Communication method and apparatus, and readable storage medium

By collaborating with the drone management entity and the open functional entity, and optimizing the USS switching process based on relationships and authentication information, the security and reliability issues of drone systems during USS switching are resolved, resulting in more efficient USS switching.

WO2026067280A1PCT designated stage Publication Date: 2026-04-02HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-20
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

The lack of security measures in existing UAV systems during USS handover can lead to errors in the authentication process, reducing the security and reliability of USS handover.

Method used

By collaborating between the drone management entity and the open functionality entity, and based on the relationships and authentication information, it is possible to clearly determine whether to execute the authentication process during USS switching, including the UUAA process, thereby reducing the risk of erroneously failing to execute the authentication process and optimizing the USS switching process.

Benefits of technology

It improves the safety and reliability of USS handover, reduces the possibility of USS handover failure, lowers latency, and ensures the safety and stability of the UAV system during the USS handover process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025122762_02042026_PF_FP_ABST
    Figure CN2025122762_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and in particular, to a communication method and apparatus, and a readable storage medium. The method comprises: a USS1, currently providing a service for an unmanned aerial vehicle, determines a candidate USS2 for providing a service for the unmanned aerial vehicle; and on the basis of first indication information from an NEF / UAS NF and / or an association relationship between the USS1 and the USS2, the USS1 determines whether or not an authentication procedure is to be executed between the USS2 and the unmanned aerial vehicle. The first indication information is used for indicating whether or not the authentication procedure is to be executed between the USS2 and the unmanned aerial vehicle. The use of the present application improves the security and reliability of switching between USSs.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method, apparatus and readable storage medium

[0001] The present application claims priority to the Chinese patent application No. 202411397847.8, filed on September 30, 2024, with the State Intellectual Property Office of China, and entitled "Communication method, apparatus and readable storage medium", the whole content of which is incorporated herein by reference. TECHNICAL FIELD

[0002] The present application relates to the field of communication technology, in particular to a communication method, apparatus and readable storage medium. BACKGROUND

[0003] An unmanned / uncrewed aerial system (UAS) includes an unmanned / uncrewed aerial vehicle (UAV) and a UAV controller (UAVC). The UAV can autonomously fly or fly by receiving control instructions from the UAVC. The UAV and the UAVC can communicate with each other using a mobile communication network. For example, the UAVC can send control instructions to the UAV through the mobile communication network to direct the flight direction of the UAV. For another example, the UAV can send data such as aerial photos and videos to the UAVC or other ground equipment through the mobile communication network. Due to the wide coverage, high reliability and support for high-speed mobile services of the mobile communication network (or communication system), the mobile communication network can enable the UAS to realize remote (e.g., over-the-horizon) high-reliability flight, thereby enabling the UAS to explore a wider application or market.

[0004] Generally, a UAS service supplier (USS) has a geographical service area. Therefore, a UAV can be served by multiple USSs during flight. For example, the UAV is served by one USS in the initial stage of its flight path, and is served by another USS in the second stage of the flight path. In this scenario, the UAV can need to switch USS.

[0005] Currently, there is no security solution for USS switching. SUMMARY

[0006] The embodiments of the present application provide a communication method, apparatus and readable storage medium, which can improve the security and reliability of USS switching.

[0007] The application is described below from different aspects. It should be understood that the implementation and benefits of different aspects below can be referred to each other.

[0008] In a first aspect, the application provides a communication method, which can be applied to a first unmanned aerial vehicle management entity (UAV management entity, USS) currently providing service for a UAV. The method comprises: determining, by the first UAV management entity currently providing service for the UAV, a candidate second UAV management entity providing service for the UAV; and determining, by the first UAV management entity, whether to perform an authentication procedure between the second UAV management entity and the UAV according to first indication information from an open function entity and / or an association relationship between the first UAV management entity and the second UAV management entity. The first indication information is used to indicate whether to perform the authentication procedure between the second UAV management entity and the UAV.

[0009] For example, the second UAV management entity can be a candidate USS. Further, the second UAV management entity can be a target UAV management entity (target USS) that will provide service for the UAV.

[0010] For example, the open function entity can be a network exposure function (network exposure function, NEF) or an unmanned aerial system function (UAS NF).

[0011] The authentication procedure of the application can only include authentication, or include authentication and authorization, such as UAV USS authentication and authorization (UAV USS authentication and authorization, UUAA) procedure. The application does not limit the specific implementation of the authentication procedure.

[0012] In the application, the UAV management entity can be used instead of the USS.

[0013] The application provides conditions for the first UAV management entity (service USS) to determine whether to perform an authentication procedure (such as UUAA procedure) between the second UAV management entity (candidate USS) and the UAV, perfects the existing USS switching procedure, reduces the security risks caused by the incorrect non-performance of the authentication procedure in the absence of clear judgment conditions, and improves the security and reliability of the USS switching.

[0014] In combination with the first aspect, in a possible implementation, the first UAV management entity determines whether to perform the authentication procedure between the second UAV management entity and the UAV according to the association relationship between the first UAV management entity and the second UAV management entity, comprising:

[0015] The first unmanned aerial vehicle management entity determines whether the second unmanned aerial vehicle management entity and the unmanned aerial vehicle perform the authentication procedure or do not perform the authentication procedure according to one or more of the following pieces of information: address information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, network information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, air traffic control information corresponding to the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, or a pre-configured trust relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity. The specific determination manner can be referred to the description of the method embodiment below, which is not described in detail here due to the limited space.

[0016] For example, the address information can include one or more of the following: a fully qualified domain name (FQDN) or an internet protocol (IP) address. The network information can include public land mobile network (PLMN) information and / or data network (DN) information, for example: data network name (DNN), single-network slice selection assistance information (S-NSSAI), protocol data unit (PDU) session identifier (PDU session ID), or PDU session IP address, and the like. The air traffic control information can include one or more of the following: unmanned aerial vehicle pilot information or USS operator information, and the like. The trust relationship can be a trust list between unmanned aerial vehicle management entities, for example, whether the second unmanned aerial vehicle management entity trusts the authentication information of the first unmanned aerial vehicle management entity, which can be stored as subscription information in a unified data management (UDM) entity or an unmanned aerial system traffic management (UTM) entity.

[0017] The present scheme specifies the conditions under which the second unmanned aerial vehicle management entity (candidate USS) and the unmanned aerial vehicle perform the authentication procedure and the conditions under which the authentication procedure is not performed, thereby reducing the security risks caused by the false non-performance of the authentication procedure without clear judgment conditions.

[0018] In a possible implementation manner of the first aspect, the method further includes: if the first unmanned aerial vehicle management entity determines that the second unmanned aerial vehicle management entity and the unmanned aerial vehicle do not perform the authentication procedure according to the association relationship, the first unmanned aerial vehicle management entity can send second indication information to the exposure function entity. The second indication information can be used to indicate that the second unmanned aerial vehicle management entity and the unmanned aerial vehicle do not perform the authentication procedure. After receiving the second indication information, the exposure function entity can store the authentication information (for example, the UUAA context) between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. For example, the authentication information can include the identifier of the unmanned aerial vehicle and the identifier of the corresponding second unmanned aerial vehicle management entity. The authentication information can indicate that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful or that the authentication is not needed.

[0019] It can be understood that when the UUAA context of the unmanned aerial vehicle and the target USS is in the NEF / UAS NF, the unmanned aerial vehicle can obtain the service of the target USS. Therefore, when the authentication procedure between the second unmanned aerial vehicle management entity (for example, the target USS) and the unmanned aerial vehicle is not needed to be performed, the present solution notifies the exposure function entity (for example, the NEF / UAS NF) to add the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, so that the unmanned aerial vehicle can obtain the service provided by the second unmanned aerial vehicle management entity without performing the authentication procedure with the second unmanned aerial vehicle management entity.

[0020] In a possible implementation manner of the first aspect, the method further includes: the first unmanned aerial vehicle management entity sends a first message to the exposure function entity, and the first message includes the identifier of the second unmanned aerial vehicle management entity, the identifier of the unmanned aerial vehicle, and verification information. The verification information can be used to verify the authenticity of the first message. For example, the verification information can be signature information, a message verification code, or a token. The first message can be used to indicate or notify that the authentication procedure between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is not performed. After receiving the first message, the exposure function entity can first verify the authenticity of the first message according to the verification information. After the verification is passed, the exposure function entity stores the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle.

[0021] The present solution protects the security of the message communicated between the first unmanned aerial vehicle management entity and the exposure function entity through the verification information, and further improves the security and reliability of the USS switching.

[0022] In a second aspect, the present application provides a communication method, which can be applied to an open function entity, such as a NEF or a UAS NF. The method comprises: the open function entity obtaining information of a second unmanned aerial vehicle management entity, and determining, according to second indication information from the first unmanned aerial vehicle management entity or the second unmanned aerial vehicle management entity, and / or an association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, whether to perform an authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. The first unmanned aerial vehicle management entity is an unmanned aerial vehicle management entity currently providing services for the unmanned aerial vehicle. The second unmanned aerial vehicle management entity is a candidate unmanned aerial vehicle management entity providing services for the unmanned aerial vehicle.

[0023] For example, the second indication information can be used to indicate that the authentication process is not performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. Therefore, the open function entity determines, according to the second indication information, that the authentication process is not performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle.

[0024] For example, the first unmanned aerial vehicle management entity can be a service USS. The second unmanned aerial vehicle management entity can be a candidate USS. Further, the second unmanned aerial vehicle management entity can be a target unmanned aerial vehicle management entity (i.e., a target USS) that will provide services for the unmanned aerial vehicle.

[0025] The present solution improves the judgment method of whether to perform an authentication process between the second unmanned aerial vehicle management entity (candidate USS) and the unmanned aerial vehicle in the USS switching process, reduces the security risks caused by the incorrect non-performance of the authentication process in the absence of clear judgment conditions, and can improve the security and reliability of the USS switching.

[0026] In combination with the second aspect, in a possible implementation manner, the open function entity determines, according to the association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, whether to perform an authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, comprising:

[0027] The open function entity determines, according to one or more of the following information: address information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, network information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, air traffic control information corresponding to the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, or a pre-configured trust relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, whether to perform an authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. The specific determination manner can be referred to the description of the method embodiment below, which is not described in detail here due to the limited space.

[0028] For example, the description of the address information, the network information, the air traffic control information, and the trust relationship can be referred to the foregoing description, which is not described in detail here.

[0029] With reference to the second aspect, in a possible implementation manner, if the authentication procedure is not performed between the second unmanned vehicle management entity and the unmanned vehicle, the open function entity can store the authentication information (for example, a UUAA context) between the second unmanned vehicle management entity and the unmanned vehicle. The authentication information indicates that the second unmanned vehicle management entity and the unmanned vehicle are successfully authenticated or do not need to be authenticated.

[0030] For example, the open function entity stores an expiration time of the authentication information between the second unmanned vehicle management entity and the unmanned vehicle, which is earlier than or equal to an expiration time of the authentication information between the first unmanned vehicle management entity and the unmanned vehicle.

[0031] With reference to the second aspect, in a possible implementation manner, according to the association relationship between the first unmanned vehicle management entity and the second unmanned vehicle management entity, the open function entity determines whether the authentication procedure is performed between the second unmanned vehicle management entity and the unmanned vehicle or not. After the determination, the method further includes: the open function entity sends first indication information to the first unmanned vehicle management entity, where the first indication information is used to indicate whether the authentication procedure is performed between the second unmanned vehicle management entity and the unmanned vehicle or not.

[0032] In this solution, after the open function entity determines whether the authentication procedure is performed between the second unmanned vehicle management entity and the unmanned vehicle or not, the first unmanned vehicle management entity can be notified, so as to determine whether to trigger the authentication procedure between the second unmanned vehicle management entity and the unmanned vehicle, thereby completing the switching of the USS.

[0033] With reference to the second aspect, in a possible implementation manner, the open function entity obtains the information of the second unmanned vehicle management entity, including: the open function entity receives a first message from the first unmanned vehicle management entity, where the first message includes an identifier of the second unmanned vehicle management entity, an identifier of the unmanned vehicle, and verification information, the verification information can be used to verify the authenticity of the first message; the open function entity verifies the authenticity of the first message according to the verification information; and if the first message is verified, the open function entity obtains the identifier of the second unmanned vehicle management entity.

[0034] With reference to the second aspect, in a possible implementation manner, the method further includes: if the authentication procedure is not performed between the second unmanned vehicle management entity and the unmanned vehicle, the open function entity can send third indication information to a third entity, where the third indication information is used to indicate that the authentication result between the second unmanned vehicle management entity and the unmanned vehicle is successful, or indicate that the second unmanned vehicle management entity and the unmanned vehicle do not need to be authenticated.

[0035] Exemplarily, the third entity is an entity storing the authentication result, for example, a session management function (SMF), an access and mobility management function (AMF), or a UDM entity.

[0036] In a third aspect, a communication method is provided. The method can be applied to a candidate second unmanned aerial vehicle management entity (USS) that provides service for an unmanned aerial vehicle. The method comprises: sending, by the second unmanned aerial vehicle management entity, one or more of the following information to the first unmanned aerial vehicle management entity or an exposure function entity: address information of the second unmanned aerial vehicle management entity, network information associated with the second unmanned aerial vehicle management entity, air traffic control information corresponding to the second unmanned aerial vehicle management entity, or a trust relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity.

[0037] Exemplarily, the exposure function entity can be a NEF or a UAS NF. The first unmanned aerial vehicle management entity can be a serving USS.

[0038] Exemplarily, the second unmanned aerial vehicle management entity can be a target unmanned aerial vehicle management entity (target USS) that provides service for the unmanned aerial vehicle.

[0039] In combination with the third aspect, in a possible implementation manner, the method further comprises: the second unmanned aerial vehicle management entity can further send an identifier of the second unmanned aerial vehicle management entity to the first unmanned aerial vehicle management entity or the exposure function entity.

[0040] In combination with the third aspect, in a possible implementation manner, the method further comprises: the second unmanned aerial vehicle management entity receives indication information from the first unmanned aerial vehicle management entity or the exposure function entity, for indicating that no authentication process is performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle.

[0041] In a fourth aspect, a communication apparatus is provided. The communication apparatus can be a first unmanned aerial vehicle management entity, or a second unmanned aerial vehicle management entity, or an exposure function entity, or a chip thereof. The communication apparatus comprises units and / or modules for performing the method provided in any one of the first aspect to the third aspect, or any one of the possible implementation manners of any one of the first aspect to the third aspect, for example, a transceiver module and / or a processing module. The transceiver module is configured to transceive various information or signaling, and thus can also achieve the beneficial effects (or advantages) of the method provided in any one of the first aspect to the third aspect.

[0042] In a fifth aspect, the present application provides a communication method, which can be applied to a first unmanned aerial vehicle management entity (UAV-ME) currently providing service for an unmanned aerial vehicle (UAV), i.e., a serving UAV service supplier (USS). The method comprises: if the first UAV-ME determines that an authentication procedure is not required to be performed between a second UAV-ME (e.g., a candidate USS) and the UAV, or the first UAV-ME determines that authentication between the second UAV-ME and the UAV is successful, the first UAV-ME can determine that the second UAV-ME is a target UAV-ME that will provide service for the UAV. Then, the first UAV-ME can send a second message to the second UAV-ME, which can be used to request the second UAV-ME to prepare for switching of the UAV-ME.

[0043] For example, the successful authentication between the second UAV-ME and the UAV comprises any one of the following: there is authentication information (e.g., a UUAA context) between the second UAV-ME and the UAV in an open function entity, or an authentication result of performing an authentication procedure between the second UAV-ME and the UAV is successful.

[0044] The present application can reduce the possibility of USS switching failure, reduce the time delay of USS switching, and improve the security and reliability of USS switching by preferably selecting a USS that does not need to perform an authentication procedure or has authentication information as a target USS.

[0045] In combination with the fifth aspect, in a possible implementation manner, the first UAV-ME determines whether an authentication procedure (e.g., a UUAA procedure) needs to be performed between the second UAV-ME and the UAV according to one or more of the following information: address information of the first UAV-ME and the second UAV-ME, network information of the first UAV-ME and the second UAV-ME, air traffic control information corresponding to the first UAV-ME and the second UAV-ME, or a pre-configured trust relationship between the first UAV-ME and the second UAV-ME. The specific determination manner can be referred to the description of the method embodiments below, which is not described herein due to the limited space.

[0046] For example, the address information, the network information, the air traffic control information, and the trust relationship can be referred to the description above, which is not described herein.

[0047] In a possible implementation manner of the fifth aspect, the first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, including: the first unmanned aerial vehicle management entity receives fourth indication information from the exposure function entity, the fourth indication information being used to indicate whether the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle exists in the exposure function entity; if the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle exists in the exposure function entity, the first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful.

[0048] Exemplarily, the exposure function entity can be a NEF or a UAS NF.

[0049] In a possible implementation manner of the fifth aspect, the first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, including: the first unmanned aerial vehicle management entity determines that the authentication procedure needs to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. The first unmanned aerial vehicle management entity sends a third message to the second unmanned aerial vehicle management entity, the third message being used to notify the second unmanned aerial vehicle management entity to perform the authentication procedure with the unmanned aerial vehicle, the third message including an identifier of the unmanned aerial vehicle; or the first unmanned aerial vehicle management entity sends a third message to the unmanned aerial vehicle, the third message being used to notify the unmanned aerial vehicle to perform the authentication procedure with the second unmanned aerial vehicle management entity, the third message including an address of the second unmanned aerial vehicle management entity. The first unmanned aerial vehicle management entity receives a first authentication result between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle; when the first authentication result is successful, the first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful.

[0050] Exemplarily, the first unmanned aerial vehicle management entity determines that the authentication procedure needs to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, which can be that the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle does not exist in the exposure function entity.

[0051] The scheme can perform the authentication procedure in advance for the candidate USS that needs to perform the authentication procedure, and after the authentication is successful, the candidate USS is selected as the target USS, thereby reducing the possibility of USS switching failure and improving the security and reliability of USS switching.

[0052] In a possible implementation manner of the fifth aspect, after the first unmanned aerial vehicle management entity sends the second message to the second unmanned aerial vehicle management entity, the method further includes: the first unmanned aerial vehicle management entity receives fifth indication information from the exposure function entity, the fifth indication information being used to indicate that the service switching from the first unmanned aerial vehicle management entity to the unmanned aerial vehicle to the second unmanned aerial vehicle management entity is provided to the unmanned aerial vehicle.

[0053] In a possible implementation manner of the fifth aspect, the method further includes: the first drone management entity determines that an authentication procedure needs to be performed between the fourth drone management entity (another candidate USS) and the drone. The first drone management entity sends a fourth message to the fourth drone management entity, where the fourth message is used to inform the fourth drone management entity to perform the authentication procedure between the fourth drone management entity and the drone, and the fourth message includes an identifier of the drone. Alternatively, the first drone management entity sends a fourth message to the drone, where the fourth message is used to inform the drone to perform the authentication procedure between the drone and the fourth drone management entity, and the fourth message includes an address of the fourth drone management entity. The first drone management entity receives a second authentication result between the fourth drone management entity and the drone, and the second authentication result is failure.

[0054] It can be understood that after the authentication procedure between a certain candidate USS and the drone fails, the serving USS can reselect a candidate USS, and re-perform the judgment procedure of the fifth aspect until the target USS is determined.

[0055] In a possible implementation manner of the fifth aspect, the second drone management entity and the drone have subscription information, and the subscription information indicates that the drone is a subscription user of the second drone management entity. It can be understood that the forms of the subscription information stored in different places can be different, but have the same or similar meanings, for example, both can indicate that the drone is a subscription user of the drone management entity.

[0056] In a possible implementation manner of the fifth aspect, the method further includes: the first drone management entity receives a fifth message from the exposure function entity, where the fifth message is used to indicate the qualified drone management entity and / or the unqualified drone management entity, the qualified drone management entity includes: a drone management entity having subscription information with the drone, and / or a drone management entity that passes the security verification; the subscription information indicates that the drone is a subscription user of the drone management entity; the first drone management entity obtains a first candidate entity list, and the first candidate entity list includes the qualified drone management entity, and the first candidate entity list includes the second drone management entity. The fifth message can include indication information b, and the indication information b can be used to indicate the qualified drone management entity and / or the unqualified drone management entity. Alternatively, the fifth message can include a candidate entity list Q, and the candidate entity list Q can include the qualified drone management entity or the unqualified drone management entity.

[0057] Exemplarily, the first drone management entity sends a sixth message to the exposure function entity, the sixth message comprising a second candidate entity list. The second candidate entity list comprises one or more candidate drone management entities providing services for the drone. The sixth message is used to obtain the drone management entities meeting the condition in the second candidate entity list.

[0058] The UUAA between the USS and the UAV in the prior art can fail because the UAV does not sign up with the USS, so the present scheme can filter the USS according to whether there is sign-up information between the USS and the UAV, thereby reducing the possibility of UUAA failure.

[0059] In combination with the fifth aspect, in a possible implementation manner, the sixth message further comprises security verification information of each drone management entity in the second candidate entity list, for example, a token or a message authentication code. The exposure function entity can perform security verification on the security verification information of each candidate drone management entity according to the information obtained from the UDM entity (for example, the key of each candidate drone management entity, the candidate drone management entity trusted by the first drone management entity, or the identifier of the drone), respectively. The exposure function entity can determine that the candidate drone management entity passing the security verification is the drone management entity meeting the condition.

[0060] In combination with the fifth aspect, in a possible implementation manner, the method further comprises: the first drone management entity determining a third candidate entity list, the third candidate entity list comprising a plurality of candidate drone management entities providing services for the drone; the first drone management entity querying whether there is sign-up information between each drone management entity in the third candidate entity list and the drone; and the first drone management entity obtaining a fourth candidate entity list, the fourth candidate entity list comprising the drone management entities having the sign-up information with the drone, and the fourth candidate entity list comprising the second drone management entity.

[0061] In the sixth aspect, the present application provides a communication method, which can be applied to an exposure function entity, for example, a NEF or a UAS NF. The method comprises: the exposure function entity obtaining information of a second drone management entity, the second drone management entity being a candidate drone management entity providing services for the drone; and the exposure function entity sending fourth indication information to a first drone management entity (namely, a service USS) currently providing services for the drone, the fourth indication information being used to indicate whether there is authentication information (for example, a UUAA context) between the second drone management entity and the drone in the exposure function entity.

[0062] Exemplarily, the exposure function entity can obtain the information of the second drone management entity from the first drone management entity, for example, the identifier, the address, and the like of the second drone management entity.

[0063] The second unmanned aerial vehicle management entity can be a candidate USS.

[0064] The open function entity can assist the target USS to select the target USS, so as to reduce the possibility of USS switching failure, reduce the time delay of USS switching, and improve the security and reliability of USS switching.

[0065] In a possible implementation manner, after the open function entity sends the fourth indication information to the first unmanned aerial vehicle management entity currently providing services for the unmanned aerial vehicle, the method further includes: receiving an authentication request message from a second unmanned aerial vehicle management entity, the authentication request message being used to request to authenticate the unmanned aerial vehicle, and the authentication request message including an identifier of the unmanned aerial vehicle; sending, by the open function entity, a first authentication result between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle to the first unmanned aerial vehicle management entity; and storing, by the open function entity, authentication information (for example, a UUAA context) between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle if the first authentication result is successful.

[0066] The open function entity can store the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle when the authentication between the second unmanned aerial vehicle management entity (for example, the target USS) and the unmanned aerial vehicle is successful, so as to enable the unmanned aerial vehicle to obtain services provided by the second unmanned aerial vehicle management entity.

[0067] In a possible implementation manner, after the open function entity sends the fourth indication information to the first unmanned aerial vehicle management entity currently providing services for the unmanned aerial vehicle, the method further includes: sending, by the open function entity, fifth indication information to the first unmanned aerial vehicle management entity, the fifth indication information being used to indicate that the services provided by the first unmanned aerial vehicle management entity to the unmanned aerial vehicle are switched to services provided by the second unmanned aerial vehicle management entity to the unmanned aerial vehicle.

