiments described in FIG. 5, the transceiver unit 1020 is configured to: send, to the first network device, information of a first task, the information of the first task being used to determine N networks, N being a positive integer greater than 1; receive, from the first network device, a first task credential; and send a message of the first task carrying the first task credential, the first task credential being used for resource scheduling of the N networks respectively to process the message of the first task.
[0359] Optionally, the transceiver unit 1020 is further configured to: send, to the first network device, first information, the first information being used to prove that a user of the terminal device has the right to use the N networks.
[0360] Optionally, the first information comprises identity information and / or permission information of a user of the terminal device.
[0361] Optionally, the transceiver 1020 is further configured to send, to the first network device, first verification information, the first verification information being used for verification of a signer of the first information.
[0362] Optionally, the transceiver 1020 is further configured to send, to the first network device, second verification information, the second verification information being used for verification that the first information comes from the terminal device.
[0363] Optionally, the user of the terminal device is an individual, a family, an enterprise, or a government organization that owns the terminal device.
[0364] Optionally, the processing unit 1010 is configured to delete or revoke the first task credential in a case where packet processing of the first task is completed, or in a case where it is determined that the packet of the first task is no longer processed.
[0365] Optionally, the transceiver 1020 is further configured to send, to the first network device, second information, the second information indicating that the first task credential has been deleted or revoked.
[0366] Optionally, the transceiver 1020 is further configured to receive, from the first network device, third information, the third information indicating that the first task credential is deleted or revoked; and delete or revoke the first task credential according to the third information.
[0367] Optionally, the information of the first task comprises information of a service required for executing the first task; and the N networks comprise networks that provide the service.
[0368] Optionally, the service comprises at least one of the following: a communication service, a sensing service, a computing service, a data service, an artificial intelligence service, or a digital twin service.
[0369] When the apparatus 1000 is configured to implement the function of the first network device in the method embodiment of FIG. 5, the transceiver 1020 is configured to receive, from the terminal device, information of a first task; the processing unit 1010 is configured to determine N networks according to the information of the first task, N being a positive integer greater than 1; and the transceiver 1020 is further configured to send, to the terminal device and the N networks, a first task credential, the first task credential being used for resource scheduling of the N networks respectively to process a packet of the first task.
[0370] Optionally, the processing unit 1010 is further configured to obtain the first task credential in a case where the user of the terminal device has permission to use the N networks.
[0371] Optionally, the transceiver 1020 is further configured to receive first information from the terminal device; and the processing unit 1010 is specifically configured to determine the first task credential in a case where the first information proves that the user of the terminal device has the authority to use the N networks.
[0372] Optionally, the transceiver 1020 is further configured to receive first information from the terminal device; and the processing unit 1010 is specifically configured to send the first information to the credential management network element in a case where the first information proves that the user of the terminal device has the authority to use the N networks, the first information being used for generation of the first task credential; and receive the first task credential from the credential management network element.
[0373] Optionally, the first information comprises identity information and / or authority information of the user of the terminal device.
[0374] Optionally, the transceiver 1020 is further configured to receive first verification information from the terminal device; and the processing unit 1010 is specifically configured to acquire the first task credential in a case where the user of the terminal device has the authority to use the N networks, and the first verification information proves that the issuer of the first information is from the N networks.
[0375] Optionally, the transceiver 1020 is further configured to receive second verification information from the terminal device; and the processing unit 1010 is specifically configured to acquire the first task credential in a case where the user of the terminal device has the authority to use the N networks, and the second verification information proves that the first information is from the terminal device.
[0376] Optionally, the user of the terminal device is an individual, a family, an enterprise, or a government organization that owns the terminal device.
[0377] Optionally, the transceiver 1020 is further configured to send user information corresponding to the first task credential to the N networks, the user information being used for resource scheduling of the N networks respectively to process the packets of the first task.
[0378] Optionally, the user information comprises at least one of the following information: a type of network service that the user can use, a maximum quota of network service that the user can use, a resource distribution area of network service that the user can use, a service level agreement of the user, a total amount of the first task, or a distribution area of the first task.
