Communication methods, communication apparatus and system

By carrying privacy-preserving computational resource information in communication requests, identifying the sensing entity and performing privacy encryption and computation, the problem of privacy and security of sensing business data in communication systems is solved, and the secure transmission and processing of sensing business data is realized.

WO2026081861A1PCT designated stage Publication Date: 2026-04-23HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-09-29
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

In communication systems, how can we protect the privacy and security of sensing service data, especially in situations involving high frequency bands, large bandwidth, and large-scale antenna arrays, to avoid privacy leaks caused by processing sensing service data in plaintext?

Method used

By including privacy computing resource information, such as privacy algorithms and encryption keys, in communication requests, the sensed entity is identified and privacy encryption and computation are performed, ensuring the security of sensed data during transmission and processing.

Benefits of technology

It achieves privacy and security protection for perception business data, avoids privacy leaks caused by plaintext processing on the network side, and improves the security of perception business data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025125278_23042026_PF_FP_ABST
    Figure CN2025125278_23042026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present application are communication methods, a communication apparatus and a system. A method comprises: a first node sending a first request, the first request being used for requesting a sensing result of a first sensing service, the first request comprising first privacy computing resource information, and the first privacy computing resource information comprising a first privacy algorithm and a privacy encryption key or the first privacy computing resource information being used for determining the first privacy algorithm and the privacy encryption key; receiving a first sensing result of the first sensing service, the first sensing result being determined on the basis of the first privacy algorithm and the privacy encryption key; and the first node can perform privacy decryption on the first sensing result to obtain a second sensing result. The method can protect privacy security of sensing service data of the first sensing service.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods, communication devices and systems

[0001] This application claims priority to Chinese Patent Application No. 202411457664.0, filed on October 17, 2024, entitled "Communication Method, Communication Device and System", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to communication methods, communication devices, and systems. Background Technology

[0003] Both wireless communication and wireless sensing are based on electromagnetic wave theory. The transmitting end can modulate electromagnetic wave signals, allowing them to carry source information. During propagation, these signals are affected by the wireless environment (i.e., subjected to environmental modulation), thus also carrying environmental information. The receiving end analyzes the received electromagnetic wave signals, obtaining not only the carried source information but also sensing information reflecting the characteristics of the propagation environment. This makes the integration of communication and sensing possible.

[0004] As communication systems evolve towards higher frequency bands, larger bandwidths, and denser deployments of large-scale antenna arrays, they will possess more powerful sensing capabilities and provide more sensing services, such as target detection or sensing environmental object information. During the provision of sensing services, sensing service data is transmitted, and how to protect the privacy and security of this data is a pressing issue that needs to be addressed. Summary of the Invention

[0005] This application discloses a communication method, communication device, and system that can protect the privacy and security of sensing service data in the first sensing service.

[0006] The present application is described below from different aspects. It should be understood that the different implementation methods and beneficial effects described below can be referenced from each other.

[0007] In a first aspect, this application discloses a communication method that can be executed by a first communication device, a second communication device, a third communication device, and a fourth communication device. The descriptions of the first communication device, the second communication device, the third communication device, and the fourth communication device are provided below and will not be elaborated here.

[0008] Taking a first communication device as the first node, a second communication device as the second node, a third communication device as the first sensing entity, and a fourth communication device as the second sensing entity as an example, the method may include: the first node sending a first request to the second node, the first request being used to request the sensing result of a first sensing service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; then, the second node may, based on the first privacy computing resource information and the privacy computing capabilities of multiple sensing entities, determine the first sensing entity and the second sensing entity from multiple sensing entities; the second node sending a first message to the first sensing entity, the first message being used to instruct the first sensing entity to obtain the sensing data of the first sensing service, the first message including the first privacy algorithm and the privacy encryption key; the second node sending a first message to the second node... The sensing entity sends a second message, which instructs the second sensing entity to obtain the sensing result of the first sensing service. The second message includes a first privacy algorithm. Then, the first sensing entity can perform privacy encryption on the second sensing data of the first sensing service based on the first privacy algorithm and a privacy encryption key to obtain the first sensing data of the first sensing service. The second sensing data is obtained based on the sensing signal of the first sensing service. The first sensing entity sends the first sensing data to the second sensing entity. Then, the second sensing entity can perform privacy calculations on the first sensing data from the first sensing entity based on the first privacy algorithm from the second node to obtain the first sensing result of the first sensing service. The second sensing entity sends the first sensing result to the first node. Finally, the first node receives the first sensing result of the first sensing service from the second sensing entity and can perform privacy decryption on the first sensing result to obtain the second sensing result.

[0009] In this embodiment, the first node issues first privacy computing resource information, and the second node can determine a first sensing entity and a second sensing entity based on the first privacy computing resource information. The first sensing entity can perform privacy encryption on the second sensing data based on a first privacy algorithm and a privacy encryption key. The second sensing entity can perform privacy computing on the first sensing data based on the first privacy algorithm. In this method, privacy encryption and privacy computing can protect the privacy and security of sensing business data (such as the aforementioned first and second sensing data).

[0010] Secondly, this application discloses a communication method that can be executed by a first communication device. The first communication device can be a first node or a module of the first node (e.g., a chip, chip system, integrated circuit, or control unit), or a software and / or hardware module for implementing the functions of the first node. Taking the execution of the method by the first node as an example, the method can include: the first node sending a first request to a second node, the first request being used to request the perception result of a first sensing service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; the first node receiving a first perception result of the first sensing service from a second sensing entity, the first perception result being determined based on the first privacy algorithm and the privacy encryption key; and the first node performing privacy decryption on the first perception result to obtain a second perception result.

[0011] In this embodiment of the application, the first node carries first privacy computing resource information in the first request. The first perception result received by the first node is determined based on the first privacy computing resource information. The first node performs privacy decryption on the first perception result to obtain the request result of the first request, i.e., the second perception result.

[0012] If the first node does not send the aforementioned first privacy computing resource when requesting the sensing result of the sensing service, then the network side will process the sensing service data in plaintext. For example, when the radio access network (RAN) or sensing data process function (SDPF) performs fusion analysis on sensing service data from multiple parties, it does so in plaintext, which poses a risk of privacy leakage. In this application, the first privacy computing resource information is applied to the sensing architecture. The first node carries the first privacy computing resource information in the first request. The network side can perform privacy computing and other processing on the sensing service data based on the first privacy computing resource, which can protect the privacy and security of the sensing service data of the first sensing service.

[0013] In conjunction with the second aspect, in one possible implementation, the first privacy computing resource information includes a first privacy algorithm and a privacy encryption key. The method further includes: a first node acquiring the privacy computing capabilities of the network side, which are related to the privacy computing of the first sensing service; and then, the first node obtaining first information based on at least one of the first node's privacy computing capabilities, the network side's privacy computing capabilities, and the service security level of the first sensing service. The first information includes the first privacy algorithm and the privacy encryption key.

[0014] In this embodiment of the application, the initiator of the first request (i.e., the first node) selects a first privacy algorithm and generates a privacy encryption key. The first privacy algorithm and the privacy encryption key are used to protect the privacy and security of the sensing service data of the first sensing service. This method can protect the privacy and security of the sensing service data.

[0015] For example, the network side can refer to one or more network elements that establish communication with the second node, such as RAN or SDPF, etc., which are not limited in this application. Wherein, the network side is related to the privacy computation of the first sensing service, and can refer to a network element capable of performing the service tasks of the first sensing service.

[0016] In one possible implementation, the second sensing entity is used to obtain the first sensing result of the first sensing service based on the first privacy algorithm and the first sensing data; the first sensing data of the first sensing service is obtained by the first sensing entity based on the first privacy algorithm and the privacy encryption key; the first sensing entity and the second sensing entity are determined by a second node, which is the node that receives the aforementioned first request. In other words, the first node sends the aforementioned first request to the second node; the second node, based on the first privacy computing resource information and the privacy computing capabilities of multiple sensing entities, determines the first sensing entity and the second sensing entity from among the multiple sensing entities; the second node sends a first message to the first sensing entity, the first message instructing the first sensing entity to obtain sensing data of the first sensing service, the first message including a first privacy algorithm and a privacy encryption key, the first sensing entity using the first privacy algorithm and the privacy encryption key to obtain the first sensing data of the first sensing service; the second node sends a second message to the second sensing entity, the second message instructing the second sensing entity to obtain the sensing result of the first sensing service, the second message including a first privacy algorithm, the second sensing entity using the first privacy algorithm and the first sensing data to obtain the first sensing result of the first sensing service; the first node receives the first sensing result of the first sensing service from the second sensing entity; the first node can perform privacy decryption on the first sensing result to obtain the second sensing result.

[0017] In conjunction with the second aspect, in one possible implementation, the first information further includes a privacy decryption key; the first node performs privacy decryption on the first perception result to obtain the second perception result, including: the first node performs privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result.

[0018] In this embodiment of the application, the privacy decryption key is generated by the initiator of the first request (i.e., the first node), and the first node performs privacy decryption on the first perception result based on the privacy decryption key, which can ensure the privacy and security of the first perception result.

[0019] In conjunction with the second aspect, in one possible implementation, the first information further includes a privacy computing key, and the first privacy computing resource information further includes the privacy computing key.

[0020] In this embodiment, the first node also generates a privacy computing key, and the first privacy computing resource information sent by the first node to the second node may also include the aforementioned privacy computing key. It should be noted that this application does not limit whether the first privacy computing resource information includes the privacy computing key, which can improve the flexibility of privacy computing.

[0021] In conjunction with the second aspect, in one possible implementation, the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key. The first privacy computing resource information includes the privacy computing capabilities of the first node and the service security level of the first sensing service.

[0022] In this embodiment, the first node sends information used to determine the first privacy algorithm and privacy encryption key (i.e., the aforementioned first privacy computing resource information) to the second node, allowing other nodes (such as the second node) to determine the first privacy algorithm and privacy encryption key. This application does not limit the other nodes, thus improving the flexibility in determining the first privacy algorithm and privacy encryption key. When other nodes possess more powerful computing capabilities, they can determine a more suitable first privacy algorithm and privacy encryption key, further protecting the privacy and security of perceived business data.

[0023] In conjunction with the second aspect, in one possible implementation, the method further includes: a first node receiving a privacy decryption key from a second node; the first node performing privacy decryption on the first perception result to obtain a second perception result, including: the first node performing privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result.

[0024] In this embodiment, the privacy decryption key is generated by other nodes (such as the second node). This application does not limit the specific implementation of the first node obtaining the privacy decryption key, which can improve the flexibility of privacy computation.

[0025] In conjunction with the second aspect, in one possible implementation, the first request further includes first business information of the first sensing service, which is used to perform the business task corresponding to the first sensing service.

[0026] In this embodiment, the second node can execute the business task corresponding to the first sensing business based on the first business information. Since more information about the first sensing business has been obtained, it is beneficial for the second node to further protect the privacy and security of the sensing business data.

[0027] In conjunction with the second aspect, in one possible implementation, the first node is an application function (AF), a terminal, or a third-party application.

[0028] Thirdly, this application discloses a communication method that can be executed by a second communication device. The second communication device can be a second node or a module of the second node (e.g., a chip, chip system, integrated circuit, or control unit), or a software and / or hardware module for implementing the functions of the second node. Taking the execution of the method by the second node as an example, the method includes: the second node receiving a first request from a first node, the first request being used to request the perception result of a first perception service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; furthermore, the second node can, based on the first... The second node uses privacy computing resource information and the privacy computing capabilities of multiple sensing entities to determine a first sensing entity and a second sensing entity from among the multiple sensing entities. A second node sends a first message to the first sensing entity, instructing it to acquire sensing data from a first sensing service. The first message includes a first privacy algorithm and a privacy encryption key. The first sensing entity uses the first privacy algorithm and the privacy encryption key to obtain the first sensing data from the first sensing service. The second node then sends a second message to the second sensing entity, instructing it to acquire the sensing result from the first sensing service. The second message includes a first privacy algorithm. The second sensing entity uses the first privacy algorithm and the first sensing data to obtain the first sensing result from the first sensing service.

[0029] In this embodiment, the second node determines the first sensing entity and the second sensing entity based on the first privacy computing resource information. Then, it sends the first privacy algorithm and the privacy encryption key to the first sensing entity and the first privacy algorithm to the second sensing entity. The first sensing entity can protect the privacy of the sensing service data (such as the first sensing data) of the first sensing service based on the first privacy algorithm and the privacy encryption key. The second sensing entity can perform calculations on the encrypted first sensing service data based on the first privacy algorithm to obtain the encrypted first sensing result. This method can protect the privacy and security of the sensing service data of the first sensing service.

[0030] The sensing entity can refer to the device that participates in the sensing service, including but not limited to: the device that provides the sensing signal for the sensing service (such as the third sensing entity that provides the sensing signal for the first sensing service), or the device that provides the sensing data for the sensing service (such as the first sensing entity that generates the first sensing data based on the first sensing signal), or the device that participates in the privacy calculation for the sensing service (such as the second sensing entity that performs privacy calculation on the first sensing data to obtain the first sensing result), etc.

[0031] It should be noted that the second node can determine one or more first sensing entities and one or more second sensing entities from multiple sensing entities. This application does not limit the number of first sensing entities and second sensing entities determined by the second node.

[0032] Among them, the first sensing entity and the second sensing entity support the first privacy algorithm.

[0033] For example, the second node can be a sensing service control function (SSCF).

[0034] In conjunction with the third aspect, in one possible implementation, the first privacy computing resource information includes a first privacy algorithm and a privacy encryption key, and the first privacy computing resource information also includes a privacy computing key. The second message also includes the privacy computing key, and the privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

[0035] In this embodiment of the application, the first privacy computing resource information sent by the first node to the second node may also include the aforementioned privacy computing key.