[0068] In a possible implementation manner, before the open function entity obtains the information of the second unmanned aerial vehicle management entity, the method further includes: receiving, by the open function entity, an authentication request message from a fourth unmanned aerial vehicle management entity, the authentication request message being used to request to authenticate the unmanned aerial vehicle, and the authentication request message including an identifier of the unmanned aerial vehicle; and sending, by the open function entity, a second authentication result between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle, the second authentication result being failure.

[0069] In a possible implementation manner, there is subscription information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, and the subscription information indicates that the unmanned aerial vehicle is a subscription user of the second unmanned aerial vehicle management entity.

[0070] In a possible implementation manner of the sixth aspect, before the open function entity obtains the information of the second drone management entity, the method further includes: determining, by the open function entity, the qualified drone management entity and / or the unqualified drone management entity, wherein the qualified drone management entity includes: a drone management entity having subscription information with the drone, and / or a drone management entity passing the security verification; the subscription information indicates that the drone is a subscription user of the drone management entity; the qualified drone management entity includes the second drone management entity; and sending, by the open function entity, a fifth message to the first drone management entity, wherein the fifth message is used to indicate the qualified drone management entity and / or the unqualified drone management entity.

[0071] In a possible implementation manner of the sixth aspect, before the open function entity determines the qualified drone management entity and / or the unqualified drone management entity, the method further includes: receiving, by the open function entity, a sixth message from the first drone management entity, wherein the sixth message includes a second candidate entity list, the second candidate entity list includes one or more candidate drone management entities providing services for the drone, and the sixth message is used to obtain the qualified drone management entity in the second candidate entity list.

[0072] In a possible implementation manner of the sixth aspect, the qualified drone management entity includes a drone management entity having first subscription information with the drone. The open function entity determines the qualified drone management entity and / or the unqualified drone management entity by: sending, by the open function entity, an information query request to the UDM entity, wherein the information query request is used to query whether there is subscription information between each drone management entity in the second candidate entity list and the drone; receiving, by the open function entity, an information query response from the UDM entity, wherein the information query is used to indicate whether there is subscription information between each drone management entity and the drone; and determining, by the open function entity, the qualified drone management entity and / or the unqualified drone management entity according to the information query response.

[0073] In a possible implementation manner of the sixth aspect, the drone management entity (for example, the candidate USS) having the subscription information (that is, having the subscription information with the drone) is the qualified drone management entity. The drone management entity (for example, the candidate USS) without the subscription information (that is, without the subscription information with the drone) is the unqualified drone management entity.

[0074] In a possible implementation manner of the sixth aspect, the qualified drone management entity is a drone management entity having subscription information of “not performing the UUAA process” with the PLMN.

[0075] Exemplarily, the open function entity determines the qualified drone management entity and / or the unqualified drone management entity, including: the open function entity queries the UDM entity whether there is subscription information of "not performing the UUAA procedure" between each drone management entity in the second candidate entity list and the PLMN; and the open function entity determines the qualified drone management entity (e.g., the USS) according to the query result, i.e., there is subscription information of "not performing the authentication procedure" between the qualified drone management entity and the PLMN. Correspondingly, the open function entity can also determine the unqualified drone management entity according to the query result, i.e., there is no subscription information of "not performing the authentication procedure" between the unqualified drone management entity and the PLMN.

[0076] In combination with the sixth aspect, in a possible implementation manner, the sixth message further includes security verification information of each drone management entity in the second candidate entity list, for example, a token or a message authentication code. The qualified drone management entity includes the drone management entity whose security verification is passed. The open function entity determines the qualified drone management entity and / or the unqualified drone management entity, including:

[0077] The open function entity sends an information obtaining request to the UDM entity, where the information obtaining request is used to request information for verifying each drone management entity; the open function entity receives an information obtaining response from the UDM entity, where the information obtaining response includes the information for verifying each drone management entity; the open function entity performs security verification on security verification information of each drone management entity respectively according to the information for verifying each drone management entity; and the open function entity determines that the drone management entity whose security verification is passed is the qualified drone management entity, and / or determines that the drone management entity whose security verification is not passed is the unqualified drone management entity.

[0078] In combination with the sixth aspect, in a possible implementation manner, after the open function entity determines the qualified drone management entity and / or the unqualified drone management entity, the method further includes: the open function entity sends a seventh message to a third entity, where the seventh message is used to update or add an authentication result between the qualified drone management entity and the drone. The authentication result is that the drone management entity and the drone are authenticated successfully and are exempted from authentication for next flight. Exemplarily, the third entity is an entity that stores the authentication result, for example, the SMF or the AMF.

[0079] In a seventh aspect, the present application provides a communication method, which can be applied to a candidate second unmanned aerial vehicle management entity (UAV-ME) for providing service for an unmanned aerial vehicle, i.e., a candidate USS. The method comprises: receiving, by the second UAV-ME, a second message from a first UAV-ME (i.e., a serving USS) currently providing service for the unmanned aerial vehicle, the second message being used for requesting the second UAV-ME to prepare for switching the UAV-ME.

[0080] For example, the second UAV-ME can be a target USS.

[0081] In combination with the seventh aspect, in a possible implementation manner, the second UAV-ME sends one or more of the following information to the first UAV-ME: address information of the second UAV-ME, network information associated with the second UAV-ME, air traffic control information corresponding to the second UAV-ME, or a trust relationship between the first UAV-ME and the second UAV-ME.

[0082] For example, the open function entity can be a NEF or a UAS NF.

[0083] In combination with the seventh aspect, in a possible implementation manner, the method further comprises: the second UAV-ME can also send, to the first UAV-ME or the open function entity, an identifier or an address of the second UAV-ME.

[0084] In combination with the seventh aspect, in a possible implementation manner, the method further comprises: the second UAV-ME receives a third message from the first UAV-ME, the third message being used for notifying the second UAV-ME to perform an authentication process with the unmanned aerial vehicle, the third message comprising an identifier of the unmanned aerial vehicle; the second UAV-ME sends an authentication request message to the open function entity, the authentication request message being used for requesting to authenticate the unmanned aerial vehicle, the authentication request message comprising the identifier of the unmanned aerial vehicle; and the second UAV-ME receives a first authentication result between the second UAV-ME and the unmanned aerial vehicle from the open function entity. The first authentication result is success or failure.

[0085] In an eighth aspect, the present application provides a communication apparatus, which can be a first UAV-ME, or a second UAV-ME, or an open function entity, or a chip thereof. The communication apparatus comprises units and / or modules for performing the method provided in any one of the fifth aspect to the seventh aspect, or any one of the possible implementation manners of any one of the fifth aspect to the seventh aspect, such as a transceiver module and / or a processing module. The transceiver module is used for transceiving various information or signaling, and thus can also achieve the beneficial effects (or advantages) of the method provided in any one of the fifth aspect to the seventh aspect.

[0086] In a ninth aspect, the present application provides a communication apparatus, which can comprise a processor configured to implement a method according to any possible implementation of the method described in the first aspect through the third aspect, or the method described in any possible implementation of the fifth aspect through the seventh aspect, or any combination thereof. Alternatively, the processor can be configured to implement a method stored in the memory, when the method is executed, the method according to any possible implementation of the first aspect through the third aspect, or the method according to any possible implementation of the fifth aspect through the seventh aspect, or any combination thereof is executed.

[0087] In a possible implementation of the ninth aspect, the memory is located outside the communication apparatus.

[0088] In a possible implementation of the ninth aspect, the memory is located inside the communication apparatus.

[0089] In the present application, the processor and the memory can also be integrated into one device, i.e., the processor and the memory can also be integrated together.

[0090] In a possible implementation of the ninth aspect, the communication apparatus further comprises a transceiver, which is configured to send or receive various information, such as various messages or indication information, etc.

[0091] In a tenth aspect, the present application provides a communication apparatus, which can comprise a logic circuit and an interface connected thereto. The interface is configured to interact (or transceive or input and output) information or data, and the logic circuit is configured to run program instructions, so that the communication apparatus executes the method described in any possible implementation of any one of the first aspect through the third aspect, or the fifth aspect through the seventh aspect, or any combination thereof. The interface can be a communication interface or a transceiver. The transceiver can be a radio frequency module in the communication apparatus, or a combination of a radio frequency module and an antenna, or an input and output interface of a chip or circuit.

[0092] In an eleventh aspect, the present application provides a readable storage medium, which stores program instructions, when the program instructions are run on a communication apparatus, the communication apparatus executes the method described in any possible implementation of any one of the first aspect through the third aspect, or the fifth aspect through the seventh aspect, or any combination thereof.

[0093] In a twelfth aspect, the present application provides a program product comprising instructions, when the instructions are run, the apparatus comprising the program product executes the method described in any possible implementation of any one of the first aspect through the third aspect, or the fifth aspect through the seventh aspect.

[0094] In a thirteenth aspect, the present application provides a communication apparatus, which can be in the form of a chip or a device. The apparatus comprises a processor. The processor is configured to read and execute a program stored in a memory to perform the model authorization method in any one of the first aspect to the third aspect or the fifth aspect to the seventh aspect, or any possible implementation of any one of the aspects. Optionally, the apparatus further comprises a memory connected to the processor by an electrical circuit. Further optionally, the apparatus further comprises a communication interface connected to the processor. The communication interface is configured to receive information and / or signaling to be processed. The processor is configured to obtain the information and / or signaling from the communication interface, process the information and / or signaling, and output the processing result through the communication interface. The communication interface can be an input / output interface.

[0095] Optionally, the processor and the memory can be physically independent units, or the memory can be integrated with the processor.

[0096] In a fourteenth aspect, the present application provides a communication system, which comprises one or more network elements, such as the first UAV management entity, the second UAV management entity, or the open function entity. The first UAV management entity can be configured to perform the method described in the first aspect, the fifth aspect, or any possible implementation of any one of the aspects. The open function entity can be configured to perform the method described in the second aspect, the sixth aspect, or any possible implementation of any one of the aspects. The second UAV management entity can be configured to perform the method described in the third aspect, the seventh aspect, or any possible implementation of any one of the aspects.

[0097] The technical effects achieved by the above aspects can be mutually referred to or referred to the beneficial effects of the method embodiments shown below, which will not be described here. BRIEF DESCRIPTION OF DRAWINGS

[0098] FIG. 1 is a schematic diagram of a network architecture according to an embodiment of the present application;

[0099] FIG. 2a is a schematic diagram of an application scenario in which multiple USSs serve one UAV according to an embodiment of the present application;

[0100] FIG. 2b is a schematic diagram of a network architecture in which multiple USSs serve one UAV according to an embodiment of the present application;

[0101] FIG. 3 is a simplified flowchart of a USS switching process according to an embodiment of the present application;

[0102] FIG. 4 is a first flowchart of a communication method according to an embodiment of the present application;

[0103] FIG. 5 is a second flow diagram of a communication method according to an embodiment of the present application;

[0104] FIG. 6 is a third flow diagram of a communication method according to an embodiment of the present application;

[0105] FIG. 7 is a fourth flow diagram of a communication method according to an embodiment of the present application;

[0106] FIG. 8 is a structural diagram of a communication apparatus according to an embodiment of the present application;

[0107] FIG. 9 is another structural diagram of a communication apparatus according to an embodiment of the present application;

[0108] FIG. 10 is a structural diagram of a communication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0109] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application.

[0110] In the description of the present application, "first" and "second" are used only to distinguish different objects, and are not used to describe a specific order. In addition, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device, etc. comprising a series of steps or units is not limited to the listed steps or units, but can optionally further comprise steps or units not listed, etc., or can optionally further comprise other steps or units inherent to the process, method, product or device, etc.

[0111] In the description of the present application, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this document is only a description of the association relationship between the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, "at least one" means one or more, and "multiple" means two or more. "One or more" or the like means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can mean a, b, c; a and b; a and c; b and c; or a and b and c. Where a, b, and c can be single or multiple.

[0112] In the present application, the element expressed by the singular is intended to represent "one or more", and not "one and only one", unless otherwise specified.

[0113] In this application, the word "exemplary" or "for example" is used to mean serving as an example, instance, or illustration. Any embodiment or design described in this application as "exemplary", "for example" or "for instance" should not be construed as preferred or advantageous over other embodiments or designs. Rather, the embodied or designed examples are intended to present concepts in a concrete manner. The word "exemplary" or "for example" is used in this application to present concepts in a concrete manner.

[0114] In the embodiments of this application, "A corresponds to B", "A and B correspond to each other" or the like means that B is associated with A, and B can be determined according to A. Determining B according to A does not mean that B is determined only according to A, but also can be determined according to A and / or other information.

[0115] In this application, "indication" can include direct indication, indirect indication, display indication, and implicit indication. When describing that a certain information is used to indicate A, it can be understood that the information carries A, directly indicates A, or indirectly indicates A. Among them, directly indicating A can be understood as including the information A; implicitly indicating A can be understood as indicating A by the corresponding relationship between A and B and directly indicating B. Among them, the corresponding relationship between A and B can be pre-defined, pre-stored, pre-burned, or pre-configured.

[0116] In this application, "sending" and "receiving" can represent the direction of signal transmission. For example, "sending information to XX" can be understood as that the destination of the information is XX, which can include direct sending through the air interface, or indirect sending through the air interface by other units or modules. "Receiving information from YY" can be understood as that the source of the information is YY, which can include direct receiving from YY through the air interface, or indirect receiving from YY through the air interface by other units or modules. The information between the source and the destination of the information transmission can be processed as necessary, such as format change, etc., but the destination can understand the valid information from the source. Similar expressions in this application can be understood similarly, and will not be repeated here.

[0117] In this application, "sending" can also be understood as "output" of chip interface, and "receiving" can also be understood as "input" of chip interface. In other words, sending and receiving can be carried out between devices, such as between network devices and terminal devices, or can be carried out within a device, such as between components, modules, chips, software modules or hardware modules within a device through bus, wire or interface.

[0118] The network architecture and application scenarios related to this application are briefly described below.

[0119] The technical solutions provided by this application can be applied in various communication systems. For example: the fifth generation (5 thA communication system can be a 5th generation, 5G, communication system or a new radio, NR, communication system, a network equipped with network functions virtualization infrastructure, NFVI, or a long term evolution, LTE, network, a MulteFire network (creating a new wireless network by running LTE technology on unlicensed spectrum, such as the global 5GHz unlicensed spectrum), or a home base station network, a mobile network with wireless fidelity, Wi-Fi, access, a wideband code division multiple access, WCDMA, network, a fixed mobile convergence network (fixed access network access mobile network), and other future communication systems, such as a 6th generation, 6G, mobile communication system, etc. th

[0120] In a mobile communication system, a part operated by an operator can be referred to as a public land mobile network, PLMN, or a mobile network operator, MNO, network, etc. The PLMN can provide a user with a terrestrial mobile communication service, such as a public network providing a user with a mobile broadband access service. The PLMN described in the present application can be a network conforming to the requirements of the 3rd generation partnership project, 3GPP, standard, referred to as a 3GPP network. The 3GPP network generally includes, but is not limited to, a 5th generation mobile communication, 5G, network (referred to as a 5G network), a 4th generation mobile communication, 4G, network (referred to as a 4G network), or other future communication systems (such as a 6G network), etc. th th generation,5G) network (referred to as a 5G network), a 4th generation mobile communication, 4G, network (referred to as a 4G network), or other future communication systems (such as a 6G network), etc.

[0121] For convenience of description, the present application will be described taking the PLMN or the 5G network as an example.

[0122] Referring to FIG. 1, FIG. 1 is a network architecture diagram provided by an embodiment of the present application. FIG. 1 takes the 5G network architecture based on the service-oriented architecture in the non-roaming scenario defined in the 3GPP standardization process as an example. In FIG. 1, three types of devices / networks / entities are exemplarily shown, such as a terminal device, an operator network (such as a PLMN), and other networks / entities. The following will be briefly described respectively.

[0123] ​​A terminal device 110, which can also be referred to as a user equipment (UE), an access terminal, a terminal, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, a remote terminal, a mobile device, a user terminal, a user agent, or a user device, etc. The terminal device can be, for example, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the terminal device can also be a handheld device having wireless communication function, a computing device, or other device connected to a wireless modem, a vehicle-mounted device, a wearable device, a drone, or a terminal in Internet of Things, Internet of Vehicles, 5G network, and future network, a relay user equipment, or a terminal in future evolved 6G network, etc. The embodiments of the present application do not limit the type or category of the terminal device. For the convenience of understanding the embodiments of the present application, the terminal device is taken as a drone in the following description. The drone can establish a connection with the operator network through an interface (such as N1, etc.) provided by the operator network, and use the data and / or voice services provided by the operator network. The drone can also access the data network 120 through the operator network, use the operator services deployed on the data network 120, and / or the services provided by a third party. The third party is a service provider other than the operator network, which can provide other data and / or voice services for the drone. The specific form of the third party can be determined according to the actual application scenario, which is not limited herein.

[0124] The operator network (such as a PLMN) can include, but is not limited to, a (radio) access network ((R)AN) 140 and a core network (CN).

[0125] The (R)AN 140 can be understood as a sub-network of an operator network (such as a PLMN) and is an implementation system between service nodes in the operator network and the terminal device 110. The terminal device 110 can be connected with the service nodes in the operator network through the (R)AN 140. The access network device (RAN device) in the embodiments of the present application can be understood as a device that provides wireless communication functions for the terminal device 110, and can also be referred to as a network device. The RAN device can include, but is not limited to, a next generation node base station (gNB) in a 5G system, an evolved node B (eNB) in long term evolution (LTE), a radio network controller (RNC), a node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (for example, a home evolved node B, or a home node B, HNB), a base band unit (BBU), a transmitting and receiving point (TRP), a transmitting point (TP), a pico, a mobile switching center, or a network device in a future network, etc. In systems using different wireless access technologies, the names of devices with access network device functions may be different. For the convenience of description, all the embodiments of the present application collectively refer to the above-mentioned devices that provide wireless communication functions for the terminal device 110 as access network devices or simply as RAN or AN. It should be understood that the specific types of access network devices are not limited herein.

[0126] A core network (CN) can include, but is not limited to, the following network functions (NFs): an access and mobility management function (AMF) 131, a network exposure function (NEF) or unmanned aircraft system function (UAS NF) 132, a network function repository function (NRF) 133, a unified data management (UDM) function 134, a policy control function (PCF) 135, a session management function (SMF) 136, and a user plane function (UPF) 137.

[0127] Among them, the access and mobility management function (AMF) 131 (also referred to as an AMF network element, an AMF network function, or an AMF network function entity) is a control plane function provided by an operator network (such as a PLMN), which can be responsible for access control and mobility management of terminal devices 110 accessing the operator network (such as a PLMN), for example: mobile state management, allocation of a user temporary identity, authentication and authorization of a user, and the like.

[0128] The unmanned aircraft system function (UAS NF) / NEF 132 is a control plane function provided by an operator network (such as a PLMN) for unmanned aircraft systems (UAS), which can be responsible for opening network support for unmanned aircraft business capabilities to external networks, for example: it can open unmanned aircraft authentication / authorization services, unmanned aircraft flight authorization services, pairing authorization of unmanned aircraft and remote controllers, re-authentication / authorization / cancellation of unmanned aircraft, location information reporting of unmanned aircraft, quality control of unmanned aircraft services, and traffic filtering for command and control communication. The UAS NF can be an instance generated by the network exposure function (NEF), or a sub-function of the NEF. Of course, the UAS NF can also be an independent function specially used to provide unmanned aircraft services, and therefore the present application does not distinguish between the UAS NF and the NEF.

[0129] The network function repository function (NRF) 133 (also referred to as an NRF network element, an NRF network function, or an NRF network function entity) is a control plane function provided by an operator network (such as a PLMN), which can be used to maintain real-time information of all network function services in the network.

[0130] The unified data management (UDM) function 134 (may also be referred to as a UDM network element, a UDM network function, or a UDM network function entity) is a control plane function provided by an operator network (such as a PLMN) and can be responsible for storing user permanent identifiers (SUPIs) of subscribed users in the operator network (such as a PLMN), generic public subscription identifiers (GPSIs) publicly used by the subscribed users, credentials, and the like. Among them, the SUPI will be encrypted first in the transmission process, and the encrypted SUPI is referred to as a subscription concealed identifier (SUCI). The information stored by the UDM function 134 can be used for authentication and authorization of a terminal device 110 accessing the operator network (such as a PLMN). Among them, the subscribed user of the operator network can be specifically a user using a service provided by the operator network, for example, a user using a China Telecom mobile phone chip card or a user using a China Mobile mobile phone chip card, and the like. The credentials of the subscribed user can be a long-term key stored by the mobile phone chip card or a small file stored by the mobile phone chip card and related to encryption of the mobile phone chip card, and the like, for authentication and / or authorization. It should be noted that the permanent identifier (such as the SUPI), the credential, the security context, the authentication data (cookie), and the token and the like are related to verification / authentication and authorization information, which are not distinguished and limited in the embodiments of the present application for the sake of description.

[0131] The policy control function (PCF) 135 (may also be referred to as a PCF network element, a PCF network function, or a PCF network function entity) is a control plane function provided by an operator network (such as a PLMN) and can support a unified policy framework to govern network behavior, provide policy rules and subscription information related to policy decision to other control functions, and the like.

[0132] The session management function (SMF) 136 (may also be referred to as an SMF network element, an SMF network function, or an SMF network function entity) is a control plane function provided by an operator network (e.g., a PLMN) and can be responsible for managing protocol data unit (PDU) sessions of the terminal device 110. A PDU session can be understood as a tunnel for transmitting PDUs, and the terminal device can transmit PDUs with the data network 120 through the PDU session. The PDU session can be responsible for establishing, maintaining, and deleting, etc. by the SMF 136. The SMF 136 includes functions related to sessions, such as session management (e.g., session establishment, modification, and release, including maintenance of a tunnel between a user plane function (UPF) 137 and a (R)AN 140), selection and control of the UPF 137, selection of a traffic and session continuity mode, and roaming.

[0133] The user plane function (UPF) 137 (may also be referred to as a UPF network element, a UPF network function, or a UPF network function entity) is a gateway provided by an operator network (e.g., a PLMN) and is a gateway for communication between the operator network and the data network 120. The UPF 137 includes functions related to the user plane, such as data packet routing and transmission, data packet detection, traffic usage reporting, quality of service processing, lawful monitoring, uplink data packet detection, and downlink data packet storage.

[0134] Other networks / entities can include, but are not limited to, the following networks or entities: a data network (DN) 120, or a UAV service supplier (USS) 121.

[0135] The data network (DN) 120 can also be referred to as a packet data network (PDN), and is generally a network located outside the operator network (such as the PLMN), for example, a third-party network. Of course, in some implementations, the DN can also be deployed by the operator, that is, the DN belongs to a part of the PLMN. The present application does not limit whether the DN belongs to the PLMN. The name of the DN is referred to as the DNN (DN name). The operator network (such as the PLMN) can access multiple DNs 120, and multiple services can be deployed on the DNs 120 to provide data and / or voice services for the terminal device 110. For example, the DN 120 can be a private network of a certain smart factory, and the sensors installed in the workshop of the smart factory can be the terminal device 110. A control server of the sensors is deployed in the DN 120, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions, and the like. For another example, the DN 120 can be an internal office network of a certain company, and the mobile phones or computers of the employees of the company can be the terminal device 110. The mobile phones or computers of the employees can access information and data resources on the internal office network of the company. The terminal device 110 can establish a connection with the operator network through an interface (such as N1, etc.) provided by the operator network (such as the PLMN) to use data and / or voice services provided by the operator network. The terminal device 110 can also access the DN 120 through the operator network (such as the PLMN) to use operator services and / or third-party services deployed on the DN 120.

