Access permission management method and apparatus, and storage medium

By introducing digital identity identifiers and structured information from the first functional network element management terminal, the problem of low access permission management efficiency in roaming scenarios is solved, and efficient access permission management is achieved.

WO2026098019A1PCT designated stage Publication Date: 2026-05-15DATANG MOBILE COMM EQUIP CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
DATANG MOBILE COMM EQUIP CO LTD
Filing Date
2025-08-27
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In roaming scenarios, access control through offline signing of roaming agreements between the terminal's home network device and the visited network device is inefficient.

Method used

The first functional network element is introduced to manage the digital identity and structured information of the terminal. Through the interaction between the first functional network element and the first network device, it is determined whether the terminal has access rights, thus avoiding frequent signaling interactions and offline signing of roaming agreements.

Benefits of technology

It enables efficient access control in roaming scenarios, improving the efficiency of access control management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025117367_15052026_PF_FP_ABST
    Figure CN2025117367_15052026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of communications, and provides an access permission management method and apparatus, and a storage medium. The method is applied to a first functional network element, and comprises: receiving a digital identifier sent by a first network device, the digital identifier being a digital identifier of a terminal; on the basis of the digital identifier, determining structured information of the terminal; and sending the structured information to the first network device, the digital identifier and the structured information being used for determining whether the terminal has permission to access the first network device. According to the solution of the present disclosure, the efficiency of access permission management can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Access control methods, devices and storage media

[0001] This disclosure claims priority to Chinese Patent Application No. 202411577590.4, filed on November 6, 2024, entitled “Access Permission Management Method, Apparatus and Storage Medium”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This disclosure relates to the field of communication technology, and more specifically, to an access control method, apparatus, and storage medium. Background Technology

[0003] To ensure the security of communication between a terminal and a visited network device, it is necessary to determine whether the terminal is allowed to access the visited network device when the terminal requests access to the visited network device.

[0004] Currently, the main method for determining whether a terminal is allowed to access a visited network device is through the authentication and key agreement (AKA) process. However, this method requires the terminal's home network device and the visited network device to sign a roaming agreement offline, which is inefficient. Summary of the Invention

[0005] This disclosure provides an access permission management method, apparatus, and storage medium, which solves the technical problem of low efficiency in roaming scenarios where the roaming agreement is signed offline between the terminal's home network device and the visited network device, and access permission management is performed based on the AKA process.

[0006] Firstly, this disclosure provides an access control method applied to a first functional network element, the method comprising:

[0007] Receives a digital identity identifier sent by the first network device, where the digital identity identifier is the terminal's digital identity identifier;

[0008] Based on the digital identity identifier, determine the terminal's structured information;

[0009] Structured information is sent to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.

[0010] In some embodiments, the structured information includes at least one of the following:

[0011] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0012] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0013] Key credential information, used to indicate the terminal's public key;

[0014] Home network device information, used to indicate the home network device of the terminal;

[0015] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0016] In some embodiments, a digital identity includes at least one of the following:

[0017] Identifiers for digital identity schemes;

[0018] Identifiers for digital identity methods;

[0019] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0020] In some embodiments, the method further includes:

[0021] Receive home network device information sent by the first network device;

[0022] Determine whether the terminal has access to the first network device based on the network device information;

[0023] A response message is sent to the first network device, which indicates whether the terminal has access rights to the first network device.

[0024] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information includes:

[0025] The string identifier is decrypted according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device;

[0026] Based on the terminal's SUCI and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that each terminal is allowed to access. The home network devices of each terminal are the second network device.

[0027] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.

[0028] Secondly, this disclosure provides an access control method applied to a first network device, the method comprising:

[0029] The receiving terminal sends a first access request message, which includes the terminal's digital identity identifier.

[0030] Send a digital identity identifier to the first functional network element;

[0031] Receive structured information sent by the first functional network element;

[0032] Based on the structured information, determine whether the terminal has access rights to the first network device.

[0033] In some embodiments, the structured information includes at least one of the following:

[0034] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0035] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0036] Key credential information, used to indicate the terminal's public key;

[0037] Home network device information, used to indicate the home network device of the terminal;

[0038] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0039] In some embodiments, the first access request further includes the terminal's digital signature information. Based on the structured information, determining whether the terminal has access rights to the first network device includes:

[0040] The digital signature information is verified using the terminal's public key to obtain the verification result;

[0041] If the verification result is successful, determine whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.

