Wireless communication methods and communication devices
By obtaining the license information of the second device and selecting the target intermediate node to process the data, the problem of information security risks in the data plane data pipeline is solved, and the secure transmission and processing of data is realized.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
- Filing Date
- 2024-10-29
- Publication Date
- 2026-05-07
AI Technical Summary
In the data plane pipeline, there are information security risks when intermediate nodes transmit and process data. Attackers may steal or attack intermediate data in order to recover the original data.
By obtaining the permission information of the second device, the target intermediate node is selected to process the target data, ensuring that only the authorized intermediate node transmits and processes the data, thus preventing unauthorized access or attacks.
It enables secure data transmission and processing, prevents unauthorized access or theft, and ensures that only authorized intermediate nodes have access to the data associated with the second device.
Smart Images

Figure CN2024128153_07052026_PF_FP_ABST
Abstract
Description
Wireless communication methods and communication devices Technical Field
[0001] This application relates to the field of communication technology, and more specifically, to a wireless communication method and a communication device. Background Technology
[0002] In the data pipeline of the data plane (DP), raw data from the data source can be processed by one or more intermediate nodes. Although the raw data becomes intermediate data (or process data) after one or more rounds of data processing, if an attacker steals the intermediate data, it is still possible to recover the original data based on the intermediate data. For example, an attacker can infer the server's model information through gradient information and the client's model. Another example is that an attacker can launch a model inversion attack or model reverse engineering attack, that is, based on observations of the model's output and input, to invert sensitive raw data.
[0003] Therefore, if intermediate nodes not only transmit data but also process it, i.e. perform in-path processing, there may be information security risks, which could lead to data being stolen or attacked during transmission.
[0004] Summary of the Invention
[0005] This application provides a wireless communication method and a communication device. The various aspects covered by this application are described below.
[0006] In a first aspect, a wireless communication method is provided, the method comprising: obtaining licensing information of a second device; selecting a target intermediate node to process target data based on the licensing information, wherein the target intermediate node is an intermediate node licensed by the second device, and the target data includes data associated with the second device.
[0007] In a second aspect, a wireless communication method is provided, the method comprising: a second device receiving first request information sent by a first device; wherein the first request information is used to request permission information, and the permission information is used to indicate whether the second device permits one or more intermediate nodes contained in the first request information to process target data.
[0008] Thirdly, a wireless communication method is provided, the method comprising: a second device sending an authorization file; wherein the authorization file is used to indicate information of an intermediate node authorized by the second device that is capable of processing data associated with the second device.
[0009] Fourthly, a communication device is provided, which is a first device, comprising: an acquisition unit for acquiring license information of a second device; and a selection unit for selecting a target intermediate node to process target data according to the license information, wherein the target intermediate node is an intermediate node licensed by the second device, and the target data includes data associated with the second device.
[0010] Fifthly, a communication device is provided, which is a second device. The communication device includes: a receiving unit for receiving first request information sent by a first device; wherein the first request information is used to request permission information, and the permission information is used to indicate whether the second device permits one or more intermediate nodes contained in the first request information to process target data.
[0011] In a sixth aspect, a communication device is provided, which is a second device, the communication device comprising: a sending unit for sending an authorization file; wherein the authorization file is used to indicate information of an intermediate node authorized by the second device that is capable of processing data associated with the second device.
[0012] In a seventh aspect, a communication device is provided, including a transceiver, a memory, and a processor. The memory is used to store a program, and the processor is used to call the program in the memory and control the transceiver to receive or send signals so that the communication device performs some or all of the steps in the methods described in the above aspects.
[0013] Eighthly, a communication system is provided, which includes one or more of the communication devices described above. In another possible design, the system may further include other devices that interact with the communication device as provided in the embodiments of this application.
[0014] Ninthly, a computer-readable storage medium is provided, which stores a computer program that causes a communication device to perform some or all of the steps in the methods described in the preceding aspects.
[0015] In a tenth aspect, embodiments of this application provide a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program operable to cause a communication device to perform some or all of the steps in the methods described above. In some implementations, the computer program product may be a software installation package.
[0016] In one aspect, embodiments of this application provide a chip including a memory and a processor, the processor being able to call and run a computer program from the memory to implement some or all of the steps described in the methods of the foregoing aspects.
[0017] It is understood that the second device is the data source. If the second device permits the target intermediate node to transmit and process the target data, then the target intermediate node is authorized by the second device, meaning that the target intermediate node is not an unauthorized accessor or attacker of the second device. Therefore, this application can prevent unauthorized accessors or attackers from accessing or stealing the target data, ensuring that the original data and processed intermediate data of the second device are only exposed to intermediate nodes that have obtained permission from the second device, thereby guaranteeing data security. Attached Figure Description
[0018] Figure 1 is a schematic diagram of the wireless communication system used in the embodiments of this application.
[0019] Figure 2 is a schematic diagram of a network architecture.
[0020] Figure 3 is a schematic diagram of another network architecture.
[0021] Figure 4 is an example diagram of the negotiation process for discovering and identifying participants in a data pipeline.
[0022] Figure 5 is a schematic flowchart of a wireless communication method provided in an embodiment of this application.
[0023] Figure 6 is a schematic flowchart of another wireless communication method provided in Embodiment 1 of this application.
[0024] Figure 7 is a schematic flowchart of another wireless communication method provided in Embodiment 2 of this application.
[0025] Figure 8 is a schematic structural diagram of a communication device provided in an embodiment of this application.
[0026] Figure 9 is a schematic structural diagram of another communication device provided in an embodiment of this application.
[0027] Figure 10 is a schematic structural diagram of another communication device provided in an embodiment of this application.
[0028] Figure 11 is a schematic structural diagram of a communication device provided in an embodiment of this application. Detailed Implementation
[0029] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0030] Communication system
[0031] Figure 1 illustrates a wireless communication system 100 according to an embodiment of this application. The wireless communication system 100 may include communication devices. These communication devices may include a network device 110 and a terminal device 120. The network device 110 may be a device that communicates with the terminal device 120.
[0032] Figure 1 illustrates an exemplary network device and two terminals. Optionally, the wireless communication system 100 may include multiple network devices, and each network device may include other terminal devices within its coverage area. This application embodiment does not limit this.
[0033] Optionally, the wireless communication system 100 may also include other network entities such as a network controller and a mobility management entity, which is not limited in this embodiment.
[0034] It should be understood that the technical solutions of the embodiments of this application can be applied to various communication systems, such as: 5th generation (5G) systems or new radio (NR), long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to future communication systems, such as 6th generation mobile communication systems, satellite communication systems, and so on.
[0035] The terminal device in this application embodiment can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. The terminal device in this application embodiment can be a device that provides voice and / or data connectivity to a user, and can be used to connect people, objects, and machines, such as a handheld device with wireless connectivity, vehicle-mounted device, etc. The terminal device in the embodiments of this application can be a mobile phone, tablet computer, laptop computer, PDA, mobile internet device (MID), wearable device, virtual reality (VR) device, augmented reality (AR) device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical surgery, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, etc. Optionally, the UE can be used to act as a base station. For example, the UE can act as a scheduling entity, providing sidelink signals between UEs in vehicle-to-everything (V2X) or device-to-device (D2D) communication. For example, cellular phones and cars communicate with each other using sidelink signals. Cellular phones and smart home devices communicate without relaying communication signals through a base station.