[0136] The unmanned aerial system service provider (USS) 121 can provide services for the operator or controller of the unmanned aerial system (UAS) to support the safe and efficient use of airspace, meet the operational requirements of the unmanned aerial system traffic management (UTM) entity for operating the unmanned aerial system. For example, the USS can store the authentication and authorization information of the unmanned aerial system, authenticate the identity of the unmanned aerial system, and authorize the flight, etc. The regulator of the unmanned aerial system can also regulate the operation of the unmanned aerial system through the USS to ensure the safety of the unmanned aerial flight control and public safety. The USS can also establish a channel with other regulatory or safe flight departments to obtain flight-related information. It should be noted that the USS can sometimes implement part of the functions of the unmanned aerial system traffic management (UTM) entity, and therefore in this application, the USS can refer to the USS itself, or represent an entity integrating the USS and the UTM, which is not limited in this application. Generally, the USS can be deployed by an external third party or by an operator, and this application does not limit whether the USS belongs to the PLMN. For the USS 121, it can interact with the core network as an application function (AF) deployed by a third party, that is, it communicates with the PLMN or the terminal device (such as the unmanned aerial vehicle) through the UAS NF (or NEF) 132 of the core network, and the USS and the AF are not distinguished in this application. In order to facilitate the understanding of the embodiments of the present application, the following will be introduced by taking the third-party-deployed USS as an example. In addition, one UAS NF 132 of the PLMN can be connected to multiple USSs 121, and one USS 121 can also be connected to multiple UAS NFs 132.

[0137] When a UAV registers in a network or establishes a PDU session related to UAV service, the UAV needs to perform a USS UAV authentication and authorization (UUAA) procedure with the USS, i.e., an authentication and authorization procedure between the USS and the UAV. After the UUAA procedure is successful, the UAS NF (or NEF) can store the UUAA context, such as the identifier of the UAV (such as GPSI and / or civil aviation administration-level UAV identity (CAA-Level UAV ID, or simply UAVID)) that successfully performs the UUAA procedure and the corresponding USS (such as the corresponding USS identifier). Therefore, the UAS NF (or NEF) can determine that the UAV has successfully passed the authentication and authorization procedure with the USS through the stored UUAA context. Only after successfully completing the UUAA procedure with the USS, the UAV can obtain the service of the USS or the service related to the USS provided by the network.

[0138] It can be understood that the above network functions are examples of an implementation manner, and the application does not exclude that network elements or devices having the above network functions have other names or other forms in a 6G or future communication system. The network functions shown in FIG. 1 can also be referred to relevant protocols or standards, and the application does not expand the description.

[0139] It can be understood that Nnef, Nnrf, Npcf, Nudm, Namf, Nsmf, N1, N2, N3, N4, N6 and N33 in FIG. 1 are interface serial numbers. For example, the meanings of the above interface serial numbers can be referred to the meanings defined in the 3GPP standard protocol, and the application does not limit the meanings of the above interface serial numbers. It can also be understood that the interface names between the network functions in FIG. 1 are only an example, and the interface names of the system architecture can also be other names in the specific implementation, and the application does not limit this. In addition, the names of the messages (or signaling) transmitted between the above network elements are also only an example, and do not constitute any limitation on the functions of the messages themselves.

[0140] In a possible implementation manner, the network element or functional entity in the embodiment of the application can be a network element in a hardware device, or a software function running on a special hardware, or a virtualized function instantiated on a platform (for example, a cloud platform). As a possible implementation manner, the network element or function of the embodiment of the application can be implemented by one device, or can be implemented by multiple devices together, or can be a functional module in one device, and the embodiment of the application does not make a specific limitation.

[0141] The 3GPP network is generally responsible for communicating with the drone system service provider USS (or AF) 121 by the UAS NF (or NEF) 132 to support the business of the drone system. Generally, one USS has a geographical service area. Therefore, there is a scenario in which one drone is served by multiple USSs on its flight path. For example, one drone is served by USS#1 in the initial stage of its flight path, and is served by another USS, such as USS#2, in the second stage of the flight path.

[0142] For example, referring to FIG. 2a, FIG. 2a is a schematic diagram of an application scenario in which multiple USSs serve one drone according to an embodiment of the present application. In FIG. 2a, two USSs serve one drone. In the example of FIG. 2a, the starting point of the flight of the drone (unmanned / uncrewed aerial vehicle, UAV) is A, and the end point is B. The flight route of the drone (UAV) is from A to B. The starting point A of the drone is served by USS#1. In the example of FIG. 2a, the service area of USS#1 does not cover the end point B, so the assistance of other USSs is needed to complete the flight of the drone from A to B. In FIG. 2a, assuming only the service areas of the USSs are considered, the USSs that can provide flight assistance are USS#2, USS#3, and USS#4. USS#1 can select one of USS#2, USS#3, and USS#4 to assist USS#1 to complete the planned flight route of the drone. In FIG. 2a, the intermediate node C of the flight route is also marked to illustrate that the drone switches from being served by USS#1 to being served by the selected other USS at point C.

[0143] In the above scenario, the present application refers to USS#1 as the serving USS (serving USS) and refers to USS#2, USS#3, and USS#4 as candidate USSs in the candidate USS list. If USS#1 finally selects to switch to USS#2 to serve the drone, then USS#2 can be referred to as the target USS (target USS).

[0144] It can be understood that, in the example of FIG. 2a described above, the USS switching is triggered due to the difference in service areas, and in actual applications, the USS switching can also have other causes, such as poor wireless signal of USS#1, too large number of drones served by USS#1, or too much data traffic of USS#1, and the like. The present application does not limit the cause of the USS switching. Further, in the example of FIG. 2a described above, only the scenario of switching the USS once is illustrated, and in actual applications, there can also be scenarios of multiple times of switching, which are also not limited by the present application.

[0145] Referring to FIG. 2b, FIG. 2b is a schematic diagram of a network architecture in which multiple USSs serve one UAV, according to an embodiment of the present application. For example, FIG. 2b is a schematic diagram of a network architecture in which multiple USSs serve one UAV using a 5G network. Compared with FIG. 1, only network functions (NFs) closely related to the scenario in which multiple USSs serve one UAV are shown in FIG. 2b. As shown in FIG. 2b, the UAS NF can directly interface with the serving USS #1, or directly interface with other USSs. For example, the UAS NF directly interfaces with the USS #2 or the USS #4. Meanwhile, the serving USS #1 interfaces with candidate USSs (e.g., the USS #2, the USS #3, and the USS #4) and can communicate with the candidate USSs.

[0146] In summary, the serving USS can select or switch a USS by using a 3GPP network (e.g., by interfacing with the UAS NF and communicating with the UAS NF), and the serving USS can interface with other USSs and communicate with the other USSs (as shown in FIG. 2b). When the serving USS detects that a UAV has left or is about to leave the service area of the serving USS, the serving USS can trigger switching to a target USS to serve the UAV. The serving USS can send information about the UAV and / or the USS to the target USS, such as an identifier of the UAV, information about the serving USS and the target USS, and the like. The serving USS can also notify the target USS to prepare for the switching of the USS, and can instruct the UAV to obtain authentication and authorization of the target USS. When the NEF / UAS NF has a UUAA context of the UAV and the target USS, the UAV can obtain the service of the target USS.

[0147] In one possible implementation, referring to FIG. 3, FIG. 3 is a simplified flowchart of USS switching, according to an embodiment of the present application. As shown in FIG. 3, the simplified flowchart of USS switching includes, but is not limited to, the following steps:

[0148] Step 1: A UAV establishes a PDU session to communicate with a serving USS (e.g., the USS 1). During this process, the UAV and the serving USS complete a UUAA procedure.

[0149] Step 2a: If necessary, the UAV requests pre-flight planning services from the serving USS (e.g., the USS 1). The request message can include an identifier of the UAV (e.g., a GPSI or a CAA-level UAV ID), information about a starting point and a next point of a flight, and requirements for a flight route (e.g., punctuality, shortest distance, maximum height, and farthest distance from a launch area). For example, the request message can also include a candidate flight path.

[0150] Step 2b, the serving USS determines the need to switch to another USS. The serving USS (e.g., USS1) determines whether a switch to another USS is needed based on information of the next point on the flight path of the UAV or a notification from the core network (e.g., when the serving USS subscribes to a UAV location reporting event from the AMF / GMLC (gateway mobile location center) / LMF (location management function)).

[0151] Step 3, the serving USS determines the neighboring USS(es) that can be used as target USS and triggers a communication with all the suitable USS(es) (e.g., USS2) that can be used as target USS to determine the candidate waypoint for the UAV.

[0152] For example, the serving USS can determine the suitable target USS and the candidate waypoint between the serving USS and the potential target USS by means outside the 3GPP scope. For this purpose, a number of criteria / indicators can be used, such as the location of the next point in the flight path, the area served by a particular USS, the number of UAVs within the area served by a particular USS, proximity to a no-launch zone, USS load, etc. In addition, the serving USS can cooperate with the UTM to derive any other information from the 5G core network that can be used to assist the USS switch and / or provide flight plan assistance information (e.g., acceptable deviation from a specified flight plan / route).

[0153] It is noted that a USS suitable to be used as a target USS can also be referred to as a candidate USS, and all the suitable USS(es) to be used as a target USS can also be referred to as all the candidate USS(es) in a candidate USS list.

[0154] Step 4, the serving USS sends a flight assistance acquisition (e.g., Nnef_UAFlightAssistance_Get) request to the NEF / UAS NF to collect information needed for the USS switch from the core network. The serving USS can include in the flight assistance acquisition request the information derived in step 3 (e.g., an indication of the USS switch, a list of addresses of suitable target USS, a list of candidate waypoints, acceptable deviation from a flight plan / route), an identifier of the UAV (e.g., GPSI), and other parameters, such as requirements on the flight path, candidate flight paths (one or more), a level of predicted accuracy related to the flight plan.

[0155] Step 5, When the NEF / UAS NF receives a request (e.g. Nnef_UAFVlightAssistance_Get request) from the serving USS with a USS switching indication, the NEF / UAS NF can translate / map the parameters contained in this request to 3GPP identifiers (if needed). For example, the NEF determines the cell identifiers (IDs) / tracking area identifiers (TAIs) of the cell / TA where the UAV requested flight path origin and the next point in this flight path are located. Similarly, if the indication that the UAV will cross the USS border and / or the list of candidate transit points listed in the form of geographical coordinates are included in this request, the NEF can map them to a list of border cell IDs / TAIs. The NEF determines the relevant NFs and specific service operations it needs to invoke in order to collect the information needed for the UAV flight plan for the serving USS. For example, the network data analytics function (NWDAF) analytics service for motion behavior analysis, the gateway mobile location center (GMLC) service for ranging / sidelink positioning, the AMF for the UAV presence in the border TA / cell, the AMF service for the UAV presence off the intended / assigned trajectory, the UDM service for providing expected UE behavior parameters provision.

[0156] Step 6, The NEF / UAS NF invokes the service operation on the identified NFs as described in the procedure for NEF-assisted pre-flight planning, see 3GPP relevant standards for details.

[0157] Step 7, If the NEF / UAS NF receives a list of candidate border transit points, the NEF / UAS NF identifies the AMF serving the next generation radio access network (NG-RAN) nodes in all the identified border TA(s) / cells. To this end, the NEF / UAS NF can invoke the NF discovery (Nnrf_NFDiscovery) service of the NRF. Once the AMF(s) information is obtained, the NEF / UAS NF can send a Namf_EventExposure_Subscribe request to this AMF to subscribe to the AMF service for timely obtaining the information that the UE / UAV is present in the border cell / TA.

[0158] Step 8, NEF / UAS NF sends a flight assistance acquisition response (e.g., Nnef_UAFlightAssistance_Getresponse) to the serving USS using the flight path information between the origin and the transit points of all candidate USSs collected from the 5G core network elements, in response to the flight assistance acquisition (e.g., Nnef_UAFlightAssistance_Get) request in Step 4.

[0159] Step 9, based on the received information, the serving USS selects a target USS (Step 3) from the pre-selected list of suitable USSs (i.e., the list of candidate USSs) and starts communicating with the target USS (e.g., USS2) to request USS2 to prepare for a USS handover, and if needed, the target USS formulates a next flight plan for the UAV, which can be from the transit point to the next point on the flight path that is located in the geographical area served by the target USS.

[0160] Step 10, the target USS (e.g., USS2) formulates the next flight plan as described in Step 9 by performing Steps 4 to 8 for the UAV.

[0161] Step 11, the target USS (e.g., USS2) provides the serving USS (e.g., USS1) with the flight path(s) information (e.g., primary flight path, secondary / alternative flight path, etc.) for the UAV to fly from the border cell(s) / TA(s) to the next point on the flight path.

[0162] Step 12, if the UAV requests a flight plan before flight in Step 2a, the serving USS responds to the request, which includes the planned flight route and schedule for the entire flight from the origin to the next point on the flight path.

[0163] Step 13, the serving USS sends a flight assistance creation (e.g., Nnef_UAVFlightAssistance_Create) request to the NEF / UAS NF, which contains the information of the planned UAV flight path(s). Additional flight path information for each segment of the path (served by USS1 and USS2) can also be included in the request, such as the speed of the UAV, the flight height / altitude, and / or the schedule of the transit / stop at each TA / cell.

[0164] Step 14, NEF / UAS NF can invoke additional services of 5G core network network elements. For example: invoke service of AMF to determine the deviation of UAV from the intended UAV flight trajectory (e.g. primary / secondary flight path); invoke service of UDM to update the intended UE behavior parameters by providing parameters; invoke service of NWDAF to analyze the motion behavior of UE / UAV to determine whether the UAV is likely to leave the service area of USS and continue to fly along the flight path. The intended UAV flight trajectory can include multiple segments, where each segment is identified by a geographical area served by a different USS (e.g. the currently serving USS and the target USS to be handed over).

[0165] In some scenarios, NEF / UAS NF can use the AMF event exposure service to be notified when the UAV does not follow (i.e. deviates from) the specified flight plan. In this case, NEF / UAS NF sends a subscription request to the serving AMF, which contains the specified flight path information including the list of 3GPP locations (i.e. TAI or cell ID), the schedule describing when the UE should be present at these locations, the range of height / altitude, and optionally the acceptable deviation (e.g. UAV does not arrive on time).

[0166] In some scenarios, NEF / UAS NF provides the planned flight path information to UDM. The flight path information includes the list of 3GPP locations (i.e. TAI or cell ID, and optionally height / altitude information), and the schedule describing when the UE should be present at these locations, and optionally the acceptable deviation (e.g. UAV does not arrive on time or UAV flies below / above the specified flight height).

[0167] In some scenarios, NEF / UAS NF obtains the analysis of the motion behavior of UE / UAV from NWDAF as described in clause 6.21 of 3GPP technical specifications (3GPP TS) 23.288.

[0168] Step 15, if NEF / UAS NF (in step 7) subscribes to the notification service of the occurrence of UAV in the border cell / TA(s), the AMF can notify the NEF / UAS NF of the event (i.e. UAV enters the area of interest) once the UAV enters the border cell / TA of the serving USS. Similarly, if NEF / UAS NF subscribes to the event report, which refers to the UAV deviating from the intended / assigned trajectory and / or moving on a different trajectory segment, the AMF notifies the NEF / UAS NF when it detects any such event.

[0169] Step 16, when the NEF / UAS NF receives a report from the AMF indicating that the UAV deviates from the designated flight plan, the NEF / UAS NF can send a request (e.g., Ngmlc_Locate_ProvideLocation service request) to the GMLC to obtain the accurate location of the UAV. In this case, the GMLC performs a 5G mobile terminating location request (5G-MT-LR) procedure to obtain the accurate location of the UAV through the AMF / LMF (specified in 3GPP TS 23.273 [8]) and provide the location of the UAV to the NEF / UAS NF.

[0170] Step 17, if the NEF / UAS NF determines that the UAV is leaving or will soon leave the geographic area served by the serving USS (e.g., USS1), the NEF / UAS NF sends a request (e.g., Nnef_UAVFlightAssistance_Notify request) to the serving USS, including in the request the transit point to be used by the UAV or when to use the transit point, so that the serving USS can timely trigger the USS handover.

[0171] Step 18, the serving USS communicates with the target USS to perform the USS handover for the UAV. The serving USS sends information to the target USS, which are the open service / notify service (e.g., subscription event and NEF address) related to the UAV, the identifier of the UAV (e.g., GPSI, CAA level UAV ID), and other information required for the target USS (or the UAV itself) to establish a connection.

[0172] Step 19, the AMF serving the border tracking area (TA) / cell on the target USS side (e.g., USS2) informs the NEF / UAS NF about the presence of the UAV in the border TA / cell, and the NEF / UAS NF further informs the target USS.

[0173] Step 20, the serving USS (e.g., USS1) informs the UAV about the information of switching to the new USS (e.g., USS2), and if necessary, the serving USS can instruct the UAV to perform the UUAA procedure with the new USS (e.g., USS2), and trigger the open services that the previous USS (i.e., the serving USS) had with the 5G core network elements before the change.

[0174] Step 21, after receiving the required information from the serving USS, the target USS responds to the request (e.g., Nnef_UAFlightAssistance_Notify request) from the NEF / UAS NF, thereby completing the UAV handover of the USS.

[0175] From the above USS switching flow, there is no security solution for USS switching at present. Therefore, the application provides a communication method, device and readable storage medium, which can improve the security and reliability of USS switching, and further can reduce the possibility of USS switching failure.

[0176] Before introducing the technical solutions of the application, some information related to UUAA will be briefly described.

[0177] Generally, before serving a UAV, a USS needs to perform a UUAA procedure (i.e., an authentication and authorization procedure between the USS and the UAV) with the UAV, and the NEF / UAS NF assisting the UUAA procedure can store the information of UUAA success, which is called UUAA context. It can be understood that the UUAA context can include the identifier of the UAV (such as GPSI and / or CAA-Level UAV ID) that successfully performs the UUAA procedure, and the corresponding USS (such as the corresponding USS identifier).

[0178] It can be understood that one of the conditions for performing the UUAA procedure includes that a secure connection (i.e., a connection with security protection) is established between the PLMN and the USS. For example, as shown in the aforementioned FIG. 1, the NEF / UAS NF of the PLMN performs a two-way authentication of transport layer security (TLS) based on digital certificates (such as certificates including the certificate of the NEF / UAS NF and the certificate of the USS) with the USS. After the authentication is completed, the messages communicated between the NEF / UAS NF and the USS are at least protected by integrity protection, anti-replay protection, and confidentiality protection. For example, the integrity protection can be implemented by a message authentication code (MAC). For example, the anti-replay protection can be implemented by a nonce that is used only once. For example, the confidentiality protection can be implemented by encryption.

[0179] Among them, performing UUAA can also be understood as performing a two-way authentication between the UAV and the USS. The authentication method of the two-way authentication between the UAV and the USS can use TLS based on digital certificates, or can be implemented by using other ways based on the pre-stored shared key, password, biological information, etc. between the UAV and the USS, or in combination with TLS. The specific method of UUAA is not limited by the application.

[0180] When the UUAA procedure is completed, the USS sends the authentication result (e.g., authentication success), the UAV ID of the UAV, and / or the GPSI to the NEF / UAS NF, which stores the UAV ID and / or the GPSI in the UUAA context of the UAV. It should be noted that the UAV ID (i.e., the UAV ID at the CAA level) is an identifier for identifying the UAV in the USS system, and the GPSI can be an identifier assigned to the UAV by the PLMN, which corresponds to the SUPI in the PLMN. Therefore, in the UUAA context, the NEF / UAS NF can actually save the mapping relationship between the UAV ID (the ID for identifying the UAV in the USS system) and the GPSI (which can be mapped to the SUPI).

[0181] The technical solutions provided by the present application will be described in detail below with reference to more drawings.

[0182] In a possible implementation, the UAV management entity provided by the present application can provide services for the operator or controller of the UAV system (UAS) to support safe and effective use of airspace and meet the operation requirements of the UAV system traffic management (UTM) entity for operating the UAV system. For example, the UAV management entity provided by the present application can be a USS entity, or a UAV system traffic management (UTM) entity, or an entity integrating the functions of the USS and the UTM, which is not limited by the present application. Hereinafter, the UAV management entity is taken as the USS for the purpose of clarity.

[0183] In a possible implementation, the open function entity provided by the present application can be responsible for opening the network support UAV service capability to the external network. For example, the open function entity provided by the present application can be a network exposure function (NEF) entity, or an instance generated by the NEF entity, or a sub-function of the NEF entity, or a function entity specially used for providing UAV services (denoted as UAS NF), which is not limited by the present application.

[0184] The technical solutions provided by the present application can be described through multiple embodiments, and specific reference can be made to the descriptions of the embodiments below. In the embodiments of the present application and the embodiments and implementation methods / realization methods in the embodiments, the terms and / or descriptions are consistent and can be referenced to each other if there is no special description and no logical conflict. The technical features in different embodiments and the embodiments and implementation methods / realization methods in the embodiments can be combined to form new embodiments, embodiments, implementation methods, or realization methods according to their inherent logical relationship. The embodiments described below do not constitute a limitation on the protection scope of the present application.

[0185] Referring to FIG. 4, FIG. 4 is a first flow diagram of a communication method according to an embodiment of the present disclosure. The method introduces a method for a serving USS to determine whether a candidate USS or a target USS performs a UUAA procedure with a UAV. In the method, the first UAV management entity can be a serving USS, the second UAV management entity can be a candidate USS or a target USS, and the open function entity can be a NEF or a UAS NF.

[0186] As shown in FIG. 4, the communication method includes but is not limited to the following steps:

[0187] S101, a first UAV management entity (e.g., USS1) currently serving a UAV determines a candidate second UAV management entity (e.g., USS2) serving the UAV.

[0188] In a possible implementation, in the switching process of the UAV management entity (e.g., the USS switching process shown in FIG. 3), the first UAV management entity (i.e., the serving USS, such as USS1) can determine a second UAV management entity (e.g., USS2) based on information received from the open function entity (e.g., NEF / UAS NF). The second UAV management entity (e.g., USS2) can be a target UAV management entity (i.e., target USS) that will serve the UAV. The determination of the target USS can refer to the related description in the existing technology, such as the 3GPP standard, which is not described herein.

[0189] In a possible implementation, in the switching process of the UAV management entity (e.g., the USS switching process shown in FIG. 3), the first UAV management entity (i.e., the serving USS, such as USS1) can determine a candidate second UAV management entity (e.g., USS2) through step 3 of FIG. 3.

[0190] In a possible implementation, before step S101, the communication method can further include steps 1 to 8 of the USS switching process shown in FIG. 3, which are not described herein.

[0191] In the embodiments of the present disclosure, the candidate UAV management entity (i.e., the candidate USS) can also be replaced by the target UAV management entity (i.e., the target USS). It can be understood that there can be one or more candidate UAV management entities (i.e., candidate USSs) serving the UAV, and the target UAV management entity (i.e., the target USS) serving the UAV can be one of the one or more candidate USSs.

[0192] S102, the first unmanned aerial vehicle management entity (e.g., USS1) determines, according to the association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, whether the second unmanned aerial vehicle management entity and the unmanned aerial vehicle perform an authentication procedure or do not perform an authentication procedure.

[0193] In the embodiments of the present application, the authentication procedure can include only authentication, or authentication and authorization, for example, a UUAA procedure. The embodiments of the present application do not limit the specific implementation of the authentication procedure, for example, TLS based on digital certificates, or other manners based on pre-stored shared keys, passwords, biological information, etc. between the UAV and the USS, or in combination with TLS.

[0194] In a possible implementation, the first unmanned aerial vehicle management entity (e.g., USS1) can determine whether the second unmanned aerial vehicle management entity (e.g., USS2) and the unmanned aerial vehicle perform an authentication procedure or do not perform an authentication procedure through one or more of the following manners. It can be understood that when the second unmanned aerial vehicle management entity (e.g., USS2) and the unmanned aerial vehicle perform an authentication procedure or do not perform an authentication procedure is determined through multiple manners, the accuracy is higher, thereby improving the security.

[0195] Manner one

[0196] The first unmanned aerial vehicle management entity (e.g., USS1) can determine, according to the address information of the first unmanned aerial vehicle management entity (e.g., USS1) and the second unmanned aerial vehicle management entity (e.g., USS2), whether the second unmanned aerial vehicle management entity (e.g., USS2) and the unmanned aerial vehicle perform an authentication procedure (e.g., a UUAA procedure) or do not perform an authentication procedure. The address information can include one or more of the following: a fully qualified domain name (FQDN) or an internet protocol (IP) address.

[0197] The FQDN is a string of strings separated by “.”, for example, the FQDN as an example can be “1111.bbb.aaa”. The rightmost label (“aaa”) is usually referred to as a top-level domain, such as “aaa” being com, org, or a country domain code cn, etc. “bbb” is usually referred to as a second-level domain. The leftmost label is usually referred to as a hostname. It should be noted that the FQDN is not limited to the above three labels, for example, 1111.abc.pub.3gppnetwork.org, which is not limited in the present application.