[0042] In some embodiments, determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes:

[0043] If the network device access information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.

[0044] In some embodiments, the method further includes:

[0045] Send a query request message to the terminal. The query request message is used to request the query terminal's SUCI.

[0046] SUCI sent by the receiving terminal;

[0047] According to SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0048] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information and / or the access network device information includes:

[0049] If the identifier of the first network device is not included in the accessed network device information, send the home network device information to the first functional network element.

[0050] The terminal receives a response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.

[0051] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message also includes the terminal's SUCI, and the method further includes:

[0052] A second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0053] In some embodiments, the second access request message includes at least one of the following:

[0054] Digital identity;

[0055] Digital signature information;

[0056] SUCI of the terminal.

[0057] In some embodiments, a digital identity includes at least one of the following:

[0058] Identifiers for digital identity schemes;

[0059] Identifiers for digital identity methods;

[0060] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0061] Thirdly, this disclosure provides an access control method for use on a terminal, the method comprising:

[0062] A first access request message is sent to a first network device. The first access request message includes the terminal's digital identity identifier. The digital identity identifier is used to obtain the terminal's structured information. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.

[0063] In some embodiments, the structured information includes at least one of the following:

[0064] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0065] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0066] Key credential information, used to indicate the terminal's public key;

[0067] Home network device information, used to indicate the home network device of the terminal;

[0068] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0069] In some embodiments, a digital identity includes at least one of the following:

[0070] Identifiers for digital identity schemes;

[0071] Identifiers for digital identity methods;

[0072] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0073] In some embodiments, the method further includes:

[0074] In response to a query request message received from the first network device, the terminal sends its SUCI to the first network device.

[0075] Fourthly, this disclosure provides an access control method applied to a second network device, the method comprising:

[0076] The terminal receives a second access request message sent by a first network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0077] In some embodiments, the second access request message includes at least one of the following:

[0078] Digital identity;

[0079] Digital signature information;

[0080] SUCI of the terminal.

[0081] In some embodiments, a digital identity includes at least one of the following:

[0082] Identifiers for digital identity schemes;

[0083] Identifiers for digital identity methods;

[0084] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0085] In some embodiments, the method further includes:

[0086] Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the network devices to which at least one terminal belongs are the second network devices.

[0087] Fifthly, this disclosure provides an access control device, the device comprising:

[0088] The first receiving module is used to receive a digital identity identifier sent by the first network device, wherein the digital identity identifier is the digital identity identifier of the terminal.

[0089] The first processing module is used to determine the structured information of the terminal based on the digital identity identifier;

[0090] The first sending module is used to send structured information to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.

[0091] Sixthly, this disclosure provides an access control device, the device comprising:

[0092] The second receiving module is used to receive a first access request message sent by the terminal, the first access request message including the digital identity identifier of the terminal;

[0093] The second sending module is used to send digital identity identifiers to the first functional network element;

[0094] The third receiving module is used to receive structured information sent by the first functional network element;

[0095] The second processing module is used to determine whether the terminal has access rights to the first network device based on the structured information.

[0096] In a seventh aspect, this disclosure provides an access control device, the device comprising:

[0097] The first transceiver module is used to send a first access request message to the first network device. The first access request message includes the digital identity of the terminal. The digital identity is used to obtain the structured information of the terminal. The digital identity and the structured information are used to determine whether the terminal has access rights to the first network device.

[0098] Eighthly, this disclosure provides an access control device, the device comprising:

[0099] The second transceiver module is used to receive a second access request message sent by the first network device. The second access request message is used by the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0100] Ninthly, this disclosure provides an access control device, including a memory, a transceiver, and a processor:

[0101] A memory for storing computer programs; a transceiver for sending and receiving data under the control of a processor; and a processor for reading computer programs from the memory and executing the access control method of any one of the first aspects.

[0102] In a tenth aspect, this disclosure provides an access control device, including a memory, a transceiver, and a processor:

[0103] A memory is used to store computer programs; a transceiver is used to send and receive data under the control of a processor; and a processor is used to read computer programs from the memory and execute the access control method of any of the second aspects.

[0104] In one aspect, this disclosure provides an access control device, including a memory, a transceiver, and a processor:

[0105] A memory is used to store computer programs; a transceiver is used to send and receive data under the control of a processor; and a processor is used to read computer programs from the memory and execute access control methods of any of the third aspects.