[0036] The network device in this application embodiment can be a device for communicating with terminal devices. The network device may also include an access network device. The access network device can provide communication coverage for a specific geographical area and can communicate with the terminal device 120 located within that coverage area. The access network device can also be called a wireless access network device or a base station, etc. In this application embodiment, the access network device can refer to a radio access network (RAN) node (or device) that connects the terminal device to the wireless network. Access network equipment can broadly encompass various names listed below, or be replaced by names such as: NodeB, Evolved NodeB (eNB), Next Generation NodeB (gNB), Relay Station, Transmitting and Receiving Point (TRP), Transmitting Point (TP), Master eNB (MeNB), Secondary eNB (SeNB), Multi-Standard Radio (MSR) Node, Home Base Station, Network Controller, Access Node, Wireless Node, Access Point (AP), Transmitter Node, Transceiver Node, Baseband Unit (BBU), Remote Radio Unit (RRU), Active Antenna Unit (AAU), Remote Radio Head (RRH), Central Unit (CU), Distributed Unit (DU), Location Node, Centralized Unit-Control Plane (CU-CP), Centralized Unit-User Plane (CU-User) Base stations can be macro base stations, micro base stations, relay nodes, donor nodes, or similar entities, or combinations thereof. A base station can also refer to a communication module, modem, or chip installed within the aforementioned equipment or apparatus. A base station can also be a mobile switching center, equipment performing base station functions in D2D, V2X, and machine-to-machine (M2M) communications, network-side equipment in 6G networks, and equipment performing base station functions in future communication systems. Base stations can support networks using the same or different access technologies. The embodiments of this application do not limit the specific technologies or equipment forms used in the access network equipment.
[0037] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move depending on the location of the mobile base station. In other examples, a helicopter or drone can be configured as a device to communicate with another base station.
[0038] Wireless communication systems involve communication equipment that can include not only access network equipment and terminal equipment, but also core network elements. Core network elements can be implemented through devices; that is, core network elements are core network devices. It can be understood that core network devices can also be a type of network device.
[0039] The core network elements in this application embodiment may include network elements that process and forward user signaling and data. For example, core network equipment may include core access and mobility management function (AMF), session management function (SMF), location management function (LMF), network slice selection function (NSSF), authentication server function (AUSF), unified data management (UDM), policy control function (PCF), user plane function (UPF), network repository function (NRF), sensing function (SF), network data analytics function (NWDAF) network elements, and artificial intelligence (AI) function management entities, etc. Of course, the core network may also include other network elements, which are not listed here.
[0040] It should be noted that in some communication systems (such as 5G systems), core network elements can also be called network functions (NFs).
[0041] In some deployments, the network device in this application embodiment may refer to a CU or a DU, or the network device may include both a CU and a DU. The gNB may also include an AAU.
[0042] Network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can also be deployed in the air on airplanes, balloons, and satellites. This application does not limit the scenario in which the network devices and terminal devices are located.
[0043] It should be understood that all or part of the functions of the communication device in this application can also be implemented by software functions running on hardware, or by virtualization functions instantiated on a platform (e.g., a cloud platform).
[0044] Data plane-based network system architecture
[0045] With the development of technology, the functions of network elements have become more diversified.
[0046] For example, some communication protocols or proposals (such as 3GPP Rel-18 and 3GPP TS23.288) define network elements such as the network data analytics function (NWDAF), data collection coordination function (DCCF), and analytics data repository function (ADRF). Based on NWDAF, devices can collect data from various network elements in the core network and network management systems, and perform big data statistics, analysis, or intelligent data analysis to obtain network-side analysis or predictive data. This, in turn, assists various network elements in more effectively controlling terminal device access based on the data analysis results.
[0047] For example, some communication protocols or proposals (such as 3GPP TS28.104, TS28.537, and TS28.622) define data service capabilities and manage data analytics frameworks, including the management data analytics function (MDAF). This focuses on collecting data and providing data analytics reports to data consumers.
[0048] However, the architecture of communication systems still needs improvement. For example, the DCCF and ADRF mentioned above are specifically designed for collecting data from network elements (NFs) within the communication system. As the 3GPP mobile network architecture evolves to become more data- and content-centric, it requires more flexible and distributed capabilities across the cloud, edge, and core to support local artificial intelligence (AI) and sensing services. The aforementioned network elements are insufficient to support this demand.
[0049] To address the above issues, relevant technologies have proposed a technical solution based on data plane services.
[0050] Data plane services can be implemented through data plane network elements. Data plane network elements can be used for one or more of the following functions: data collection, data storage, data access, data sharing, data tracking, and data openness. For example, a data plane network element can collect and / or store data from a data source. It can also send data from a data source to a data consumer. Furthermore, it can share data from a data source with a data consumer. It can control data consumer access to data from the data source. Finally, it can store data from the data source.
[0051] To make it easier to understand, we will first explain the data source and the data consumer.
[0052] A data source can provide data. A data source can be any mobile communication system entity. For example, a data source may include one or more of the following: terminal equipment, core network elements, RAN, OAM, third-party servers, etc.
[0053] Data from a data source can be data generated, perceived, or acquired by the data source. The data provided by the data source can be called raw data or metadata.
[0054] Data consumers can acquire and / or use data from data sources (including raw data and / or processed raw data). Data consumers can also be referred to as data requesters. Data consumers can be any mobile communication system entity. For example, data consumers can include one or more of the following: terminal equipment, RAN, OAM, third-party servers, etc.
[0055] A data transaction can be defined as either the provision of data by a data source or the acquisition of data by a data consumer.
[0056] It should be noted that "data plane" is just an example name. "Data plane" can also be called "data surface", "user data plane", "distributed data plane", etc.
[0057] The following description, with reference to Figure 2, illustrates a data plane network element. Figure 2 is a schematic diagram of a mobile communication system architecture supporting data plane services provided in an embodiment of this application.
[0058] As shown in Figure 2, data plane network elements may include data plane access controller (DPAC) and data plane repository infrastructure.
[0059] DPAC can serve as an interface between network data and data plane infrastructure. DPAC functions can include one or more of the following: data collection; management and verification of data source and data consumer IDs; data processing and sharing; interaction with data plane storage facilities to store or retrieve data; and support for data tracking. A data transaction is a data service exchange between the data source or data consumer and the DPAC, such as data storage or retrieval. Therefore, based on DPAC, the data plane can support trusted data collection, data storage, data access, and data sharing.
[0060] For example, when the core network's data plane collects data from a terminal device, the terminal device is considered the data source, and a data transaction occurs between the core network's data plane and the terminal device. The terminal device sends a data transaction request to the DPAC, carrying the data source ID, the source data itself, and data description information. Based on the data transaction request sent by the terminal device, the DPAC verifies the data source ID. If the verification is successful, the DPAC sends the data source ID, the source data itself, and the data description information to the data plane storage facility.
[0061] Optionally, DPAC can be a newly defined network element. Alternatively, DPAC can be obtained by enhancing the functionality of network elements in related technologies. For example, DPAC can be obtained by enhancing DCCF.
[0062] It should be noted that DPAC is merely an example name for this network element, which can also be referred to by other names. For example, this network element can be called a data plane management network element, a data plane interface, a data plane control network element, etc.
[0063] Optionally, the data plane is a distributed architecture. Therefore, data sources can choose to connect to the data plane that is closer to them, thereby reducing data transmission latency and enabling the network to support flexible and efficient data management.
[0064] It should be noted that the network elements in Figure 2 can be network components in hardware devices, software functions running on dedicated hardware, or virtualization functions instantiated on a platform (e.g., a cloud platform). It should also be noted that the network architecture shown in Figure 2 is merely an illustrative representation of the network elements included in the overall network architecture. In this embodiment, the network elements included in the overall network architecture are not limited.
[0065] Those skilled in the art will understand that the network architecture shown in Figure 2 does not constitute a limitation on the network architecture. In specific implementations, the network architecture may include more or fewer network elements than that shown in Figure 2, or may combine certain network elements, etc. In addition, it should be understood that AN or RAN is represented in Figure 2 as (R)AN.
[0066] Data Pipeline
[0067] In some communication systems (such as 6G systems), considering the diverse needs of services, different nodes may need to operate on data separately. For example, different nodes may need to perform operations such as data collection, processing, and reception (or aggregation). Based on these needs, as a possible implementation, data in some communication systems can be manipulated within a data pipeline to simplify data management processes and improve data processing efficiency. The following section introduces data pipelines.