[0198] For example, the first drone management entity is USS1 and the second drone management entity is USS2. USS1 can communicate with USS2 to obtain the FQDN of USS2. USS1 can compare whether the FQDN of USS1 and the FQDN of USS2 satisfy a preconfigured policy. When the FQDN of USS1 and the FQDN of USS2 satisfy the preconfigured policy, USS1 determines that no authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone; when the FQDN of USS1 and the FQDN of USS2 do not satisfy the preconfigured policy, USS1 determines that an authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone. For example, the preconfigured policy 1 can be that the FQDNs are the same, i.e., when the FQDN of USS1 and the FQDN of USS2 are the same, USS1 determines that no authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone. When the FQDN of USS1 and the FQDN of USS2 are not the same, USS1 determines that an authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone. For another example, the preconfigured policy 2 can be that the domain names of the FQDNs are the same, and the host names can be the same or different, which is not limited by embodiments of the present application. Or in general, the preconfigured policy can be that the rightmost N labels of the FQDNs are the same, or the rightmost N labels of the domain names are the same. N is a positive integer. For example, “1111.bbb.aaa” and “1112.bbb.aaa” are the same in the rightmost 2 labels (“bbb.aaa”), and only the host names “1111” and “1112” are different in the FQDNs; for another example, “1111.cc1.bbb.aaa” and “1113.cc2.bbb.aaa” are the same in the rightmost 2 labels (“bbb.aaa”), and only the leftmost 2 labels (“1111.cc1” and “1113.cc2”) are different in the FQDNs. That is, when the FQDN of USS1 and the FQDN of USS2 are the same in the rightmost N labels, USS1 determines that no authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone. When the FQDN of USS1 and the FQDN of USS2 are not the same in the rightmost N labels, USS1 determines that an authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone. Similarly, under the policy that the domain names are the same in the rightmost N labels, it can also be defined that no authentication procedure (e.g., UUAA procedure) or an authentication procedure (e.g., UUAA procedure) is performed between USS2 and the drone.

[0199] It can be appreciated that when the domain names of the FQDNs of two USSs are the same, it can indicate that the two USSs are under the same domain name. It can also indicate that the FQDNs of the two USSs are in the same security domain. In some implementations, it can imply that both use the same authentication server, and thus the authentication procedure can not be repeated. It can also be appreciated that when two USSs have the same FQDN, it means that they use the exact same authentication server. In some implementations, it can indicate that the two USSs use the same credential, and thus the authentication procedure can not be repeated. In other words, when the FQDNs of USS1 and USS2 are the same, or the FQDNs of USS1 and USS2 are different only in the host name (other labels are the same), the UUAA procedure can not be performed between USS2 and the drone. For example, when the FQDNs of USS1 and USS2 are completely different, or the domain names of the FQDNs of USS1 and USS2 are different, the UUAA procedure is performed between USS2 and the drone.

[0200] The IP address can be IPv4 or IPv6. Taking IPv4 as an example, the IP address can be represented as a string of four decimal numbers separated by “.”, for example, 192.168.111.111. The IP address can be logically divided into two parts, i.e., a network address and a host address. There are many logical division methods, which are not limited in the present application. For example, the first three numbers “192.168.111” of 192.168.111.0 can be taken as the network address, and the last number “111” of 0.0.0.111 can be taken as the host address.

[0201] For example, taking the first drone management entity as USS1 and the second drone management entity as USS2. USS1 can communicate with USS2 to obtain the IP address of USS2. USS1 can compare whether the IP address of itself and the IP address of USS2 satisfy a preconfigured policy. When the IP address of USS1 and the IP address of USS2 satisfy the preconfigured policy, USS1 determines that the authentication procedure (e.g., the UUAA procedure) is not performed between USS2 and the drone; when the IP address of USS1 and the IP address of USS2 do not satisfy the preconfigured policy, USS1 determines that the authentication procedure (e.g., the UUAA procedure) is performed between USS2 and the drone. Here, the preconfigured policy can be that the IP addresses are the same, or the network addresses of the IP addresses are the same. The method of determining whether the authentication procedure (e.g., the UUAA procedure) is performed or not performed between USS2 and the drone according to the policy can refer to the description for the FQDN, which will not be repeated here.

[0202] It can be understood that when the IP addresses of two USSs are the same, it can mean that they use the same address. In some implementations, this can imply that both use the same authentication server, credential, or digital certificate, etc., so that the authentication process can not be repeated. It can also be understood that when the network addresses of the IP addresses of two USSs are the same (only the host addresses are different), it means that they are under the same network domain. In some implementations, this can indicate that the two USSs are in the same security domain, or use the same authentication server, so that the authentication process can not be repeated. In other words, when the IP addresses of USS1 and USS2 are the same, or the network addresses of the IP addresses of USS1 and USS2 are the same, the UUAA process can not be performed between USS2 and the UAV. For example, when the IP addresses of USS1 and USS2 are completely different, or the network addresses of the IP addresses of USS1 and USS2 are different, the UUAA process is performed between USS2 and the UAV.

[0203] Method two

[0204] The first UAV management entity (such as USS1) can determine whether to perform an authentication process (such as a UUAA process) between the second UAV management entity (such as USS2) and the UAV according to the network information associated with the first UAV management entity (such as USS1) and the second UAV management entity (such as USS2), such as PLMN information and / or data network (DN) information. The network information can include one or more of the following: data network name (DNN), single-network slice selection assistance information (S-NSSAI), PDU session ID, or PDU session IP address, etc.

[0205] For example, assume that the first drone management entity is USS1 and the second drone management entity is USS2. USS1 can communicate with USS2 to obtain network information associated with USS2. USS1 can compare the network information associated with itself with the network information associated with USS2. When one or more of the above network information used by USS1 and USS2 are the same, it indicates that USS1 and USS2 use the same data network (DNN is the same), the same network slice (S-NSSAI is the same), or the same PDU session (PDU session identifier is the same or IP address of the PDU session is the same). In some implementations, this can indicate that the two USSs are in the same security domain or use the same authentication server, and thus the authentication procedure can not be repeated.

[0206] In other words, when the network information used by USS1 and USS2 are the same (e.g., USS1 and USS2 belong to the same data network, and / or the same network slice, and / or the same PDU session), the UUAA procedure can not be performed between USS2 and the drone. For example, when the network information used by USS1 and USS2 are not the same, the UUAA procedure is performed between USS2 and the drone.

[0207] Method three

[0208] The first drone management entity (e.g., USS1) can determine whether the authentication procedure (e.g., the UUAA procedure) is performed between the second drone management entity (e.g., USS2) and the drone based on the corresponding ATC information of the first drone management entity (e.g., USS1) and the second drone management entity (e.g., USS2). The ATC information can include one or more of the following: drone pilot information, USS operator information, and the like.

[0209] For example, assume that the first drone management entity is USS1 and the second drone management entity is USS2. USS1 can communicate with USS2 to obtain the corresponding ATC information of USS2. USS1 can compare the corresponding ATC information of itself with the corresponding ATC information of USS2. When the corresponding ATC information of USS1 and USS2 are the same, it indicates that USS1 and USS2 correspond to the same (group) pilot or belong to the same USS operator, and the like. In some implementations, this can indicate that the two USSs are in the same security domain or use the same authentication server or the same credential, and thus the authentication procedure can not be repeated.

[0210] In other words, when the one or more ATC information corresponding to USS1 and USS2 are the same (e.g., the pilot information is the same, and / or the USS operator information is the same), the UUAA procedure can not be performed between USS2 and the UAV. For example, when the ATC information corresponding to USS1 and USS2 are different, the UUAA procedure is performed between USS2 and the UAV.

[0211] Mode four

[0212] The first UAV management entity (e.g., USS1) can determine, according to a pre-configured trust relationship between the first UAV management entity (e.g., USS1) and the second UAV management entity (e.g., USS2), whether the authentication procedure (e.g., the UUAA procedure) is performed between the second UAV management entity (e.g., USS2) and the UAV.

[0213] For example, the trust relationship of the embodiments of the present application can be a trust list between USSs, which can be stored in the UDM entity or the UTM entity as subscription information. In addition, the subscription information can be verified, for example: this list can be digitally signed by the UTM entity, or USS1, or USS2, and the verifier can verify the list by the public key information of the signer.

[0214] Taking the first UAV management entity as USS1 and the second UAV management entity as USS2 as an example. USS1 can query / obtain from the UDM entity or the UTM entity whether USS2 trusts USS1. If USS1 queries that USS2 trusts USS1, USS1 determines that the authentication procedure can not be performed between USS2 and the UAV. If USS1 queries that USS2 does not trust USS1, USS1 determines that the authentication procedure needs to be performed between USS2 and the UAV.

[0215] Mode five

[0216] It is assumed that the second UAV management entity (e.g., USS2) can obtain the public key of the first UAV management entity (e.g., USS1), or the first UAV management entity (e.g., USS1) and the second UAV management entity (e.g., USS2) can pre-configure a shared key. The public key or the shared key can be used to verify whether the message sent by the first UAV management entity (e.g., USS1) to the second UAV management entity (e.g., USS2) is tampered.

[0217] The first drone management entity (e.g., USS1) can send a message to the second drone management entity (e.g., USS2), which includes the authentication result between the first drone management entity (e.g., USS1) and the drone, and digital signature information or a message authentication code (MAC). The digital signature information can be obtained by digitally signing the authentication result between the first drone management entity (e.g., USS1) and the drone using a private key of the first drone management entity (e.g., USS1). The message authentication code (MAC) can be generated based on the authentication result between the first drone management entity (e.g., USS1) and the drone and a shared key. Upon receiving the message, the second drone management entity (e.g., USS2) can verify the digital signature information in the message using the public key of the first drone management entity (e.g., USS1) obtained. Alternatively, upon receiving the message, the second drone management entity (e.g., USS2) can verify the authentication result in the message based on the shared key and the message authentication code (MAC) in the message. If the verification is passed, it indicates that the message sent by the first drone management entity to the second drone management entity is not tampered, and the second drone management entity can trust the authentication result between the first drone management entity and the drone. The second drone management entity (e.g., USS2) can send a response to the first drone management entity (e.g., USS1), which includes the verification result, or indicates whether to trust the authentication result between the first drone management entity and the drone. The first drone management entity (e.g., USS1) can determine whether to perform an authentication procedure (e.g., a UUAA procedure) between the second drone management entity (e.g., USS2) and the drone based on the received response. For example, if the verification result in the response is passed, the authentication procedure is not performed between the second drone management entity (e.g., USS2) and the drone; if the verification result in the response is failed, the authentication procedure is performed between the second drone management entity (e.g., USS2) and the drone. For another example, if the response indicates to trust the authentication result between the first drone management entity and the drone, the authentication procedure is not performed between the second drone management entity (e.g., USS2) and the drone; if the response indicates not to trust the authentication result between the first drone management entity and the drone, the authentication procedure is performed between the second drone management entity (e.g., USS2) and the drone.

[0218] Mode six

[0219] The first drone management entity (e.g., USS1) can determine whether the authentication procedure is needed between the second drone management entity (e.g., USS2) and the drone according to whether there is the subscription information of "not performing the UUAA procedure" between the second drone management entity (e.g., USS2) and the PLMN. For example, if there is the subscription information between the second drone management entity (e.g., USS2) and the PLMN, the second drone management entity (e.g., USS2) can not perform the authentication procedure in the case that the first drone management entity (i.e., serving USS) and the drone are authenticated (or the authentication information of the first drone management entity (i.e., serving USS) is in the UUAA context). It should be noted that the subscription information between the second drone management entity and the PLMN can include multiple serving drone management entities (i.e., serving USS). For example, the subscription information includes a list of serving drone management entities (i.e., serving USS) (e.g., USS1, USS1a). The second drone management entity (e.g., USS2) can not perform the authentication procedure with the drone in the case that the serving drone management entities (e.g., USS1, USS1a) in the list are authenticated (or the authentication information of the serving drone management entities is in the UUAA context). The second drone management entity (e.g., USS2) without the subscription information cannot not perform the UUAA procedure according to the subscription information. It can be understood that the subscription information between the second drone management entity and the PLMN is the subscription information of "not performing the UUAA procedure", which can indicate that the second drone management entity trusts the serving drone management entities (i.e., serving USS) included in the subscription information and the authentication results thereof.

[0220] The first drone management entity (i.e., serving USS, e.g., USS1) can query the second drone management entity or the UTM entity whether there is the subscription information between the second drone management entity and the PLMN. The first drone management entity (e.g., USS1) can determine whether the authentication procedure is needed between the second drone management entity and the drone according to whether the list of serving drone management entities (i.e., serving USS) of "not performing the UUAA procedure" included in the subscription information of the second drone management entity and the PLMN includes the first drone management entity (e.g., USS1). If there is the subscription information of "not performing the UUAA procedure" between the second drone management entity and the PLMN, the first drone management entity determines that the authentication procedure is not needed between the second drone management entity and the drone. If there is no subscription information of "not performing the UUAA procedure" between the second drone management entity and the PLMN, the first drone management entity determines that the authentication procedure is needed between the second drone management entity and the drone.

[0221] In a possible implementation, the first drone management entity (e.g., USS1) can determine the association (e.g., associated or not associated) between the first drone management entity (e.g., USS1) and the second drone management entity (e.g., USS2) by one or more of the above manners. Then, the first drone management entity (e.g., USS1) can determine whether to perform the authentication procedure between the second drone management entity (e.g., USS2) and the drone based on the association. For example, when the association is associated, the USS1 determines not to perform the authentication procedure between the USS2 and the drone; when the association is not associated, the USS1 determines to perform the authentication procedure between the USS2 and the drone.

[0222] In a possible implementation, if the first drone management entity (e.g., USS1) determines to perform the authentication procedure between the second drone management entity (e.g., USS2) and the drone, the first drone management entity can inform the drone of the information about switching to the second drone management entity, and instruct the drone to perform the authentication procedure (e.g., UUAA procedure) with the second drone management entity. When the authentication between the drone and the second drone management entity (e.g., USS2) is successful (e.g., UUAA is successful), the exposure function entity (e.g., NEF / UAS NF) can store the UUAA context, such as the identifier (e.g., GPSI and / or CAA-Level UAV ID) of the drone that successfully performs the UUAA procedure, and the identifier of the corresponding USS2. For example, the step S102 can be performed after the step 18 of the USS switching procedure shown in FIG. 3.

[0223] It can be understood that one of the necessary conditions for the USS2 to serve the drone is that there is a secure connection between the PLMN (e.g., NEF / UAS NF) and the USS2. Therefore, before the drone performs the authentication procedure with the USS2, the NEF / UAS NF or the USS1 can check whether there is a secure connection between the PLMN and the USS2. If there is no secure connection between the PLMN and the USS2, the NEF / UAS NF can first establish a secure connection with the USS2. It should be noted that the secure connection between the PLMN (e.g., NEF / UAS NF) and the USS2 can serve multiple UAVs. Therefore, in some scenarios, this condition can be met first. For example, if the USS2 is serving other UAVs through the same PLMN, the USS2 has actually established a secure connection with the PLMN (e.g., NEF / UAS NF). Therefore, checking whether there is a secure connection between the PLMN and the USS2 can also be completed by checking whether the USS2 is serving other UAVs.

[0224] In another possible implementation, if the first drone management entity (e.g., USS1) determines that the authentication procedure is not performed between the second drone management entity (e.g., USS2) and the drone, the communication method shown in FIG. 4 can further include one or more of the following steps:

[0225] At S103, the first drone management entity (e.g., USS1) sends second indication information to the exposure function entity (e.g., NEF / UAS NF). The second indication information is used to indicate that the authentication procedure is not performed between the second drone management entity and the drone.

[0226] For example, if the first drone management entity (e.g., USS1) determines that the authentication procedure is not performed between the second drone management entity (e.g., USS2) and the drone, the first drone management entity (e.g., USS1) can further inform the drone of information about switching to the second drone management entity (e.g., USS2).

[0227] In a possible implementation, the second indication information can be used to indicate that the authentication procedure is not performed between the second drone management entity (e.g., USS2) and the drone. The second indication information can be a certain message, in other words, the first drone management entity (i.e., the serving USS, such as USS1) can send a first message to the exposure function entity (e.g., NEF / UAS NF), and the first message can be used to indicate or inform that the authentication procedure is not performed between the second drone management entity (e.g., USS2) and the drone. Alternatively, the second indication information can be an information element (IE) in a message, for example, the second indication information is included in the first message. For example, the first message can include an identifier of the second drone management entity (e.g., USS2) and an identifier of the drone. Optionally, the first message can further include an identifier of the first drone management entity (e.g., USS1).

[0228] Here, the identifier of the USS (which can be USS1 or USS2) can include one or more of the following: the FQDN of the USS, the IP address of the USS, the identifier of the USS in the digital certificate used by the NEF / UAS NF and the USS to establish a secure connection (e.g., the identifier of the USS included in the digital certificate used by the USS when the NEF / UAS NF and the USS establish a TLS connection), the identifier obtained by the NEF / UAS NF through a mapping relationship when the NEF / UAS NF and the USS establish a connection, and the like. For example, one or a combination of the certificate serial number, the public key of the USS, the extension information, and the like included in the digital certificate used by the USS when the NEF and the USS establish a TLS connection can be used as the identifier of the USS. For another example, in the process of establishing a TLS connection between the UAS NF and the USS, a pre-shared key (PSK), a session identifier (ID), a random number, a key identifier, and the like can be generated or used, and the UAS NF can use one or a combination of these parameters as the identifier of the USS. The embodiments of the present application do not limit this.

[0229] The identifier of the UAV in the embodiments of the present application includes the GPSI and / or the UAV ID. It can be understood that the UAV ID is an identifier for identifying the UAV in the USS system, and the GPSI can be an identifier assigned to the UAV by the PLMN, and the GPSI corresponds to the SUPI in the PLMN. For example, here, the identifier of the UAV can include one or more of the following: UAV ID#2, GPSI#2, UAV ID#1, and GPSI#1. Wherein #2 can represent the identifier of the UAV corresponding to USS2, and #1 can represent the identifier of the UAV corresponding to USS1 (USS-specific identifier). If GPSI#1 and GPSI#2 are the same, only one GPSI can be included. Similarly, if UAV ID#1 and UAV ID#2 are the same, only one UAV ID can be included.

[0230] As an optional embodiment, in the case of the above-mentioned mode five, the above-mentioned first message (which can include the second indication information) can be sent by the second UAV management entity (such as USS2) to the open function entity (such as NEF / UAS NF). At this time, the first message can include the identifier of the first UAV management entity (such as USS1) and the identifier of the UAV. Optionally, the first message can further include one or more of the following: the identifier of the second UAV management entity (such as USS2) or the second indication information. Wherein, the description of the identifier of the USS and the identifier of the UAV is as described above, and will not be repeated here.

[0231] As another optional embodiment, the second indication information can indicate an association relationship (e.g., association or non-association) between the first UAV management entity (e.g., USS1) and the second UAV management entity (e.g., USS2). The open function entity (e.g., NEF / UAS NF) can determine, according to the association relationship being association, that the second UAV management entity (e.g., USS2) does not perform the authentication procedure with the UAV.

[0232] In a possible implementation, the first message can further include verification information. The verification information can be used to verify the authenticity of the first message or the second indication information, for example, the verification information can be signature information, or a message authentication code (MAC), or a token. Wherein, the signature information can be obtained by using the private key of the USS to digitally sign the first message (if the first message is sent by USS1, the private key of USS1 is used here; if the first message is sent by USS2, the private key of USS2 is used here). The message authentication code (MAC) can be generated using a shared key (if the first message is sent by USS1, the shared key between USS1 and NEF / UAS NF is used here; if the first message is sent by USS2, the shared key between USS2 and NEF / UAS NF is used here) and the first message. The token includes the second indication information and the digital signature of the USS (if the second indication information is sent by USS1, the USS1 is used here; if the second indication information is sent by USS2, the USS2 is used here).

[0233] Correspondingly, after receiving the first message, the open function entity (e.g., NEF / UAS NF) can first verify the authenticity of the first message according to the verification information. After verification, the open function entity (e.g., NEF / UAS NF) obtains the content contained in the first message, such as the identifier of the UAV management entity, the identifier of the UAV, or the second indication information, etc.

[0234] S104, the open function entity (e.g., NEF / UAS NF) determines, according to the second indication information, that the second UAV management entity does not perform the authentication procedure with the UAV.

[0235] In a possible implementation, the open function entity (such as the NEF / UAS NF) determines, according to the received second indication information, that the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle do not perform an authentication process (for example, a UUAA process). The open function entity (such as the NEF / UAS NF) can further store authentication information (for example, a UUAA context) between the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle. For example, the authentication information can include an identifier (such as a GPSI and / or a UAV ID) of the unmanned aerial vehicle and an identifier of the corresponding USS 2. The authentication information can indicate that the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle are successfully authenticated or do not need to be authenticated.

[0236] In a possible implementation, the open function entity (such as the NEF / UAS NF) stores an expiration time of the authentication information between the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle, which is earlier than or equal to an expiration time of the authentication information between the first unmanned aerial vehicle management entity (such as the USS 1) and the unmanned aerial vehicle.

[0237] In a possible implementation, if the second unmanned aerial vehicle management entity and the unmanned aerial vehicle do not perform the authentication process, the open function entity (such as the NEF / UAS NF) can further send third indication information to a third entity. The third indication information can be used to indicate that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, or that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is not needed. The third entity is an entity that stores the authentication result, for example, an SMF, an AMF, or a UDM entity.

[0238] In the process of switching the USS serving the UAV from the USS 1 to the USS 2, the embodiments of the present application clearly define the conditions for the USS 2 to perform the authentication process with the UAV and the conditions for the USS 2 not to perform the authentication process, reduce the security risks caused by the incorrect non-performance of the authentication process without clear judgment conditions, simplify the process, and do not introduce additional security risks, thereby improving the security and reliability of the USS switching.

[0239] Referring to FIG. 5, FIG. 5 is a second flowchart of a communication method provided by the embodiments of the present application. The method introduces another method for a serving USS to determine whether a candidate USS or a target USS and a UAV (unmanned aerial vehicle) perform a UUAA process or do not perform the UUAA process. In the method, the first unmanned aerial vehicle management entity can be the serving USS, the second unmanned aerial vehicle management entity can be the candidate USS or the target USS, and the open function entity can be the NEF or the UAS NF.

[0240] As shown in FIG. 5, the communication method includes but is not limited to the following steps:

[0241] S201, an open function entity (such as NEF / UAS NF) obtains information of a second unmanned aerial vehicle management entity.

[0242] In a possible implementation, the open function entity (such as NEF / UAS NF) can obtain the information of the second unmanned aerial vehicle management entity (such as USS2) from a first unmanned aerial vehicle management entity (that is, a serving USS such as USS1) currently serving the unmanned aerial vehicle, for example, address information of the second unmanned aerial vehicle management entity, network information (such as PLMN information and / or data network information) associated with the second unmanned aerial vehicle management entity, air traffic control information corresponding to the second unmanned aerial vehicle management entity, and the like. The second unmanned aerial vehicle management entity can be a candidate unmanned aerial vehicle management entity (that is, a candidate USS) serving the unmanned aerial vehicle, or the second unmanned aerial vehicle management entity can be a target unmanned aerial vehicle management entity (that is, a target USS) serving the unmanned aerial vehicle. For example, the NEF / UAS NF can obtain the information of USS2 through step 6 of the USS switching process shown in FIG. 3. For another example, the USS1 can also separately send a message to the NEF / UAS NF, and the message carries the address information, PLMN information, or corresponding air traffic control information of USS2.

[0243] In another possible implementation, the open function entity can also obtain the information of the second unmanned aerial vehicle management entity (such as USS2) from the second unmanned aerial vehicle management entity (such as USS2). For example, the NEF / UAS NF can obtain the information of USS2 when establishing a secure connection with USS2. For another example, the USS2 can also separately send a message to the NEF / UAS NF, and the message carries the address information, PLMN information, or corresponding air traffic control information of USS2.