[0379] Optionally, the transceiver 1020 is further configured to send time information corresponding to the first task credential to the N networks, the time information indicating a maximum time interval of the packets of the first task.
[0380] Optionally, the transceiver 1020 is further configured to receive second information, the second information indicating that the first task credential has been deleted or revoked; and the processing unit 1010 is further configured to delete or revoke the first task credential according to the second information.
[0381] Optionally, the transceiver 1020 is further configured to send third information to the terminal device and / or the N networks, the third information indicating deletion or revocation of the first task credential.
[0382] Optionally, the information of the first task includes information of a service required for executing the first task; and the N networks include a network providing the service.
[0383] Optionally, the service includes at least one of the following: a communication service, a perception service, a computing service, a data service, an artificial intelligence service, or a digital twin service.
[0384] When the apparatus 1000 is configured to implement the function of the second network device in the method embodiment described in FIG. 5, the transceiver 1020 is configured to receive, from a first network device, a first task credential used for resource scheduling of N networks respectively to process a packet of a first task, N being a positive integer greater than 1; the processing unit 1010 is configured to determine an association between the first task credential and a resource scheduling policy; the transceiver 1020 is further configured to receive, from a terminal device, the first task credential and the packet of the first task; and the processing unit 1010 is further configured to determine the resource scheduling policy according to the first task credential received from the terminal device and the association, and to schedule resources in the first network to process the packet of the first task according to the resource scheduling policy.
[0385] Optionally, the processing unit 1010 is further configured to generate the resource scheduling policy according to the first task credential.
[0386] Optionally, the transceiver 1020 is further configured to receive, from the first network device, user information corresponding to the first task credential; and the processing unit 1010 is specifically configured to determine the resource scheduling policy according to the first task credential and the user information.
[0387] Optionally, the user information includes at least one of the following: a type of network service available to the user, a maximum quota of network service available to the user, a resource distribution area of network service available to the user, a service level agreement of the user, a total amount of the first task, or a distribution area of the first task.
[0388] Optionally, the transceiver 1020 is further configured to receive, from the first network device, time information corresponding to the first task credential, the time information indicating a maximum time interval of the packet of the first task; and the processing unit 1010 is further configured to delete or revoke the first task credential when an interval between a current time and a time of last reception of the packet of the first task is greater than or equal to the maximum time interval.
[0389] Optionally, the transceiver 1020 is further configured to send second information to the first network device, the second information indicating that the first task credential has been deleted or revoked.
[0390] Optionally, the transceiver 1020 is further configured to receive third information from the first network device, the third information indicating that the first task credential is deleted or revoked, and the processing unit 1010 is further configured to delete or revoke the first task credential according to the third information.
[0391] Optionally, the transceiver 1020 is further configured to receive a packet of the first task, and the processing unit 1010 is further configured to query a task credential corresponding to the packet of the first task, and determine not to process the packet of the first task in a case that the task credential corresponding to the packet of the first task is not found or in a case that the first task credential is revoked.
[0392] The apparatus 1000 can be a terminal device or a network device, or the apparatus 1000 can be a chip applied to a terminal device or a network device. The processing unit 1010 can be implemented by hardware or software. When implemented by hardware, the processing unit 1010 is a logic circuit, an integrated circuit, or the like. When implemented by software, the processing unit 1010 can be a general-purpose processor, which reads software code stored in a storage unit to implement the processing unit 1010. The storage unit can be integrated in the processing unit 1010 or exist independently of the processing unit 1010.
[0393] As shown in FIG. 11, the apparatus 1100 includes a processor 1110 and an interface circuit 1120. The processor 1110 and the interface circuit 1120 are coupled to each other. It can be understood that the interface circuit 1120 can be a transceiver or an input / output interface. Optionally, the apparatus 1100 can further include a memory 1130 for storing instructions executed by the processor 1110 or storing input data required by the processor 1110 to run instructions or storing data generated after the processor 1110 runs instructions.
[0394] When the apparatus 1100 is used to implement the method shown in FIG. 5, the processor 1110 is configured to implement the functions of the processing unit 1010, and the interface circuit 1120 is configured to implement the functions of the transceiver 1020.