[0068] A data pipeline can be a combination of a series of data processing steps. Data is collected from a data source and sent to the next node for processing. The node receiving the data processes it and forwards it to the next node, thus enabling data processing along the way. Therefore, the operation of a data pipeline is similar to an assembly line in a manufacturing process. Data pipelines simplify data management processes, improve data processing efficiency, and ensure data integrity.
[0069] This application does not limit the name of the data pipeline. For example, a data pipeline can also be called a "data channel" or a "data processing set". It should be noted that in future communication systems, this name can be replaced with a name in the future communication system that has the same or similar function as the data pipeline. For ease of understanding, this application uses a data pipeline as an example for description.
[0070] This application does not specifically limit the data processing that the data pipeline can provide. For example, the data pipeline can provide one or more of the following data processing: compression processing, normalization processing, AI model-based data processing, anonymization processing, data filtering, data analysis, data computation, etc.
[0071] This application does not limit the data types that the data pipeline can handle; in other words, the data pipeline can handle any type of data. For example, the data pipeline can handle one or more of the following data types: continuous data, intermittent data, and batch data. Of course, this application is not limited to these. For instance, if the data types are divided according to other methods, the data pipeline can handle any type of data under those other methods. As an example, the data pipeline can handle one or more of the following data types: perception-type data, location-type data, AI-type data, etc.
[0072] To facilitate understanding, the composition of a data pipeline is described below with reference to Figure 3. As shown in Figure 3, a data pipeline can consist of data pipeline participants (or data plane contributors (DPCs), or simply participants or participating nodes) and / or the data processing performed by data pipeline participants.
[0073] This application does not limit the type of data pipeline participants. For example, the type of data pipeline participants may include one or more of the following types: data source in the data pipeline (hereinafter referred to as data source), intermediate node in the data pipeline (hereinafter referred to as intermediate node), and data receiver in the data pipeline (hereinafter referred to as data receiver, data consumer, data requester or business requester).
[0074] A data source can be understood as the starting point of a data pipeline, providing data collection services. A data pipeline can include one or more data sources to achieve diverse data services. For example, in the example in Figure 3, the data source can include data pipeline participant A and data pipeline participant C. Data pipeline participant A and data pipeline participant C can provide different data.
[0075] In some embodiments, after collecting data, the data source can send the data to the next node (such as an intermediate node). For example, the data source collects and processes the data, and then sends the data to the next node. Alternatively, the data source collects the data and directly sends it to the next node. The next node of the data source can be an intermediate node, but this embodiment is not limited to this; the next node of the data source can also be a data receiver.
[0076] This application does not limit the data source. Exemplarily, the data source may include one or more of the following: terminal devices, access network devices, network elements in the core network, network management devices, and application devices. In some embodiments, network management devices may include, for example, operations, administration, and maintenance (OAM) devices. In some embodiments, application devices may include one or more of the following: application servers, application servers (AFs), third-party applications, third-party servers, etc.
[0077] Intermediate nodes can provide data processing services. For example, intermediate nodes can provide one or more of the following data processing services: compression, normalization, AI model-based data processing, anonymization, data filtering, data analysis, and data computation.
[0078] A data pipeline can include one or more intermediate nodes. Different intermediate nodes can provide the same or different data processing. For example, in the example of Figure 3, intermediate nodes can include data pipeline participant X and data pipeline participant Y. Data pipeline participant X and data pipeline participant Y can provide the same data processing, such as both performing data compression, although the specific compression method or the values of the compressed data may differ. Alternatively, data pipeline participant X and data pipeline participant Y can provide different data processing, such as data pipeline participant X performing data compression and data pipeline participant Y performing data normalization.
[0079] An intermediate node can perform one or more processing operations on the data in the data pipeline, and this application embodiment is not limited in this regard. For example, data pipeline participant X can perform only compression processing on the data. Alternatively, data pipeline participant X can perform compression processing and normalization processing on the data, etc.
[0080] In some embodiments, after processing the data in the data pipeline, an intermediate node can send the processed data to the next node, such as the next intermediate node or the data receiver. For example, in the example of Figure 3, data pipeline participant X can send the processed data to data pipeline participant Y. Data pipeline participant Y can then send the processed data to the data receiver.
[0081] This application does not limit the intermediate nodes. For example, the intermediate nodes may include one or more of the following: terminal devices, access network devices, network elements in the core network, network management devices, and application devices.
[0082] A data receiver can be understood as the end point of a data pipeline. The data receiver receives the final processed data and does not process it further. A data pipeline can include one or more data receivers. For example, in the example in Figure 3, the data receiver can include data pipeline participant B.
[0083] This application does not limit the data receiver. For example, the data receiver may include one or more of the following: terminal equipment, access network equipment, network element in the core network, network management equipment, and application equipment.
[0084] In some embodiments, a data pipeline may also include a controller. The controller can manage and / or control the entire service flow of the data pipeline. For example, the controller may perform one or more of the following operations: identify the nodes of the data pipeline (such as data sources, intermediate nodes, data receivers, etc.), establish the data pipeline, allocate data processing strategies in the data pipeline, determine the data routing topology, manage the nodes in the data pipeline, and perform performance monitoring of the data pipeline.
[0085] This application does not limit the controller of the data pipeline. For example, the controller of the data pipeline can be the DPAC mentioned above, or it can be the name of a new network element introduced in a future communication system, as long as it is used to manage and / or control the data pipeline.
[0086] It should be noted that in some embodiments, the controller of the data pipeline may be a component of the data pipeline. In some embodiments, the controller of the data pipeline may not be a component of the data pipeline, and this application does not limit this aspect.
[0087] Referring again to Figure 3, the other nodes in Figure 3 are nodes that are not involved in the data pipeline shown in Figure 3, or in other words, the controller of the data pipeline did not select the other nodes shown in Figure 3 as nodes in this data pipeline. In some embodiments, the other nodes may be nodes in another data pipeline, or the other nodes may not participate in any data pipeline; this application embodiment does not limit this.
[0088] Data processing (or data manipulation) in a data pipeline can include, but is not limited to, one or more of the following types: data collection, data refinement, data preprocessing, data transformation, model training, data transfer, and analysis. These will be explained in detail below.
[0089] Data collection: Data is extracted from different data sources. Since the data comes from different data sources, there may be compatibility issues. The data pipeline will use a predefined data profile as a reference to aggregate the raw data into a unified state.
[0090] Data refinement: Due to inconsistencies, incompleteness, or outliers in the original data, data pipelines can improve accuracy through a series of data refinement methods, such as extracting missing values, removing duplicates, and correcting errors.
[0091] Data preprocessing: In order to obtain better performance and serve as input for machine learning algorithms, data preprocessing is required before training (e.g., data quality assessment, data imputation, data encoding, data sampling, data labeling, etc.).
[0092] Data transformation: Refined data may require data transformation or standardization to make it suitable for data analysis or to feed the data into training models.
[0093] Model training: The transformed data can be used to assist in model training and model inference, depending on the specific model algorithm.
[0094] Analysis: Reasoning about data or results in a way that stakeholders can understand.
[0095] Data pipeline contributors can be part of a data plane function and can reside in network entities (i.e., terminal equipment, RAN functions, core network functions, OAM functions, or application functions, etc.). When the data plane initiates a data pipeline operation to support data plane services, network entities that support DPC functions will be selected to participate in a specific data pipeline and perform one or more of the aforementioned data processing.
[0096] Negotiation process for discovering and identifying data pipeline participants
[0097] Figure 4 is an example diagram of a negotiation process for discovering and identifying participants in a data pipeline. The method shown in Figure 4 may include steps S400 to S412. These will be explained below.
[0098] In step S400, the service requester sends a service request to the DPAC. The service request is used to request data retrieval.
[0099] In steps S401 to S402, DPAC collects relevant information from each network element based on one or more of the end-to-end latency requirements, accuracy requirements, reliability requirements, computing power requirements, storage requirements, energy consumption requirements, security requirements, and location requirements in the request.