[0244] The embodiments of the present application do not limit the method for the NEF / UAS NF to obtain the address information, associated network information, or corresponding air traffic control information of the second unmanned aerial vehicle management entity, and the time for obtaining the information is not limited.

[0245] The description of the address information, network information (such as PLMN information and / or data network information), and air traffic control information can be referred to the related description in the foregoing embodiment shown in FIG. 4, and will not be repeated here.

[0246] In yet another possible implementation, the open function entity can obtain the authentication information of the second unmanned aerial vehicle management entity (such as USS2) and the unmanned aerial vehicle from the stored authentication context, and the authentication information indicates that the authentication result between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful or indicates that the authentication process is not performed.

[0247] S202, the open function entity (such as NEF / UAS NF) determines whether to perform an authentication procedure between the second UAV management entity and the UAV or not.

[0248] The description about the authentication procedure can refer to the related description in the foregoing embodiment shown in FIG. 4, which will not be repeated here.

[0249] If the authentication information between the second UAV management entity and the UAV obtained by the open function entity (such as NEF / UAS NF) indicates that the authentication result of the second UAV management entity and the UAV is successful or the authentication procedure is not performed, the open function entity (such as NEF / UAS NF) can directly determine that the authentication procedure is not performed between the second UAV management entity and the UAV. Otherwise, that is, the open function entity obtains the information of the second UAV management entity from the first UAV management entity or the second UAV management entity, the open function entity (such as NEF / UAS NF) can determine whether to perform the authentication procedure between the second UAV management entity and the UAV according to the association relationship between the first UAV management entity and the second UAV management entity currently serving the UAV.

[0250] In a possible implementation manner, the open function entity (such as NEF / UAS NF) can refer to one or more of the manners one to six in the foregoing embodiment shown in FIG. 4 to determine whether to perform the authentication procedure between the second UAV management entity (such as USS2) and the UAV. For example, in the manner one, the subject in “the first UAV management entity determines whether to perform the authentication procedure between the second UAV management entity and the UAV according to the address information of the first UAV management entity and the second UAV management entity” is replaced with “the open management function”, that is, “the open management function determines whether to perform the authentication procedure between the second UAV management entity and the UAV according to the address information of the first UAV management entity and the second UAV management entity”. The other procedures and other manners are processed similarly, which will not be described here.

[0251] In a possible implementation manner, the open function entity (such as NEF / UAS NF) can also refer to one or more of the manners one to six in the foregoing embodiment shown in FIG. 4 to determine the association relationship (for example, association or non-association) between the first UAV management entity (such as USS1) and the second UAV management entity (such as USS2). Then, the open function entity (such as NEF / UAS NF) determines whether to perform the authentication procedure between the second UAV management entity (such as USS2) and the UAV according to the association relationship.

[0252] S203, the open function entity (e.g., NEF / UAS NF) sends first indication information to the first drone management entity (e.g., USS1). The first indication information is used to indicate whether the second drone management entity and the drone perform an authentication procedure or do not perform an authentication procedure.

[0253] In a possible implementation, if the open function entity (e.g., NEF / UAS NF) determines that the drone is leaving or about to leave the geographic area served by the first drone management entity (i.e., serving USS, such as USS1), the open function entity (e.g., NEF / UAS NF) can send a request to the serving USS, in which the request includes the transit point to be used by the drone or when to use the transit point, so that the serving USS can timely trigger the replacement of the USS. The request can also include the first indication information described above. For example, the request can be a Nnef_UAVFlightAssistance_Notify request.

[0254] S204, the first drone management entity (e.g., USS1) determines, according to the first indication information, whether the second drone management entity and the drone perform an authentication procedure or do not perform an authentication procedure.

[0255] In a possible implementation, if the first drone management entity (e.g., USS1) determines that the second drone management entity (e.g., USS2) and the drone perform an authentication procedure, the first drone management entity can inform the drone of information about switching to the second drone management entity, and instruct the drone to perform an authentication procedure (e.g., UUAA procedure) with the second drone management entity. When the authentication between the drone and the second drone management entity (e.g., USS2) is successful (e.g., UUAA is successful), the open function entity (e.g., NEF / UAS NF) can store the UUAA context, such as the identifier of the drone (e.g., GPSI and / or CAA-Level UAV ID) that successfully performs the UUAA procedure, and the identifier of the corresponding USS2.

[0256] In a possible implementation, if the first unmanned aerial vehicle management entity (such as the USS 1) determines that the second unmanned aerial vehicle management entity (such as the USS 2) does not perform the authentication procedure with the unmanned aerial vehicle, the first unmanned aerial vehicle management entity (that is, the serving USS, such as the USS 1) can send, to the open function entity (such as the NEF / UAS NF), an identifier of the second unmanned aerial vehicle management entity (such as the USS 2) and an identifier of the unmanned aerial vehicle. Wherein, the identifier of the USS and the identifier of the unmanned aerial vehicle are described in the foregoing related description of the embodiment shown in FIG. 4, and are not described herein. After receiving the identifier of the second unmanned aerial vehicle management entity (such as the USS 2) and the identifier of the unmanned aerial vehicle, the open function entity (such as the NEF / UAS NF) can store authentication information (for example, a UUAA context) between the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle. For example, the authentication information can include the identifier of the unmanned aerial vehicle (such as the GPSI and / or the UAV ID) and the identifier of the corresponding USS 2. The authentication information can indicate that the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle are successfully authenticated or do not need to be authenticated.

[0257] In a possible implementation, the open function entity (such as the NEF / UAS NF) stores an expiration time of the authentication information between the second unmanned aerial vehicle management entity (such as the USS 2) and the unmanned aerial vehicle, which is earlier than or equal to an expiration time of the authentication information between the first unmanned aerial vehicle management entity (such as the USS 1) and the unmanned aerial vehicle.

[0258] In a possible implementation, if the second unmanned aerial vehicle management entity (such as the USS 2) does not perform the authentication procedure with the unmanned aerial vehicle, the open function entity (such as the NEF / UAS NF) can further send third indication information to a third entity. The third indication information can be used to indicate that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, or that the second unmanned aerial vehicle management entity and the unmanned aerial vehicle do not need to be authenticated. Wherein, the third entity is an entity that stores the authentication result, for example, an SMF, an AMF, or a UDM entity.

[0259] In the process of switching the USS serving the UAV from the USS 1 to the USS 2, the embodiment of the application clearly defines the conditions for the USS 2 to perform the authentication procedure with the UAV and the conditions for not performing the authentication procedure, reduces the security risks caused by incorrectly not performing the authentication procedure without clear judgment conditions, simplifies the procedure, does not introduce additional security risks, and can improve the security and reliability of the USS switching.

[0260] As can be seen from the USS switching flow shown in FIG. 3, there are some safety problems in the scenario of switching the USS in the flight path of the UAV. For example, (1) the UAV-USS AA flow of the UAV and the target USS is performed only when the UAV flies to the boundary of the serving USS, which may cause the UAV to fail to complete the UAV-USS AA in time, resulting in a failure of the USS switching and the inability to complete the designated flight route. (2) The serving USS does not consider the safety flow (such as the UAV-USS AA flow or the authorization flow) when selecting the target USS. Since there is a possibility of failure of the UAV-USS AA flow, it may cause a failure of the USS switching and the inability to complete the designated flight route. The UAV-USS AA flow also introduces a longer time delay, which may cause the USS switching to take longer than planned, and the inability to complete the designated flight route in time according to the predetermined plan.

[0261] Based on this, the embodiment of the present application provides a communication method, which can reduce the possibility of failure of the USS switching, reduce the time delay of the USS switching, and improve the safety and reliability of the USS switching.

[0262] Referring to FIG. 6, FIG. 6 is a third flow diagram of a communication method provided by the embodiment of the present application. The method mainly introduces a method for the serving USS to determine the target USS. In the method, the first UAV management entity can be the serving USS, the second UAV management entity can be the candidate USS, and the open function entity can be the NEF or the UAS NF.

[0263] As shown in FIG. 6, the communication method includes but is not limited to the following steps:

[0264] S301, the first UAV management entity (such as USS1) currently providing service for the UAV determines that the second UAV management entity (such as USS2) is a target UAV management entity that will provide service for the UAV. Wherein, the second UAV management entity (such as USS2) and the UAV do not need to perform an authentication flow, or the authentication between the second UAV management entity (such as USS2) and the UAV is successful.

[0265] The authentication flow of the embodiment of the present application can only include authentication, or include authentication and authorization, for example, the UAV-USS AA flow. The embodiment of the present application does not limit the specific implementation manner of the authentication flow, for example, it can be based on the TLS of the digital certificate, or be implemented by using other manners based on the pre-stored shared key, password, biological information, etc. between the UAV and the USS, or in combination with the TLS.

[0266] In one possible implementation manner, before step S301, the communication method shown in FIG. 6 can further include steps 1 and 2b (and optionally step 2a) of the USS switching flow shown in FIG. 3, which is not described herein.

[0267] In a possible implementation, a serving USS (such as the USS 1) determines one or more USSs that can be used as a target USS, for ease of description, these USSs that can be used as a target USS are referred to as candidate USSs. For example, the manner in which the serving USS determines the candidate USSs herein can refer to the prior art, and the embodiments of the present application do not elaborate, for example, the serving USS can determine the candidate USSs by means outside the scope of 3GPP, which can use multiple criteria / indicators, such as the location of the next point in the flight path, the area served by a particular USS, the number of UAVs in the area served by a particular USS, proximity to a no-launch zone, USS load, and the like.

[0268] For ease of description, the list including one or more candidate USSs is referred to as a candidate entity list (or a candidate USS list) below. It can be understood that, in actual application, the one or more candidate USSs determined by the serving USS can exist in the form of a list (list), or can exist in other forms, such as a group (group); the present application is not limited. The following is described by way of example.

[0269] In a possible implementation, the first UAV management entity (that is, the serving USS, such as the USS 1) currently providing services for the UAV determines the target UAV management entity (that is, the target USS) from the candidate entity list in multiple manners. The following is discussed in different cases.

[0270] Implementation 1

[0271] In the switching process of the UAV management entity (such as the USS switching process shown in FIG. 3), the first UAV management entity (that is, the serving USS, such as the USS 1) currently providing services for the UAV can select a candidate UAV management entity (for ease of description, referred to as a second UAV management entity) from the candidate entity list W based on the information received from the exposure function entity (such as the NEF / UAS NF). The candidate entity list W includes one or more candidate UAV management entities that can be used as a target UAV management entity, that is, includes one or more candidate USSs. In the present application, the candidate entity list includes one or more candidate UAV management entities, which can be understood as including the address and / or identifier and the like of the one or more candidate UAV management entities; the following is not described one by one.

[0272] Then, the first drone management entity (e.g., USS1) can determine whether the authentication procedure needs to be performed between the second drone management entity (e.g., USS2) and the drone according to the address information of the first drone management entity (e.g., USS1) and the second drone management entity (e.g., USS2). The specific determination manner can be referred to the description of the first manner in the embodiment shown in FIG. 4, and will not be described here. Alternatively, the first drone management entity (e.g., USS1) can determine whether the authentication procedure needs to be performed between the second drone management entity (e.g., USS2) and the drone according to the network information (e.g., PLMN information and / or data network information) of the first drone management entity (e.g., USS1) and the second drone management entity (e.g., USS2). The specific determination manner can be referred to the description of the second manner in the embodiment shown in FIG. 4, and will not be described here. Alternatively, the first drone management entity (e.g., USS1) can determine whether the authentication procedure needs to be performed between the second drone management entity (e.g., USS2) and the drone according to the corresponding air traffic information of the first drone management entity (e.g., USS1) and the second drone management entity (e.g., USS2). The specific determination manner can be referred to the description of the third manner in the embodiment shown in FIG. 4, and will not be described here. The first drone management entity (e.g., USS1) can determine whether the authentication procedure needs to be performed between the second drone management entity (e.g., USS2) and the drone according to the trust relationship between the first drone management entity (e.g., USS1) and the second drone management entity (e.g., USS2). The specific determination manner can be referred to the description of the fourth or fifth manner in the embodiment shown in FIG. 4, and will not be described here. The first drone management entity (e.g., USS1) can determine whether the authentication procedure needs to be performed between the second drone management entity (e.g., USS2) and the drone according to whether there is the subscription information of “not performing the UUAA procedure” between the second drone management entity (e.g., USS2) and the PLMN. The specific determination manner can be referred to the description of the sixth manner in the embodiment shown in FIG. 4, and will not be described here. Of course, the first drone management entity (e.g., USS1) can also determine whether the authentication procedure needs to be performed between the second drone management entity (e.g., USS2) and the drone according to the combination of the above manners.

[0273] If the authentication procedure (e.g., UUAA procedure) is not needed between the second drone management entity and the drone, the first drone management entity (i.e., serving USS, such as USS1) can determine that the second drone management entity (e.g., USS2) is a target drone management entity (i.e., target USS) that will serve the drone. In addition, the first drone management entity (e.g., USS1) can also send a first message to an exposure function entity (e.g., NEF / UAS NF). The first message (or a second indication information included in the first message) is used to indicate or inform that the authentication procedure is not needed between the second drone management entity (e.g., USS2) and the drone. The first message can include an identifier of the second drone management entity (e.g., USS2) and an identifier of the drone. Optionally, the first message can also include an identifier of the first drone management entity (e.g., USS1). Upon receiving the first message, the exposure function entity (e.g., NEF / UAS NF) can store authentication information (e.g., UUAA context) between the second drone management entity (e.g., USS2) and the drone. For example, the authentication information can include the identifier of the drone (e.g., GPSI and / or UAV ID) and the identifier of the corresponding USS2. The authentication information can indicate that the authentication between the second drone management entity (e.g., USS2) and the drone is successful or not needed.

[0274] If the authentication procedure is needed between the second drone management entity and the drone, the first drone management entity (i.e., serving USS, such as USS1) can send a third message to the second drone management entity (e.g., USS2) to inform the second drone management entity (e.g., USS2) to perform the authentication procedure (e.g., UUAA procedure) with the drone. The third message can include an identifier of the drone, such as GPSI and / or UAV ID. Accordingly, upon receiving the third message, the second drone management entity (e.g., USS2) can perform the authentication procedure, such as UUAA procedure, with the drone. The embodiments of the present application do not limit the specific implementation of the authentication procedure. For example, taking the first drone management entity is USS1 and the second drone management entity is USS2 as an example. Upon receiving the third message, the USS2 can send an authentication request message to the exposure function entity (e.g., NEF / UAS NF). The authentication request message can be used to request to authenticate the drone. The authentication request message can include the identifier of the drone and optionally the identifier of the USS2. The exposure function entity (e.g., NEF / UAS NF) can determine the SMF and / or AMF, such as the SMF and / or AMF corresponding to the USS1. The exposure function entity (e.g., NEF / UAS NF) can further send an authentication request for the drone to the determined SMF and / or AMF to continue the authentication procedure between the drone and the USS2.

[0275] Alternatively, if an authentication procedure needs to be performed between the second drone management entity and the drone, the first drone management entity (i.e. a serving USS such as USS1) can send a third message to the drone for informing the drone to perform an authentication procedure (e.g. a UUAA procedure) with the second drone management entity (e.g. USS2). The third message can comprise an address of the second drone management entity (e.g. USS2). Accordingly, upon receiving the third message, the drone can initiate the authentication procedure (e.g. the UUAA procedure) with the second drone management entity. The specific implementation of the drone initiating the UUAA procedure can refer to the prior art, e.g. 3GPP standards, which will not be described in detail herein.

[0276] After the authentication between the second drone management entity and the drone is completed, the second drone management entity (e.g. USS2) or the exposure function entity (e.g. NEF / UAS NF) or the drone can send an authentication result 1 between the second drone management entity and the drone to the first drone management entity (e.g. USS1). If the authentication result 1 between the second drone management entity and the drone is successful, the first drone management entity (e.g. USS1) can determine that the second drone management entity (e.g. USS2) is a target drone management entity (i.e. target USS) that will provide services for the drone. In addition, if the authentication result 1 between the second drone management entity and the drone is successful (i.e. UUAA is successful), the exposure function entity (e.g. NEF / UAS NF) can store the authentication information (e.g. UUAA context) of the successful authentication between the drone and the second drone management entity. It can be understood that in this case, the exposure function entity (e.g. NEF / UAS NF) stores the authentication information (e.g. UUAA context) of the successful authentication between the drone and the first drone management entity and / or the authentication information (e.g. UUAA context) of the successful authentication between the drone and the second drone management entity. In other words, in the embodiments of the present application, the NEF / UAS NF can store the UUAA contexts of multiple USSs.

[0277] If the authentication result 1 between the second drone management entity and the drone is unsuccessful, the first drone management entity (e.g. USS1) can reselect a candidate drone management entity (e.g. USS3) from the candidate entity list W and re-perform the procedure of implementation manner 1 until a target drone management entity (i.e. target USS) is determined.

[0278] In some scenarios, if the authentication between the second drone management entity and the drone fails, the authentication procedure between the second drone management entity and the drone can also be re-performed according to the failure reason (e.g. password error, timeout, etc.).

[0279] Implementation manner 2

[0280] In the handover procedure of the UAV management entity (e.g., the USS handover procedure as shown in FIG. 3), the first UAV management entity (i.e., the serving USS, such as USS1) currently serving the UAV can send a candidate entity list W to the exposure function entity (e.g., NEF / UAS NF). The candidate entity list W includes one or more candidate UAV management entities that can be used as the target UAV management entity, i.e., includes one or more candidate USSs. The second UAV management entity (e.g., USS2) is included in the candidate entity list W. For example, the candidate entity list W can be carried in a request message (e.g., Nnef_UAVFlightAssistance_Get request), which can be used to collect information required for the USS handover from the core network.

[0281] In some scenarios, the first UAV management entity (e.g., USS1) can send a function indication to the exposure function entity (e.g., NEF / UAS NF) at the same time as sending the candidate entity list W. Or, the request message can also include the function indication. The function indication can be used to indicate whether there is authentication information (e.g., UUAA context) between one or more candidate UAV management entities in the candidate entity list W and the UAV. Or, the function indication is used to indicate whether it is necessary to perform an authentication procedure (e.g., UUAA procedure) between the one or more candidate UAV management entities in the candidate entity list W and the UAV.

[0282] After receiving the candidate entity list W, the open function entity (e.g., NEF / UAS NF) can query / determine whether there is authentication information (e.g., UUAA context) between each candidate drone management entity in the candidate entity list W and the drone. Alternatively, the open function entity (e.g., NEF / UAS NF) determines whether an authentication procedure (e.g., UUAA procedure) needs to be performed between one or more candidate drone management entities in the candidate entity list W and the drone. It can be understood that the open function entity (e.g., NEF / UAS NF) queries / determines whether there is authentication information between each candidate drone management entity and the drone before the first drone management entity (e.g., USS1) sends the identifier of the drone, such as GPSI and / or UAV ID, to the open function entity. Among them, if GPSI and / or UAV ID are at the USS level (or USS specific), for example, the GPSI of the same drone in candidate drone management entity i is GPSI#i, and the GPSI in candidate drone management entity j is GPSI#j; then the open function entity can first perform the mapping of GPSI and / or UAV ID between different candidate drone management entities for each candidate drone management entity. Then, the open function entity (e.g., NEF / UAS NF) queries / determines whether there is authentication information between each candidate drone management entity in the candidate entity list W and the drone. Alternatively, the open function entity (e.g., NEF / UAS NF) determines whether an authentication procedure (e.g., UUAA procedure) needs to be performed between one or more candidate drone management entities in the candidate entity list W and the drone. For specific implementation manners, please refer to the implementation manners of step S202 in the embodiment shown in FIG. 5.

[0283] The open function entity (e.g., NEF / UAS NF) can send indication information to the first drone management entity (e.g., USS1) to indicate whether there is authentication information between each candidate drone management entity and the drone in the open function entity. Alternatively, the indication information is used to indicate whether an authentication procedure (e.g., UUAA procedure) needs to be performed between each candidate drone management entity in the candidate entity list W and the drone. Among them, if there is authentication information between a certain candidate drone management entity and the drone in the open function entity, it means that the authentication procedure does not need to be performed between the candidate drone management entity and the drone. On the contrary, if there is no authentication information between a certain candidate drone management entity and the drone in the open function entity, it means that the authentication procedure needs to be performed between the candidate drone management entity and the drone.

[0284] Exemplarily, the indication information can be carried in a response message, which can be used to respond to the above-mentioned request message (e.g., Nnef_UAVFlightAssistance_Get request). It can be understood that because the second UAV management entity (e.g., USS2) is included in the candidate entity list W, there is a fourth indication information in the indication information, which is used to indicate whether there is authentication information (e.g., UUAA context) between the second UAV management entity and the UAV in the open function entity, or to indicate whether the authentication process (e.g., UUAA process) needs to be performed between the second UAV management entity and the UAV.

[0285] After receiving the indication information, the first UAV management entity (e.g., USS1) can select a target UAV management entity (i.e., target USS) from the candidate entity list W according to the indication information. Exemplarily, the first UAV management entity can select a candidate UAV management entity which has authentication information (e.g., UUAA context) with the UAV or does not need to perform the authentication process with the UAV as the target UAV management entity (i.e., target USS). If there is no authentication information (e.g., UUAA context) between all candidate UAV management entities and the UAV, or all candidate UAV management entities need to perform the authentication process, the first UAV management entity can select a candidate UAV management entity to trigger the authentication process (e.g., UUAA process) between it and the UAV, and determine it as the target UAV management entity (i.e., target USS) after the authentication result between it and the UAV is successful. For the sake of clarity, the above-mentioned process is described by taking a candidate UAV management entity (denoted as a second UAV management entity, which can also be referred to as a preselected USS) in the candidate entity list W as an example.

[0286] After the first drone management entity (e.g., USS1) receives the fourth indication information, if the fourth indication information indicates that the authentication information between the second drone management entity and the drone exists in the exposure function entity, it means that the authentication between the second drone management entity and the drone is (already) successful, and the first drone management entity can determine that the second drone management entity is the target drone management entity (i.e., target USS) that will provide services for the drone. If the fourth indication information indicates that the authentication information between the second drone management entity and the drone does not exist in the exposure function entity, the first drone management entity can determine that the authentication procedure (e.g., UUAA procedure) needs to be performed between the second drone management entity and the drone, and the first drone management entity can send a third message to the second drone management entity (e.g., USS2) or the drone to trigger the authentication procedure (e.g., UUAA procedure) between the second drone management entity and the drone, which is described in the foregoing and will not be described here. Alternatively, if the fourth indication information indicates that the authentication procedure does not need to be performed between the second drone management entity and the drone, the first drone management entity can also determine that the second drone management entity is the target drone management entity (i.e., target USS) that will provide services for the drone. If the fourth indication information indicates that the authentication procedure needs to be performed between the second drone management entity and the drone, the first drone management entity can send a third message to the second drone management entity (e.g., USS2) or the drone.

[0287] After the authentication between the second drone management entity and the drone is completed, the second drone management entity (e.g., USS2) or the exposure function entity (e.g., NEF / UAS NF) or the drone can send the authentication result 1 between the second drone management entity and the drone to the first drone management entity (e.g., USS1). If the authentication result 1 between the second drone management entity and the drone is successful, the first drone management entity (e.g., USS1) can determine that the second drone management entity (e.g., USS2) is the target drone management entity (i.e., target USS) that will provide services for the drone. In addition, if the authentication result 1 between the second drone management entity and the drone is successful (i.e., UUAA is successful), the exposure function entity (e.g., NEF / UAS NF) can store the authentication information (e.g., UUAA context) between the drone and the second drone management entity that is successfully authenticated.

[0288] If the authentication result 1 between the second drone management entity and the drone is unsuccessful, the first drone management entity (e.g., USS1) can re-determine whether there is authentication information or whether the authentication is successful between another candidate drone management entity and the drone according to the indication information from the exposure function entity until the target drone management entity (i.e., target USS) is determined.

[0289] In some scenarios, if the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle fails, the second unmanned aerial vehicle management entity and the unmanned aerial vehicle can also re-perform the authentication process according to the failure reason (such as password error, timeout, etc.).