[0106] In a twelfth aspect, this disclosure provides an access control device, including a memory, a transceiver, and a processor:

[0107] Memory is used to store computer programs; transceiver is used to send and receive data under the control of the processor; processor is used to read computer programs from memory and execute access control methods of any of the fourth aspects.

[0108] In a thirteenth aspect, this disclosure provides a non-transitory readable storage medium storing a computer program for causing a processor to perform the method of any one of the first to fourth aspects.

[0109] In a fourteenth aspect, this disclosure provides a computer program product, including a computer program, wherein the computer program, when executed by a processor, implements the method of any one of the first to fourth aspects.

[0110] The access permission management method, apparatus, and storage medium provided in this disclosure allow a terminal to send a first access request message to a first network device when the terminal needs to access a first network device. The first access request message includes the terminal's digital identity identifier. The first network device then sends the digital identity identifier to a first functional network element. The first functional network element determines the terminal's structured information based on the digital identity identifier and sends the structured information back to the first network device. This solution uses a first functional network element to uniformly manage the terminal's digital identity identifier and structured information. When a terminal requests access to a first network device, the first functional network element sends the terminal's structured information to the first network device, enabling the first network device to determine whether the terminal has access rights to the first network device based on the digital identity identifier and structured information. This achieves high efficiency in access permission management based on digital identity identifiers and structured information in roaming scenarios without requiring offline roaming agreements between the terminal's home network device and the first network device, or frequent signaling interactions.

[0111] It should be understood that the description in the foregoing summary section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0112] Figure 1 is a signaling diagram of a 5A-AKA process provided in an embodiment of this disclosure;

[0113] Figure 2 is a schematic diagram of identity verification management under a 6G network provided in an embodiment of this disclosure;

[0114] Figure 3 is a signaling diagram of the access control method provided in the embodiments of this disclosure;

[0115] Figure 4 is a schematic diagram of a connection relationship provided in an embodiment of this disclosure;

[0116] Figure 5 is a schematic diagram of the composition of a DID identifier provided in an embodiment of this disclosure;

[0117] Figure 6 is a schematic diagram of the composition of the DID document provided in the embodiments of this disclosure;

[0118] Figure 7 is a schematic diagram of the composition of the VC provided in the embodiments of this disclosure;

[0119] Figure 8 is a signaling diagram of the access control method provided in the embodiments of this disclosure;

[0120] Figure 9 is a signaling diagram of the access control method provided in the embodiments of this disclosure;

[0121] Figure 10 is a schematic diagram of the access control device provided in an embodiment of this disclosure.

[0122] Figure 11 is a second structural schematic diagram of the access control device provided in an embodiment of this disclosure;

[0123] Figure 12 is a schematic diagram of the access control device provided in an embodiment of this disclosure.

[0124] Figure 13 is a schematic diagram of the access control device provided in an embodiment of this disclosure;

[0125] Figure 14 is a schematic diagram of the access control device provided in an embodiment of this disclosure.

[0126] Figure 15 is a schematic diagram of the access control device provided in an embodiment of this disclosure.

[0127] Figure 16 is a schematic diagram of the access control device provided in an embodiment of this disclosure.

[0128] Figure 17 is a schematic diagram of the access control device provided in an embodiment of this disclosure. Detailed Implementation

[0129] In this disclosure, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0130] In this disclosure, the term "at least one" means one or more, "multiple" means two or more, and other quantifiers are similar.

[0131] The terms "first," "second," etc., used in the embodiments of this disclosure are for illustrative purposes and to distinguish the objects being described. They do not indicate any order and do not imply any particular limitation on the number of objects in the embodiments of this disclosure. They do not constitute any limitation on the embodiments of this disclosure.

[0132] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this disclosure.

[0133] This disclosure provides an access permission management method, apparatus, and storage medium to address the technical problem of low efficiency in managing terminal access permissions when a terminal needs to access network devices in a roaming scenario.

[0134] The method and apparatus are based on the same concept of the application. Since the methods and apparatus solve problems in similar ways, the implementation of the apparatus and methods can refer to each other, and the repeated parts will not be described again.

[0135] The technical solutions provided in this disclosure can be applied to a variety of systems. For example, applicable systems may include Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, and 6G (sixth generation mobile communication technology) systems. These systems may include terminal equipment and network equipment. The systems may also include a core network component, such as the Evolved Packet Core (EPC) or the 5G Core Network (5GC).