[0100] Steps S401 to S402 can be adjusted flexibly for different cases. The following explanation uses cases 1 to 3 as examples.
[0101] Scenario 1: When a service requester sends a service request to DPAC, it includes the participant IDs it has initially determined. In this case, DPAC can send a computing power information request to the computing power management network element for each ID, or for each group of IDs. The request includes the participant IDs and computing power requirements. The computing power requirements may include the maximum or minimum total computing power the service requester can require to complete the service, the type of heterogeneous computing power, etc. The computing power management network element stores the computing power type of each participating node and the maximum computing power it can currently support. The computing power management network element returns one or more node combinations that satisfy the computing power type to DPAC, ensuring that under different combinations, the total computing power supported by all nodes is not less than the minimum computing power requirement.
[0102] For example, the node combinations fed back by the computing power management network element can include combination 1 and combination 2. Combination 1 can be: {node 1, available computing power x FLOPS}, {node 2, available computing power y FLOPS}, {node 3, available computing power z FLOPS}, and x+y+z is not less than the minimum computing power requirement. Combination 2 can have a similar format to combination 1.
[0103] Scenario 2: The service request does not carry a participant ID. In this case, DPAC can determine the candidate participating nodes based on its local configuration; that is, DPAC can store candidate participating nodes corresponding to different services. Then, each node can execute the steps in Scenario 1.
[0104] Scenario 3: Participants include terminal devices. In this case, DPAC can interact with AMF based on the service type and / or location information in the service request to identify multiple terminal devices within the area that have the capability to support the service as candidate participants. Then, each node can execute the steps in Scenario 1.
[0105] Steps S403-S404 are similar to steps S401-S402. DPAC interacts with the model management network element to determine the participating nodes that can support the model corresponding to the service. Based on the service type, end-to-end latency requirements, accuracy requirements, etc., in the service request, DPAC sends a model information retrieval request to the model management network element. The request carries the service type, candidate node ID, end-to-end latency requirements, and accuracy requirements. The model management network element stores the models that each participating node can support. The information fed back to DPAC can include one or more combinations. For example, combination 3 can be: {Node 1, Model ID used, Interoperability information (which models on which nodes support interoperability)}, {Node 2, Model ID used, Interoperability information}, {Node 3, Model ID used, Interoperability information}. Combination 4 can have a similar format to combination 3.
[0106] It should be noted that in the method shown in Figure 4, DPAC can also interact with energy management network elements to determine data pipeline participants based on energy consumption.
[0107] In step S405, DPAC determines the candidate combinations of participating nodes based on the information fed back from the computing power management network element and the model management network element. Each node with the same role can have multiple candidate nodes, thereby meeting real-time and reliability requirements. For example, there can be multiple UEs or gNBs that meet the conditions.
[0108] In step S406, DPAC sends a data pipeline configuration request to the participating nodes. The request includes the data pipeline configuration strategy / rules. DPAC sends each node the maximum local processing latency, or latency range, the maximum computing power, or computing power range, that each node can use, and the model required by each node, etc.
[0109] Each node, based on its own circumstances, determines whether the requirements indicated in the strategy can be met. For example, a node determines whether it can meet the latency and computing power ranges based on its own supported computing power, energy consumption, and the indicated model information.
[0110] Step S407: If the conditions are met, the node sends a data pipeline policy configuration receive message to the DPAC. The message includes the specific computing power the node can use, the specific processing latency it can support, and the model the node ultimately selects.
[0111] If the conditions cannot be met, the node sends a data pipeline policy configuration rejection message to DPAC. The message includes the specific computing power that the node can use, the specific processing latency it can support, and the model that the node ultimately chooses.
[0112] In step S408, if the node feedback policy is configured to send a rejection message, the DPAC can send a business request rejection to the business requester. The rejection message can carry a reason for rejection, such as end-to-end latency not meeting the requirement or computing power not meeting the requirement. The business requester can use this information to determine whether it needs to modify its business requirements.
[0113] In step S409, DPAC determines the final participating nodes and the final data pipeline strategy for each node based on the feedback from all nodes.
[0114] Furthermore, since DPAC determines the processing latency of each node, the end-to-end latency includes both processing latency and communication latency. DPAC subtracts the processing latency of all nodes from the end-to-end latency requirement to obtain the communication latency requirement for the data pipeline. DPAC then sends the communication latency requirement to PCF. PCF, based on existing mechanisms, uses the communication latency as a Quality of Service (QoS) parameter for the service flow to guarantee data communication latency.
[0115] In steps S410-S411, DPAC sends policy configurations to each node. Each node then reports whether the policy configuration has been accepted.
[0116] In step S412, DAPC sends a notification to the service requester that the service request has been accepted.
[0117] As discussed above, intermediate nodes can not only transmit data but also process it, enabling in-network data processing. For example, some networks (such as 6G networks) require processing of various data types (service data, user data, network data, sensing data, and external data) to support converged communication sensing and native AI. For instance, in V2X services based on native AI, a model is trained based on traffic conditions at a specific location to predict traffic conditions at a later time. To train the model, data needs to be collected from multiple participating nodes, including UEs, base stations, and sensing function (SF) network elements. UEs and base stations can provide sensing measurement results. The base station can aggregate information from different angles of the same vehicle sent by different UEs to generate 3D point cloud information of the vehicle. The sensing measurement results and 3D point cloud information can be provided to the NWDAF for sensing model training. The trained model can then be provided to the SF for model inference to generate traffic condition prediction information. It can be seen that in the above process, data from UEs and base stations undergoes multiple processing steps by various intermediate nodes.
[0118] It is understandable that in-path processing in the data pipeline differs from the data processing methods of the control plane and user plane services. For the control plane, apart from the corresponding control endpoints, other intermediate nodes are only responsible for transmitting signaling and are not aware of the signaling content. For the user plane, the user plane only involves the temporary storage and forwarding of data packets; core network elements are not responsible for processing the content of the data packets.
[0119] In a data pipeline, raw data from a data source is processed by one or more intermediate nodes (i.e., Data Processing Controllers). Although the raw data undergoes one or more rounds of processing to become intermediate or process data, an attacker who steals the intermediate data may still be able to recover the original data based on it. For example, an attacker can infer the server's model information using gradient information and the client's model, or an attacker can launch a model inversion attack or model reverse engineering attack, that is, based on observations of the model's output and input, to invert sensitive raw data.
[0120] Therefore, if intermediate nodes not only transmit data but also process it, i.e. perform in-path processing, there may be information security risks, which could lead to data being stolen or attacked during transmission.
[0121] Figure 5 is a schematic flowchart of a wireless communication method provided in an embodiment of this application to solve the above-mentioned problems. The method shown in Figure 5 can be executed by a first device. The first device can be a data plane device. For example, the first device can be a controller of a data pipeline. Exemplarily, the first device can be a DPAC.
[0122] The method shown in Figure 5 may include steps S510 and S520.
[0123] Step S510: The first device obtains the license information of the second device.
[0124] Step S520: Based on the permission information, the first device selects the target intermediate node to process the target data.
[0125] The second device can be a data source that provides the data. The target data may include data associated with the second device. For example, the target data may include raw data and / or processed raw data provided by the second device.
[0126] Intermediate nodes can be nodes capable of transmitting data. In this application, intermediate nodes can also provide data processing services (i.e., perform in-path processing). These data processing services require the intermediate nodes to perceive or read the content of the data. For example, intermediate nodes can provide one or more of the following data processing services: compression, normalization, AI model-based data processing, anonymization, data filtering, data analysis, data computation, data collection, data refinement, data preprocessing, data transformation, model training, etc.
[0127] This application can be applied to data pipelines. For example, the method shown in Figure 5 can be applied to the process of discovering and identifying participants in a data pipeline.