[0290] In some scenarios, if the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle does not exist in the open function entity or the open function entity determines that the authentication process needs to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, the first unmanned aerial vehicle management entity can determine whether there is authentication information (or whether the authentication process needs to be performed) between other candidate unmanned aerial vehicle management entities in the candidate entity list W and the unmanned aerial vehicle. If there is authentication information between a certain other candidate unmanned aerial vehicle management entity and the unmanned aerial vehicle or the authentication process does not need to be performed, the first unmanned aerial vehicle management entity can determine that this other candidate unmanned aerial vehicle management entity is the target unmanned aerial vehicle management entity (i.e., the target USS). If there is no authentication information between the other candidate unmanned aerial vehicle management entities and the unmanned aerial vehicle or the authentication process needs to be performed, the first unmanned aerial vehicle management entity sends a third message to the second unmanned aerial vehicle management entity or the unmanned aerial vehicle, triggering the authentication process (such as the UUAA process) between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. For details, refer to the foregoing description, which will not be described here. If the authentication result 1 between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is a failure, the first unmanned aerial vehicle management entity (such as USS1) can reselect a candidate unmanned aerial vehicle management entity to perform the authentication process with the unmanned aerial vehicle until the target unmanned aerial vehicle management entity (i.e., the target USS) is determined.

[0291] S302, the first unmanned aerial vehicle management entity (such as USS1) sends a second message to the second unmanned aerial vehicle management entity (such as USS2), and the second message is used to request the second unmanned aerial vehicle management entity to prepare for switching the unmanned aerial vehicle management entity.

[0292] In a possible implementation, after step S302, if the open function entity (such as NEF / UAS NF) determines that the unmanned aerial vehicle is leaving or will leave the geographic area served by the first unmanned aerial vehicle management entity (i.e., the serving USS, such as USS1), the open function entity can send a request (such as Nnef_UAVFlightAssistance_Notify request) to the first unmanned aerial vehicle management entity. The request (or the fifth indication information included in the request) can be used to indicate that the service provided to the unmanned aerial vehicle by the first unmanned aerial vehicle management entity is switched to the service provided to the unmanned aerial vehicle by the second unmanned aerial vehicle management entity. The request includes the transit point to be used by the unmanned aerial vehicle or when to use the transit point, so that the first unmanned aerial vehicle management entity can timely trigger the switching of the unmanned aerial vehicle management entity.

[0293] In a possible implementation, after step S302, the communication method shown in FIG. 6 can further include steps 10 to 21 of the USS switching process shown in FIG. 3, which are not described herein again. It can be understood that, since the authentication process does not need to be performed between the target USS and the UAV, or the authentication between the target USS and the UAV has been successful, in step 20, the service USS (for example, USS1) can only inform the UAV about the information of switching to the target USS, without performing the UUAA process between the UAV and the target USS in this step.

[0294] The embodiments of the present application can reduce the possibility of USS switching failure, reduce the latency of USS switching, and improve the security and reliability of USS switching, by preferably selecting the candidate USS that does not need to perform the UUAA process or has the UUAA context as the target USS. In addition, the embodiments of the present application can perform the UUAA in advance for the candidate USS that needs to perform the UUAA process, and then select the candidate USS as the target USS after the UUAA is successful, thereby reducing the possibility of USS switching failure and improving the security and reliability of USS switching.

[0295] Referring to FIG. 7, FIG. 7 is a fourth flowchart provided by the embodiments of the present application. The method mainly introduces how to select the candidate USS. In the method, the first UAV management entity can be a service USS, and the exposure function entity can be a NEF or a UAS NF. In a possible implementation, the method can be implemented independently, or can be implemented in combination with the embodiments shown in FIG. 6. The present application does not make any limitation.

[0296] As shown in FIG. 7, the communication method includes but is not limited to the following steps:

[0297] S401, the first UAV management entity (for example, USS1) currently providing services for the UAV sends a sixth message to the exposure function entity (for example, NEF / UAS NF), and the sixth message includes a candidate entity list X.

[0298] The candidate entity list X includes one or more candidate UAV management entities that can be used as target UAV management entities. In the present application, the candidate entity list includes one or more candidate UAV management entities, which can be understood as including the address and / or identifier of the one or more candidate UAV management entities. Details are not described herein again.

[0299] In a possible implementation, before step S401, the communication method shown in FIG. 7 can further include steps 1 and 2b (and optionally step 2a) of the USS switching process shown in FIG. 3, which are not described herein again.

[0300] In a possible implementation, the first drone management entity (i.e., a serving USS such as USS1) determines one or more candidate drone management entities (e.g., candidate USSs) that can serve as the target drone management entity (e.g., a target USS). For example, the serving USS can determine the candidate USSs according to the prior art, which will not be described herein.

[0301] In a possible implementation, the candidate entity list X can include all candidate drone management entities that can serve as the target drone management entity, determined by the first drone management entity.

[0302] In another possible implementation, assume that the candidate entity list Z includes all candidate drone management entities that can serve as the target drone management entity, determined by the first drone management entity. The first drone management entity (i.e., a serving USS such as USS1) can query each candidate drone management entity or UTM entity in the candidate entity list Z, to determine whether there is subscription information between the each candidate drone management entity and the drone. The first drone management entity (e.g., USS1) can generate the candidate entity list X according to the query result. The candidate entity list X includes the candidate drone management entities that have the subscription information with the drone. For example, the first drone management entity (e.g., USS1) can remove the candidate drone management entities that do not have the subscription information from the candidate entity list Z, to obtain the candidate entity list X. The subscription information can indicate that the drone is a subscriber of the drone management entity, and the drone management entity can provide the drone with drone-related services.

[0303] It can be understood that, when querying whether there is subscription information between each candidate drone management entity and the drone, the first drone management entity (e.g., USS1) can send the identifier of the drone, such as GPSI and / or UAV ID, to each candidate drone management entity or UTM entity. If the GPSI and / or UAV ID is USS-level (or USS specific), each candidate drone management entity or UTM entity can need to know the mapping relationship between the GPSI and / or UAV ID and different candidate drone management entities in advance.

[0304] In yet another possible implementation, the candidate entity list Z includes all candidate UAV management entities determined by the first UAV management entity that can be used as the target UAV management entity. The first UAV management entity (i.e., the serving USS such as USS1) can determine whether an authentication procedure (e.g., a UUAA procedure) needs to be performed between each candidate UAV management entity in the candidate entity list Z and the UAV. The determination can be made according to any one or more of the above-described manners one to six in the embodiment shown in FIG. 4. The first UAV management entity (e.g., USS1) can generate the candidate entity list X according to whether an authentication procedure needs to be performed between each candidate UAV management entity and the UAV. The candidate entity list X includes the candidate UAV management entities that do not need to perform an authentication procedure with the UAV. For example, the first UAV management entity (e.g., USS1) can remove the candidate UAV management entities that need to perform an authentication procedure with the UAV from the candidate entity list Z to obtain the candidate entity list X.

[0305] In yet another possible implementation, the first UAV management entity (e.g., USS1) can also determine whether an authentication procedure needs to be performed between each candidate UAV management entity (e.g., USS2, USS3) and the UAV according to whether there is subscription information of “not performing a UUAA procedure” between each candidate UAV management entity and the PLMN, and generate the candidate entity list X. The candidate entity list X includes the candidate UAV management entities that do not need to perform an authentication procedure with the UAV. For example, assume that there is subscription information between some candidate UAV management entities (e.g., USS2) and the PLMN, which indicates that the candidate UAV management entity (e.g., USS2) can not perform an authentication procedure with the UAV if the serving UAV management entity (i.e., the serving USS) and the UAV are authenticated (or there is authentication information of the serving UAV management entity (i.e., the serving USS) in a UUAA context). It should be noted that the subscription information between the candidate UAV management entity and the PLMN can include multiple serving UAV management entities (i.e., serving USS). For example, the subscription information includes a list of serving UAV management entities (i.e., serving USS) (e.g., USS1, USS1a). If the serving UAV management entity (e.g., USS1, USS1a) in the list and the UAV are authenticated (or there is authentication information of the serving UAV management entity in a UUAA context), the candidate UAV management entity (e.g., USS2) can not perform an authentication procedure with the UAV. The candidate UAV management entity (e.g., USS3) without the subscription information cannot not perform a UUAA procedure according to the subscription information. It can be understood that the subscription information between the candidate UAV management entity and the PLMN is the subscription information of “not performing a UUAA procedure”, which indicates that the candidate UAV management entity trusts the serving UAV management entities (i.e., the serving USS) included in the subscription information and the authentication results of the serving UAV management entities.

[0306] The first drone management entity (i.e. serving USS, such as USS1) can query each candidate drone management entity or UTM entity in the candidate entity list Z about whether there is subscription information between the each candidate drone management entity and the PLMN. The first drone management entity (such as USS1) can generate the candidate entity list X according to the query result, i.e. whether the list of serving drone management entities (i.e. serving USS) included in the subscription information of each candidate drone management entity and the PLMN includes the first drone management entity (such as USS1) includes the first drone management entity (such as USS1). For example, the first drone management entity (such as USS1) can exclude the candidate drone management entity (such as USS3) which requires the drone to perform the authentication procedure from the candidate entity list Z to obtain the candidate entity list X.

[0307] In some scenarios, the first drone management entity (such as USS1) can also exclude the candidate drone management entity without querying the subscription information and / or the candidate drone management entity which requires the drone to perform the authentication procedure from the candidate entity list Z to obtain the candidate entity list X.

[0308] In a possible implementation, the sixth message described above can be used to obtain the drone management entity meeting the condition in the candidate entity list X. For example, the sixth message can be a request message (such as Nnef_UAVFlightAssistance_Get request), which can also be used to collect information required for the drone management entity (such as USS) switching from the core network.

[0309] For example, the sixth message can also include indication information a, which can be used to indicate that the "flight assistance" procedure is only performed for the candidate drone management entity (such as candidate USS) having the subscription information with the drone. Wherein the description of the "flight assistance" procedure can refer to the prior art, such as 3GPP standard, which is not described in detail here.

[0310] In a possible implementation, the sixth message can further include indication information b, and security verification information of each candidate drone management entity in the candidate entity list X, for example, a token, or a digital signature, or a message authentication code (MAC). The indication information b can be used to indicate that the authentication process is not performed between the drone and each candidate drone management entity in the candidate entity list X. The candidate entity list X includes candidate drone management entities that do not need to perform the authentication process with the drone. If the security verification information is a token, the claim of the token can include to-be-verified information, such as the indication information b. If the security verification information is a digital signature, the digital signature is a signature of to-be-verified information, such as at least the indication information b. If the security verification information is a message authentication code (MAC), the generation parameter of the message authentication code includes at least to-be-verified information, such as the indication information b.

[0311] The security verification information is generated or issued by each candidate drone management entity in the candidate entity list X, and optionally, the security verification information can also be generated or issued by the UTM entity. The first drone management entity (for example, the USS 1) obtains the security verification information issued by each candidate drone management entity or the UTM entity from the candidate drone management entity or the UTM entity.

[0312] In S402, the open function entity (for example, the NEF / UAS NF) determines the qualified drone management entity and / or the unqualified drone management entity.

[0313] In a possible implementation, the open function entity (for example, the NEF / UAS NF) can determine the qualified drone management entity and / or the unqualified drone management entity from the candidate entity list X. The qualified drone management entity can be: a drone management entity that has subscription information with the drone, a drone management entity that has subscription information of "not performing the UUAA process" with the PLMN, or a drone management entity that passes the security verification. The following cases are discussed.

[0314] 1. The qualified drone management entity is a drone management entity that has subscription information with the drone.

[0315] In a possible implementation, the UDM entity can pre-store subscription information between a UAV and a UAV management entity (e.g., a USS). After receiving the sixth message, the exposure function entity (e.g., a NEF / UAS NF) can query the UDM entity about whether there is subscription information between each candidate UAV management entity in the candidate entity list X and the UAV. For example, the exposure function entity sends an information query request to the UDM entity, to query whether there is subscription information between each candidate UAV management entity in the candidate entity list X and the UAV. The UDM entity sends an information query response to the exposure function entity, and the information query response is used to indicate whether there is subscription information between each candidate UAV management entity and the UAV. According to the information query response, the exposure function entity can determine the qualified UAV management entity (e.g., a USS). Correspondingly, the exposure function entity can also determine the unqualified UAV management entity (e.g., a USS) according to the information query response. The candidate UAV management entity (e.g., a candidate USS) that has subscription information (e.g., the UDM entity stores subscription information with the UAV) is the qualified UAV management entity. The candidate UAV management entity (e.g., a candidate USS) that does not have subscription information (e.g., the UDM entity does not store subscription information with the UAV) is the unqualified UAV management entity.

[0316] It can be understood that, before querying the UDM entity about whether there is subscription information between each candidate UAV management entity and the UAV, the exposure function entity or the UDM entity can obtain the identifier of the UAV, for example, the GPSI and / or the UAV ID. If the GPSI and / or the UAV ID is at the USS level (or USS specific), the exposure function entity or the UDM entity can store the mapping relationship between the GPSI and / or the UAV ID and different candidate UAV management entities.

[0317] In a possible implementation, if the indication information a is included in the sixth message, after determining the qualified UAV management entity, the exposure function entity can perform the flight assistance procedure for the qualified UAV management entity.

[0318] In the prior art, the UUAA between the USS and the UAV can fail because the UAV is not subscribed to the USS, so the embodiment of the present application can filter the USS according to whether there is subscription information between the USS and the UAV, to reduce the possibility of UUAA failure.

[0319] 2. The qualified UAV management entity is a UAV management entity that has subscription information of "not performing the UUAA procedure" with the PLMN.

[0320] In a possible implementation, the UDM entity can pre-store subscription information between an operator network (such as a PLMN) and a UAV management entity (such as a USS). The subscription information can indicate that, in a case where a serving UAV management entity (that is, a serving USS) and a UAV pass authentication (or the UUAA context has authentication information of the serving UAV management entity), a subscribed UAV management entity can not perform an authentication procedure. In the subscription information, each subscribed UAV management entity (such as a candidate USS) corresponds to one or more serving UAV management entities (that is, a serving USS), and when a serving UAV management entity (such as USS1) in the one or more serving UAV management entities and the UAV pass authentication (or the UUAA context has authentication information of the serving UAV management entity), the subscribed UAV management entity (such as candidate USS2) can not perform an authentication procedure with the UAV.

[0321] After receiving the sixth message, the open function entity (such as a NEF / UAS NF) can query the UDM entity about whether there is subscription information of "not performing a UUAA procedure" between each candidate UAV management entity in the candidate entity list X and the PLMN. For example, the open function entity sends an information query request to the UDM entity, to query the subscription information between each candidate UAV management entity in the candidate entity list X and the PLMN, and the information query request further includes the identifier of the first UAV management entity. The UDM entity sends an information query response to the open function entity, to indicate whether there is subscription information of "not performing a UUAA procedure" between each candidate UAV management entity and the PLMN. The open function entity can determine the UAV management entity (such as a USS) that meets the condition (that is, there is subscription information of "not performing an authentication procedure" between the PLMN) according to the information query response. Accordingly, the open function entity can also determine the candidate UAV management entity (such as a candidate USS) in the candidate entity list X that does not meet the condition (that is, there is no subscription information of "not performing an authentication procedure" between the PLMN) according to the information query response.

[0322] In a possible implementation, if the indication information a is included in the sixth message, the open function entity can perform a "flight assistance" procedure for the UAV management entities that meet the condition after determining the UAV management entities that meet the condition.

[0323] In the prior art, the UUAA between the USS and the UAV can fail because the UAV is not subscribed to the USS, and therefore, the embodiments of the present application can filter the USS according to whether there is subscription information between the USS and the UAV, to reduce the possibility of UUAA failure.

[0324] 3. The UAV management entity that meets the condition is a UAV management entity that passes security verification.

[0325] In a possible implementation, the sixth message further includes indication information b, and security verification information of each candidate drone management entity in the candidate entity list X, such as Token, digital signature, or MAC. The indication information b can be used to indicate that the authentication procedure is not performed between the drone and each candidate drone management entity in the candidate entity list X. The candidate entity list X includes candidate drone management entities that do not need to perform the authentication procedure with the drone.

[0326] The UDM entity can pre-store information for verifying each candidate drone management entity (such as a candidate USS), such as a key (which can include a public key used to verify Token or digital signature, or a shared key used to verify MAC) of each candidate drone management entity (such as a candidate USS) or the UTM entity, an identifier of each candidate drone management entity (such as a candidate USS), or an identifier of the UTM entity. After receiving the sixth message, if the open function entity (such as the NEF / UAS NF) does not store the information for verifying the candidate drone management entity, the open function entity can send an information obtaining request to the UDM entity, and the information obtaining request can be used to request information for verifying the candidate drone management entity. The UDM entity sends an information obtaining response to the open function entity, and the information obtaining response includes the information for verifying the candidate drone management entity. The open function entity can perform security verification on the security verification information of each candidate drone management entity according to the information obtained from the UDM entity (for example, the key of each candidate drone management entity or the UTM entity, or the identifier of each candidate drone management entity). The open function entity can determine that the candidate drone management entity that passes the security verification is a qualified drone management entity. Correspondingly, the open function entity can also determine that the candidate drone management entity that fails the security verification is an unqualified drone management entity. Alternatively, the open function entity can determine that the candidate drone management entity that passes the security verification can not perform the authentication procedure. Correspondingly, the open function entity can also determine that the candidate drone management entity that fails the security verification does not meet the condition of not performing the authentication procedure.

[0327] In a possible implementation, if the sixth message includes the indication information a, the open function entity can perform the flight assistance procedure for the qualified drone management entities after determining the qualified drone management entities.

[0328] In a possible implementation, after determining the qualified UAV management entity, the open function entity can further send a seventh message to a third entity. The seventh message can be used to update or add the authentication result between the qualified UAV management entity and the UAV. The authentication result is that the qualified UAV management entity and the UAV are authenticated successfully again for the flight without authentication. For example, the third entity can be an entity that stores the authentication result, such as an SMF or an AMF. Then, when the SMF or the AMF receives a new authentication request initiated by the UAV, the SMF or the AMF can perform no authentication process according to the stored authentication result.

[0329] In S403, the open function entity (such as an NEF / UAS NF) sends a fifth message to the first UAV management entity (such as an USS1). The fifth message is used to indicate the qualified UAV management entity and / or the unqualified UAV management entity.

[0330] In S404, the first UAV management entity (such as an USS1) obtains a candidate entity list Y according to the fifth message. The candidate entity list Y includes the qualified UAV management entity. The candidate entity list Y is a subset of the candidate entity list X.

[0331] In a possible implementation, the fifth message can include indication information c, which can be used to indicate the qualified UAV management entity and / or the unqualified UAV management entity. After receiving the fifth message, the first UAV management entity (such as an USS1) can determine the candidate entity list Y from the candidate entity list X according to the indication of the indication information c. For example, if the indication information c indicates the qualified UAV management entity, the first UAV management entity can take the UAV management entity indicated by the indication information c in the candidate entity list X as the candidate entity list Y. If the indication information c indicates the unqualified UAV management entity, the first UAV management entity can exclude the UAV management entity indicated by the indication information c from the candidate entity list X to obtain the candidate entity list Y.

[0332] In another possible implementation, the fifth message can include a candidate entity list Q, which can include the qualified UAV management entity or the unqualified UAV management entity. If the candidate entity list Q includes the qualified UAV management entity, the first UAV management entity (such as an USS1) can directly take the candidate entity list Q as the candidate entity list Y after receiving the fifth message. If the candidate entity list Q includes the unqualified UAV management entity, the first UAV management entity (such as an USS1) can take the difference set between the candidate entity list X and the candidate entity list Q as the candidate entity list Y.

[0333] In a possible implementation, after obtaining the candidate entity list Y, the first UAV management entity (i.e., the serving USS) can select a target UAV management entity (i.e., the target USS) from the candidate entity list Y. Then, the first UAV management entity (i.e., the serving USS) can communicate with the target UAV management entity (i.e., the target USS) to request the target UAV management entity (i.e., the target USS) to prepare for the UAV management entity (USS) switching.

[0334] In a possible implementation, when the embodiment of the present application is combined with the embodiment shown in the foregoing FIG. 6, the candidate entity list W in the foregoing FIG. 6 is the same as the candidate entity list Y of the embodiment of the present application, or the candidate entity list W and the candidate entity list Y are the same list. It can be understood that when the embodiment of the present application is combined with the embodiment shown in the foregoing FIG. 6, the implementation manner 1 of the embodiment shown in the foregoing FIG. 6 and the implementation manner of the embodiment of the present application that "the first UAV management entity generates a candidate entity list X according to whether each candidate UAV management entity needs to perform an authentication process with the UAV" can be executed alternatively.

[0335] In a possible implementation, after the first UAV management entity (i.e., the serving USS) determines the target UAV management entity (i.e., the target USS), the communication method shown in FIG. 7 can further include steps 10 to 21 of the USS switching process shown in the foregoing FIG. 3, which are not described herein again.

[0336] The embodiment of the present application can reduce the number of pre-flight preparation processes performed by the PLMN network for the USS switching, reduce the network resource consumption, and reduce the possibility of UUAA failure between the subsequent UAV and the target USS, thereby reducing the possibility of USS switching failure, improving the security and reliability of the USS switching.

[0337] The foregoing describes the method of the present application in detail, and the embodiment of the present application further provides a corresponding device or equipment for better implementing the foregoing scheme of the embodiment of the present application.

[0338] The embodiments of the present application can divide the functions of each entity of the present application according to the above method examples, and divide the functions of the above entities according to the above method examples. For example, each function module can be divided according to each function, or two or more functions can be integrated into one processing module. The integrated module can be realized in the form of hardware or in the form of a software function module. It should be noted that the division of the modules in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, another division method can be used. The communication device of the embodiments of the present application will be described in detail below with reference to FIGS. 8 to 10.

[0339] Referring to FIG. 8, FIG. 8 is a structural schematic diagram of a communication device provided by an embodiment of the present application. As shown in FIG. 8, the communication device includes a transceiver module 10 and a processing module 20. The transceiver module 10 can realize corresponding communication functions, and the processing module 20 is configured to perform data processing. The transceiver module 10 can also be referred to as a communication interface or a communication unit, etc.

[0340] In some embodiments of the present application, the communication device can be the first unmanned aerial vehicle management entity shown above. That is, the communication device shown in FIG. 8 can be used to perform the steps or functions performed by the first unmanned aerial vehicle management entity in the above method embodiments. For example, the communication device can be a chip or a function module in the first unmanned aerial vehicle management entity, and the embodiments of the present application do not limit this. The transceiver module 10 is configured to perform the operations related to the transceiving of the first unmanned aerial vehicle management entity in the above method embodiments, and the processing module 20 is configured to perform the operations related to the processing of the first unmanned aerial vehicle management entity in the above method embodiments.

[0341] In one design, the processing module 20 is configured to determine a candidate second unmanned aerial vehicle management entity for providing services for the unmanned aerial vehicle. The processing module 20 is further configured to determine, according to the first indication information and / or the association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, whether to perform an authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle. The transceiver module 10 is configured to receive the first indication information from the open function entity, and the first indication information is used to indicate whether to perform the authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle.

[0342] The processing module 20 is further configured to determine whether the second UAV management entity and the UAV perform the authentication procedure or do not perform the authentication procedure according to one or more of the following information: address information of the first UAV management entity and the second UAV management entity, network information of the first UAV management entity and the second UAV management entity, air traffic control information corresponding to the first UAV management entity and the second UAV management entity, or a pre-configured trust relationship between the first UAV management entity and the second UAV management entity.

[0343] The second UAV management entity is a target UAV management entity that provides services for the UAV.

[0344] The transceiver module 10 is further configured to send second indication information to the exposure function entity when the first UAV management entity determines that the second UAV management entity and the UAV do not perform the authentication procedure according to the association relationship. The second indication information is used to indicate that the second UAV management entity and the UAV do not perform the authentication procedure.

[0345] The transceiver module 10 is further configured to send a first message to the exposure function entity. The first message includes an identifier of the second UAV management entity, an identifier of the UAV, and verification information. The verification information is used to verify the authenticity of the first message.

[0346] In the embodiments of the present application, the specific descriptions of various indication information, association relationship, authentication procedure, first message, and the like can refer to the method embodiments shown in FIG. 4 or FIG. 5, and will not be repeated here.