[0036] In conjunction with the third aspect, in one possible implementation, before the second node receives the first request, the method further includes: the second node receiving a second request from the first node; and based on the second request, sending a first response message to the first node, the first response message including network-side privacy computing capabilities used to determine the first request.

[0037] In this embodiment of the application, the second node responds to the second request by sending the privacy computing capability of the network side to the first node. Then, the initiator of the first request (i.e. the first node) can select the first privacy algorithm and generate a privacy encryption key based on the privacy computing capability of the network side, which can improve the privacy and security protection of perceived business data.

[0038] In conjunction with the third aspect, in one possible implementation, the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key. The first privacy computing resource information includes the privacy computing capability of the first node and the service security level of the first sensing service. The method further includes: obtaining first information based on at least one of the privacy computing capability of the network side, the privacy computing capability of the first node, and the service security level of the first sensing service. The first information includes the first privacy algorithm and the privacy encryption key.

[0039] In this embodiment, the second node receives information for determining the first privacy algorithm and the privacy encryption key (i.e., the aforementioned first privacy computing resource information), and selects the first privacy algorithm and generates the privacy encryption key based on the first privacy computing resource information.

[0040] In conjunction with the third aspect, in one possible implementation, the first information further includes a privacy decryption key, and the method further includes: the second node sending the privacy decryption key to the first node.

[0041] In conjunction with the third aspect, in one possible implementation, the first message further includes a privacy computing key, and the second message further includes a privacy computing key, which is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

[0042] Fourthly, this application discloses a communication method that can be executed by a third communication device. The third communication device can be a first sensing entity or a module of the first sensing entity (e.g., a chip, chip system, integrated circuit, or control unit), or a software and / or hardware module for implementing the functions of the first sensing entity. Taking the execution of the method by the first sensing entity as an example, the method includes: the first sensing entity receiving a first message from a second node, the first message instructing the first sensing entity to acquire sensing data of a first sensing service, the first message including a first privacy algorithm and a privacy encryption key; then, the first sensing entity performs privacy encryption on second sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key to obtain first sensing data of the first sensing service; the second sensing data is obtained based on the sensing signal of the first sensing service; and the first sensing data is transmitted.

[0043] In this embodiment, the first sensing entity can perform privacy encryption on the second sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key, thereby protecting the privacy and security of the sensing service data of the first sensing service.

[0044] For example, the first sensing entity may be an access network device or a terminal.

[0045] Fifthly, this application discloses a communication method that can be executed by a fourth communication device. This fourth communication device can be a second sensing entity or a module of the second sensing entity (e.g., a chip, chip system, integrated circuit, or control unit), or a software and / or hardware module for implementing the functions of the second sensing entity. Taking the execution of the method by the second sensing entity as an example, the method includes: the second sensing entity receiving a second message from a second node, the second message instructing the second sensing entity to obtain the sensing result of a first sensing service, the second message including a first privacy algorithm; furthermore, the second sensing entity can perform privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm to obtain the first sensing result of the first sensing service; and the second sensing entity sending the first sensing result to a first node.

[0046] In this embodiment of the application, the second sensing entity can perform privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm, thereby protecting the privacy and security of the sensing service data of the first sensing service.

[0047] For example, the second sensing entity can be a RAN or an SDPF.

[0048] Sixthly, this application provides a communication device, which may be a first node or a chip / circuit therein. The communication device is used to perform the methods of the second aspect or any possible implementation thereof. The communication device includes units having the ability to perform the methods of the second aspect or any possible implementation thereof.

[0049] In a seventh aspect, this application provides a communication device, which may be a second node or a chip / circuit therein. The communication device is used to perform the methods in the third aspect or any possible implementation thereof. The communication device includes units having the ability to perform the methods in the third aspect or any possible implementation thereof.

[0050] Eighthly, this application provides a communication device, which may be a first sensing entity or a chip / circuit therein. The communication device is used to perform the methods in the fourth aspect or any possible implementation thereof. The communication device includes units having the ability to perform the methods in the fourth aspect or any possible implementation thereof.

[0051] Ninthly, this application provides a communication device, which may be a second sensing entity or a chip / circuit therein. The communication device is used to perform the methods in the fifth aspect or any possible implementation thereof. The communication device includes units having the ability to perform the methods in the fifth aspect or any possible implementation thereof.

[0052] In the sixth, seventh, eighth, or ninth aspect, the aforementioned communication apparatus may include a transceiver unit and a processing unit. For a detailed description of the transceiver unit and the processing unit, please refer to the apparatus embodiments shown below. The beneficial effects of the sixth to ninth aspects can be referred to the relevant descriptions of the second to fifth aspects, which will not be repeated here.

[0053] In a tenth aspect, this application provides a communication device, which includes a processor for executing the method described in the second aspect, or the third aspect, the fourth aspect, the fifth aspect, or any possible implementation thereof.

[0054] Eleventhly, this application provides a communication device including a processor coupled to a memory storing instructions that, when executed by the processor, cause the communication device to perform the method described in any possible implementation of the second, third, fourth, or fifth aspect above.

[0055] In one possible implementation, the communication device further includes a memory. Optionally, the processor and memory are integrated (i.e., the memory is built-in memory). Optionally, the memory and processor are independently configured (i.e., the memory is external memory).

[0056] In a twelfth aspect, this application provides a communication device that may include a processor and an interface circuit connected together. The interface circuit is used for exchanging (or sending, receiving, or inputting / outputting) information or data, and the processor is used to execute program instructions that cause the communication device to perform the methods described in any possible implementation of the second, third, fourth, or fifth aspect above. The interface circuit may be a communication interface or a transceiver. The transceiver may be a radio frequency module in the communication device, or a combination of a radio frequency module and an antenna, or an input / output interface of a chip or circuit.

[0057] In a thirteenth aspect, this application provides a readable storage medium storing program instructions that, when run on a computer, cause the computer to perform the method described in any possible implementation of the second, third, fourth, or fifth aspect above.

[0058] In a fourteenth aspect, this application provides a program product containing program instructions that, when executed, cause the method described in any possible implementation of the second aspect, or the third aspect, the fourth aspect, the fifth aspect, or any of the aspects above to be performed.

[0059] In a fifteenth aspect, this application provides an apparatus, which can be implemented as a chip or as a device, comprising a processor. The processor is configured to read and execute a program stored in a memory to perform one or more of the second, third, fourth, or fifth aspects described above, or one or more of any possible implementations of any of these aspects, providing an information interaction method. Optionally, the apparatus further includes a memory connected to the processor via a circuit. Further optionally, the apparatus includes a communication interface to which the processor is connected. The communication interface is configured to receive information to be processed, the processor obtains the information from the communication interface, processes the information, and outputs the processing result through the communication interface. The communication interface can be an input / output interface.

[0060] In one possible implementation, the processor and memory can be physically independent units, or the memory can be integrated with the processor.

[0061] In a sixteenth aspect, this application provides a communication system comprising a first node, a second node, a first sensing entity, and a second sensing entity; wherein the first node is configured to execute the method described in the second aspect or any possible implementation thereof, the second node is configured to execute the method described in the third aspect or any possible implementation thereof, the first sensing entity is configured to execute the method described in the fourth aspect or any possible implementation thereof, and the second sensing entity is configured to execute the method described in the fifth aspect or any possible implementation thereof. The technical effects achieved by the above aspects can be referred to mutually or to the beneficial effects in the method embodiments shown below, and will not be repeated here. Attached Figure Description

[0062] Figure 1 is a schematic diagram of the perception scenario provided in an embodiment of this application;

[0063] Figure 2A is a schematic diagram of a communication network structure provided in an embodiment of this application;

[0064] Figures 2B and 2C are schematic diagrams of the perception architecture provided in the embodiments of this application;

[0065] Figure 2D is a schematic diagram of an application scenario provided by an embodiment of this application;

[0066] Figure 3 is a schematic diagram of the system architecture of a communication system provided in an embodiment of this application;

[0067] Figure 4 is a flowchart illustrating a communication method provided in an embodiment of this application;

[0068] Figures 5A and 5B are schematic flowcharts of the communication method provided in the embodiments of this application;

[0069] Figure 6 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0070] Figure 7 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0071] Figure 8 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0072] Figure 9 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0073] Figure 10 is a structural schematic diagram of a communication device provided in an embodiment of this application;

[0074] Figure 11 is another structural schematic diagram of the communication device provided in an embodiment of this application;

[0075] Figure 12 is another structural schematic diagram of the communication device provided in the embodiment of this application. Detailed Implementation

[0076] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0077] In the description of this application, the terms "first," "second," etc., are used only to distinguish different objects and do not limit the quantity or order of execution, nor do they imply that they are necessarily different. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.

[0078] In the description of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. "And / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one item", "one or more of the following", or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent: a, b, c; a and b; a and c; b and c; or a and b and c. Here, a, b, and c can be single or multiple.

[0079] In the description of this application, the words "exemplary" or "for example" are used to indicate that something is an example, illustration, or illustration. Any embodiment or design that is described as "exemplary," "for example," or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of the words "exemplary," "for example," or "for example" is intended to present the relevant concepts in a specific manner.

[0080] It is understood that in the description of this application, "when," "if," and "if" all refer to the device performing a corresponding action under certain objective circumstances, and are not time-limited, nor do they require the device to perform a judgment action when it is implemented, nor do they imply any other limitations. The device performing a corresponding action under certain objective circumstances includes: satisfying the objective circumstances, i.e., being able to perform the corresponding action; or satisfying both the objective circumstances and other circumstances, in order to perform the corresponding action.

[0081] In this application, the use of singular designations for elements is intended to represent "one or more" rather than "one and only one," unless otherwise specified.

[0082] In addition, the terms “system” and “network” are often used interchangeably in this article.

[0083] It is understood that in the various embodiments of this application, expressions such as "A corresponds to B", "A and B correspond", "A corresponds to B" or similar expressions indicate that B is associated with A, and B can be determined based on A. Determining B based on A does not mean that B is determined solely based on A; B can also be determined based on A and / or other information.

[0084] The technical terms and related technologies involved in this application are described below.

[0085] I. Perception

[0086] 1. Wireless sensing (or perception)

[0087] Wireless sensing uses wireless signals for perception. Sensing is the process of collecting, processing, and generating sensing results from data. For example, data can be used to determine the distance, shape, and type of surrounding obstacles, or to determine the breathing rate and heart rate of a monitored object. The collected data can be obtained through sensors or through wireless signals.

[0088] Both wireless sensing and wireless communication are based on electromagnetic wave theory. At the transmitting end, electromagnetic wave signals are modulated, allowing them to carry source information. During propagation, these signals are affected by the wireless environment, meaning they can also carry environmental information. At the receiving end, by analyzing the electromagnetic wave signals, not only can the carried source information be obtained, but also sensing information reflecting the characteristics of the propagation environment can be extracted. In other words, electromagnetic waves inherently possess both communication and sensing capabilities, making integrated sensing and communication (ISAC) possible. ISAC can also be called joint communications and sensing (JCAS) or simply integrated sensing and communication. Compared to systems where sensing and communication are separated, ISAC offers several advantages, such as cost savings, reduced equipment size, lower power consumption, improved frequency efficiency, and reduced mutual interference between communication and sensing.

[0089] 2. Perceiving the Scene

[0090] Perception scenarios can be categorized into perception scenarios based on access network devices, perception scenarios based on both access network devices and terminal devices, and perception scenarios based on terminal devices. For example, the perception scenarios shown in Figure 1 can be considered.

[0091] The sensing scenario shown in Scenario 1 of Figure 1 is a sensing scenario based on access network devices. The access network devices act as both the transmitting (TX) and receiving (RX) ends of the sensing signals. For example, when sensing signal 1 sent by the access network device reaches the target object (e.g., a person), the sensing signal 1 is reflected by the target object, and the access network device can receive sensing signal 2, which can then be processed to obtain the sensing result.

[0092] The sensing scenario shown in Scenario 2 of Figure 1 is also a sensing scenario based on access network devices. One access network device acts as the transmitter (TX) of the sensing signal, and the other access network device acts as the receiver (RX) of the sensing signal. For example, sensing signal 1 transmitted by the access network device acting as TX reaches the target object. After being reflected by the target object, sensing signal 1 can be received by the access network device acting as RX, which can then process sensing signal 2 to obtain the sensing result.

[0093] The sensing scenario shown in Scenario 3 of Figure 1 is a sensing scenario based on access network equipment and terminal equipment. The access network equipment acts as the transmitter of the sensing signal, and the terminal equipment acts as the receiver of the sensing signal. For example, sensing signal 1 sent by the access network equipment reaches the target object. After being reflected by the target object, sensing signal 1 can be received by the terminal equipment as sensing signal 2. The terminal equipment can then process sensing signal 2 to obtain the sensing result.

[0094] The sensing scenario shown in Scenario 4 of Figure 1 is also a sensing scenario based on access network equipment and terminal equipment. The terminal equipment acts as the transmitter of the sensing signal, and the access network equipment acts as the receiver of the sensing signal. For example, sensing signal 1 sent by the terminal equipment reaches the target object. After being reflected by the target object, sensing signal 1 can be received by the access network equipment as sensing signal 2. The access network equipment can then process sensing signal 2 to obtain the sensing result.

[0095] The sensing scenario shown in Scenario 5 of Figure 1 is a sensing scenario based on a terminal device, where the terminal device acts as both the sender and receiver of the sensing signal. For example, sensing signal 1 sent by the terminal device reaches the target object. After being reflected by the target object, sensing signal 1 is received by the terminal device as sensing signal 2, which can then be processed to obtain the sensing result.

[0096] The sensing scenario shown in Scenario 6 of Figure 1 is also a terminal device-based sensing scenario, where one terminal device acts as the transmitter of the sensing signal and the other terminal device acts as the receiver of the sensing signal. For example, sensing signal 1 sent by the terminal device acting as TX reaches the target object. After being reflected by the target object, sensing signal 1 can be received by the terminal device acting as RX, which can then process sensing signal 2 to obtain the sensing result.