[0128] A data requester can request to obtain target data. For example, a data requester can send a second request message to a first device. This second request message can be used by the data requester to obtain the target data. That is, the second request message can be a data plane service request sent by the data requester as described above. The service request can also include the type of service request. The type can include, for example, one or more of the following: positioning, sensing, and intrinsic AI. The service request can also include the type of data source required. The type of data source can include, for example, one or more of the following: terminal device, base station, and core network element.
[0129] Optionally, if the first device receives the second request information, the first device may execute steps S510 and S520.
[0130] In some embodiments, the target data may include raw data provided by the second device. In other words, the first device may select a target intermediate node to transmit and process the raw data. In this case, the target intermediate node may directly receive the raw data provided by the second device and process it before sending it to other nodes (e.g., the data requester or other intermediate nodes).
[0131] In some embodiments, the target data may include processed data (i.e., intermediate data) of the raw data provided by the second device. In other words, the first device may select a target intermediate node to transmit and process the processed raw data. In this case, the target intermediate node may receive processed raw data sent by other intermediate nodes and send the processed raw data to other nodes (e.g., the data requester or other intermediate nodes).
[0132] The second device may authorize intermediate nodes to transmit and process target data. In other words, the second device may authorize intermediate nodes to perform in-path processing of the data provided by the second device. An intermediate node may transmit and process target data only if the second device authorizes it. If the second device does not authorize an intermediate node to transmit and process target data, that intermediate node cannot transmit and process the target data, or it cannot process the target data and can only transparently transmit the data if it cannot parse it.
[0133] In some embodiments, the target data can be of any type. That is, the second device can permit the target intermediate node to process any type of data along with the data. In other words, regardless of the type of the target data, the second device can permit the target intermediate node to perform along-the-path processing.
[0134] In some embodiments, the target data can be a specific type of data. That is, the second device can permit the target intermediate node to process the specific type of data along with it. In other words, if the target data is of a specific type, the second device can permit the target intermediate node to perform along-processing.
[0135] It is understood that if the second device permits the target intermediate node to transmit and process the target data, then the target intermediate node is authorized by the second device, meaning that the target intermediate node is not an unauthorized accessor or attacker of the second device. Therefore, this application can prevent unauthorized accessors or attackers from accessing or stealing the target data, that is, it ensures that the original data and processed intermediate data of the second device are only exposed to intermediate nodes that have obtained permission from the data source, thereby ensuring data security.
[0136] In some embodiments, all nodes selected by the first device for transmitting and processing data (including raw data and / or intermediate data from one or more data sources) are permitted by each data source (including the second device). That is, in the process of selecting intermediate nodes for processing and transmitting the raw data and / or intermediate data of the second device, all intermediate nodes selected by the first device are nodes permitted by the second device.
[0137] During the process of discovering and identifying participants in the data pipeline, the first device can select a target intermediate node permitted by the data source as a participant in the data pipeline. In other words, the target central node can be a Data Processing Control (DPC). Therefore, the selection of the target central node can also be referred to as the selection of the DPC.
[0138] In some embodiments, the first device may select one or more candidate data sources capable of providing the target data. The second device may be selected from the one or more candidate data sources. A candidate data source may become the provider of the target data (i.e., become the second device), or it may not become the provider of the target data (i.e., not become the second device). That is, in this step, the first device may perform an initial selection of data sources to obtain candidate data sources. Based on the permission of the candidate data sources for intermediate nodes to process data, the first device may determine the final data source as the second device.
[0139] Optionally, the first device may select one or more candidate data sources capable of providing the target data based on the second request information. The second request information is explained above and will not be repeated here.
[0140] For example, the first device can interact with other network elements to collect information and select a suitable data source based on the requirements in the second request information. For instance, if the second request information indicates that the required data source is a terminal device, the first device can interact with the AMF (Application Function Framework) based on the location preference in the service request to obtain information about the terminal device at a suitable location.
[0141] Optionally, the first device can determine one or more candidate data sources capable of providing the target data based on a metadata catalogue. The metadata catalogue can be used to provide information about the data stored on the data surface. The first device can retrieve information about the data stored on the data surface by querying the metadata catalogue, thereby selecting candidate data sources.
[0142] After selecting one or more candidate data sources, the selection of the target intermediate node can be achieved based on the following two embodiments.
[0143] Example 1
[0144] In Embodiment 1, the first device sends a first request message to the second device. For example, the method shown in FIG5 may include step S503.
[0145] The first request information is used to request permission information, which instructs the second device whether to authorize one or more intermediate nodes to transmit and process the target data. That is, the permission information can indicate whether one or more intermediate nodes can obtain data processing permission from the second device. Optionally, the first request can also be called an authorization request. The permission information can also be called data-as-a-path processing authorization feedback.
[0146] The first device can identify one or more candidate intermediate nodes and carry their information in the first request information. The permission information can be used to provide feedback to the second device on whether to permit the one or more candidate intermediate nodes to transmit and process the target data. As mentioned above, an intermediate node can also be a DPC; therefore, a candidate intermediate node can also be called a candidate DPC.
[0147] In this application, the target intermediate node is selected based on licensing information. For example, the target intermediate node may belong to one or more intermediate nodes licensed by the second device based on the licensing information feedback.
[0148] Therefore, the first request information can be used to inquire whether the second device can authorize one or more intermediate nodes to perform in-path processing, that is, whether one or more intermediate nodes can obtain authorization from the second device. In other words, the method shown in Figure 6 is the process by which the first device requests authorization from the second device for data in-path processing. Based on this, the first request information can also be called a data in-path processing authorization request, and the authorization information can also be called a data in-path processing authorization response.
[0149] In some embodiments, in response to receiving a first request message, the second device may send license information to the first device.
[0150] In some embodiments, the second device may not send permission information to the first device. If the first device does not receive permission information from the second device after sending the first request information, the first device may assume that the permission information is preset. Preset permission information may, for example, instruct the second device not to permit all intermediate nodes in the first request information to transmit and process the target data.
[0151] The first request information inquires whether one or more intermediate nodes can obtain authorization from the second device. This can be determined based on one or more of the following: the second request information, the computing power of the intermediate node, the models supported by the intermediate node, and the energy consumption of the intermediate node.
[0152] The description of the second request information is as described above and will not be repeated here. For example, the one or more intermediate nodes that the first request information inquires about whether authorization from the second device can be obtained can be some or all of the intermediate nodes initially determined by the data requester carried in the second request information.
[0153] In some embodiments, if the second request information carries information about intermediate nodes initially determined by the data requester, the first request information may include the intermediate nodes initially determined by the data requester carried in the second request information.
[0154] In some embodiments, the first request information inquiring whether one or more nodes can obtain authorization from the second device can be determined based on participants initially identified by the first device. The first device can initially identify participants based on one or more of the following: the computing power of the intermediate node (e.g., feedback from a computing power management network element), the model supported by the intermediate node (e.g., feedback from a model management network element), and the energy consumption of the intermediate node. Therefore, the first request information inquiring whether one or more intermediate nodes can obtain authorization from the second device can be determined based on participants initially identified by the first device.
[0155] The transmission of the first request information is illustrated below using Figure 6 as an example. In Figure 6, the first device is a DPAC.
[0156] Figure 6 shows an improvement upon Figure 4. The method shown in Figure 6 may include some or all of the steps in Figure 4. For the steps in Figure 4 included in Figure 6, please refer to Figure 4 for relevant explanations, which will not be repeated here.
[0157] The method shown in Figure 6 may include step S710. In step S710, the DPAC selects a second device.
[0158] Optionally, the method shown in FIG6 may include steps S721 and S722. For example, in step S400, if the service request carries the participant identifier initially determined by the service requester, the method shown in FIG6 may include steps S721 and S722.
[0159] In step S721, DPAC sends a first request message to the second device. This first request message can be used to inquire whether one or more candidate data sources authorize one or more intermediate nodes to perform in-path processing. The one or more intermediate nodes can be participants initially identified by the business requester carried in the business request.