[0347] It can be understood that the specific descriptions of the transceiver module and the processing module shown in the embodiments of the present application are only examples. For the specific functions or steps of the transceiver module and the processing module, the method embodiments shown in FIG. 4 or FIG. 5 can be referred to, and will not be described here. In addition, the technical effects of the embodiments of the present application refer to the technical effects of the method embodiments shown in FIG. 4 or FIG. 5, and will not be described here for brevity.

[0348] In another design, the processing module 20 is configured to determine that the second UAV management entity is a target UAV management entity that provides services for the UAV when it is determined that the second UAV management entity and the UAV do not need to perform the authentication procedure or when it is determined that the authentication between the second UAV management entity and the UAV is successful. The transceiver module 10 is configured to send a second message to the second UAV management entity. The second message is used to request the second UAV management entity to prepare for switching the UAV management entity.

[0349] Exemplarily, the processing module 20 is further configured to determine that the authentication procedure between the second UAV management entity and the UAV is not needed according to one or more of the following information: address information of the first UAV management entity and the second UAV management entity, network information of the first UAV management entity and the second UAV management entity, air traffic control information corresponding to the first UAV management entity and the second UAV management entity, or a pre-configured trust relationship between the first UAV management entity and the second UAV management entity.

[0350] Exemplarily, the processing module 20 is further configured to control the transceiver module 10 to receive fourth indication information from the open function entity, the fourth indication information being used to indicate whether there is authentication information between the second UAV management entity and the UAV in the open function entity; and the processing module 20 is further configured to determine that the authentication between the second UAV management entity and the UAV is successful when there is authentication information between the second UAV management entity and the UAV in the open function entity.

[0351] Exemplarily, the processing module 20 is further configured to determine that the authentication procedure between the second UAV management entity and the UAV is needed. The processing module 20 is further configured to control the transceiver module 10 to send a third message to the second UAV management entity, the third message being used to notify the second UAV management entity to perform the authentication procedure with the UAV, the third message including an identifier of the UAV. Alternatively, the processing module 20 is further configured to control the transceiver module 10 to send a third message to the UAV, the third message being used to notify the UAV to perform the authentication procedure with the second UAV management entity, the third message including an address of the second UAV management entity. The processing module 20 is further configured to control the transceiver module 10 to receive a first authentication result between the second UAV management entity and the UAV; and when the first authentication result is successful, the processing module 20 is further configured to determine that the authentication between the second UAV management entity and the UAV is successful.

[0352] Exemplarily, the transceiver module 10 is further configured to receive fifth indication information, the fifth indication information being used to indicate that the service provided from the first UAV management entity to the UAV is switched to the service provided from the second UAV management entity to the UAV.

[0353] Exemplarily, the processing module 20 is further configured to determine that an authentication procedure needs to be performed between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle; the transceiver 10 is further configured to send a fourth message to the fourth unmanned aerial vehicle management entity, the fourth message being used to inform the fourth unmanned aerial vehicle management entity to perform the authentication procedure between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle, the fourth message comprising an identifier of the unmanned aerial vehicle; or, the transceiver 10 is further configured to send a fourth message to the unmanned aerial vehicle, the fourth message being used to inform the unmanned aerial vehicle to perform the authentication procedure between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle, the fourth message comprising an address of the fourth unmanned aerial vehicle management entity; and the transceiver 10 is further configured to receive a second authentication result between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle, the second authentication result being a failure.

[0354] Exemplarily, the first subscription information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle indicates that the unmanned aerial vehicle is a subscription user of the second unmanned aerial vehicle management entity.

[0355] Exemplarily, the transceiver 10 is further configured to receive a fifth message from the opening function entity, the fifth message being used to indicate the qualified unmanned aerial vehicle management entity and / or the unqualified unmanned aerial vehicle management entity, the qualified unmanned aerial vehicle management entity comprising: the unmanned aerial vehicle management entity having the first subscription information with the unmanned aerial vehicle, and / or the unmanned aerial vehicle management entity passing the security verification; and the processing module 20 is further configured to obtain a first candidate entity list, the first candidate entity list comprising the qualified unmanned aerial vehicle management entity, the first candidate entity list comprising the second unmanned aerial vehicle management entity.

[0356] Exemplarily, the transceiver 10 is further configured to send a sixth message to the opening function entity, the sixth message comprising a second candidate entity list, the second candidate entity list comprising one or more candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle, the sixth message being used to obtain the qualified unmanned aerial vehicle management entity in the second candidate entity list.

[0357] Exemplarily, the sixth message further comprises security verification information of each unmanned aerial vehicle management entity in the second candidate entity list.

[0358] Exemplarily, the processing module 20 is further configured to determine a third candidate entity list, the third candidate entity list comprising a plurality of candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle; the processing module 20 is further configured to query whether second subscription information exists between each unmanned aerial vehicle management entity in the third candidate entity list and the unmanned aerial vehicle; and the processing module 20 is further configured to obtain a fourth candidate entity list, the fourth candidate entity list comprising the unmanned aerial vehicle management entity having the second subscription information with the unmanned aerial vehicle, the fourth candidate entity list comprising the second unmanned aerial vehicle management entity.

[0359] In the embodiments of this application, the specific description of each indication information, the association relationship, the authentication process, the second message, the third message, the fourth message, the fifth message, the sixth message and the like can refer to the method embodiments shown in FIG. 6 or FIG. 7, which will not be repeated here.

[0360] It can be understood that the specific description of the transceiver module and the processing module shown in the embodiments of this application is only an example. For the specific functions or steps of the transceiver module and the processing module, etc., it can be referred to the method embodiments shown in FIG. 6 or FIG. 7, which will not be described here. In addition, the technical effects of the embodiments of this application refer to the technical effects in the method embodiments shown in FIG. 6 or FIG. 7. For the sake of brevity, it will not be described here.

[0361] In another embodiment of the application, the communication device shown in FIG. 8 can be the open function entity shown above. That is, the communication device shown in FIG. 8 can be used to perform the steps or functions performed by the open function entity in the above method embodiments. For example, the communication device can be an open function entity or a chip or functional module configured in the open function entity, etc. The embodiments of this application do not limit this. The transceiver module 10 is used to perform the operations related to the transceiving of the open function entity in the above method embodiments, and the processing module 20 is used to perform the operations related to the processing of the open function entity in the above method embodiments.

[0362] In one design, the processing module 20 is configured to obtain information of a second unmanned aerial vehicle management entity, the second unmanned aerial vehicle management entity being a candidate unmanned aerial vehicle management entity for providing services to the unmanned aerial vehicle. The processing module 20 is further configured to determine whether to perform an authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle according to second indication information and / or an association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity. The first unmanned aerial vehicle management entity is a current unmanned aerial vehicle management entity for providing services to the unmanned aerial vehicle. The transceiver module 10 is configured to receive the second indication information from the first unmanned aerial vehicle management entity or the second unmanned aerial vehicle management entity. The second indication information is used to indicate that the authentication process is not performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle.

[0363] For example, the processing module 20 is further configured to determine whether to perform the authentication process between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle according to one or more of the following information: address information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, network information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, air traffic control information corresponding to the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, or a pre-configured trust relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity.

[0364] For example, the second unmanned aerial vehicle management entity is a target unmanned aerial vehicle management entity that will provide services to the unmanned aerial vehicle.

[0365] The processing module 20 is further configured to store the authentication information between the second UAV management entity and the UAV, when the authentication procedure is not performed between the second UAV management entity and the UAV, the authentication information indicating that the second UAV management entity and the UAV are authenticated successfully or do not need to be authenticated.

[0366] The authentication information between the second UAV management entity and the UAV has an expiration deadline earlier than or equal to the expiration deadline of the authentication information between the first UAV management entity and the UAV.

[0367] The transceiver module 10 is further configured to send first indication information to the first UAV management entity, the first indication information indicating whether the authentication procedure is performed between the second UAV management entity and the UAV or not.

[0368] The processing module 20 is further configured to control the transceiver module 10 to receive a first message from the first UAV management entity, the first message including an identifier of the second UAV management entity, an identifier of the UAV, and verification information for verifying authenticity of the first message; the processing module 20 is further configured to verify authenticity of the first message according to the verification information; and the processing module 20 is further configured to obtain the identifier of the second UAV management entity when the first message is verified.

[0369] The transceiver module 10 is further configured to send third indication information to a third entity, when the authentication procedure is not performed between the second UAV management entity and the UAV, the third indication information indicating that the authentication result between the second UAV management entity and the UAV is successful or indicating that the second UAV management entity and the UAV do not need to be authenticated, the third entity being an entity that stores the authentication result.

[0370] In the embodiments of the present application, the specific description of each indication information, the association relationship, the authentication procedure, the first message, and the like can refer to the method embodiments shown in FIG. 4 or FIG. 5, which will not be repeated here.

[0371] It can be understood that the specific description of the transceiver module and the processing module shown in the embodiments of the present application is only an example, and the specific functions or steps of the transceiver module and the processing module can refer to the method embodiments shown in FIG. 4 or FIG. 5, which will not be repeated here. In addition, the technical effects of the embodiments of the present application refer to the technical effects of the method embodiments shown in FIG. 4 or FIG. 5, which will not be repeated here for brevity.

[0372] In another design, the processing module 20 is configured to obtain information of a second UAV management entity, the second UAV management entity being a candidate UAV management entity for providing service to the UAV; and the transceiver 10 is configured to send fourth indication information to a first UAV management entity currently providing service to the UAV, the fourth indication information being used to indicate whether there is authentication information between the second UAV management entity and the UAV in the open function entity.

[0373] In an example, the transceiver 10 is further configured to receive an authentication request message from the second UAV management entity, the authentication request message being used to request to authenticate the UAV, the authentication request message including an identifier of the UAV; the transceiver 10 is further configured to send a first authentication result between the second UAV management entity and the UAV; and the processing module 20 is further configured to, when the first authentication result is successful, store authentication information between the second UAV management entity and the UAV.

[0374] In an example, the transceiver 10 is further configured to send fifth indication information to the first UAV management entity, the fifth indication information being used to indicate switching from the first UAV management entity to the second UAV management entity to provide service to the UAV.

[0375] In an example, the transceiver 10 is further configured to receive an authentication request message from the fourth UAV management entity, the authentication request message being used to request to authenticate the UAV, the authentication request message including an identifier of the UAV; the transceiver 10 is further configured to send a second authentication result between the fourth UAV management entity and the UAV, the second authentication result being failed.

[0376] In an example, there is first subscription information between the second UAV management entity and the UAV, the first subscription information indicating that the UAV is a subscription user of the second UAV management entity.

[0377] In an example, the processing module 20 is further configured to determine a qualified UAV management entity and / or an unqualified UAV management entity, the qualified UAV management entity including: a UAV management entity having first subscription information with the UAV, and / or a UAV management entity passing security verification; the first subscription information indicating that the UAV is a subscription user of the UAV management entity; and the qualified UAV management entity including the second UAV management entity; and the transceiver 10 is further configured to send a fifth message to the first UAV management entity, the fifth message being used to indicate the qualified UAV management entity and / or the unqualified UAV management entity.

[0378] Exemplarily, the transceiver module 10 is further configured to receive a sixth message from the first unmanned aerial vehicle management entity, the sixth message comprising a second candidate entity list, the second candidate entity list comprising one or more candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle, and the sixth message being used to obtain a qualified unmanned aerial vehicle management entity in the second candidate entity list.

[0379] Exemplarily, the qualified unmanned aerial vehicle management entity comprises an unmanned aerial vehicle management entity having first subscription information with the unmanned aerial vehicle. The processing module 20 is further configured to control the transceiver module 10 to send an information query request to the UDM entity, the information query request being used to query whether the first subscription information exists between each unmanned aerial vehicle management entity in the second candidate entity list and the unmanned aerial vehicle; the processing module 20 is further configured to control the transceiver module 10 to receive an information acquisition response from the UDM entity, the information acquisition response being used to indicate whether the first subscription information exists between the each unmanned aerial vehicle management entity and the unmanned aerial vehicle; and the processing module 20 is further configured to determine the qualified unmanned aerial vehicle management entity and / or determine an unqualified unmanned aerial vehicle management entity according to the information acquisition response.

[0380] Exemplarily, the sixth message further comprises security verification information of each unmanned aerial vehicle management entity in the second candidate entity list. The qualified unmanned aerial vehicle management entity comprises an unmanned aerial vehicle management entity that passes security verification. The processing module 20 is further configured to control the transceiver module 10 to send an information acquisition request to the UDM entity, the information acquisition request being used to request information for verifying each unmanned aerial vehicle management entity; the processing module 20 is further configured to control the transceiver module 10 to receive an information acquisition response from the UDM entity, the information acquisition response comprising the information for verifying each unmanned aerial vehicle management entity; the processing module 20 is further configured to respectively perform security verification on the security verification information of each unmanned aerial vehicle management entity according to the information for verifying each unmanned aerial vehicle management entity; and the processing module 20 is further configured to determine that an unmanned aerial vehicle management entity that passes the security verification is the qualified unmanned aerial vehicle management entity, and / or determine that an unmanned aerial vehicle management entity that fails the security verification is the unqualified unmanned aerial vehicle management entity.

[0381] Exemplarily, the transceiver module 10 is further configured to send a seventh message to a third entity, the seventh message being used to update or add an authentication result between the qualified unmanned aerial vehicle management entity and the unmanned aerial vehicle, the authentication result being that the qualified unmanned aerial vehicle management entity and the unmanned aerial vehicle are exempted from authentication again after successfully authenticating each other. The third entity is an entity that stores the authentication result.

[0382] In the embodiments of the present application, the specific description of each indication information, the association relationship, the authentication process, the second message, the third message, the fourth message, the fifth message, the sixth message, the seventh message and the like can refer to the method embodiments shown in FIG. 6 or FIG. 7, and will not be repeated here.

[0383] It can be understood that the specific description of the transceiver module and the processing module shown in the embodiments of the present application is only an example. For the specific functions or executed steps of the transceiver module and the processing module, it can be referred to the method embodiments shown in FIG. 6 or FIG. 7, and will not be described here. In addition, the technical effects of the embodiments of the present application refer to the technical effects in the method embodiments shown in FIG. 6 or FIG. 7. For brevity, it will not be described here.

[0384] The communication device of the embodiments of the present application is introduced above. The possible product forms of the communication device are introduced below. It should be understood that any form of product with the functions of the communication device described in FIG. 8 falls within the protection scope of the embodiments of the present application. It should also be understood that the following introduction is only an example, and the product form of the communication device of the embodiments of the present application is not limited to this.

[0385] In a possible implementation, in the communication device shown in FIG. 8, the processing module 20 can be one or more processors, and the transceiver module 10 can be a transceiver, or the transceiver module 10 can also be a sending module and a receiving module, the sending module can be a transmitter, and the receiving module can be a receiver. The sending module and the receiving module are integrated in one device, such as a transceiver. In the embodiments of the present application, the processor and the transceiver can be coupled, and the connection mode of the processor and the transceiver is not limited in the embodiments of the present application. In the process of executing the above method, the process of sending information in the above method can be understood as the process of outputting the above information by the processor. When outputting the above information, the processor outputs the above information to the transceiver for transmission by the transceiver. The above information may need to be processed further after being output by the processor, and then reaches the transceiver. Similarly, the process of receiving information in the above method can be understood as the process of receiving the input above information by the processor. When the processor receives the input information, the transceiver receives the above information and inputs it to the processor. Further, after the transceiver receives the above information, the above information may need to be processed further, and then input to the processor.

[0386] Referring to FIG. 9, FIG. 9 is another structural schematic diagram of the communication apparatus provided in the embodiments of the present application. As shown in FIG. 9, the communication apparatus provided in the embodiments of the present application can be used to implement the methods described in the method embodiments, and the descriptions can be referred to the descriptions in the method embodiments. The communication apparatus can be any of the aforementioned entities, or a chip or circuit thereof. For example, the communication apparatus comprises one or more processors 1001 and a transceiver 1002. The communication apparatus can further comprise a memory 1003. In an implementation, the communication apparatus further comprises an input / output device (not shown in the figure).

[0387] The processor 1001 is mainly used for processing communication protocols and communication data, and controlling the whole communication apparatus, executing software programs, and processing data of the software programs. The memory 1003 is mainly used for storing software programs and data. The transceiver 1002 can comprise a control circuit and an antenna, and the control circuit is mainly used for converting baseband signals and radio frequency signals, and processing the radio frequency signals. The antenna is mainly used for receiving and transmitting radio frequency signals in the form of electromagnetic waves. The input / output device, such as a touch screen, a display screen, a keyboard, etc., is mainly used for receiving user input data and outputting data to the user.

[0388] When the communication apparatus is powered on, the processor 1001 can read the software programs in the memory 1003, interpret and execute the instructions of the software programs, and process the data of the software programs. When data needs to be transmitted wirelessly, the processor 1001 performs baseband processing on the data to be transmitted, and outputs the baseband signals to the radio frequency circuit. The radio frequency circuit converts the baseband signals into radio frequency signals, and transmits the radio frequency signals in the form of electromagnetic waves through the antenna. When data is transmitted to the communication apparatus, the radio frequency circuit receives the radio frequency signals through the antenna, converts the radio frequency signals into baseband signals, and outputs the baseband signals to the processor 1001. The processor 1001 converts the baseband signals into data and processes the data.

[0389] In another implementation, the radio frequency circuit and the antenna can be arranged independently of the processor performing the baseband processing, for example, in a distributed scenario, the radio frequency circuit and the antenna can be arranged remotely from the communication apparatus.

[0390] In the implementation, the processor 1001, the transceiver 1002, and the memory 1003 can be connected through a communication bus.

[0391] For example, when the communication apparatus is used to execute the steps or methods or functions executed by the first unmanned aerial vehicle management entity in the method embodiment shown in FIG. 4, the processor 1001 can be used to execute steps S101 and S102 in FIG. 4, and / or other processes of the technologies described herein; and the transceiver 1002 can be used to execute step S103 in FIG. 4, and / or other processes of the technologies described herein.

[0392] Exemplarily, when the communication apparatus is configured to perform the steps or methods or functions performed by the open function entity in the method embodiment shown in FIG. 4, the processor 1001 can be configured to perform step S104 in FIG. 4, and / or other processes for implementing the techniques described herein; the transceiver 1002 can be configured to receive the second indication information, and / or other processes for implementing the techniques described herein.

[0393] Exemplarily, when the communication apparatus is configured to perform the steps or methods or functions performed by the first UAV management entity in the method embodiment shown in FIG. 5, the processor 1001 can be configured to perform step S204 in FIG. 5, and / or other processes for implementing the techniques described herein; the transceiver 1002 can be configured to receive the first indication information, and / or other processes for implementing the techniques described herein.

[0394] Exemplarily, when the communication apparatus is configured to perform the steps or methods or functions performed by the open function entity in the method embodiment shown in FIG. 5, the processor 1001 can be configured to perform steps S201 and S202 in FIG. 5, and / or other processes for implementing the techniques described herein; the transceiver 1002 can be configured to perform step S203 in FIG. 5, and / or other processes for implementing the techniques described herein.

[0395] Exemplarily, when the communication apparatus is configured to perform the steps or methods or functions performed by the first UAV management entity in the method embodiment shown in FIG. 6, the processor 1001 can be configured to perform step S301 in FIG. 6, and / or other processes for implementing the techniques described herein; the transceiver 1002 can be configured to perform step S302 in FIG. 6, and / or other processes for implementing the techniques described herein.

[0396] Exemplarily, when the communication apparatus is configured to perform the steps or methods or functions performed by the second UAV management entity in the method embodiment shown in FIG. 6, the processor 1001 can be configured to prepare for switching the UAV management entity, and / or other processes for implementing the techniques described herein; the transceiver 1002 can be configured to receive the second message, and / or other processes for implementing the techniques described herein.

[0397] Exemplarily, when the communication apparatus is configured to perform the steps or methods or functions performed by the first UAV management entity in the method embodiment shown in FIG. 7, the processor 1001 can be configured to perform step S404 in FIG. 7, and / or other processes for implementing the techniques described herein; the transceiver 1002 can be configured to perform step S401 in FIG. 7, and / or other processes for implementing the techniques described herein.

[0398] For example, when the communication apparatus is configured to perform the steps or methods or functions performed by the open function entity in the method embodiment shown in FIG. 7, the processor 1001 can be configured to perform step S402 in FIG. 7, and / or other processes described herein for implementing the techniques described herein; the transceiver 1002 can be configured to perform step S403 in FIG. 7, and / or other processes described herein for implementing the techniques described herein.

[0399] In any of the above implementation manners, the processor 1001 can include a transceiver for implementing the receiving and sending functions. For example, the transceiver can be a transceiver circuit, or an interface, or an interface circuit. The transceiver circuit, interface or interface circuit for implementing the receiving and sending functions can be separate or integrated together. The transceiver circuit, interface or interface circuit described above can be used for reading and writing of code / data, or the transceiver circuit, interface or interface circuit described above can be used for transmission or transfer of signals.

[0400] In any of the above implementation manners, the processor 1001 can store instructions, which can be a computer program. The computer program can run on the processor 1001, and can cause the communication apparatus to perform the methods described in the above method embodiments. The computer program can be fixed in the processor 1001, and in this case, the processor 1001 can be implemented by hardware.

[0401] In an implementation, the communication apparatus can include circuitry that can implement the functions of transmitting or receiving or communicating in the foregoing method embodiments. The processor and transceiver described in the present application can be implemented on an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFIC), a mixed-signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), N-type metal oxide semiconductor (NMOS), positive channel metal oxide semiconductor (PMOS), bipolar junction transistor (BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.

[0402] It can be understood that the communication apparatus shown in the embodiments of the present application can also have more components, etc. than Figure 9, which is not limited in the embodiments of the present application. The methods performed by the processor and transceiver shown above are only examples, and the specific steps performed by the processor and transceiver can be referred to the description of the method embodiments above.

[0403] In another possible implementation, in the communication apparatus shown in FIG. 10, the processing module 20 can be one or more logic circuits, and the transceiver module 10 can be an input / output interface, also referred to as a communication interface, or an interface circuit, or an interface, etc. Alternatively, the transceiver module 10 can also be a sending module and a receiving module, the sending module can be an output interface, and the receiving module can be an input interface, and the sending module and the receiving module are integrated into one module, for example, an input / output interface. Referring to FIG. 10, FIG. 10 is another structural schematic diagram of the communication apparatus provided by the embodiment of the present application. As shown in FIG. 10, the communication apparatus can be any of the foregoing entities. The communication apparatus shown in FIG. 10 includes a logic circuit 901 and an interface 902. That is, the processing module 20 can be implemented by the logic circuit 901, and the transceiver module 10 can be implemented by the interface 902. The logic circuit 901 can be a chip, a processing circuit, an integrated circuit, or a system on chip (SoC) chip, etc., and the interface 902 can be a communication interface circuit, an input / output interface circuit, a pin, etc. For example, FIG. 10 is a chip with the foregoing communication apparatus as an example, and the chip includes the logic circuit 901 and the interface 902.

[0404] In the embodiment of the present application, the logic circuit and the interface can also be coupled to each other. The specific connection manner of the logic circuit and the interface is not limited in the embodiment of the present application.

[0405] For example, when the communication apparatus is used to execute the method or the function or the step executed by the first UAV management entity in the method embodiment shown in FIG. 4 or FIG. 5, the logic circuit 901 is configured to determine a candidate second UAV management entity for providing a service for a UAV; and the logic circuit 901 is further configured to determine, according to the first indication information and / or the association relationship between the first UAV management entity and the second UAV management entity, whether to perform an authentication process between the second UAV management entity and the UAV. The interface 902 is configured to receive the first indication information from the open function entity, and the first indication information is used to indicate whether to perform the authentication process between the second UAV management entity and the UAV.

[0406] Exemplarily, when the communication apparatus is configured to perform the method or function or step performed by the open function entity in the method embodiments shown in FIG. 4 or FIG. 5, the logic circuit 901 is configured to obtain information of a second UAV management entity, the second UAV management entity being a candidate UAV management entity for providing service for the UAV; and the logic circuit 901 is further configured to determine, according to the second indication information and / or the association relationship between the first UAV management entity and the second UAV management entity, whether to perform an authentication procedure between the second UAV management entity and the UAV. The first UAV management entity is a current UAV management entity for providing service for the UAV. The interface 902 is configured to receive the second indication information from the first UAV management entity or the second UAV management entity. The second indication information is used to indicate that the authentication procedure is not performed between the second UAV management entity and the UAV.