[0097] The aforementioned sensing signal 2 can be understood as a reflection signal of the aforementioned sensing signal 1. The sensing signal 2 carries more information than the sensing signal 1. For example, the sensing signal 2 can carry source information and environmental information.

[0098] 3. Sensor network architecture

[0099] The existing 5G network communication mode is developed based on traditional voice services. It is a point-to-point, single-connection communication mode between terminals or between a terminal and a server, providing an on-demand high-speed pipeline service. The RAN (such as gNB) and the core network include the control plane and data plane of the connection, thereby providing this on-demand high-speed pipeline service. As shown in Figure 2A, the RAN connects to the access and mobility management function (AMF) and the user plane function (UPF). The N1 interface serves as a reference point between the user equipment (UE) and the AMF, and is used for control plane signaling interactions between the UE and the AMF, such as non-access-stratum (NAS) signaling. The N2 interface serves as a reference point between the RAN and the AMF, and is used for control plane signaling interactions between the RAN and the AMF, such as the N2 INITIAL UE Message. The N3 interface serves as a reference point between the RAN and the UPF, and is used for user plane data interactions between the RAN and the UPF. The N6 interface serves as the interaction interface between the data network (DN) and the UPF.

[0100] With the rapid development of communication and sensing technologies, sensing-related entities may be introduced into the communication network structure. These entities can also be called sensing function (SF) entities (or simply sensing entities). The network architecture that introduces SF entities can also be called a sensory network structure (or sensing architecture).

[0101] For example, an SF entity may include a sensing control entity and a sensing processing entity. It should be noted that, in the embodiments of this application, the functional module used to receive sensing capability information and orchestrate sensing services can be referred to as the sensing control entity, and the functional module used to process sensing data to obtain sensing results can be referred to as the sensing processing entity. The names "sensing control entity" and "sensing processing entity" are used as examples and do not constitute a limitation on the embodiments of this application. With the development of communication technology and sensing technology, these two modules may adopt other names. For example, the sensing control entity can also be described as a sensing service control function (SSCF), a sensing service control network element, or a sensing control network element, etc.; the sensing processing entity can also be described as a sensing data processing function (SDPF), a sensing data processing network element, or a sensing processing network element, etc. For ease of description, the sensing control entity is described as SSCF and the sensing processing entity is described as SDPF in the following embodiments.

[0102] This application uses the introduction of SSCF and SDPF in the core network architecture of a 5G system as an example, and provides an exemplary description of the perception architecture in conjunction with Figures 2B and 2C. The SSCF can be mounted to the SBI bus via a service-based interface (SBI) to communicate with other core network functional modules; the SDPF can be mounted to the SBI bus via an SBI to communicate with other core network functional modules, or it can communicate via a separate interface, such as communicating with other SDPFs or the SSCF via a separate interface.

[0103] Figure 2B is a schematic diagram of a sensing architecture provided in an embodiment of this application. In this sensing architecture, access network devices can directly connect to a data communication proxy (DCP). Access network device 1 acts as the sensing source, directly transmitting sensing data to the DCP. Access network device 2, after obtaining sensing data from the terminal device, transmits the sensing data to the DCP. The DCP is a new network function introduced to improve data transmission efficiency. The functions of the DCP include: supporting multiple transmission protocols, such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Quick UDP Internet Connection (QUIC), or other transmission protocols; and enabling communication with other devices through interfaces. It should be understood that DCP is merely an example name; other names can be used instead of DCP. Any device with the same function as the DCP can be considered a DCP, and this application does not limit this. The DCP can be deployed as an independent network element in a 3GPP network, or it can be co-located with other network elements or devices in a 3GPP network, and this application does not limit this. Optionally, the DCP can be deployed in the access network or in the core network; this application does not limit this.

[0104] In this sensing architecture, the SSCF can be used to implement control plane functions for sensing services. For example, the SSCF receives sensing capability information of sensing entities and orchestrates sensing services based on this information (including the selection of sensing signal receiving and transmitting entities). The SSCF can be mounted on the SBI bus to communicate with other network elements. The SSCF also registers the services it can provide with the network repository function (NRF).

[0105] SDPF can be used to implement data plane functions for sensing services. For example, SDPF can process sensing data from sensing services to obtain sensing results. SDPF can be mounted to the SBI bus via SBI to communicate with other core network elements, or it can communicate through separate interfaces, such as communicating with other SDPFs or SSCFs via separate interfaces.

[0106] Data storage function (DSF) network elements can store sensing data.

[0107] Among them, the core network elements in this sensing architecture, such as AF, AMF, network exposure function (NEF) network elements, policy control function (PCF) network elements, charging function (CHF) network elements, service communication proxy (SCP) network elements, and sensing service subscriber management (SSSM) network elements, can subscribe to data from DCP as data consumers, or send data to DCP as data producers.

[0108] Figure 2C is a schematic diagram of another sensing architecture provided in an embodiment of this application. This sensing architecture may include terminal devices, access network devices (such as access network device 1 and access network device 2), SSCF, SDPF, SSSM, and AMF, NEF, full name session management function (SMF), PCF, UPF, DN, etc.

[0109] The main difference between the perception architecture shown in Figure 2B and the perception architecture shown in Figure 2C lies in the presence or absence of DCP. For an example of the description of other nodes, please refer to the above text, which will not be repeated here.

[0110] The method provided in this application is applicable to the sensing architecture shown in Figures 2B and 2C. It should be understood that the devices included in the sensing architecture shown in Figures 2B and 2C are merely examples, and the sensing architecture may also include other devices, or may not include some of the devices shown in Figures 2B and 2C; this application does not limit this.

[0111] The embodiments of this application can be applied to 5G systems or future communication systems, satellite communication, and short-range wireless communication systems. The wireless communication systems mentioned in these embodiments include, but are not limited to, the three major application scenarios of 5G / future communication systems: enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and massive machine-type communications (mMTC), as well as long-range (LoRa) systems or vehicle-to-everything (V2X) systems. These embodiments can also be applied to open RAN (ORAN) systems, cloud radio access network (CRAN) systems, etc.

[0112] II. Privacy Computing

[0113] With societal progress and increased awareness of data ownership, the requirements for data privacy protection are becoming increasingly stringent. Data processing and use must comply with regulations such as the General Data Protection Regulation (GDPR). If data is subjected to various security and privacy attacks from internal and external entities, it can pose serious risks.

[0114] Privacy-preserving computation refers to a technological system that enables data analysis and computation while protecting the data itself from external disclosure. It involves numerous fields such as cryptography, distributed computing, artificial intelligence, and data science. Compared to traditional data usage, privacy-preserving computation focuses more on protecting the data usage process and computation results, aiming to maximize data value while ensuring data security. Privacy-preserving computation is a systems engineering technology originating from contemporary cryptography, mathematics, hardware, and other fields. It primarily includes technologies such as multi-party secure computation, homomorphic encryption, trusted execution environments, and federated learning, as well as differential privacy, zero-knowledge proofs, and graph federation.

[0115] Figure 2D is a schematic diagram of an application scenario provided by an embodiment of this application. This scenario includes a key generator, an encryptor, a privacy computer, and a decryptor. The key generator can be a DN or a UE, and the encryptor can also be a DN or a UE. The key generator and encryptor can be the same device or different devices. The privacy computer can be a wireless network, such as a RAN or a core network (CN). The decryptor can be a DN or a UE. As shown in Figure 2D, the key generator can generate a privacy encryption key, a privacy decryption key, and a privacy computer key based on security parameters. It then sends the privacy encryption key to the encryptor, the privacy decryption key to the decryptor, and the privacy computer key to the privacy computer. Taking plaintext m1 as an example, the encryptor can encrypt plaintext m1 based on the privacy encryption key to obtain ciphertext c1. The privacy computer can use function f to perform privacy computers on ciphertext c1 to obtain ciphertext cf. After receiving ciphertext cf, the decryptor can perform privacy decryption on ciphertext cf based on the privacy decryption key to obtain plaintext f(m1).

[0116] In this process, the privacy encryption key and privacy decryption key can be negotiated and generated at the application layer (such as DN or UE), and are only sent to the encryptor and decryptor. The encryptor encrypts the data based on the encryption key, and the decryptor decrypts the ciphertext based on the privacy decryption key. The privacy computation key can be derived from the privacy encryption key and privacy decryption key, and can be sent to the privacy computation party, which performs privacy computation tasks based on the privacy computation key. Therefore, in this process, the wireless network can access but cannot see the application layer data, which can improve privacy protection during the computation phase.

[0117] For ease of description, the parties involved in privacy encryption, privacy decryption, or privacy computation can be referred to as privacy computation nodes. Optionally, each privacy computation node (UE / RAN / NF / independent node) may contain one or more privacy computation enablers (PCEs). A PCE is encapsulated with algorithms (privacy computations such as data processing and model computation, encryption, and decryption), hardware and software resource information, etc., and is a modular unit capable of independently performing privacy computation functions.

[0118] To better understand the communication method and related apparatus proposed in this application, the system architecture of the embodiments of this application is described below.

[0119] Please refer to Figure 3, which is a schematic diagram of the system architecture of a communication system provided in an embodiment of this application.

[0120] The communication system includes a first node (or request initiator), a second node, a first sensing entity (or sensing data source or sensing signal receiver), and a second sensing entity (or privacy computing entity). For example, the first node can be an AF or UE, the second node can be an SSCF, and the second sensing entity can be a RAN or SDPF.

[0121] Optionally, the communication system may include a first sensing entity that can be a UE or a RAN, as exemplified by the six scenarios shown in Figure 1, which are not limited in this application.

[0122] The first node is used to send a first request and to perform privacy decryption on the request result of the first request (or the first perception result or the encrypted perception result) to obtain a second perception result (or the plaintext perception result). The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information, which includes a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key.

[0123] The second node is used to determine the first and second sensing entities based on the first privacy computing resource information and the privacy computing capabilities of multiple sensing entities, and to send a first message to the first sensing entity and a second message to the second sensing entity. The first message is used to instruct the first sensing entity to obtain sensing data of the first sensing service, and the first message includes a first privacy algorithm and a privacy encryption key. The second node sends a second message to the second sensing entity, and the second message is used to instruct the second sensing entity to obtain the sensing results of the first sensing service. The second message includes the first privacy algorithm.

[0124] The first sensing entity is used to obtain the first sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key; the second sensing entity is used to obtain the first sensing result of the first sensing service based on the first privacy algorithm and the first sensing data.

[0125] It should be noted that the number and types of network elements included in the system architecture shown in Figure 3 are merely examples, and the embodiments of this application are not limited thereto. For example, it may also include more or fewer devices communicating with the gateway; for the sake of brevity, they are not described one by one in the figures.

[0126] Furthermore, although the system architecture shown in Figure 3 includes a first node, a second node, a first sensing entity, and a second sensing entity, the system architecture may not be limited to including the first node, the second node, the first sensing entity, and the second sensing entity; it may also include other devices, which this application does not limit.

[0127] Based on the above system architecture, a communication method provided by an embodiment of this application will be described below.

[0128] Please refer to Figure 4, which is a flowchart illustrating a communication method provided in an embodiment of this application.

[0129] In this embodiment, the function is executed by a first node (e.g., AF or UE), which may also be a module within the first node (e.g., a chip, chip system, integrated circuit, or control unit); in this embodiment, the function is executed by a second node (e.g., SSCF), which may also be a module within the second node (e.g., a chip, chip system, integrated circuit, or control unit); the function executed by the first sensing entity in this embodiment may also be executed by a module within the first sensing entity (e.g., a chip, chip system, integrated circuit, or control unit); the function executed by the second sensing entity in this embodiment may also be executed by a module within the second sensing entity (e.g., a chip, chip system, integrated circuit, or control unit).

[0130] As shown in Figure 4, the communication method may include the following steps:

[0131] Step S401: The first node sends a first request to the second node. The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information. The first privacy computing resource information includes a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key.

[0132] Correspondingly, the second node receives the first request from the first node.

[0133] In one possible implementation, the first request may further include first service information of the first sensing service. For example, the first service information may include service type and quality of service (QoS). This application does not limit the specific content of the first service information. The first service information is used to perform the service tasks corresponding to the first sensing service. For example, the first service information is used to determine the sensing entity (such as the second node determining at least one of the first sensing entity, the second sensing entity, or the third sensing entity) and to enable the determined sensing entity to perform the service tasks corresponding to the first sensing service, such as the third sensing entity sending the sensing signal of the first sensing service, the first sensing entity receiving the sensing signal of the first sensing service, and the second sensing entity performing privacy calculations on the sensing data of the first sensing service. In this application, the first request may also be called a sensing service request, and this application does not limit it to that.

[0134] For example, the first node is an AF, a terminal, or a third-party application.

[0135] For example, the first sensing service may be locating a target object, motion monitoring, ambient temperature, or medical imaging, etc.; the first privacy algorithm may be a homomorphic encryption algorithm, a multi-party secure computation algorithm, or a differential privacy algorithm, etc. This application does not limit the first sensing service or the first privacy algorithm.

[0136] In this application, the meaning of "first privacy computing resource" can be: first privacy computing resource information includes a first security context or first privacy computing resource information used to determine a first security context, wherein the first security context includes, but is not limited to, the aforementioned first privacy algorithm and privacy encryption key. For example, the first security context may also include at least one of a privacy decryption key or a privacy computing key.

[0137] The following describes some possible implementation methods for two different implementation methods: the first privacy computing resource information includes the first privacy algorithm and the privacy encryption key (hereinafter referred to as implementation method 1), and the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key (hereinafter referred to as implementation method 2).