[0160] Step S722: Based on the first request information, the second device sends license information to DPAC.
[0161] In step S405, based on the licensing information, DPAC can determine the initial participants.
[0162] Optionally, the method shown in FIG6 may include steps S731 and S732.
[0163] In step S731, DPAC sends a first request message to the second device. This first request message can be used to inquire whether one or more second devices authorize one or more intermediate nodes to perform accompanying processing. The one or more intermediate nodes can be initial participants determined by DPAC.
[0164] In step S732, based on the first request information, the second device sends license information to the DPAC.
[0165] In step S409, based on the licensing information, DPAC can determine the final participant.
[0166] Optionally, the first request information may include information about the candidate intermediate nodes. For example, the first request information may include one or more of the following: the identifier of the intermediate node, the data processing method of the intermediate node, and the data type processed by the intermediate node. The data type may include one or more of the following: perception-type data, positioning-type data, endogenous AI-type data, etc. In some embodiments,
[0167] Optionally, the first request information may include information about the target data being requested. For example, the first request information may include business description information corresponding to the target data. The business description information may, for example, include how the data requester will use the target data collected in the request. For instance, the business description information may indicate the purpose of the collected target data. For example, the business description information may be used to indicate that the collected target data is used to train a model.
[0168] In some embodiments, if the license information instructs the second device to allow one or more intermediate nodes in the first request information to transmit and process target data, that is, if some or all of the intermediate nodes in the first request information have obtained the license of the second device, then the first device may select the target intermediate node from the licensed intermediate nodes, that is, the first device may select one or more as participants in the data pipeline from the licensed intermediate nodes.
[0169] Continuing with Figure 6 as an example, after receiving the permission information, if the first request information contains N candidate DPCs, and all N candidate DPCs obtain data processing permission for the second device, then the DPAC will determine the final data pipeline participant based on these N candidate DPCs. If some of these N candidate DPCs obtain data processing permission for the data source, then the DPAC will select the final participant from among these permitted DPCs. Here, N is a positive integer.
[0170] In some embodiments, if the permission information indicates that the second device does not allow all of the one or more intermediate nodes to transmit and process the target data, that is, none of the intermediate nodes in the first request information have obtained permission from the second device, then the first device may select other devices as the device to provide the target data; and / or, the target intermediate node is selected from other intermediate nodes besides the one or more intermediate nodes, that is, the first device may select the second device from other candidate data sources, and / or, the first device may select other intermediate nodes to query the candidate data source again.
[0171] Continuing with Figure 6 as an example, after the DPAC receives the data-in-the-path processing authorization feedback, if there are N candidate DPCs in the authorization request, and none of the N candidate DPCs obtain data processing permission from the data source, the DPAC will either reselect a candidate data source or reselect a DPC. Here, N is a positive integer.
[0172] Example 2
[0173] In Embodiment 2, the licensing information can be determined based on an authorization document. The authorization document can be used to indicate information about nodes authorized by the second device that are capable of transmitting and processing the raw data and / or processed raw data of the second device. The authorization document can also be referred to as an authorization check document or a license check document.
[0174] It should be noted that the second device may include terminal equipment or network equipment. Among them, network equipment may be core network elements or base stations.
[0175] When the first device obtains the authorization file, it can select the target central node based on the authorization file for multiple data requests from the data requester. This eliminates the need to interact with the second device to request permission each time, thus reducing information exchange between the first and second devices. Furthermore, when the second device includes a terminal device, using the authorization file to select the target central node reduces signaling interaction between the first and terminal devices, thereby reducing air interface signaling and saving transmission resources.
[0176] In the case where the second device includes a terminal device, the authorization file may be stored on the terminal device, and / or the authorization file may be stored in the subscription data of the terminal device stored on the network.
[0177] In cases where the second device includes a core network element or an access network device, the license file may be stored in the NRF, and / or the license file may be stored in the core network element or access network device.
[0178] For example, after selecting a candidate data source, the first device can obtain the authorization file of the candidate data source. If the candidate data source is a core network element, the first device can check whether the authorization file of that network element is stored locally. If the authorization file of that network element is not stored, the first device can obtain and store the authorization check file of that NF by requesting it from the NF or NRF. If the candidate data source is a terminal device, the first device can check whether the authorization file of that terminal device is stored locally. If the authorization file of that terminal device is not stored, the first device can request and store the authorization file of that terminal device from the terminal device or UDM.
[0179] The authorization document can be sent by a second device. Taking Figure 5 as an example, the method shown in Figure 5 may include step S501.
[0180] Step S501: The second device sends the authorization file. In some embodiments, the second device may send the authorization file to a device that stores the authorization file, and / or the second device may send the authorization file to the first device so that the first device can select a target intermediate node.
[0181] In some embodiments, the first device may send a third request message. This third request message can be used to request an authorization file. For example, after selecting a candidate data source, the first device may check whether the authorization file for that candidate data source is stored locally. If the first device does not store the authorization file for that data source, it may send a third request message to request and store the authorization file for the candidate data source.
[0182] The recipient of the third request information can be the second device. In other words, the first device can directly request the second device to obtain its authorization file.
[0183] The recipient of the third request information does not have to be the second device. For example, the recipient of the third request information could be a device that stores the authorization file.
[0184] The license document may include one or more of the following: first information, second information.
[0185] The first information can be used to instruct the second device to allow or disallow the intermediate node to perform data processing for the first service.
[0186] For example, the first information may be used to instruct any of the following: the second device allows the intermediate node to perform data processing for the first service; the second device does not allow the intermediate node to perform data processing for the first service; the intermediate node is allowed to perform data processing for the first service without notifying the second device; the intermediate node is allowed to perform data processing for the first service after notifying the second device; the intermediate node is allowed to perform data processing for the first service after notifying the second device and obtaining permission from the second device. In some embodiments, the content of the first information may be mandatory to be included in the authorization document.
[0187] It should be noted that, for the scenarios of "allowing intermediate nodes to perform data processing for the first service upon notification of the second device" and "allowing intermediate nodes to perform data processing for the first service upon notification of the second device and obtaining permission from the second device," the first device may send a notification to the second device to instruct the first device to select one or more intermediate nodes to transmit and process the data for the first service. For the scenario of "allowing intermediate nodes to perform data processing for the first service upon notification of the second device and obtaining permission from the second device," the first device may send a first request message to the second device to request permission from the second device.
[0188] For example, the first information may instruct the second device to allow the intermediate node to perform data processing for the first service within a specified time period. In some embodiments, the content of the first information may be optionally included in the authorization file. If the time when the data requester requests to obtain the target data falls within this event period, the first device may select an intermediate node that meets the requirements of the authorization file as the target intermediate node.
[0189] For example, the first information may indicate the geographic location (e.g., a geographic area) that the second device allows the intermediate node to perform data processing for the first service. In some embodiments, the content of the first information may be optionally included in the authorization file. If the intermediate node belongs to that geographic location, the first device can select an intermediate node that meets the requirements of the authorization file as the target intermediate node.
[0190] The second information can be used to indicate information about intermediate nodes that the second device allows to perform data processing for the second service.
[0191] In some embodiments, the second information includes one or more of the following: an identifier of a first intermediate node that the second device allows to perform data processing for the second service; the data type that the second device allows the first intermediate node to process; the processing type that the second device allows the first intermediate node to perform; and the data type corresponding to the processing type allowed by the second device.
[0192] It should be noted that the first intermediate node can be a network device or a non-network device. If the first intermediate node is a network device, it can be a core network element, base station, etc. In this case, the second information can include information about intermediate nodes related to the PLMN operator. If the first intermediate node is a non-network device (i.e., a non-network element), it can be a terminal device, AF (Automatic Field Controller), client, etc. In this case, the second information can include information about intermediate nodes not related to the PLMN operator.
[0193] Table 1 is an example of an authorization document provided in the embodiments of this application.