[0395] When the apparatus 1100 is a terminal device chip (i.e., a chip applied to a terminal device), the terminal device chip implements the functions of the terminal device in the above method embodiments. The terminal device chip receives information from a base station, which can be understood as the information being first received by other modules (such as a radio frequency module or an antenna) in the terminal device and then transmitted to the terminal device chip by the modules. The terminal device chip transmits information to the base station, which can be understood as the information being first transmitted to other modules (such as a radio frequency module or an antenna) in the terminal device and then transmitted to the base station by the modules.
[0396] When the apparatus 1100 is a base station chip (i.e., a chip applied to a base station), the base station chip implements the functions of the base station in the above method embodiments. The base station chip receives information from a terminal device, which can be understood as the information being first received by other modules (such as a radio frequency module or an antenna) in the base station and then transmitted to the base station chip by the modules. The base station chip transmits information to the terminal device, which can be understood as the information being first transmitted to other modules (such as a radio frequency module or an antenna) in the base station and then transmitted to the terminal device by the modules.
[0397] When the communication apparatus 1100 is a chip applied to a cloud computing infrastructure, the chip implements the functions of the first network device or the second network device in the above method embodiments. The chip receives information from other modules, which can be understood as the information being first received by a transceiving module (such as a transceiving circuit or a software interface) in the cloud computing infrastructure and then transmitted to the chip by the transceiving module. The chip transmits information to other modules, which can be understood as the information being first transmitted to the transceiving module (such as a transceiving circuit or a software interface) in the cloud computing infrastructure and then transmitted to other modules by the transceiving module.
[0398] In this application, entity A transmitting information to entity B can be A directly transmitting to B, or A indirectly transmitting to B through other entities. Similarly, entity B receiving information from entity A can be entity B directly receiving the information transmitted by entity A, or entity B indirectly receiving the information transmitted by entity A through other entities. Here, entity A and B can be network elements or modules inside network elements. The transmission and reception of information can be information interaction between network elements, such as information interaction between hyper-service and distributed network scheduling service; the transmission and reception of information can also be information interaction between different modules inside an apparatus, such as internal information interaction when the distributed network scheduling service executes a business decision algorithm.
[0399] It is to be understood that the processor in the embodiments of the present application can be a central processing unit (CPU) or a system on chip (SoC), and can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0400] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions executable by a processor. The software instructions can be composed of corresponding software modules, which can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a compact disc read-only memory (CD-ROM) or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from and write information to the storage medium. The storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal device. The processor and the storage medium can also exist as discrete components in the base station or the terminal device.
[0401] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer programs or instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments are performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment or other programmable apparatus. The computer programs or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer programs or instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center and the like integrated with one or more available media. The available media can be a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape; an optical medium, such as a digital video disc; a semiconductor medium, such as a solid state disk. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile storage media.
[0402] Finally, regarding the embodiments of the present application, the following points are explained:
[0403] First, in the embodiments of the present application, the first, second and various numerical numbers are distinguished for convenience of description, and do not limit the scope of the embodiments of the present application. The size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined by its function and inherent logic.
[0404] Second, in the embodiments of the present application, "indication" can include direct indication and indirect indication, and can also include explicit indication and implicit indication. The information indicated by a certain information is called to-be-indicated information, and there are many ways to indicate the to-be-indicated information in the specific implementation process, for example, the to-be-indicated information can be directly indicated, such as the to-be-indicated information itself or the index of the to-be-indicated information. The to-be-indicated information can also be indirectly indicated by indicating other information, wherein the other information and the to-be-indicated information have an association relationship. A part of the to-be-indicated information can also be indicated, and the other part of the to-be-indicated information is known or agreed in advance, for example, whether a certain information element exists can be used to indicate the to-be-indicated information by means of pre-agreement (for example, agreement), thereby reducing the indication overhead to a certain extent.
[0405] Thirdly, the "protocol" involved in the embodiments of the present application can refer to a standard protocol in the communication field, which can include a long term evolution (LTE) protocol, an NR protocol, and a related protocol in a future communication system, and the present application does not make any limitation.