[0138] Implementation Method 1: The first privacy computing resource information includes a first privacy algorithm and a privacy encryption key. This implementation method 1 may include some or all of the following possible implementation methods:

[0139] In one possible implementation, before the first node sends the first request to the second node, the first node can obtain the privacy computing capabilities of the network side, which are related to the privacy computing of the first sensing service. Then, based on at least one of the first node's privacy computing capabilities, the network side's privacy computing capabilities, and the service security level of the first sensing service, the first node obtains first information, which includes a first privacy algorithm and a privacy encryption key. That is, the first node is the key generator, selecting the first privacy algorithm and generating the privacy encryption key. This application does not limit the specific implementation of the first node determining the first privacy algorithm and the privacy encryption key.

[0140] The business security level is used to indicate the privacy protection needs or requirements of the sensing business. Optionally, the business security level is related to the anti-hacking capabilities of the sensing business and / or the importance of the data. In this application, the business security level can also be referred to as the privacy protection level, and this application does not limit it to that.

[0141] For example, the first node can obtain network-side privacy computing capabilities from the second node (such as SSCF). For instance, the first node sends a second request to the second node; based on the second request, the second node sends a first response message to the first node, the first response message including the network-side privacy computing capabilities. For example, the network side can refer to one or more network elements that establish communication with the second node, such as RAN or SDPF, etc., and this application does not limit this.

[0142] In one possible implementation, the first node can also obtain the privacy computing capabilities of the terminal. For example, the first node can obtain the privacy computing capabilities of at least one terminal from the second node (such as SSCF). The at least one terminal can be a terminal that has established communication with the second node. The at least one terminal reports its own privacy computing capabilities to the second node. The second node sends the privacy computing capabilities of the network side and the privacy computing capabilities of at least one terminal to the first node. The first node obtains the first information based on at least one of the privacy computing capabilities of the at least one terminal, the privacy computing capabilities of the first node, the privacy computing capabilities of the network side, and the service security level of the first perception service.

[0143] In one possible implementation, the first information may further include a privacy decryption key (i.e., the first node also generates a privacy decryption key); the process by which the first node performs privacy decryption on the first perception result to obtain the second perception result may be: the first node performs privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result. This application embodiment does not limit the specific implementation of the first node generating the privacy decryption key.

[0144] In one possible implementation, the first information also includes a privacy computing key (i.e., the first node also generates a privacy computing key), and the first privacy computing resource information also includes a privacy computing key (i.e., the first node also sends a privacy computing key to the second node).

[0145] Implementation Method 2: First privacy-preserving computational resource information is used to determine the first privacy algorithm and the privacy encryption key. This implementation method 2 may include some or all of the following possible implementation methods:

[0146] In one possible implementation, the first privacy computing resource information includes the privacy computing capabilities of the first node and the service security level of the first sensing service. That is, the first node sends a first request to the second node, the first request being used to request the sensing result of the first sensing service. The first request includes the first privacy computing resource information, which includes the privacy computing capabilities of the first node and the service security level of the first sensing service. The privacy computing capabilities of the first node and the service security level of the first sensing service are used to determine the first privacy algorithm and the privacy encryption key. In this method, the first node sends its own privacy computing capabilities and the security level of the first sensing service to the second node, allowing other nodes (such as the second node) to calculate the first privacy algorithm and the privacy encryption key.

[0147] In one possible implementation, the first node may also receive a privacy decryption key from the second node. For example, the second node may be the key generator, and after generating the privacy decryption key, it sends it to the first node. The process by which the first node performs privacy decryption on the first perception result to obtain the second perception result can be as follows: the first node performs privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result. In this method, after the first node sends its own privacy computing capabilities and the security level of the first perception service to the second node, it receives the privacy decryption key from the second node. That is to say, other nodes (such as the second node) calculate the privacy decryption key based on the first node's privacy computing capabilities and the service security level of the first perception service, and send the privacy decryption key to the first node, such as the privacy decryption key being included in the response message of the first request sent by the second node to the first node.

[0148] It should be noted that this application does not limit the relationship between the privacy computing key and the privacy encryption / decryption key (privacy encryption key and privacy decryption key). For example, the privacy computing key may be unrelated to the privacy encryption / decryption key. This application does not limit the method of generating the privacy computing key. The privacy computing key may be generated by the key generator (i.e., the first node or the second node) or by other network nodes. For example, it may be generated by the privacy computing party itself. For example, the privacy computing party (such as SDPF) may generate the privacy computing key according to the first privacy algorithm and the algorithm parameters. The algorithm parameters may also be sent by the key generator to the privacy computing party. There may be other generation methods, which this application does not limit.

[0149] Step S402: The second node determines the first and second sensing entities from the multiple sensing entities based on the first privacy computing resource information and the privacy computing capabilities of the multiple sensing entities.

[0150] In one implementation, after receiving the first request, the second node obtains first privacy computing resource information from the first request or determines the first privacy computing resource information based on the first request; then, based on the first privacy computing resource information and the privacy computing capabilities of multiple sensing entities, the second node determines one or more first sensing entities and one or more second sensing entities from the multiple sensing entities.

[0151] Optionally, when the sensing scenario is not a scenario where the sensing data source originates and receives data (as shown in scenario 1 and scenario 5 in Figure 1), the second node can also determine one or more sensing signal transmitters (or third sensing entities) from multiple sensing entities.

[0152] In this application, the determination of the first sensing entity and the second sensing entity can also be referred to as the orchestration of sensing services. The orchestration of sensing services may include selecting one of a transmitting sensing entity (such as the third sensing entity), a receiving sensing entity (such as the first sensing entity), or a calculating sensing entity (such as the second sensing entity). The transmitting sensing entity and the receiving sensing entity can be the same sensing entity. The transmitting sensing entity is the transmitting end of the sensing signal, used to transmit the sensing signal; the receiving sensing entity is the receiving end of the sensing signal, used to receive the sensing signal. It should be noted that this application does not limit the number of first sensing entities, second sensing entities, and third sensing entities determined by the second node.

[0153] Among them, the first sensing entity and the second sensing entity support the first privacy algorithm.

[0154] Privacy computing capability can refer to the supported privacy computing algorithms. For example, the privacy computing capability of the first node can refer to the privacy computing algorithms supported by the first node or the privacy computing algorithms that the first node can use. The privacy computing algorithms are used for at least one of privacy encryption, privacy decryption or privacy computing.

[0155] Optionally, the privacy computing capabilities of multiple sensing entities can be pre-acquired by the second node, such as multiple sensing entities reporting their own privacy computing capabilities to the second node. For example, the multiple sensing entities may include access network devices (such as base stations) or terminals.

[0156] The following describes some possible implementation methods for two implementation methods: the first privacy computing resource information includes the first privacy algorithm and the privacy encryption key (hereinafter referred to as implementation method 1), and the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key (hereinafter referred to as implementation method 2).

[0157] Implementation method 1 may include some or all of the following possible implementation methods:

[0158] In one possible implementation, the first privacy computing resource information further includes a privacy computing key. Specifically, the first request sent by the first node to the second node includes a first privacy algorithm, a privacy encryption key, and a privacy computing key; the second message also includes the privacy computing key (i.e., the second message sent by the second node to the second sensing entity includes the first privacy algorithm and the privacy computing key). The privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result. In this implementation, the second sensing entity can perform privacy computing on the first sensing data of the first sensing service based on the first privacy algorithm and the privacy computing key to obtain the first sensing result, as detailed in step S407.

[0159] In one possible implementation, before the second node receives the first request, the second node may also receive a second request from the first node; based on the second request, the second node sends a first response message to the first node, the first response message including the privacy computing capability on the network side, the privacy computing capability on the network side being used to determine the first request.

[0160] Implementation method 2 may include some or all of the following possible implementation methods:

[0161] In one possible implementation, the aforementioned first privacy computing resource information may include the privacy computing capabilities of the first node and the service security level of the first sensing service (i.e., the privacy computing capabilities of the first node and the service security level of the first sensing service are used to determine the first privacy algorithm and the privacy encryption key). Then, the second node obtains first information based on at least one of the network-side privacy computing capabilities, the first node's privacy computing capabilities, and the service security level of the first sensing service. The first information includes the first privacy algorithm and the privacy encryption key. In other words, the second node is the key generator; the second node selects the first privacy algorithm and generates the privacy encryption key. This application does not limit the specific implementation of the second node determining the first privacy algorithm and the privacy encryption key.

[0162] In one possible implementation, the first information may also include a privacy decryption key. Then, the second node sends the privacy decryption key to the first node. The privacy decryption key is used by the first node to perform privacy decryption on the first perception result, as detailed in step S409.

[0163] In one possible implementation, the first message further includes a privacy computing key, and the second message further includes a privacy computing key. The privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

[0164] In this application, the second node can determine the first sensing entity and the second sensing entity by combining more information (such as the first service information of the first sensing service and / or the sensing capability information of multiple sensing entities). For example, the first request also includes the first service information, which the second node obtains from the first request; for example, the above-mentioned sensing capability information includes one or more of the following: device identifier, role identifier, device type, geographic location information, sensing processing capability, and supported sensing service types. Wherein, the device identifier is used to uniquely identify the sensing entity; the role identifier is used to indicate that the sensing entity is a sending sensing entity and / or a receiving sensing entity; the device type is used to indicate that the sensing entity is one or more of the following: network device, user equipment, vehicle-mounted device, IoT device, etc.; the geographic location information is used to indicate the current geographic location of the sensing entity; the sensing processing capability is used to indicate which sensing data the sensing entity can process; and the supported sensing service types are used to indicate the types of sensing services the sensing entity can provide. This application does not limit the method for obtaining more information (such as the first service information and the above-mentioned sensing capability information) or the method for determining the first and second sensing entities.

[0165] Step S403: The second node sends a first message to the first sensing entity. The first message includes a first privacy algorithm and a privacy encryption key.

[0166] Correspondingly, the first sensing entity receives the first message from the second node.

[0167] The first message is used to instruct the first sensing entity to obtain the sensing data of the first sensing service. The first sensing entity is used to obtain the first sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key. For details, please refer to step S405.

[0168] Optionally, the first message may also include first service information of the first sensing service, etc. This application does not limit the information carried by the first message.

[0169] Step S404: The second node sends a second message to the second sensing entity, the second message including the first privacy algorithm.

[0170] Correspondingly, the second sensing entity receives the second message from the second node.

[0171] The second message is used to instruct the second sensing entity to obtain the sensing result of the first sensing service. The second sensing entity is used to obtain the first sensing result of the first sensing service based on the first privacy algorithm and the first sensing data. For details, please refer to step S407.

[0172] Optionally, the second message may also include first service information of the first sensing service, etc. This application does not limit the information carried by the first message.

[0173] Step S405: The first sensing entity performs privacy encryption on the second sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key, thereby obtaining the first sensing data of the first sensing service.

[0174] The second sensing data can be obtained based on the sensing signals from the first sensing service.

[0175] In one implementation, the first sensing entity receives the aforementioned first message from the second node; then, the first sensing entity obtains a first privacy algorithm and a privacy encryption key from the first message; the first sensing entity determines the second sensing data based on the sensing signal of the first sensing service sent by the third sensing entity (or the sending end of the sensing signal); then, the first sensing entity can perform privacy encryption on the second sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key to obtain the first sensing data of the first sensing service.

[0176] Optionally, there can be one or more transmitters of the sensing signal, and the aforementioned second sensing data can be obtained from sensing signals transmitted by one or more transmitters of the sensing signal. Optionally, the first message may also include first service information of the first sensing service, etc. The first sensing entity can receive and process the sensing signal (such as privacy encryption) based on the information carried in the first message. For example, the first sensing entity can receive the sensing signal of the first sensing service based on the time-frequency resource information of the sensing signal, wherein the time-frequency resource information may come from the transmitter of the sensing signal or the second node; based on the first service information, the received sensing signal is measured to obtain the aforementioned first sensing data. This application does not limit the specific implementation of the first sensing entity's reception and processing of the sensing signal.

[0177] In this application, the first sensing entity and the third sensing entity can be the same sensing entity, as shown in scenario 1 or scenario 5 in Figure 1; or the first sensing entity and the second sensing entity can be different sensing entities, as shown in scenario 2, scenario 3, scenario 4, or scenario 6 in Figure 1. This application applies to the six sensing scenarios in Figure 1, and this application does not limit the first sensing entity and the third sensing entity.

[0178] Step S406: The first sensing entity sends the first sensing data to the second sensing entity.

[0179] Correspondingly, the second sensing entity receives the first sensing data from the first sensing entity.

[0180] Step S407: The second sensing entity performs privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm to obtain the first sensing result of the first sensing service.

[0181] In one implementation, the second sensing entity receives first sensing data from the first sensing entity; the second sensing entity receives a second message from a second node; the second sensing entity obtains a first privacy algorithm from the second message; and then, the second sensing entity can perform privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm to obtain the first sensing result of the first sensing service.

[0182] Optionally, there can be one or more first sensing entities. If a second sensing entity receives first sensing data from multiple first sensing entities, the second sensing entity can perform privacy calculations on the multiple first sensing data to obtain the aforementioned first sensing result. The privacy calculations include fusion processing of the multiple first sensing data. This method ensures the privacy and security of data from the fusion processing through privacy calculations, avoiding the risk of privacy leakage caused by the network side fusing plaintext sensing service data.

[0183] Optionally, if the second message also includes a privacy calculation key, the second sensing entity can perform privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm and the privacy calculation key to obtain the first sensing result of the first sensing service.

[0184] Optionally, the second message may also include first service information of the first sensing service, etc. The second sensing entity may process the sensing signal based on the information carried by the second message (such as privacy calculation, etc.). This application does not limit the specific implementation of the second sensing entity's processing of the sensing signal.

[0185] Step S408: The second sensing entity sends the first sensing result to the first node.