[0194] Table 1
[0195] It should be noted that some contents in Table 1 can be implemented independently. For example, in some embodiments, only authorization instructions related to the business type are included, and in other embodiments, only authorization instructions related to intermediate nodes are included. In Table 1, M indicates that the item can be a mandatory item, that is, an item that must be present in the authorization file. O indicates that the item can be an optional item, that is, an item that may not be present in the authorization file.
[0196] It should be noted that Embodiment 1 and Embodiment 2 can be implemented individually or in combination. For example, the first device can determine the target intermediate node based solely on the licensing information. Alternatively, the first device can determine the target intermediate node based solely on the authorization document. Or, the first device can determine whether to send the first request information based on the authorization document.
[0197] Taking Table 1 as an example, after checking the authorization file of the data source, DPAC can determine, based on the "Authorization Instructions for Data Processing Business Types (Location, Sensing, Intrinsic AI) in the authorization file" item, that authorization of intermediate nodes requires either a candidate data source or a response from the candidate data source. In such cases, DPAC also needs to send a first request message or notification to the candidate data source. The subsequent processing method is the same as in Example 1.
[0198] The method embodiments of this application have been described in detail above. The apparatus embodiments of this application are described in detail below. It should be understood that the descriptions of the method embodiments correspond to the descriptions of the apparatus embodiments. Therefore, any parts not described in detail can be referred to the foregoing method embodiments.
[0199] Figure 8 is a schematic structural diagram of a communication device 1000 provided in an embodiment of this application. The communication device 1000 can be a first device. The communication device 1000 may include an acquisition unit 1010 and a selection unit 1020.
[0200] The acquisition unit 1010 is used to acquire the license information of the second device.
[0201] The selection unit 1020 is configured to select a target intermediate node to process target data based on the licensing information. The target intermediate node is an intermediate node licensed by the second device, and the target data includes data associated with the second device.
[0202] In this embodiment, the communication device 1000 can be used to execute some or all of the method steps executed by the first device in the above method embodiments. The communication device 1000 includes units or modules for executing the aforementioned method steps. The method flow has been described in detail in the foregoing embodiments. The modules in this embodiment have the same function or perform the same steps, and will not be described again here. However, those skilled in the art should know that the textual descriptions corresponding to the foregoing method embodiments can be incorporated into this embodiment and correspond to the modules in the communication device 1000.
[0203] In an optional embodiment, the selection unit 1020 or the acquisition unit 1010 may be a processor 1310. The communication device 1000 may also include a memory 1320 and a transceiver 1330, as shown in FIG11.
[0204] Figure 9 is a schematic structural diagram of a communication device 1100 provided in an embodiment of this application. The communication device 1100 can be a second device. The communication device 1100 may include a receiving unit 1110.
[0205] The receiving unit 1110 is used to receive a first request information sent by the first device; wherein the first request information is used to request permission information, and the permission information is used to indicate whether the second device permits one or more intermediate nodes contained in the first request information to process the target data.
[0206] In an optional embodiment, the receiving unit 1110 may be a transceiver 1330. The communication device 1100 may also include a processor 1310 and a memory 1320, as shown in FIG11.
[0207] In this embodiment, the communication device 1100 can be used to execute some or all of the method steps executed by the second device in the above method embodiments. The communication device 1100 includes units or modules for executing the aforementioned method steps. The method flow has been described in detail in the foregoing embodiments. The modules in this embodiment have the same function or perform the same steps, and will not be described again here. However, those skilled in the art should know that the textual descriptions corresponding to the foregoing method embodiments can be incorporated into this embodiment and correspond to the modules in the communication device 1100.
[0208] Figure 10 is a schematic structural diagram of a communication device 1200 provided in an embodiment of this application. The communication device 1200 can be a second device. The communication device 1200 may include a transmitting unit 1210.
[0209] The sending unit 1210 is used to send an authorization file; wherein the authorization file is used to indicate information about intermediate nodes authorized by the second device that are capable of processing data associated with the second device.
[0210] In an optional embodiment, the receiving unit 1110 may be a transceiver 1330. The communication device 1100 may also include a processor 1310 and a memory 1320, as shown in FIG11.
[0211] In this embodiment, the communication device 1200 can be used to execute some or all of the method steps executed by the second device in the above method embodiments. The communication device 1200 includes units or modules for executing the aforementioned method steps. The method flow has been described in detail in the foregoing embodiments. The modules in this embodiment have the same function or perform the same steps, and will not be described again here. However, those skilled in the art should know that the textual descriptions corresponding to the foregoing method embodiments can be incorporated into this embodiment and correspond to the modules in the communication device 1200.
[0212] Figure 11 is a schematic structural diagram of a communication apparatus according to an embodiment of this application. The dashed lines in Figure 11 indicate that the unit or module is optional. The apparatus 1300 can be used to implement the methods described in the above method embodiments. The apparatus 1300 can be a chip, a terminal device, or a network device.
[0213] Apparatus 1300 may include one or more processors 1310. The processor 1310 may support apparatus 1300 in implementing the methods described in the preceding method embodiments. The processor 1310 may be a general-purpose processor or a special-purpose processor. For example, the processor may be a central processing unit (CPU). Alternatively, the processor may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0214] The apparatus 1300 may further include one or more memories 1320. The memories 1320 store a program that can be executed by the processor 1310, causing the processor 1310 to perform the methods described in the preceding method embodiments. The memories 1320 may be independent of the processor 1310 or integrated within the processor 1310.
[0215] The device 1300 may also include a transceiver 1330. The processor 1310 can communicate with other devices or chips via the transceiver 1330. For example, the processor 1310 can send and receive data with other devices or chips via the transceiver 1330.
[0216] This application also provides a computer-readable storage medium for storing a program. This computer-readable storage medium can be applied to a terminal or network device provided in this application, and the program causes a computer to execute the methods performed by the terminal or network device in various embodiments of this application.
[0217] This application also provides a computer program product. The computer program product includes a program. The computer program product can be applied to a terminal or network device provided in this application embodiment, and the program causes a computer to execute the methods performed by the terminal or network device in various embodiments of this application.
[0218] This application also provides a computer program. This computer program can be applied to the terminal or network device provided in this application, and the computer program causes the computer to execute the methods performed by the terminal or network device in various embodiments of this application.
[0219] It should be understood that the terms "system" and "network" in this application can be used interchangeably. Furthermore, the terminology used in this application is only for explaining specific embodiments of the application and is not intended to limit the application. The terms "first," "second," "third," and "fourth," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. In addition, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.
[0220] In the embodiments of this application, the term "instruction" can be a direct instruction, an indirect instruction, or an indication of a relationship. For example, A instructing B can mean that A directly instructs B, such as B being able to obtain information through A; it can also mean that A indirectly instructs B, such as A instructing C, so B can obtain information through C; or it can mean that there is a relationship between A and B.
[0221] In the embodiments of this application, "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean that B is determined solely based on A; B can also be determined based on A and / or other information.
[0222] In the embodiments of this application, the term "correspondence" can indicate a direct or indirect correspondence between two things, or an association between two things, or a relationship such as instruction and being instructed, configuration and being configured.
[0223] In this application embodiment, "predefined" or "preconfigured" can be implemented by pre-storing corresponding codes, tables, or other means that can be used to indicate relevant information in the device (e.g., including terminal devices and network devices). This application does not limit the specific implementation method. For example, predefined can refer to what is defined in the protocol.
[0224] In this application embodiment, the "protocol" may refer to a standard protocol in the field of communication, such as the LTE protocol, the NR protocol, and related protocols applied to future communication systems. This application does not limit this.
[0225] In the embodiments of this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0226] In the embodiments of this application, "comprising" can refer to direct inclusion or indirect inclusion. Optionally, "comprising" mentioned in the embodiments of this application can be replaced with "indicating" or "used to determine". For example, "A includes B" can be replaced with "A indicates B" or "A is used to determine B".