[0406] Fourthly, "predefined" or "preconfigured" can be implemented by pre-storing corresponding codes, tables or other information indicating related information in a device (for example, a terminal device or a base station), and the present application does not make any limitation on the specific implementation manner. Wherein, "storing" can refer to storing in one or more memories, which can be separately arranged or integrated in a processor or a communication device; the one or more memories can be partially separately arranged and partially integrated in the processor or the communication device. The type of the memory can be any form of storage medium, and the present application does not make any limitation.
[0407] Fifthly, "at least one" refers to one or more, and "multiple" refers to two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can represent: A exists alone, B exists alone, and A and B exist at the same time, wherein A and B can be a single object or multiple objects. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b and c can represent: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Wherein a, b and c can be a single object or multiple objects.
[0408] Sixthly, in the embodiments of the present application, the descriptions such as "when", "in the case of", "if" and "if" all refer to the objective situation that the device (for example, a terminal device or a base station) will make corresponding processing, which is not limited by time, and does not require the device to have a judgment action when implemented, nor means that there are other limitations.
[0409] Seventhly, in various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be mutually referenced if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
Claims
1. A communication method characterized by comprising: The method comprises: sending first task information to a first network device, the first task information being used to determine N networks, N being a positive integer greater than 1; receiving first task credentials from the first network device; sending the first task credentials and packets of the first task, the first task credentials being used for resource scheduling of the N networks respectively to process the packets of the first task.
2. The method of claim 1, wherein, The method further comprises: sending first information to the first network device, the first information being used to prove that a user of a terminal device has the right to use the N networks.
3. The method of claim 2, wherein, The first information comprises: identity information and / or right information of the user of the terminal device.
4. The method according to claim 2 or 3, characterized in that, The method further comprises: sending first verification information to the first network device, the first verification information being used to verify the issuer of the first information.
5. The method according to any one of claims 2 to 4, characterized in that, The method further comprises: sending second verification information to the first network device, the second verification information being used to verify that the first information comes from the terminal device.
6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: deleting or revoking the first task credentials in a case where the processing of the packets of the first task is completed, or in a case where it is determined that the packets of the first task are no longer processed.
7. The method of claim 6, wherein, The method further comprises: sending second information to the first network device, the second information indicating that the first task credentials have been deleted or revoked.
8. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: receiving third information from the first network device, the third information indicating that the first task credentials are deleted or revoked; deleting or revoking the first task credentials according to the third information.
9. A communication method characterized by comprising: The method comprises: receiving first task information from a terminal device; determining N networks according to the first task information, N being a positive integer greater than 1; sending first task credentials to the terminal device and the N networks, the first task credentials being used for resource scheduling of the N networks respectively to process packets of the first task.
10. The method of claim 9, wherein, The method further comprises: obtaining the first task credentials in a case where a user of the terminal device has the right to use the N networks.
11. The method of claim 10, wherein, The method further comprises: receiving first information from the terminal device; The obtaining the first task credentials in the case where the user of the terminal device has the right to use the N networks comprises: determining the first task credentials in a case where the first information proves that the user of the terminal device has the right to use the N networks.
12. The method of claim 10, wherein, The method further comprises: receiving first information from the terminal device; The obtaining the first task credentials in the case where the user of the terminal device has the right to use the N networks comprises: sending the first information to a credential management network element in a case where the first information proves that the user of the terminal device has the right to use the N networks, the first information being used for generation of the first task credentials; receiving the first task credentials from the credential management network element.
13. The method according to claim 11 or 12, characterized in that, The first information comprises: identity information and / or right information of the user of the terminal device.
14. The method according to any one of claims 10 to 13, characterized in that, The method further comprises: receiving first verification information from the terminal device; The first task credential is obtained in a case that the user of the terminal device has the permission to use the N networks. The first task credential is obtained in a case that the user of the terminal device has the permission to use the N networks, and the first verification information proves that the issuer of the first information is from the N networks.
15. The method according to any one of claims 10 to 14, characterized in that, The method further comprises: receiving second verification information from the terminal device; The first task credential is obtained in a case that the user of the terminal device has the permission to use the N networks. The first task credential is obtained in a case that the user of the terminal device has the permission to use the N networks, and the second verification information proves that the first information is from the terminal device.