[0186] Accordingly, the first node receives the first perception result from the second sensing entity, which is determined based on the first privacy algorithm and the privacy encryption key.

[0187] Step S409: The first node performs privacy decryption on the first perception result to obtain the second perception result.

[0188] In one possible implementation, the first node can perform privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result. The privacy decryption key can be generated by the first node or sent to the first node by the second node. This application does not limit the process of obtaining the privacy decryption key; the process can be exemplarily described above and will not be repeated here.

[0189] In this application, the first sensing data can also be called ciphertext sensing data, the first sensing result can also be called ciphertext sensing result, and the second sensing result can also be called plaintext sensing result.

[0190] The method embodiments shown in Figure 4 above include many possible implementation schemes. Some of these implementation schemes will be illustrated below with reference to Figures 5A to 9. It should be noted that related concepts, operations or logical relationships not explained in Figures 5A to 9 can be referred to the corresponding descriptions in the embodiments shown in Figure 4.

[0191] In this application, the embodiments shown in Figures 5A to 9 can be used as a single embodiment, and the embodiments shown in Figures 5A to 9 can all be independent of the technical solution in Figure 4; some steps in the embodiments shown in Figures 5A to 9 can also be used as a single embodiment.

[0192] Among them, the embodiments of Figures 5A, 6, and 7 take AF as the first node as an example, while Figures 8 and 9 take UE as the first node as an example.

[0193] In this application, the functions performed by the AF can also be performed by modules in the AF (e.g., chips, chip systems, integrated circuits, control units, or software modules). Similarly, the functions performed by the SSCF in this application embodiment can also be performed by modules in the SSCF (e.g., chips, chip systems, integrated circuits, control units, or software modules). Likewise, the functions performed by the SDPF (e.g., SDPF1 or SDPF2) in this application embodiment can also be performed by modules in the SDPF (e.g., chips, chip systems, integrated circuits, control units, or software modules). Furthermore, the functions performed by the RAN (e.g., RAN1 or RAN2) in this application embodiment can also be performed by modules in the RAN (e.g., chips, chip systems, integrated circuits, control units, or software modules). Finally, the functions performed by the UE (e.g., UE1 or UE2) in this application embodiment can also be performed by modules in the UE (e.g., chips, chip systems, integrated circuits, or control units).

[0194] Figure 5A is a flowchart illustrating another communication method provided in an embodiment of this application.

[0195] This application uses an example where the first node is AF (i.e., AF requests a privacy-protected sensing service), the second node is SSCF, the first sensing entity is RAN1 (i.e., the access network device is the sensing data source), and the second sensing entity is SDPF1 to provide a detailed description of the communication method provided in this application. In this application embodiment, the third sensing entity can be an access network device or a terminal. Figure 5A illustrates this using UE1 as an example of the third sensing entity.

[0196] In the embodiments of this application, dashed boxes represent optional steps, such as step S501, which is an optional step.

[0197] As shown in Figure 5A, the method may include the following steps:

[0198] S501: SSCF acquires privacy computing capabilities on the network side.

[0199] Among them, the privacy computing capability on the network side includes the privacy computing capability of at least one sensing entity. For example, at least one sensing entity can be RAN and / or SDPF.

[0200] Optionally, the SSCF can also obtain privacy computing capabilities from the terminal side. For example, the SSCF can also obtain the privacy computing capabilities of at least one UE and the network side. For example, the implementation of step S501 can be seen in Figure 5B. Figure 5B exemplifies at least one UE, at least one RAN (such as an access network device), and at least one SDPF. Step S501 can include at least one of steps S5011 to S5013, whereby at least one UE, at least one RAN, and at least one SDPF report their own privacy computing capabilities to the SSCF. For example, the access network device can report privacy computing capabilities through an access network configuration update; the terminal can carry privacy computing capabilities in a registration request, so that privacy computing capabilities are reported only each time the device joins the network, rather than in each service; the SDPF can report privacy computing capabilities through the SBI interface. This application does not limit the execution order of steps S5011 to S5013.

[0201] S502: AF sends a second request to SSCF. Correspondingly, SSCF receives the second request.

[0202] The second request is used to request privacy-preserving computation capabilities on the network side. In this application, the second request may also be referred to as a network-side privacy-preserving computation capability request.

[0203] S503: The SSCF sends a first response message to the AF, which includes information about the network-side privacy computing capabilities. The AF then receives this first response message.

[0204] In this application, the second request may also be referred to as a network-side privacy computing capability response.

[0205] S504: Based on its own privacy computing capabilities, the network-side privacy computing capabilities, and the business security level, AF determines the first privacy algorithm, the privacy encryption key, the privacy decryption key, and the privacy computing key.

[0206] It should be noted that in the method shown in Figure 5A, the privacy computing key is optional, that is, the information determined by AF may not include the privacy computing key, and the following messages (such as the first request or the first message) may also not include the privacy computing key.

[0207] S505: The AF sends a first request to the SSCF, the first request including a first privacy algorithm, a privacy encryption key, first business information, and a privacy computation key. Accordingly, the SSCF receives the first request.

[0208] The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information, which includes a first privacy algorithm and a privacy encryption key.

[0209] S506: SSCF determines RAN1 and SDPF1 from multiple sensing entities.

[0210] Optionally, the SSCF can determine, based on the first request and the privacy computing capabilities of multiple sensing entities, that the first sensing entity is RAN1, the second sensing entity is SDPF1, and the third sensing entity is UE1. The process of obtaining the privacy computing capabilities of the multiple sensing entities can be found in step S501, and the multiple sensing entities may include at least one of RAN, SDPF, and UE.

[0211] S507: The SSCF sends a first message to the SDPF1, which includes first service information, a privacy computation key, and a first privacy algorithm. The SDPF1 then receives this first message.

[0212] In this application, the first message may also be referred to as the first sensing service control message. The first message may also include the first service information of the first sensing service, such as the service security level.

[0213] S508: The SSCF sends a second message to RAN1, which includes the first service information, the first privacy algorithm, and the privacy encryption key. RAN1 receives the second message accordingly.

[0214] The second message is used to indicate that RAN1 is the receiver of the sensing signal.

[0215] In this application, the second message may also be referred to as the second sensing service control message, and the second message may also include the first service information of the first sensing service, such as the service security level.

[0216] S509: The SSCF sends a third message to UE1, which indicates that UE1 is the transmitter of the sensing signal. The third message includes the first service information. Accordingly, UE1 receives the third message.

[0217] S510: UE1 sends a sensing signal based on a third message. For example, if the first service information is QoS, UE1 determines itself as the sender of the sensing signal based on the third message; then, it determines the configuration information of the sensing signal (such as frequency and period) based on QoS; and sends the sensing signal based on the configuration information.

[0218] S511: RAN1 encrypts the second sensing data based on the privacy encryption key to obtain the first sensing data. The second sensing data is obtained by measuring the sensing signal.

[0219] S512: RAN1 sends the first sensing data to SDPF1. Correspondingly, SDPF1 receives the first sensing data.

[0220] S513: SDPF1 performs privacy calculations on the first perception data based on the first privacy algorithm and the privacy calculation key to obtain the first perception result.

[0221] S514: SDPF1 sends the first sensing result to AF. Correspondingly, AF receives the first sensing result.

[0222] S515: AF decrypts the first perception result based on the privacy decryption key to obtain the second perception result.

[0223] This application embodiment takes the terminal as the transmitting end of the sensing signal (i.e., the third sensing entity mentioned above) and the access network device as the receiving end of the sensing signal (i.e., scenario 4 in Figure 1) as an example. It should be understood that the third sensing entity can also be the access network device (such as RAN1 or other RAN mentioned above). That is, this application embodiment is also applicable to the scenario where the access network device transmits and receives the signal on its own, as well as the scenario where the transmitting end of the sensing signal and the receiving end of the sensing signal are different access network devices, such as scenario 1 or scenario 2 in Figure 1, which will not be elaborated here.

[0224] Figure 6 is a flowchart illustrating another communication method provided in an embodiment of this application.

[0225] This application uses an example where the first node is AF (i.e., AF requests a privacy-protected sensing service), the second node is SSCF, and the second sensing entity is a terminal (UE1 and UE2 as shown in Figure 6, i.e., the terminal is the sensing data source) to describe the communication method provided in this application in detail. In this application embodiment, the first sensing entity can be an access network device or SDPF, and the third sensing entity can be an access network device or a terminal. Figure 6 illustrates this using RAN1 as an example where the first and third sensing entities are RAN1.

[0226] In this application, the steps in Figure 6 that differ from those in Figure 5A are steps S606 to S612. In the embodiment of Figure 5A, the sensing data source is RAN1, while in the embodiment of Figure 6, the sensing data sources are UE1 and UE2. The steps in Figure 6 that are the same as those in Figure 5A can be exemplarily referred to in the relevant content of Figure 5A. As shown in Figure 6, the method may include the following steps:

[0227] S601: SSCF acquires privacy computing capabilities on the network side.

[0228] For example, step S601 can be implemented as shown in Figure 5B, where at least one UE, at least one RAN, and at least one SDPF can report their privacy computing capabilities to the SSCF.

[0229] S602: AF sends a second request to SSCF. SSCF then receives the second request.

[0230] S603: The SSCF sends a first response message to the AF. The AF then receives this first response message.

[0231] The first response message includes privacy computing capabilities on the network side.

[0232] S604: Based on its own privacy computing capabilities, the network-side privacy computing capabilities, and the business security level, AF determines the first privacy algorithm, the privacy encryption key, the privacy decryption key, and the privacy computing key.

[0233] It should be noted that in the method shown in Figure 6, the privacy computing key is optional, that is, the information determined by AF may not include the privacy computing key, and the following messages (such as the first request or the first message) may also not include the privacy computing key.

[0234] S605: AF sends a first request to SSCF. Correspondingly, SSCF receives the first request.

[0235] The first request includes a first privacy algorithm, a privacy encryption key, first business information, and a privacy computation key.

[0236] The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information, which includes a first privacy algorithm and a privacy encryption key.

[0237] The specific implementation of the above steps S601 to S605 can be exemplarily referred to steps S501 to S505, and will not be repeated here.

[0238] S606: SSCF determines RAN1, UE1 and UE2 from multiple sensing entities.

[0239] Optionally, the SSCF can determine, based on the first request and the privacy computing capabilities of multiple sensing entities, that the first sensing entity is RAN1, the second sensing entities are UE1 and UE2, and the third sensing entity is RAN1. The process of obtaining the privacy computing capabilities of the multiple sensing entities can be found in step S501, and the multiple sensing entities may include at least one of RAN, SDPF, and UE.

[0240] Optionally, the SSCF can also determine the SDPF from multiple sensing entities, and the SDPF can pass through the information sent by RAN1 (such as the first sensing result described below) to the AF.

[0241] S607: The SSCF sends a first message to RAN1, which includes first service information, a privacy calculation key, and a first privacy algorithm. RAN1 receives this first message accordingly.

[0242] In this application, the first message may also be referred to as the first sensing service control message. The first message may also include the first service information of the first sensing service, such as the service security level.

[0243] S608: The SSCF sends a second message to UE1 and UE2. The second message includes first service information, a first privacy algorithm, and a privacy encryption key. Accordingly, UE1 and UE2 receive the second message.

[0244] The second message is used to indicate that UE1 and UE2 are the receivers of the sensing signal.

[0245] It should be noted that the SSCF can send a second message to UE1 and UE2 separately, or it can multicast a second message; this application does not limit this.

[0246] Optionally, the SSCF may also send a second message to UE1 and UE2 via the AMF, but this application does not limit this.

[0247] In this application, the second message may also be referred to as the second sensing service control message, and the second message may also include the first service information of the first sensing service, such as the service security level.

[0248] S609: The SSCF sends a third message to RAN1, which indicates that RAN1 is the transmitter of the sensing signal. The third message includes the first service information. Accordingly, RAN1 receives the third message.

[0249] S610: RAN1 transmits sensing signals.

[0250] S611: UE1 and UE2 encrypt the second sensing data using a privacy encryption key to obtain the first sensing data. The second sensing data is obtained by measuring the sensing signal. For example, UE1 and UE2 can each receive a sensing signal from RAN1; then, UE1 and UE2 can obtain the second sensing data based on the received sensing signal; and then, encrypt the second sensing data using a privacy encryption key to obtain the first sensing data. S612: UE1 and UE2 send the first sensing data to RAN1. Correspondingly, RAN1 receives the first sensing data.

[0251] S613: RAN1 performs privacy calculations on the first perception data based on the first privacy algorithm and the privacy calculation key to obtain the first perception result.

[0252] S614: RAN1 sends the first sensing result to AF. Correspondingly, AF receives the first sensing result.

[0253] Optionally, the SSCF can also determine the SDPF from multiple sensing entities; RAN1 can send the first sensing result to the SDPF, and then the SDPF sends the first sensing result to the AF. In this method, the first sensing result is forwarded to the AF through the SDPF, without directly exposing the access network equipment to the outside world, which can ensure the security of the access network equipment (such as RAN1).

[0254] S615: AF decrypts the first perception result based on the privacy decryption key to obtain the second perception result.

[0255] The specific implementation of the above steps S613 to S615 can be exemplarily referred to steps S513 to S515, and will not be repeated here.

[0256] In this embodiment of the application, RAN1 is the transmitting end of the sensing signal (i.e., the third sensing entity mentioned above), and UE1 and UE2 are the receiving ends of the sensing signal (i.e., scenario 3 in Figure 1). It should be understood that the third sensing entity can also be a terminal, such as UE1 or UE2 or other UEs, i.e., scenario 5 and scenario 6 in Figure 1, which will not be elaborated here.

[0257] Figure 7 is a flowchart illustrating another communication method provided in an embodiment of this application.