[0407] In this application, the specific description of the first UAV management entity, the second UAV management entity, the association relationship, the authentication procedure, the first indication information, the second indication information, etc. can refer to the method embodiments shown in the above, which will not be repeated here.

[0408] Exemplarily, when the communication apparatus is configured to perform the method or function or step performed by the first UAV management entity in the method embodiments shown in FIG. 6 or FIG. 7, the logic circuit 901 is configured to determine that the second UAV management entity is a target UAV management entity for providing service for the UAV when it is determined that the authentication procedure is not needed between the second UAV management entity and the UAV or the authentication between the second UAV management entity and the UAV is successful; and the interface 902 is configured to send a second message to the second UAV management entity, the second message being used to request the second UAV management entity to prepare for switching the UAV management entity.

[0409] Exemplarily, when the communication apparatus is configured to perform the method or function or step performed by the open function entity in the method embodiments shown in FIG. 4 or FIG. 5, the logic circuit 901 is configured to obtain information of a second UAV management entity, the second UAV management entity being a candidate UAV management entity for providing service for the UAV; and the interface 902 is configured to send fourth indication information to a first UAV management entity currently providing service for the UAV, the fourth indication information being used to indicate whether there is authentication information between the second UAV management entity and the UAV in the open function entity.

[0410] In this application, the specific description of the first UAV management entity, the second UAV management entity, the association relationship, the authentication procedure, the second message, the fourth indication information, etc. can refer to the method embodiments shown in the above, which will not be repeated here.

[0411] It can be understood that the communication apparatuses shown in the embodiments of the present application can implement the methods provided by the embodiments of the present application in the form of hardware, or implement the methods provided by the embodiments of the present application in the form of software, and the like, and the embodiments of the present application do not limit this.

[0412] For the specific implementation of each embodiment shown in FIG. 10, reference can also be made to the above-mentioned embodiments, and details are not described here.

[0413] The embodiments of the present application further provide a communication system, which comprises a first unmanned aerial vehicle management entity and an exposure function entity, and the first unmanned aerial vehicle management entity and the exposure function entity can be used to execute the method in any of the preceding method embodiments. Optionally, the communication system further comprises a second unmanned aerial vehicle management entity, and the second unmanned aerial vehicle management entity can be used to execute the method in any of the preceding method embodiments.

[0414] In addition, the present application further provides a computer program for implementing the operations and / or processes performed by the above-mentioned entities in the methods provided by the present application.

[0415] The present application further provides a computer readable storage medium, which stores computer code, and when the computer code is run on a computer, the computer code causes the computer to execute the operations and / or processes performed by the above-mentioned entities in the methods provided by the present application.

[0416] The present application further provides a computer program product, which comprises computer code or a computer program, and when the computer code or the computer program is run on a computer, the operations and / or processes performed by the above-mentioned entities in the methods provided by the present application are executed.

[0417] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can also be electrical, mechanical or other forms of connection.

[0418] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the technical effects of the scheme provided by the embodiments of the present application.

[0419] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0420] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the technical solutions, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a readable storage medium, including a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned readable storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0421] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A communication method characterized by comprising: The method comprises: A first UAV management entity currently serving a UAV determines a candidate second UAV management entity serving the UAV; The first UAV management entity determines, according to first indication information and / or an association relationship between the first UAV management entity and the second UAV management entity, whether to perform an authentication procedure between the second UAV management entity and the UAV. The first indication information is used to indicate whether to perform the authentication procedure between the second UAV management entity and the UAV, and the first indication information is from an open function entity.

2. The method of claim 1, wherein, The first UAV management entity determines, according to the association relationship between the first UAV management entity and the second UAV management entity, whether to perform the authentication procedure between the second UAV management entity and the UAV, comprising: The first UAV management entity determines, according to one or more of the following information: address information of the first UAV management entity and the second UAV management entity, network information of the first UAV management entity and the second UAV management entity, air traffic control information corresponding to the first UAV management entity and the second UAV management entity, or a pre-configured trust relationship between the first UAV management entity and the second UAV management entity, whether to perform the authentication procedure between the second UAV management entity and the UAV.

3. The method according to claim 1 or 2, characterized in that, The second UAV management entity is a target UAV management entity serving the UAV.

4. The method according to any one of claims 1 to 3, characterized in that, The method further comprises: If the first UAV management entity determines, according to the association relationship, not to perform the authentication procedure between the second UAV management entity and the UAV, the first UAV management entity sends second indication information to the open function entity, the second indication information being used to indicate not to perform the authentication procedure between the second UAV management entity and the UAV.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: The first UAV management entity sends a first message to the open function entity, the first message comprising an identifier of the second UAV management entity, an identifier of the UAV, and verification information used to verify authenticity of the first message.

6. A communication method characterized by comprising: The method comprises: An open function entity obtains information of a second UAV management entity, the second UAV management entity being a candidate UAV management entity serving a UAV; The open function entity determines, according to second indication information and / or an association relationship between a first UAV management entity and the second UAV management entity, whether to perform an authentication procedure between the second UAV management entity and the UAV, the first UAV management entity being a UAV management entity currently serving the UAV. The second indication information is used to indicate not to perform the authentication procedure between the second UAV management entity and the UAV, and the second indication information is from the first UAV management entity or the second UAV management entity.

7. The method of claim 6, wherein, The open function entity determines whether to perform an authentication procedure between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle according to an association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, including: The open function entity determines whether to perform an authentication procedure between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle according to one or more of the following information: address information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, network information of the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, air traffic control information corresponding to the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, or a pre-configured trust relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity.

8. The method according to claim 6 or 7, characterized in that, The second unmanned aerial vehicle management entity is a target unmanned aerial vehicle management entity that will provide services for the unmanned aerial vehicle.

9. The method according to any one of claims 6 to 8, characterized in that, The method further includes: If the authentication procedure is not performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, the open function entity stores authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, and the authentication information indicates that the second unmanned aerial vehicle management entity and the unmanned aerial vehicle are successfully authenticated or do not need to be authenticated.

10. The method of claim 9, wherein, The expiration time of the authentication information between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is earlier than or equal to the expiration time of the authentication information between the first unmanned aerial vehicle management entity and the unmanned aerial vehicle.

11. The method according to any one of claims 6 to 10, characterized in that, After the open function entity determines whether to perform an authentication procedure between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle according to an association relationship between the first unmanned aerial vehicle management entity and the second unmanned aerial vehicle management entity, the method further includes: The open function entity sends first indication information to the first unmanned aerial vehicle management entity, and the first indication information is used to indicate whether to perform an authentication procedure between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle.

12. The method according to any one of claims 6 to 11, characterized in that, The open function entity obtains information of the second unmanned aerial vehicle management entity, including: The open function entity receives a first message from the first unmanned aerial vehicle management entity, and the first message includes an identifier of the second unmanned aerial vehicle management entity, an identifier of the unmanned aerial vehicle, and verification information used to verify authenticity of the first message; The open function entity verifies authenticity of the first message according to the verification information; If the first message is verified, the open function entity obtains the identifier of the second unmanned aerial vehicle management entity.

13. The method according to any one of claims 6 to 12, characterized in that, The method further includes: If the authentication procedure is not performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, the open function entity sends third indication information to a third entity, and the third indication information is used to indicate that the authentication result between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful or that the second unmanned aerial vehicle management entity and the unmanned aerial vehicle do not need to be authenticated, and the third entity is an entity that stores the authentication result.

14. A communication method, comprising: It includes: If the first UAV management entity currently serving the UAV determines that no authentication procedure needs to be performed between the second UAV management entity and the UAV, or the first UAV management entity determines that the authentication between the second UAV management entity and the UAV is successful, the first UAV management entity determines that the second UAV management entity is a target UAV management entity that will serve the UAV; The first UAV management entity sends a second message to the second UAV management entity, where the second message is used to request the second UAV management entity to prepare for switching the UAV management entity.

15. The method of claim 14, wherein, The first UAV management entity determines that no authentication procedure needs to be performed between the second UAV management entity and the UAV, including: The first UAV management entity determines that no authentication procedure needs to be performed between the second UAV management entity and the UAV according to one or more of the following information: address information of the first UAV management entity and the second UAV management entity, network information of the first UAV management entity and the second UAV management entity, air traffic control information corresponding to the first UAV management entity and the second UAV management entity, or a pre-configured trust relationship between the first UAV management entity and the second UAV management entity.

16. The method of claim 14, wherein, The first UAV management entity determines that the authentication between the second UAV management entity and the UAV is successful, including: The first UAV management entity receives fourth indication information from the open function entity, where the fourth indication information is used to indicate whether there is authentication information between the second UAV management entity and the UAV in the open function entity; If there is authentication information between the second UAV management entity and the UAV in the open function entity, the first UAV management entity determines that the authentication between the second UAV management entity and the UAV is successful.

17. The method of claim 14, wherein, The first UAV management entity currently serving the UAV determines that no authentication procedure needs to be performed between the second UAV management entity and the UAV, and the first UAV management entity determines that the second UAV management entity is a target UAV management entity that will serve the UAV, including: The first UAV management entity receives fourth indication information from the open function entity, where the fourth indication information is used to indicate whether an authentication procedure needs to be performed between the second UAV management entity and the UAV; If the fourth indication information indicates that no authentication procedure needs to be performed between the second UAV management entity and the UAV, the first UAV management entity determines that the second UAV management entity is a target UAV management entity that will serve the UAV.

18. The method of claim 14 or 17, wherein, The method further includes: The first unmanned aerial vehicle management entity receives fourth indication information from the opening function entity, the fourth indication information being used to indicate whether an authentication procedure needs to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle; if the fourth indication information indicates that the authentication procedure needs to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, the first unmanned aerial vehicle management entity sends a third message to the second unmanned aerial vehicle management entity or the unmanned aerial vehicle, the third message being used to notify the second unmanned aerial vehicle management entity to perform the authentication procedure with the unmanned aerial vehicle, the third message comprising an identifier of the unmanned aerial vehicle; or the third message being used to notify the unmanned aerial vehicle to perform the authentication procedure with the second unmanned aerial vehicle management entity, the third message comprising an address of the second unmanned aerial vehicle management entity.

19. The method of claim 14, wherein, The first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, comprising: The first unmanned aerial vehicle management entity determines that the authentication procedure needs to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle; The first unmanned aerial vehicle management entity sends a third message to the second unmanned aerial vehicle management entity, the third message being used to notify the second unmanned aerial vehicle management entity to perform the authentication procedure with the unmanned aerial vehicle, the third message comprising an identifier of the unmanned aerial vehicle; or the first unmanned aerial vehicle management entity sends a third message to the unmanned aerial vehicle, the third message being used to notify the unmanned aerial vehicle to perform the authentication procedure with the second unmanned aerial vehicle management entity, the third message comprising an address of the second unmanned aerial vehicle management entity; The first unmanned aerial vehicle management entity receives a first authentication result between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle; When the first authentication result is successful, the first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful.

20. The method of any one of claims 14 to 19, wherein, After the first unmanned aerial vehicle management entity sends the second message to the second unmanned aerial vehicle management entity, the method further comprises: The first unmanned aerial vehicle management entity receives fifth indication information, the fifth indication information being used to indicate that the service provided by the first unmanned aerial vehicle management entity to the unmanned aerial vehicle is switched to the service provided by the second unmanned aerial vehicle management entity to the unmanned aerial vehicle.

21. The method according to any one of claims 14 to 20, characterized in that, Before the first unmanned aerial vehicle management entity determines that the authentication procedure does not need to be performed between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle, or the first unmanned aerial vehicle management entity determines that the authentication between the second unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, the method further comprises: The first unmanned aerial vehicle management entity determines that the authentication procedure needs to be performed between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle; The first unmanned aerial vehicle management entity sends a fourth message to the fourth unmanned aerial vehicle management entity, the fourth message being used to inform the fourth unmanned aerial vehicle management entity to perform an authentication procedure with the unmanned aerial vehicle, the fourth message comprising an identifier of the unmanned aerial vehicle; or the first unmanned aerial vehicle management entity sends a fourth message to the unmanned aerial vehicle, the fourth message being used to inform the unmanned aerial vehicle to perform an authentication procedure with the fourth unmanned aerial vehicle management entity, the fourth message comprising an address of the fourth unmanned aerial vehicle management entity. The first unmanned aerial vehicle management entity receives a second authentication result between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle, the second authentication result being a failure.

22. The method of any one of claims 14 to 21, wherein, The second unmanned aerial vehicle management entity and the unmanned aerial vehicle have first subscription information, the first subscription information indicating that the unmanned aerial vehicle is a subscription user of the second unmanned aerial vehicle management entity.

23. The method of any one of claims 14 to 22, wherein, The method further comprises: The first unmanned aerial vehicle management entity receives a fifth message from an exposure function entity, the fifth message being used to indicate qualified unmanned aerial vehicle management entities and / or unqualified unmanned aerial vehicle management entities, the qualified unmanned aerial vehicle management entities comprising: unmanned aerial vehicle management entities having first subscription information with the unmanned aerial vehicle, and / or unmanned aerial vehicle management entities passing security verification; the first subscription information indicating that the unmanned aerial vehicle is a subscription user of the unmanned aerial vehicle management entity. The first unmanned aerial vehicle management entity obtains a first candidate entity list, the first candidate entity list comprising the qualified unmanned aerial vehicle management entities, the first candidate entity list comprising the second unmanned aerial vehicle management entity.

24. The method of claim 23, wherein, The method further comprises: The first unmanned aerial vehicle management entity sends a sixth message to an exposure function entity, the sixth message comprising a second candidate entity list, the second candidate entity list comprising one or more candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle, the sixth message being used to obtain qualified unmanned aerial vehicle management entities in the second candidate entity list.

25. The method of claim 24, wherein, The sixth message further comprises security verification information of each unmanned aerial vehicle management entity in the second candidate entity list.

26. The method of any one of claims 14 to 25, wherein, The method further comprises: The first unmanned aerial vehicle management entity determines a third candidate entity list, the third candidate entity list comprising a plurality of candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle; The first unmanned aerial vehicle management entity queries whether each unmanned aerial vehicle management entity in the third candidate entity list has second subscription information with the unmanned aerial vehicle; The first unmanned aerial vehicle management entity obtains a fourth candidate entity list, the fourth candidate entity list comprising unmanned aerial vehicle management entities having second subscription information with the unmanned aerial vehicle, the fourth candidate entity list comprising the second unmanned aerial vehicle management entity.

27. A method of communication, comprising: The method further comprises: An exposure function entity obtains information of a second unmanned aerial vehicle management entity, the second unmanned aerial vehicle management entity being a candidate unmanned aerial vehicle management entity providing services for the unmanned aerial vehicle; The method further comprises: The first unmanned aerial vehicle management entity sends a fourth message to the fourth unmanned aerial vehicle management entity, the fourth message being used to inform the fourth unmanned aerial vehicle management entity to perform an authentication procedure with the unmanned aerial vehicle, the fourth message comprising an identifier of the unmanned aerial vehicle; or the first unmanned aerial vehicle management entity sends a fourth message to the unmanned aerial vehicle, the fourth message being used to inform the unmanned aerial vehicle to perform an authentication procedure with the fourth unmanned aerial vehicle management entity, the fourth message comprising an address of the fourth unmanned aerial vehicle management entity. The first unmanned aerial vehicle management entity receives a second authentication result between the fourth unmanned aerial vehicle management entity and the unmanned aerial vehicle, the second authentication result being a failure. The second unmanned aerial vehicle management entity and the unmanned aerial vehicle have first subscription information, the first subscription information indicating that the unmanned aerial vehicle is the subscription user of the second unmanned aerial vehicle management entity. The method further comprises: The first unmanned aerial vehicle management entity receives a fifth message from an exposure function entity, the fifth message being used to indicate qualified unmanned aerial vehicle management entities and / or unqualified unmanned aerial vehicle management entities, the qualified unmanned aerial vehicle management entities comprising: unmanned aerial vehicle management entities having first subscription information with the unmanned aerial vehicle, and / or unmanned aerial vehicle management entities passing security verification; the first subscription information indicating that the unmanned aerial vehicle is a subscription user of the unmanned aerial vehicle management entity. The first unmanned aerial vehicle management entity obtains a first candidate entity list, the first candidate entity list comprising the qualified unmanned aerial vehicle management entities, the first candidate entity list comprising the second unmanned aerial vehicle management entity. The method further comprises: The first unmanned aerial vehicle management entity sends a sixth message to an exposure function entity, the sixth message comprising a second candidate entity list, the second candidate entity list comprising one or more candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle, the sixth message being used to obtain qualified unmanned aerial vehicle management entities in the second candidate entity list. The sixth message further comprises security verification information of each unmanned aerial vehicle management entity in the second candidate entity list. The method further comprises: The first unmanned aerial vehicle management entity determines a third candidate entity list, the third candidate entity list comprising a plurality of candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle; The first unmanned aerial vehicle management entity queries whether each unmanned aerial vehicle management entity in the third candidate entity list has second subscription information with the unmanned aerial vehicle; The first unmanned aerial vehicle management entity obtains a fourth candidate entity list, the fourth candidate entity list comprising unmanned aerial vehicle management entities having second subscription information with the unmanned aerial vehicle, the fourth candidate entity list comprising the second unmanned aerial vehicle management entity. The method further comprises: An exposure function entity obtains information of a second unmanned aerial vehicle management entity, the second unmanned aerial vehicle management entity being a candidate unmanned aerial vehicle management entity providing services for the unmanned aerial vehicle; The method further comprises: The open function entity sends fourth indication information to a first drone management entity currently providing service for the drone, the fourth indication information being used to indicate whether there is authentication information between the second drone management entity and the drone in the open function entity, or the fourth indication information being used to indicate whether an authentication process needs to be performed between the second drone management entity and the drone.

28. The method of claim 27, wherein, After the open function entity sends the fourth indication information to the first drone management entity currently providing service for the drone, the method further comprises: The open function entity receives an authentication request message from the second drone management entity, the authentication request message being used to request to authenticate the drone, and the authentication request message comprising an identifier of the drone; The open function entity sends a first authentication result between the second drone management entity and the drone. If the first authentication result is successful, the open function entity stores authentication information between the second drone management entity and the drone.

29. The method of claim 27 or 28, wherein, After the open function entity sends the fourth indication information to the first drone management entity currently providing service for the drone, the method further comprises: The open function entity sends fifth indication information to the first drone management entity, the fifth indication information being used to indicate switching from the first drone management entity to the second drone management entity to provide service for the drone.

30. The method of any one of claims 27-29, wherein, Before the open function entity obtains information of the second drone management entity, the method further comprises: The open function entity receives an authentication request message from a fourth drone management entity, the authentication request message being used to request to authenticate the drone, and the authentication request message comprising an identifier of the drone; The open function entity sends a second authentication result between the fourth drone management entity and the drone, the second authentication result being failure.

31. The method of any one of claims 27-30, wherein, There is first subscription information between the second drone management entity and the drone, the first subscription information indicating that the drone is a subscription user of the second drone management entity.

32. The method of any one of claims 27-31, wherein, Before the open function entity obtains information of the second drone management entity, the method further comprises: The open function entity determines a qualified drone management entity and / or an unqualified drone management entity, the qualified drone management entity comprising: a drone management entity having first subscription information with the drone, and / or a drone management entity passing security verification; the first subscription information indicating that the drone is a subscription user of the drone management entity; and the qualified drone management entity comprising the second drone management entity. The open function entity sends a fifth message to the first drone management entity, the fifth message being used to indicate the qualified drone management entity and / or the unqualified drone management entity.

33. The method of claim 32, wherein, Before the open function entity determines the qualified drone management entity and / or the unqualified drone management entity, the method further comprises: The open function entity receives a sixth message from the first unmanned aerial vehicle management entity, the sixth message comprising a second candidate entity list comprising one or more candidate unmanned aerial vehicle management entities providing services for the unmanned aerial vehicle, and the sixth message is used to obtain a qualified unmanned aerial vehicle management entity in the second candidate entity list.

34. The method of claim 33, wherein, The qualified unmanned aerial vehicle management entity comprises a first subscription information between the unmanned aerial vehicle and the unmanned aerial vehicle management entity. The open function entity determines the qualified unmanned aerial vehicle management entity and / or the unqualified unmanned aerial vehicle management entity, comprising: The open function entity sends an information query request to a unified data management function (UDM) entity, and the information query request is used to query whether there is a first subscription information between each unmanned aerial vehicle management entity in the second candidate entity list and the unmanned aerial vehicle; The open function entity receives an information query response from the UDM entity, and the information query response is used to indicate whether there is a first subscription information between the each unmanned aerial vehicle management entity and the unmanned aerial vehicle; The open function entity determines the qualified unmanned aerial vehicle management entity and / or determines the unqualified unmanned aerial vehicle management entity according to the information query response.

35. The method of claim 33, wherein, The sixth message further comprises security verification information of each unmanned aerial vehicle management entity in the second candidate entity list, and the qualified unmanned aerial vehicle management entity comprises a security verification passed unmanned aerial vehicle management entity; The open function entity determines the qualified unmanned aerial vehicle management entity and / or the unqualified unmanned aerial vehicle management entity, comprising: The open function entity sends an information acquisition request to a unified data management function (UDM) entity, and the information acquisition request is used to request information for verifying the each unmanned aerial vehicle management entity; The open function entity receives an information acquisition response from the UDM entity, and the information acquisition response comprises information for verifying the each unmanned aerial vehicle management entity; The open function entity respectively performs security verification on security verification information of the each unmanned aerial vehicle management entity according to the information for verifying the each unmanned aerial vehicle management entity; The open function entity determines that a security verification passed unmanned aerial vehicle management entity is a qualified unmanned aerial vehicle management entity, and / or determines that a security verification failed unmanned aerial vehicle management entity is an unqualified unmanned aerial vehicle management entity.

36. The method of claim 35, wherein, After the open function entity determines the qualified unmanned aerial vehicle management entity and / or the unqualified unmanned aerial vehicle management entity, the method further comprises: The open function entity sends a seventh message to a third entity, and the seventh message is used to update or add an authentication result between the qualified unmanned aerial vehicle management entity and the unmanned aerial vehicle, and the authentication result is a flight without authentication after the authentication between the qualified unmanned aerial vehicle management entity and the unmanned aerial vehicle is successful, and the third entity is an entity storing the authentication result.

37. A communications device, characterized by comprising a module for performing the method of any one of claims 1 to 5, or the method of any one of claims 6 to 13, or the method of any one of claims 14 to 26, or the method of any one of claims 27 to 36.

38. A communications device, characterized by comprising a logic circuit and an interface, the logic circuit and the interface being coupled; the interface for inputting and / or outputting information, the logic circuit for executing instructions to cause the communication device to perform the method of any one of claims 1 to 5, or the method of any one of claims 6 to 13, or the method of any one of claims 14 to 26, or the method of any one of claims 27 to 36.

39. A readable storage medium characterized by, a program for use by or in connection with the one or more apparatuses, such that the apparatuses perform a method according to any one of claims 1 to 36.

40. A computer program product, characterised in that, The computer program product, when run on a computer, causes the computer to perform the method of any one of claims 1 to 36.

41. A communication system, characterized by comprising a first drone management entity and an open function entity; wherein the first drone management entity is configured to perform the method of any one of claims 1 to 5, and the open function entity is configured to perform the method of any one of claims 6 to 13; or, the first drone management entity is configured to perform the method of any one of claims 14 to 26, and the open function entity is configured to perform the method of any one of claims 27 to 37.

Citation Information

Patent Citations

  • Managing unmanned flight system service provider examples

    CN118103893A

  • Re-allocation of unmanned aerial vehicle system service providers

    CN118104295A

  • Communication method and device in wireless communication system supporting unmanned aerial system service

    US20230115431A1

  • Systems and methods for secure and reliable command and control of in-flight uncrewed aerial vehicles via public land mobile networks

    US20240267817A1