[0227] In the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0228] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0229] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0230] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0231] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can read or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital video discs, DVDs) or semiconductor media (e.g., solid-state disks, SSDs), etc.
[0232] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A wireless communication method, characterized in that, include: The first device obtains the license information of the second device; The first device selects a target intermediate node to process target data based on the permission information. The target intermediate node is an intermediate node permitted by the second device, and the target data includes data associated with the second device.
2. The method according to claim 1, characterized in that, The method further includes: Send the first request information to the second device; The first request information is used to request the permission information, and the permission information is used to indicate whether the second device permits one or more intermediate nodes included in the first request information to process the target data.
3. The method according to claim 2, characterized in that, The first request information includes one or more of the following: The business description information corresponding to the target data; The identifier of the one or more intermediate nodes; The data processing method of the one or more intermediate nodes; The data types processed by the one or more intermediate nodes.
4. The method according to claim 2 or 3, characterized in that, The one or more intermediate nodes are determined based on one or more of the following: The data requester sends a second request message, which is used to request the acquisition of the target data; The computing power of the one or more intermediate nodes; The model supported by the one or more intermediate nodes.
5. The method according to any one of claims 2-4, characterized in that, If the permission information indicates that the second device does not allow all one or more intermediate nodes to process the target data, the method further includes: Choose another device as the device for providing the target data; and / or, Select the target intermediate node from other intermediate nodes besides the one or more intermediate nodes.
6. The method according to any one of claims 1-5, characterized in that, The licensing information is determined based on the license document of the second device, which indicates information about intermediate nodes authorized by the second device that can process data associated with the second device.
7. The method according to claim 6, characterized in that, The authorization document includes one or more of the following: The first information is used to instruct the second device to allow or disallow the intermediate node from performing data processing for the first service; The second information is used to indicate information about intermediate nodes that the second device is permitted to perform data processing for the second service.
8. The method according to claim 7, characterized in that, The first information is used to indicate any of the following: The second device allows the intermediate node to perform data processing for the first service; The second device does not allow intermediate nodes to perform data processing for the first service; Without notifying the second device, the intermediate node is allowed to perform data processing for the first service; Upon notification of the second device, the intermediate node is permitted to perform data processing for the first service; Upon receiving feedback from the second device and obtaining permission from the second device, the intermediate node is allowed to perform data processing for the first service.
9. The method according to claim 7 or 8, characterized in that, The first information includes: The second device allows the intermediate node to perform data processing for the first service for a specified period of time; and / or The second device allows the intermediate node to perform data processing for the first service based on its geographic location.
10. The method according to any one of claims 7-9, characterized in that, The second information includes one or more of the following: The second device is authorized to identify the first intermediate node that performs data processing for the second service; The second device allows the first intermediate node to process the following data types; The second device allows the first intermediate node to perform certain types of processing; The data type corresponding to the processing type allowed by the second device.
11. The method according to any one of claims 7-10, characterized in that, The method further includes: The first device sends a third request message; The third request information is used to request the authorization file.
12. The method according to any one of claims 7-11, characterized in that, In the case where the second device includes a terminal device, the authorization file is stored in the terminal device and / or the authorization file is stored in the subscription data of the terminal device stored on the network; And / or, In the case that the second device includes a core network element or an access network device, the authorization file is stored in the NRF, and / or, the The authorization file is stored in the core network element or access network device.
13. The method according to any one of claims 1-12, characterized in that, The first device is a data plane device.
14. A wireless communication method, characterized in that, include: The second device receives the first request information sent by the first device; The first request information is used to request permission information, and the permission information is used to indicate whether the second device permits one or more intermediate nodes included in the first request information to process the target data.
15. The method according to claim 14, characterized in that, The first request information includes one or more of the following: The business description information corresponding to the target data; The identifier of the one or more intermediate nodes; The data processing method of the one or more intermediate nodes; The data types processed by the one or more intermediate nodes.
16. The method according to claim 14 or 15, characterized in that, The one or more intermediate nodes are determined based on one or more of the following: The data requester sends a second request message, which is used to request the acquisition of the target data; The computing power of the one or more intermediate nodes; The model supported by the one or more intermediate nodes.
17. The method according to any one of claims 14-16, characterized in that, The first device is a data plane device.
18. A wireless communication method, characterized in that, include: The second device sends the authorization document; The authorization document is used to indicate information about intermediate nodes authorized by the second device that are capable of processing data associated with the second device.
19. The method according to claim 18, characterized in that, The authorization document includes one or more of the following: The first information is used to instruct the second device to allow or disallow the intermediate node from performing data processing for the first service; The second information is used to indicate information about intermediate nodes that the second device is permitted to perform data processing for the second service.
20. The method according to claim 19, characterized in that, The first information is used to indicate any of the following: The second device allows the intermediate node to perform data processing for the first service; The second device does not allow intermediate nodes to perform data processing for the first service; Without notifying the second device, the intermediate node is allowed to perform data processing for the first service; Upon notification of the second device, the intermediate node is permitted to perform data processing for the first service; Upon receiving feedback from the second device and obtaining permission from the second device, the intermediate node is allowed to perform data processing for the first service.
21. The method according to claim 19 or 20, characterized in that, The first information includes: the time period during which the second device allows the intermediate node to perform data processing for the first service; and / or the geographical location at which the second device allows the intermediate node to perform data processing for the first service.
22. The method according to any one of claims 19-21, characterized in that, The second information includes one or more of the following: The second device is authorized to identify the first intermediate node that performs data processing for the second service; The second device allows the first intermediate node to process the following data types; The second device allows the first intermediate node to perform certain types of processing; The data type corresponding to the processing type allowed by the second device.
23. The method according to any one of claims 18-22, characterized in that, In the case where the second device includes a terminal device, the authorization file is stored in the terminal device and / or the authorization file is stored in the subscription data of the terminal device stored on the network; And / or, In the case where the second device includes a core network element or an access network device, the authorization file is stored in the NRF, and / or the authorization file is stored in the core network element or the access network device.
24. A communication device, characterized in that, The communication device is a first device, and the communication device includes: The acquisition unit is used to acquire the license information of the second device; The selection unit is configured to select a target intermediate node to process target data based on the license information, wherein the target intermediate node is an intermediate node licensed by the second device, and the target data includes data associated with the second device.
25. A communication device, characterized in that, The communication device is a second device, and the communication device includes: The receiving unit is used to receive the first request information sent by the first device; The first request information is used to request license information, and the license information is used to indicate whether the second device grants permission. The first request information includes one or more intermediate nodes that process the target data.
26. A communication device, characterized in that, The communication device is a second device, and the communication device includes: The sending unit is used to send the authorization file; The authorization document is used to indicate information about intermediate nodes authorized by the second device that are capable of processing data associated with the second device.
27. A communication device, characterized in that, The device includes a transceiver, a memory, and a processor. The memory stores a program, and the processor invokes the program in the memory and controls the transceiver to receive or transmit signals so that the communication device performs the method as described in any one of claims 1-23.
28. An apparatus, characterized in that, Includes a processor for calling a program from memory to cause the device to perform the method as described in any one of claims 1-23.
29. A chip, characterized in that, Includes a processor for calling a program from memory, causing a device on which the chip is mounted to perform the method as described in any one of claims 1-23.
30. A computer-readable storage medium, characterized in that, It contains a program that causes a computer to perform the method as described in any one of claims 1-23.
31. A computer program product, characterized in that, Includes a program that causes a computer to perform the method as described in any one of claims 1-23.
32. A computer program, characterized in that, The computer program causes the computer to perform the method as described in any one of claims 1-23.
Citation Information
Patent Citations
User-level data management method and device, communication equipment and readable storage medium
CN117792647A
Database collaborative computing processing system, method and equipment and storage medium
CN117972786A
Communication method, device and system
WO2022027492A1
Authorized data scheduling method and apparatus, and network side device
WO2023088161A1
Authorization method and apparatus
WO2023213226A1