[0258] This application uses an example where the first node is AF (i.e., AF requests a privacy-protected awareness service), the second node is SSCF, and the second node determines the first privacy algorithm to provide a detailed description of the communication method provided in this application.

[0259] The embodiments of this application do not limit the first sensing entity, the second sensing entity, and the third sensing entity. For example, the first sensing entity can be an access network device or a terminal, the second sensing entity can be an access network device or an SDPF, and the third sensing entity can be an access network device or a terminal. Figure 7 illustrates the example with RAN1 (i.e., the access network device is the sensing data source), SDPF1 as the second sensing entity, and UE1 as the third sensing entity.

[0260] In the embodiments of this application, dashed boxes represent optional steps, such as step S701, which is an optional step.

[0261] In this application, the steps that differ between Figure 7 and Figure 5A are steps S702 to S704. The embodiment in Figure 7 determines the first privacy algorithm and privacy encryption key, etc., by means of the SSCF, while the embodiment shown in Figure 5A determines the first privacy algorithm and privacy encryption key, etc., by means of the AF. The steps in Figure 7 that are the same as those in Figure 5A can be exemplarily referred to in the relevant content of Figure 5A.

[0262] As shown in Figure 7, the method may include the following steps:

[0263] S701: SSCF acquires privacy computing capabilities on the network side.

[0264] For example, step S701 can be implemented as shown in Figure 5B, where at least one UE, at least one RAN, and at least one SDPF can report their privacy computing capabilities to the SSCF.

[0265] S702: The AF sends a first request to the SSCF, which includes the AF's privacy computing capabilities, first business information, and business security level. The SSCF then receives this first request.

[0266] The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information (such as the privacy computing capability of AF mentioned above). The first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key.

[0267] S703: Based on the privacy computing capabilities of AF, the privacy computing capabilities of the network side, and the service security level, SSCF determines the first privacy algorithm, the privacy encryption key, the privacy decryption key, and the privacy computing key.

[0268] It should be noted that in the method shown in Figure 7, the privacy computing key is optional, that is, the information determined by SSCF may not include the privacy computing key, and the following messages (such as the first request or the first message) may also not include the privacy computing key.

[0269] S704: The SSCF sends a privacy decryption key to the AF. The AF then receives the privacy decryption key.

[0270] In one implementation, after generating the privacy decryption key, the SSCF can send a service request response to the AF, which includes the aforementioned privacy decryption key.

[0271] S705: SSCF determines RAN1 and SDPF1 from multiple sensing entities.

[0272] Optionally, the SSCF can determine, based on the first request and the privacy computing capabilities of multiple sensing entities, that the first sensing entity is RAN1, the second sensing entity is SDPF1, and the third sensing entity is UE1. The process of obtaining the privacy computing capabilities of the multiple sensing entities can be found in step S501, and the multiple sensing entities may include at least one of RAN, SDPF, and UE.

[0273] S706: The SSCF sends a first message to the SDPF1, which includes first service information, a privacy computation key, and a first privacy algorithm. The SDPF1 then receives this first message.

[0274] In this application, the first message may also be referred to as the first sensing service control message. The first message may also include the first service information of the first sensing service, such as the service security level.

[0275] S707: The SSCF sends a second message to RAN1, which includes the first service information, the first privacy algorithm, and the privacy encryption key. RAN1 receives the second message accordingly.

[0276] The second message is used to indicate that RAN1 is the receiver of the sensing signal.

[0277] In this application, the second message may also be referred to as the second sensing service control message, and the second message may also include the first service information of the first sensing service, such as the service security level.

[0278] S708: The SSCF sends a third message to UE1. The third message indicates that UE1 is the transmitter of the sensing signal, and includes the first service information. Accordingly, UE1 receives the third message.

[0279] S709: UE1 sends a sensing signal.

[0280] S710: RAN1 encrypts the second sensing data based on the privacy encryption key to obtain the first sensing data. The second sensing data is obtained by measuring the sensing signal.

[0281] S711: RAN1 sends the first sensing data to SDPF1. Correspondingly, SDPF1 receives the first sensing data.

[0282] S712: SDPF1 performs privacy calculations on the first perception data based on the first privacy algorithm and the privacy calculation key to obtain the first perception result.

[0283] S713: SDPF1 sends the first sensing result to AF. Correspondingly, AF receives the first sensing result.

[0284] S714: AF decrypts the first perception result based on the privacy decryption key to obtain the second perception result.

[0285] The specific implementation of steps S705 to S714 can be exemplarily described in steps S506 to S515, and will not be repeated here.

[0286] This application embodiment takes the terminal as the transmitting end of the sensing signal (i.e., the third sensing entity mentioned above) and the access network device as the receiving end of the sensing signal (i.e., scenario 4 in Figure 1) as an example. This application embodiment is also applicable to any other scenario in Figure 1 except scenario 4. The implementation of other scenarios can be found in the relevant description above, and will not be repeated here.

[0287] It should be noted that the examples in Figures 5A and 7 use UE1, RAN1 and SDPF1 as examples, which does not mean that the sensing entities determined in Figures 5A and 7 are the same. The examples in Figures 5A and 7 should not constitute a limitation on the selection of sensing entities.

[0288] Figure 8 is a flowchart illustrating another communication method provided in an embodiment of this application.

[0289] This application takes the first node as the terminal (such as UE2, i.e., the terminal requests a privacy-protected sensing service) and the first node determines the first privacy algorithm as an example to provide a detailed description of the communication method provided in this application.

[0290] This application embodiment does not limit the second node, the first sensing entity, the second sensing entity, and the third sensing entity. For example, the second node can be an SSCF, the first sensing entity can be an access network device or a terminal, the second sensing entity can be an access network device or an SDPF, and the third sensing device can be an access network device or a terminal. This application embodiment is applicable to any scenario in Figure 1.

[0291] Figure 8 illustrates the case with the second node being SSCF, the first sensing entity being RAN2 (i.e., the access network equipment is the sensing data source), and the second sensing entity being SDPF2 as an example.

[0292] In the embodiments of this application, dashed boxes represent optional steps, such as step S801, which is an optional step.

[0293] As shown in Figure 8, the method may include the following steps:

[0294] S801: SSCF acquires privacy computing capabilities on the network side.

[0295] For example, step S801 can be implemented as shown in Figure 5B, where at least one UE, at least one RAN, and at least one SDPF can report their privacy computing capabilities to the SSCF.

[0296] S802: UE2 sends a second request to the SSCF. The SSCF then receives the second request.

[0297] S803: The SSCF sends a first response message to UE2, which includes the network-side privacy computing capabilities. UE2 then receives this first response message.

[0298] S804: Based on its own privacy computing capabilities, the network-side privacy computing capabilities, and the service security level, UE2 determines the first privacy algorithm, the privacy encryption key, the privacy decryption key, and the privacy computing key.

[0299] It should be noted that in the method shown in Figure 8, the privacy calculation key is optional, that is, the information determined by UE2 may not include the above privacy calculation key, and the following messages (such as the first request or the first message) may also not include the above privacy calculation key.

[0300] S805: UE2 sends a first request to SSCF, the first request including a first privacy algorithm, a privacy encryption key, first service information, and a privacy computation key. Correspondingly, SSCF receives the first request.

[0301] The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information, which includes a first privacy algorithm and a privacy encryption key.

[0302] S806: SSCF determines RAN2 and SDPF2 from multiple sensing entities.

[0303] Optionally, the SSCF can determine the first sensing entity as RAN2 and the second sensing entity as SDPF2 from the multiple sensing entities based on the first request and the privacy computing capabilities of the multiple sensing entities. The process of obtaining the privacy computing capabilities of the multiple sensing entities can be found in step S501, and the multiple sensing entities may include at least one of RAN, SDPF, and UE.

[0304] S807: The SSCF sends a first message to the SDPF2, which includes first service information, a privacy computation key, and a first privacy algorithm. The SDPF2 then receives this first message.

[0305] In this application, the first message may also be referred to as the first sensing service control message. The first message may also include the first service information of the first sensing service, such as the service security level.

[0306] S808: The SSCF sends a second message to RAN2, which includes the first service information, the first privacy algorithm, and the privacy encryption key. RAN2 receives the second message accordingly.

[0307] The second message indicates that RAN1 is the receiver of the sensing signal. It should be noted that in other embodiments of this application, the second message may also indicate that RAN1 is simultaneously the transmitter of the sensing signal, i.e., a self-transmitting and self-receiving scenario.

[0308] In this application, the second message may also be referred to as the second sensing service control message, and the second message may also include the first service information of the first sensing service, such as the service security level.

[0309] For example, assuming the third sensing entity is UE1, the SSCF can send a third message to UE1. The third message is used to indicate that UE1 is the sender of the sensing signal. The third message includes first service information. Based on the third message, UE1 sends the sensing signal.

[0310] S809: RAN2 encrypts the second sensing data based on the privacy encryption key to obtain the first sensing data. The second sensing data is obtained by measuring the sensing signal.

[0311] S810: RAN2 sends the first sensing data to SDPF2. Correspondingly, SDPF2 receives the first sensing data.

[0312] S811: SDPF2 performs privacy calculations on the first perception data based on the first privacy algorithm and the privacy calculation key to obtain the first perception result.

[0313] S812: SDPF2 sends the first sensing result to UE2. Correspondingly, UE2 receives the first sensing result.

[0314] S813: UE2 decrypts the first perception result based on the privacy decryption key to obtain the second perception result.

[0315] In this embodiment of the application, the steps performed by UE2 can be referred to the relevant description of AF in Figure 7, and the steps performed by other nodes can be referred to the relevant description of other nodes in Figure 7.

[0316] Figure 9 is a flowchart illustrating another communication method provided in an embodiment of this application.

[0317] This application uses an example where the first node is the terminal (e.g., UE2, i.e., the terminal requests a privacy-protected awareness service) and the second node (e.g., SSCF) determines the first privacy algorithm to provide a detailed description of the communication method provided in this application.

[0318] This application embodiment does not limit the second node, the first sensing entity, the second sensing entity, and the third sensing entity. For example, the second node can be an SSCF, the first sensing entity can be an access network device or a terminal, the second sensing entity can be an access network device or an SDPF, and the third sensing device can be an access network device or a terminal. This application embodiment is applicable to any scenario in Figure 1.

[0319] Figure 9 illustrates the example with the second node being SSCF, the first sensing entity being RAN2 (i.e., the access network equipment being the sensing data source), and the second sensing entity being SDPF2.

[0320] In the embodiments of this application, dashed boxes represent optional steps, such as step S901, which is an optional step.

[0321] In this application, the steps in Figure 9 that differ from those in Figure 8 are steps S902 to S904. The embodiment in Figure 9 determines the first privacy algorithm and privacy encryption key, etc., by the SSCF, while the embodiment in Figure 8 determines the first privacy algorithm and privacy encryption key, etc., by the UE2. As shown in Figure 9, the method may include the following steps:

[0322] S901: SSCF acquires privacy computing capabilities on the network side.

[0323] For example, step S901 can be implemented as shown in Figure 5B, where at least one UE, at least one RAN, and at least one SDPF can report their privacy computing capabilities to the SSCF.

[0324] S902: UE2 sends a first request to SSCF, which includes UE2's privacy computing capabilities, first service information, and service security level. Accordingly, SSCF receives the first request.

[0325] The first request is used to request the perception result of the first perception service. The first request includes first privacy computing resource information (such as the privacy computing capability of UE2 mentioned above). The first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key.

[0326] S903: Based on UE2's privacy computing capabilities, network-side privacy computing capabilities, and service security levels, SSCF determines the first privacy algorithm, privacy encryption key, privacy decryption key, and privacy computing key.

[0327] It should be noted that in the method shown in Figure 9, the privacy computing key is optional, that is, the information determined by the SSCF may not include the privacy computing key, and the following messages (such as the first request or the first message) may also not include the privacy computing key.

[0328] S904: The SSCF sends a privacy decryption key to UE2. UE2 then receives the privacy decryption key.

[0329] In one implementation, after generating the privacy decryption key, the SSCF can send a service request response to the UE2, which includes the aforementioned privacy decryption key.

[0330] S905: SSCF determines RAN2 and SDPF2 from multiple sensing entities.

[0331] Optionally, the SSCF can determine the first sensing entity as RAN2 and the second sensing entity as SDPF2 from the multiple sensing entities based on the first request and the privacy computing capabilities of the multiple sensing entities. The process of obtaining the privacy computing capabilities of the multiple sensing entities can be found in step S501, and the multiple sensing entities may include at least one of RAN, SDPF, and UE.

[0332] S906: The SSCF sends a first message to the SDPF2, which includes first service information, a privacy computation key, and a first privacy algorithm. The SDPF2 then receives this first message.

[0333] In this application, the first message may also be referred to as the first sensing service control message. The first message may also include the first service information of the first sensing service, such as the service security level.

[0334] S907: The SSCF sends a second message to RAN2, which includes the first service information, the first privacy algorithm, and the privacy encryption key. RAN2 receives the second message accordingly.

[0335] The first message is used to indicate that RAN1 is the receiver of the sensing signal.

[0336] In this application, the second message may also be referred to as the second sensing service control message, and the second message may also include the first service information of the first sensing service, such as the service security level.

[0337] For example, assuming the third sensing entity is UE1, the SSCF can send a third message to UE1. The third message is used to indicate that UE1 is the sender of the sensing signal. The third message includes first service information. Based on the third message, UE1 sends the sensing signal.

[0338] S908: RAN2 encrypts the second sensing data based on the privacy encryption key to obtain the first sensing data. The second sensing data is obtained by measuring the sensing signal.

[0339] S909: RAN2 sends the first sensing data to SDPF2. Correspondingly, SDPF2 receives the first sensing data.

[0340] S910: SDPF2 performs privacy calculations on the first perception data based on the first privacy algorithm and the privacy calculation key to obtain the first perception result.