16. The method according to any one of claims 9 to 15, characterized in that, The method further comprises: sending user information corresponding to the first task credential to the N networks, the user information being used for resource scheduling of the N networks respectively to process the first task message.
17. The method according to any one of claims 9 to 16, characterized in that, The method further comprises: sending time information corresponding to the first task credential to the N networks, the time information indicating a maximum time interval of the first task message.
18. The method according to any one of claims 9 to 17, characterized in that, The method further comprises: receiving second information indicating that the first task credential has been deleted or revoked; deleting or revoking the first task credential according to the second information.
19. The method according to any one of claims 9 to 18, characterized in that, The method further comprises: sending third information to the terminal device and / or the N networks, the third information indicating that the first task credential is deleted or revoked.
20. A method of communication, comprising: The method is applied to a first network, comprising: receiving a first task credential from a first network device, the first task credential being used for resource scheduling of N networks respectively to process a first task message, the N being a positive integer greater than 1, and the N networks including the first network; determining an association between the first task credential and a resource scheduling policy; receiving the first task credential and the first task message from a terminal device; determining the resource scheduling policy according to the first task credential received from the terminal device and the association; scheduling resources in the first network to process the first task message according to the resource scheduling policy.
21. The method of claim 20, wherein, Before the association between the first task credential and the resource scheduling policy is determined, the method further comprises: generating the resource scheduling policy according to the first task credential.
22. The method of claim 21, wherein, The method further comprises: receiving user information corresponding to the first task credential from the first network device; The resource scheduling policy is generated according to the first task credential and the user information. The method further comprises:
23. The method of any one of claims 20-22, wherein, receiving time information corresponding to the first task credential from the first network device, the time information indicating a maximum time interval of the first task message; deleting or revoking the first task credential when an interval between a current time and a time when the last first task message is received is greater than or equal to the maximum time interval. The method further comprises:
24. The method of claim 23, wherein, sending second information to the first network device, the second information indicating that the first task credential has been deleted or revoked.
25. The method of any one of claims 20-22, wherein, The method further comprises: receiving third information from the first network device, the third information indicating that the first task credential is deleted or revoked; deleting or revoking the first task credential according to the third information.
26. The method of any one of claims 23-25, wherein, The method further comprises: receiving a packet of the first task; inquiring a task credential corresponding to the packet of the first task; in a case where the task credential corresponding to the packet of the first task is not found, or in a case where the first task credential is revoked, determining not to process the packet of the first task.
27. The method of claim 16 or 22, wherein, The user information comprises at least one of the following information: a type of network service available to the user, a maximum quota of network service available to the user, a resource distribution area of network service available to the user, a service level agreement of the user, a total amount of the first task, or a distribution area of the first task.
28. A communications device, characterized by comprise: a module for performing the method of any one of claims 1 to 8, or a module for performing the method of any one of claims 9 to 19, or a module for performing the method of any one of claims 20 to 27.
29. A communications device, characterized by comprise: a processor for implementing the method of any one of claims 1 to 8, or the method of any one of claims 9 to 19, or the method of any one of claims 20 to 27, by means of a logic circuit or executing a computer program or instructions; a memory for storing the computer program or instructions.
30. A computer program product, characterised in that, The computer program product comprises a computer program or instructions, which, when executed by a communication device, implement the method of any one of claims 1 to 8, or the method of any one of claims 9 to 19, or the method of any one of claims 20 to 27.
31. A computer readable storage medium, characterized in that, The computer readable storage medium stores a computer program or instructions, which, when executed on a communication device, cause the communication device to perform the method of any one of claims 1 to 8, or the method of any one of claims 9 to 19, or the method of any one of claims 20 to 27.
32. A communication system, characterized by comprise a communication device for performing the method of any one of claims 9 to 19 and a communication device for performing the method of any one of claims 20 to 27.
Citation Information
Patent Citations
Heterogeneous network resource allocation method based on reinforcement learning
CN112351433A
Heterogeneous task scheduling strategy optimization method and device and related product
CN114003355A
Communication method, device and system
CN114630341A
Task execution method and related device
CN116709553A
Communication method and apparatus, computer-readable storage medium, and communication system
WO2024067641A1