[0341] S911: SDPF2 sends the first sensing result to UE2. Accordingly, UE2 receives the first sensing result.

[0342] S912: UE2 decrypts the first perception result based on the privacy decryption key to obtain the second perception result.

[0343] In this embodiment of the application, the steps performed by UE2 can be referred to the relevant description of AF in Figure 7, and the steps performed by other nodes can be referred to the relevant description of other nodes in Figure 7.

[0344] The foregoing details the method provided in this application. To facilitate the implementation of the above-described solutions in the embodiments of this application, corresponding apparatus or devices are also provided in the embodiments of this application.

[0345] This application divides the first node, second node, first sensing entity, and second sensing entity into functional modules according to the above method embodiments. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated modules can be implemented in hardware or as software functional modules. It should be noted that the module division in this application is illustrative and only represents one logical functional division; other division methods may be used in actual implementation. The communication device of the embodiment of this application will be described in detail below with reference to Figures 10 to 12.

[0346] Referring to Figure 10, which is a schematic diagram of a communication device provided in an embodiment of this application, the communication device may include a transceiver unit 10 and a processing unit 20.

[0347] In some embodiments of this application, the communication device may be the first node shown above, or a chip or circuit disposed in the first node. That is, the communication device may be used to perform the steps or functions performed by the first node in the method embodiments described above.

[0348] In one design, the transceiver unit 10 is configured to: send a first request, the first request being used to request the perception result of a first perception service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; receive a first perception result of the first perception service from a second perception entity, the first perception result being determined based on the first privacy algorithm and the privacy encryption key; and perform privacy decryption on the first perception result to obtain a second perception result.

[0349] In one possible implementation, the first privacy computing resource information includes a first privacy algorithm and a privacy encryption key. The processing unit 20 is used to: obtain the privacy computing capabilities of the network side, which are related to the privacy computing of the first sensing service; and obtain first information based on at least one of the privacy computing capabilities of the first node, the privacy computing capabilities of the network side, and the service security level of the first sensing service. The first information includes the first privacy algorithm and the privacy encryption key.

[0350] Optionally, the first information also includes a privacy decryption key; the processing unit 20 is specifically used for: the first node to perform privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result.

[0351] Optionally, the first information may also include a privacy computing key, and the first privacy computing resource information may also include the privacy computing key.

[0352] Optionally, the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key. The first privacy computing resource information includes the privacy computing capabilities of the first node and the business security level of the first sensing service.

[0353] In one possible implementation, the transceiver unit 10 is further configured to: receive a privacy decryption key from the second node; the processing unit 20 is specifically configured to: perform privacy decryption on the first perception result based on the privacy decryption key to obtain a second perception result.

[0354] Optionally, the first request may also include first business information of the first sensing service, which is used to execute the business task corresponding to the first sensing service.

[0355] Optionally, the first node can be an application function AF, a terminal, or a third-party application.

[0356] In this application embodiment, the description of the first privacy computing resource information and the first request, etc., can be referred to the description in the method embodiment shown in Figures 4 to 9 above, and will not be described in detail here.

[0357] It is understood that the specific descriptions of the transceiver unit 10 and processing unit 20 shown in the embodiments of this application are merely examples. For the specific functions or execution steps of the transceiver unit 10 and processing unit 20, please refer to the method embodiments shown in Figures 4 to 9 above, which will not be described in detail here. In addition, the technical effects of the embodiments of this application are the same as those in the method embodiments shown in Figures 4 to 9 above, and will not be repeated here for the sake of brevity.

[0358] Reusing Figure 10, in some embodiments of this application, the communication device may be the second node shown above, or a chip or circuit disposed in the second node. That is, the communication device may be used to perform the steps or functions performed by the second node in the method embodiments above.

[0359] In one design, the transceiver unit 10 is configured to: receive a first request, the first request being used to request the perception result of a first sensing service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; the processing unit 20 is configured to: determine a first sensing entity and a second sensing entity from multiple sensing entities based on the first privacy computing resource information and the privacy computing capabilities of multiple sensing entities; the transceiver unit 10 is further configured to: send a first message to the first sensing entity, the first message being used to instruct the first sensing entity to obtain the perception data of the first sensing service, the first message including the first privacy algorithm and the privacy encryption key, the first sensing entity being used to obtain the first perception data of the first sensing service based on the first privacy algorithm and the privacy encryption key; and send a second message to the second sensing entity, the second message being used to instruct the second sensing entity to obtain the perception result of the first sensing service, the second message including the first privacy algorithm, the second sensing entity being used to obtain the first perception result of the first sensing service based on the first privacy algorithm and the first perception data.

[0360] In one possible implementation, the first privacy computing resource information includes a first privacy algorithm and a privacy encryption key, and the first privacy computing resource information also includes a privacy computing key. The second message also includes the privacy computing key, and the privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

[0361] In one possible implementation, before the second node receives the first request, the transceiver unit 10 is further configured to: receive a second request from the first node; and based on the second request, send a first response message, the first response message including privacy computing capabilities on the network side, the privacy computing capabilities on the network side being used to determine the first request.

[0362] In one possible implementation, the first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key. The first privacy computing resource information includes the privacy computing capability of the first node and the service security level of the first sensing service. The processing unit 20 is further used to: obtain first information based on at least one of the privacy computing capability of the network side, the privacy computing capability of the first node, and the service security level of the first sensing service. The first information includes the first privacy algorithm and the privacy encryption key.

[0363] Optionally, the first information may also include a privacy decryption key, and the method may further include: the second node sending the privacy decryption key to the first node.

[0364] Optionally, the first message may also include a privacy computing key, and the second message may also include a privacy computing key. The privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

[0365] In this application embodiment, the description of the first privacy computing resource information and the first request, etc., can be referred to the description in the method embodiment shown in Figures 4 to 9 above, and will not be described in detail here.

[0366] It is understood that the specific descriptions of the transceiver unit 10 and processing unit 20 shown in the embodiments of this application are merely examples. For the specific functions or execution steps of the transceiver unit 10 and processing unit 20, please refer to the method embodiments shown in Figures 4 to 9 above, which will not be described in detail here. In addition, the technical effects of the embodiments of this application are the same as those in the method embodiments shown in Figures 4 to 9 above, and will not be repeated here for the sake of brevity.

[0367] Reusing Figure 10, in some embodiments of this application, the communication device may be the first sensing entity shown above or a chip or circuit disposed in the first sensing entity. That is, the communication device may be used to perform the steps or functions performed by the first sensing entity in the method embodiments described above.

[0368] In one design, the transceiver unit 10 is configured to: receive a first message, the first message being used to instruct a first sensing entity to acquire sensing data of a first sensing service, the first message including a first privacy algorithm and a privacy encryption key; the processing unit 20 is configured to: perform privacy encryption on the second sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key, to obtain the first sensing data of the first sensing service; the second sensing data is obtained based on the sensing signal of the first sensing service; the transceiver unit 10 is further configured to: send the first sensing data.

[0369] In this application embodiment, the description of the first message and the first privacy algorithm, etc., can be referred to the description in the method embodiment shown in Figures 4 to 9 above, and will not be described in detail here.

[0370] It is understood that the specific descriptions of the transceiver unit 10 and processing unit 20 shown in the embodiments of this application are merely examples. For the specific functions or execution steps of the transceiver unit 10 and processing unit 20, please refer to the method embodiments shown in Figures 4 to 9 above, which will not be described in detail here. In addition, the technical effects of the embodiments of this application are the same as those in the method embodiments shown in Figures 4 to 9 above, and will not be repeated here for the sake of brevity.

[0371] Reusing Figure 10, in some embodiments of this application, the communication device may be the second sensing entity shown above, or a chip or circuit disposed in the second sensing entity. That is, the communication device may be used to perform the steps or functions performed by the second sensing entity in the method embodiments above.

[0372] In one design, the transceiver unit 10 is configured to: receive a second message, the second message being used to instruct a second sensing entity to obtain the sensing result of a first sensing service, the second message including a first privacy algorithm; the processing unit 20 is configured to: perform privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm to obtain the first sensing result of the first sensing service; the transceiver unit 10 is further configured to: send the first sensing result.

[0373] In this application embodiment, the description of the second message and the first perception result, etc., can be referred to the description in the method embodiment shown in Figures 4 to 9 above, and will not be described in detail here.

[0374] It is understood that the specific descriptions of the transceiver unit 10 and processing unit 20 shown in the embodiments of this application are merely examples. For the specific functions or execution steps of the transceiver unit 10 and processing unit 20, please refer to the method embodiments shown in Figures 4 to 9 above, which will not be described in detail here. In addition, the technical effects of the embodiments of this application are the same as those in the method embodiments shown in Figures 4 to 9 above, and will not be repeated here for the sake of brevity.

[0375] The foregoing has described the first node, second node, first sensing entity, and second sensing entity of the embodiments of this application. The following describes possible product forms of the first node, second node, first sensing entity, and second sensing entity. It should be understood that any product possessing the functions of the first node, second node, first sensing entity, and second sensing entity falls within the protection scope of the embodiments of this application. It should also be understood that the following descriptions are merely examples and do not limit the product form of the communication device in the embodiments of this application to these specific examples.

[0376] In one possible implementation, in the communication device shown in FIG10, the processing unit 20 can be a processing circuit, and the transceiver unit 10 can be a communication circuit. The processing circuit can be one or more processors, or all or part of the control or processing circuitry within one or more processors. When the communication device is a first node, a second node, a first sensing entity, or a second sensing entity, the communication circuit can be a transceiver circuit, which can be a transceiver. When the communication device is a chip or a chip system, the communication circuit can be an interface circuit. When the communication device is a server, the communication circuit can be an interface circuit or a transceiver circuit. The transceiver unit 10 can also be a sending unit and / or a receiving unit. The sending unit can be a sending circuit, and the receiving unit can be a receiving circuit, integrated into a single device. In this embodiment, the processing circuit and the communication circuit can be coupled, etc., and the connection method between the processing circuit and the communication circuit is not limited in this embodiment. During the execution of the above method, the process of sending information in the above method can be understood as the process of the processing circuit outputting the above information. When outputting the above information, the processing circuit outputs the above information to the communication circuit for transmission by the communication circuit. After the aforementioned information is output by the processing circuit, it may require further processing before reaching the communication circuit. Similarly, the process of receiving information in the above method can be understood as the process by which the processing circuit receives the input information. When the processing circuit receives the input information, the communication circuit receives the information and inputs it into the processing circuit. Furthermore, after the communication circuit receives the information, it may require further processing before being input into the processing circuit.

[0377] In one possible implementation, in the communication device shown in FIG10, the processing unit 20 may be one or more processors, and the transceiver unit 10 may be a transceiver, or the transceiver unit 10 may also be a transmitting unit and / or a receiving unit. The transmitting unit may be a transmitter, and the receiving unit may be a receiver. The transmitting unit and the receiving unit are integrated into one device, such as a transceiver. In the embodiments of this application, the processor and the transceiver may be coupled, etc., and the connection method of the processor and the transceiver is not limited in the embodiments of this application. In the process of executing the above method, the process of sending information in the above method can be understood as the process of the processor outputting the above information. When outputting the above information, the processor outputs the above information to the transceiver so that the transceiver can transmit it. After the above information is output by the processor, it may need to undergo other processing before reaching the transceiver. Similarly, the process of receiving information in the above method can be understood as the process of the processor receiving the input above information. When the processor receives the input information, the transceiver receives the above information and inputs it into the processor. Furthermore, after the transceiver receives the aforementioned information, the information may need to undergo further processing before being input into the processor.

[0378] Referring to Figure 11, which is another structural schematic diagram of the communication device provided in an embodiment of this application, the communication device provided in this application embodiment can be used to implement the methods described in the above method embodiments, as can be seen from the description in the above method embodiments. The communication device can be a first node, a second node, a first sensing entity, a second sensing entity, or a chip therein. Exemplarily, the communication device includes one or more processors 1001. Optionally, the communication device may further include a memory 1003. Optionally, the communication device may further include a transceiver 1002. In one implementation, the communication device further includes an input / output device (not shown in Figure 11).

[0379] The processor 1001 is mainly used to process communication protocols and communication data, control the entire communication device, execute software programs, and process the data of the software programs. The memory 1003 is mainly used to store software programs and data. In one possible implementation, the transceiver 1002 may include control circuitry and an antenna; the transceiver may also be a communication circuit, a communication interface, an input / output interface, or chip pins. The control circuitry is mainly used for converting baseband signals to radio frequency signals and processing radio frequency signals. The antenna is mainly used for transmitting and receiving radio frequency signals in the form of electromagnetic waves. Input / output devices, such as touchscreens, displays, and keyboards, are mainly used for receiving user input data and outputting data to the user.

[0380] In one possible implementation, the processor 1001 can read the software program in the memory 1003, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be transmitted wirelessly, the processor 1001 performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit then performs RF processing on the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor 1001. The processor 1001 converts the baseband signal into data and processes the data.

[0381] In another implementation, the radio frequency circuit and antenna can be set up independently of the processor that performs baseband processing. For example, in a distributed scenario, the radio frequency circuit and antenna can be arranged in a remote manner, independent of the communication device.

[0382] In one possible implementation, the processor 1001, transceiver 1002, and memory 1003 can be connected via a communication bus.

[0383] For example, when the communication device is used to execute the steps, methods or functions performed by the first node in the embodiment shown in FIG4, the transceiver 1002 can be used to execute steps S401 and S408 in FIG4, and the processor 1001 can be used to execute step S409 in FIG4.

[0384] For example, when the communication device is used to execute the steps, methods or functions performed by the second node in the embodiment shown in FIG4, the transceiver 1002 can be used to execute steps S403 and S404 in FIG4, and the processor 1001 can be used to execute step S402 in FIG4.

[0385] For example, when the communication device is used to perform the steps, methods or functions performed by the first sensing entity in the embodiment shown in FIG4, the transceiver 1002 can be used to perform step S406 in FIG4, and the processor 1001 can be used to perform step S405 in FIG4.

[0386] For example, when the communication device is used to execute the steps, methods or functions performed by the second sensing entity in the embodiment shown in FIG4, the transceiver 1002 can be used to execute steps S404, S406 and S408 in FIG4, and the processor 1001 can be used to execute step S407 in FIG4.

[0387] In any of the above implementations, the processor 1001 may include a transceiver for implementing receiving and transmitting functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing receiving and transmitting functions may be separate or integrated. The aforementioned transceiver circuit, interface, or interface circuit can be used for reading and writing code / data, or it can be used for transmitting or relaying signals.

[0388] In any of the above implementations, the processor 1001 may store instructions, which may be computer programs. These computer programs, running on the processor 1001, cause the communication device to execute the methods described in the above method embodiments. The computer program may be embedded in the processor 1001; in this case, the processor 1001 may be implemented in hardware.

[0389] In one implementation, the communication device may include circuitry that performs the functions of transmitting, receiving, or communicating as described in the foregoing method embodiments. The processor and transceiver described in this application can be implemented on integrated circuits (ICs), analog ICs, radio frequency integrated circuits (RFICs), mixed-signal ICs, application-specific integrated circuits (ASICs), printed circuit boards (PCBs), electronic devices, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductors (CMOS), n-metal-oxide-semiconductor (NMOS), positive channel metal oxide semiconductors (PMOS), bipolar junction transistors (BJTs), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.

[0390] For example, the processor described in this application may include one or more of the following: a central processing unit (CPU), an ASIC, a digital signal processor (DSP), a microprocessor unit (MPU), a microcontroller unit (MCU), a graphics processing unit (GPU), a field-programmable gate array (FPGA), an artificial intelligence processor (AI processor), or a neural processing unit (NPU). It is understood that the communication device shown in the embodiments of this application may also have more components than those in Figure 11, and this application embodiment does not limit this. The methods performed by the processor and transceiver shown above are merely examples; for the specific steps performed by the processor and transceiver, please refer to the description of the method embodiments above.

[0391] In another possible implementation, the communication device provided in this application embodiment may include one or more processors and a memory. The processor is used to execute a program stored in the memory, and when the program is executed, the method embodiment described above is performed. Exemplarily, the processor and memory may also be integrated into a single device, i.e., the processor and memory may be integrated together.

[0392] For example, the memory described in this application (e.g., memory 1003) may include, but is not limited to, cache, read-only memory (ROM), random access memory (RAM), synchronous dynamic random access memory (SDRAM), hard disk drive (HDD) or solid-state drive (SSD), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM), etc. Memory is any other medium capable of carrying or storing desired program code having an instruction or data structure form and accessible by a computer, but is not limited thereto. The memory in the embodiments of this application may also be a circuit or any other means capable of implementing storage functions for storing computer programs or instructions, and / or data.

[0393] For more details about the processor and memory, please refer to the relevant information about processor 1001 and memory 1003 in Figure 11.

[0394] In another possible implementation, the communication device shown in Figure 11 may further include a processing unit, which may be one or more logic circuits. The transceiver unit 10 may be an input / output interface, or a communication interface, or an interface circuit, or an interface, etc. Alternatively, the transceiver unit 10 may also be a transmitting unit and a receiving unit. The transmitting unit may be an output interface, and the receiving unit may be an input interface. The transmitting unit and the receiving unit are integrated into one unit, such as an input / output interface.

[0395] Referring to Figure 12, which is another structural schematic diagram of the communication device provided in an embodiment of this application, the communication device shown in Figure 12 includes a logic circuit 901 and an interface 902. That is, the processing unit described above can be implemented using the logic circuit 901, and the transceiver unit 10 can be implemented using the interface 902. The logic circuit 901 can be a chip, processing circuit, integrated circuit, or system-on-chip (SoC) chip, etc., and the interface 902 can be a communication interface, input / output interface, pins, etc. For example, Figure 12 illustrates the communication device as a chip, which includes the logic circuit 901 and the interface 902.

[0396] In this embodiment, the logic circuit and the interface can also be coupled to each other. The specific connection method between the logic circuit and the interface is not limited in this embodiment.

[0397] For example, when the communication device is used to execute the steps, methods, or functions performed by the first node in the method embodiment shown in Figure 4 above, the interface 902 is used to transmit the first request and the first perception result; the logic circuit is used to perform privacy decryption on the first perception result to obtain the second perception result.

[0398] For example, when the communication device is used to execute the steps, methods, or functions performed by the second node in the method embodiment shown in FIG4 above, the interface 902 is used to transmit the first request, the first message, and the second information; the logic circuit is used to determine the first sensing entity and the second sensing entity from the multiple sensing entities based on the first privacy computing resource information and the privacy computing capabilities of the multiple sensing entities.

[0399] For example, when the communication device is used to execute the steps, methods, or functions performed by the first sensing entity in the method embodiment shown in FIG4 above, the interface 902 is used to transmit the first message and the first sensing data; the logic circuit is used to perform privacy encryption on the second sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key to obtain the first sensing data of the first sensing service.

[0400] For example, when the communication device is used to execute the steps, methods, or functions performed by the second sensing entity in the method embodiment shown in FIG4 above, the interface 902 is used to transmit the second message, the first sensing data, and the first sensing result; the logic circuit is used to perform privacy calculations on the first sensing data of the first sensing service based on the first privacy algorithm to obtain the first sensing result of the first sensing service.

[0401] In this embodiment of the application, the description of the first request, etc., can be referred to the description in the method embodiment shown in Figure 4 above, and will not be described in detail here. It is understood that the specific description of the logic circuit 901 and the interface 902 can also be referred to the description of the processing unit and transceiver unit shown in Figure 10, and will not be repeated here.

[0402] It is understood that the communication device shown in the embodiments of this application can implement the method provided in the embodiments of this application in hardware form or in software form, etc., and the embodiments of this application do not limit it in this way.

[0403] For specific implementation methods of the various embodiments shown in Figure 12, please refer to the above embodiments, which will not be described in detail here.

[0404] This application also provides a communication system, which includes a first node, a second node, a first sensing entity, and a second sensing entity. The first node, the second node, the first sensing entity, and the second sensing entity can be used to execute the methods in any of the foregoing method embodiments (Figures 4 to 9).

[0405] In addition, this application also provides a computer program for implementing the operations and / or processes performed by communication devices (such as the first node, second node, first sensing entity and second sensing entity described above) in the method provided in this application.

[0406] This application also provides a computer-readable storage medium storing computer code that, when executed on a computer, causes the computer to perform the operations and / or processes performed by communication devices (such as the first node, second node, first sensing entity, and second sensing entity described above) in the method provided in this application.

[0407] This application also provides a computer program product, which includes computer code or a computer program that, when run on a computer, causes the operations and / or processes performed by communication devices (such as the first node, second node, first sensing entity, and second sensing entity described above) in the method provided in this application to be executed.

[0408] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, or it may be an electrical, mechanical, or other form of connection.

[0409] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the technical effects of the solutions provided in the embodiments of this application.

[0410] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0411] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to existing technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0412] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method characterized by comprising: Applied to the first node, the method includes: Send a first request, the first request being used to request the perception result of the first perception service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; Receive the first perception result of the first perception service, wherein the first perception result is determined based on the first privacy algorithm and the privacy encryption key; Privacy decryption is performed on the first perception result to obtain the second perception result.

2. The method of claim 1, wherein, The first privacy computing resource information includes the first privacy algorithm and the privacy encryption key, and the method further includes: Acquire privacy computing capabilities on the network side, wherein the network side is related to the privacy computing of the first sensing service; Based on at least one of the privacy computing capabilities of the first node, the privacy computing capabilities of the network side, and the service security level of the first sensing service, first information is obtained, the first information including the first privacy algorithm and the privacy encryption key.

3. The method of claim 2, wherein, The first information also includes a privacy decryption key; the step of performing privacy decryption on the first perception result to obtain the second perception result includes: Based on the privacy decryption key, the first perception result is decrypted to obtain the second perception result.

4. The method according to claim 2 or 3, characterized in that, The first information also includes a privacy computing key, and the first privacy computing resource information also includes the privacy computing key.

5. The method according to claim 1, characterized in that, The first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key. The first privacy computing resource information includes the privacy computing capability of the first node and the service security level of the first sensing service.

6. The method according to claim 5, characterized in that, The method further includes: Receive privacy decryption key; The step of performing privacy decryption on the first perception result to obtain the second perception result includes: performing privacy decryption on the first perception result based on the privacy decryption key to obtain the second perception result.

7. The method according to any one of claims 1-6, characterized in that, The first request also includes first service information of the first sensing service, which is used to execute the service task corresponding to the first sensing service.

8. The method according to any one of claims 1-7, characterized in that, The first node is an application function AF, a terminal, or a third-party application.

9. A communication method, characterized in that, The method includes: Receive a first request, the first request being used to request the perception result of a first perception service, the first request including first privacy computing resource information, the first privacy computing resource information including a first privacy algorithm and a privacy encryption key, or the first privacy computing resource information being used to determine the first privacy algorithm and the privacy encryption key; Based on the first privacy computing resource information and the privacy computing capabilities of multiple sensing entities, a first sensing entity and a second sensing entity are determined from the multiple sensing entities. Send a first message to the first sensing entity. The first message is used to instruct the first sensing entity to obtain sensing data of the first sensing service. The first message includes the first privacy algorithm and the privacy encryption key. The first sensing entity is used to obtain the first sensing data of the first sensing service based on the first privacy algorithm and the privacy encryption key. A second message is sent to the second sensing entity, the second message being used to instruct the second sensing entity to obtain the sensing result of the first sensing service, the second message including the first privacy algorithm, the second sensing entity being used to obtain the first sensing result of the first sensing service based on the first privacy algorithm and the first sensing data.

10. The method according to claim 9, characterized in that, The first privacy computing resource information includes the first privacy algorithm and the privacy encryption key. The first privacy computing resource information also includes a privacy computing key. The second message also includes the privacy computing key. The privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

11. The method according to claim 10, characterized in that, Before receiving the first request, the method further includes: Receive the second request; Based on the second request, a first response message is sent, the first response message including the privacy computing capability on the network side, the privacy computing capability on the network side being used to determine the first request.

12. The method according to claim 9, characterized in that, The first privacy computing resource information is used to determine the first privacy algorithm and the privacy encryption key. The first privacy computing resource information includes the privacy computing capability of the first node and the service security level of the first sensing service. The method further includes: First information is obtained based on at least one of the network-side privacy computing capabilities, the privacy computing capabilities of the first node, and the service security level of the first sensing service. The first information includes the first privacy algorithm and the privacy encryption key.

13. The method according to claim 12, characterized in that, The first information also includes a privacy decryption key, and the method further includes: Send the privacy decryption key to the first node.

14. The method according to claim 12 or 13, characterized in that, The first information also includes a privacy computing key, and the second message also includes the privacy computing key. The privacy computing key is used by the second sensing entity to perform privacy computing to obtain the first sensing result.

15. A communication method, characterized in that, Applied to a first sensing entity, the method includes: Receive a first message, the first message being used to instruct the first sensing entity to obtain sensing data from the first sensing service, the first message including a first privacy algorithm and a privacy encryption key; Based on the first privacy algorithm and the privacy encryption key, the second sensing data of the first sensing service is encrypted to obtain the first sensing data of the first sensing service; the second sensing data is obtained based on the sensing signal of the first sensing service. Send the first sensed data.

16. A communication method, characterized in that, Applied to a second sensing entity, the method includes: Receive a second message, the second message being used to instruct the second sensing entity to obtain the sensing result of the first sensing service, the second message including a first privacy algorithm; Based on the first privacy algorithm, privacy calculations are performed on the first perception data of the first perception service to obtain the first perception result of the first perception service. Send the first sensing result.

17. A communication device, characterized in that, It includes modules or units for performing the method as described in any one of claims 1 to 8, or modules or units for performing the method as described in any one of claims 9 to 14, or modules or units for performing the method as described in claim 15, or modules or units for performing the method as described in claim 16.

18. A communication device, characterized in that, The system includes a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices and transmit them to the processor, or to send signals from the processor to other communication devices. The processor executes code instructions via logic circuits. The communication device enables the method as described in any one of claims 1 to 8; or, The communication device enables the method as described in any one of claims 1 to 8; or, The communication device enables the method as described in any one of claims 9 to 14; or, The communication device enables the method as described in claim 15; or, This enables the communication device to perform the method as described in claim 16.

19. A readable storage medium, characterized in that, Used to store computer programs or instructions, which are executed by one or more processors. Cause the apparatus including the one or more processors to perform the method as described in any one of claims 1 to 8; or, Cause the apparatus including the one or more processors to perform the method as described in any one of claims 9 to 14; or, Cause the apparatus including the one or more processors to perform the method of claim 15; or, This causes the apparatus including the one or more processors to perform the method as described in claim 16.

20. A computer program product, characterized in that, When the computer program product is run. Cause the communication device to perform the method as described in any one of claims 1 to 8; or, Cause the communication device to perform the method as described in any one of claims 9 to 14; or, Cause the communication device to perform the method as described in claim 15; or, This causes the communication device to perform the method as described in claim 16.

Citation Information

Patent Citations

  • Method for encryption in sensor network, encryption device and sensor network

    CN103297959A

  • Data transmission system, method and device thereof

    CN111464934A

  • Data transmission method based on privacy computing network, electronic equipment and storage medium

    CN115913790A

  • Wireless sensing communication method, apparatus, device and storage medium

    WO2024138580A1

  • Communication method and communication apparatus

    WO2024199072A1