[0136] The terminal devices involved in the embodiments of this disclosure can be devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The names of the terminal devices may differ in different systems; for example, in 5G or 6G systems, the terminal device may be called User Equipment (UE). Wireless terminal devices can be USB storage devices, other personal computer memory devices, and dongles. They can also communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal devices can be mobile terminal devices, such as mobile phones (or "cellular" phones) and computers with mobile terminal devices. For example, they can be portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the radio access network. Examples of such devices include Personal Communication Service (PCS) telephones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), personal computers, tablets, and Machine-type Communication (MTC) terminal devices. Wireless terminal devices can also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile devices, remote stations, access points, remote terminals, access terminals, user terminals, user agents, user devices, and wireless access devices and routers / modems that meet the limitations of this definition, but are not limited to these in the embodiments of this disclosure.

[0137] The network device involved in this disclosure can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with wireless terminal devices through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network device involved in this disclosure can be an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, or a Home evolved Node B (HeNB), relay node, femto, pico, network testing equipment, etc., and is not limited in this disclosure. In some network architectures, network devices may include centralized unit (CU) nodes and distributed unit (DU) nodes, which may also be geographically separated.

[0138] In roaming scenarios, terminals have a need to access network devices. The network device where the terminal is registered can be called the terminal's home network device, and the network device that the terminal needs to access when roaming to other locations can be called the terminal's visited network device.

[0139] To ensure the security of data transmission between the terminal and the visited network device, when the terminal requests access to the visited network device, it is necessary to manage the terminal's access permissions to determine whether the terminal is allowed to access the visited network device.

[0140] In 5G New Radio (NR), terminal access permission management is achieved through the AKA process. The AKA process in the 5G network is described below with reference to Figure 1.

[0141] Figure 1 is a signaling diagram of a 5A-AKA process provided in an embodiment of this disclosure. As shown in Figure 1, the main network elements involved include a User Data Management (UDM) network element, an Authentication Credential Repository and Processing Function (ARPF) network element, an Authentication Server Function (AUSF) network element, a Security Anchor Function (SEAF) network element, and a terminal. Among them, the AUSF network element, UDM network element, and ARPF network element belong to the network elements in the home network device, while the SEAF network element belongs to the network elements in the visited network device. As shown in Figure 1, the process includes the following steps:

[0142] 1. UDM network elements generate authentication vectors (AVs).

[0143] AV (Authenticator) is a set of parameters used for authentication, verifying the authenticity of terminals or network devices to ensure secure communication. AV typically includes the following parameters:

[0144] Random challenge (RAND) is an unpredictable random number provided to the terminal by the home network device to initiate the authentication process;

[0145] An authentication token (AUTN) is used to ensure two-way authentication between a terminal and a visited network device. The AUTN provides information to the terminal, enabling the terminal to authenticate the visited network device based on the AUTN.

[0146] 2. The UDM / ARPF network element sends an authentication vector retrieval request response message (Nudm_UEAuthenticate_Get Response) to the AUSF network element.

[0147] The authentication vector retrieval request response message includes RAND, AUTN, and the expected response (XRES*), where XRES* represents the authentication response that the network device expects to receive from the terminal. If the authentication vector retrieval request message contains a Subscription Concealed Identifier (SUCI), the authentication vector retrieval request response message also carries a Subscription Permanent Identifier (SUPI).

[0148] 3. AUSF network element storage XRES*.

[0149] 4. Calculate the hidden expected response (Hidden XRES*, HXRES*) for AUSF network elements.

[0150] HXRES* is an encrypted or hidden form of XRES*, used to enhance the security of the authentication process. During authentication, the terminal calculates an authentication response RES* based on the RAND and key provided by the home network device. To verify the terminal's identity, the home network device expects a hidden authentication response XRES* that matches the RES calculated by the terminal. For added security, the network device does not transmit XRES* directly, but instead transmits its hidden form, HXRES*.

[0151] The introduction of HXRES* prevents XRES* from being maliciously intercepted or abused during the authentication process. By hiding XRES*, HXRES* can reduce security risks while ensuring the effectiveness of the authentication process.

[0152] 5. The AUSF network element sends an authentication request service response message (Nausf_UEAuthentication_Authenticate_Response) to the SEAF network element.

[0153] The authentication request service response message carries 5G SE AV (RAND, AUTN, and HXRES*).

[0154] 6. The SEAF network element sends a NAS message (Authentication-Request) to the terminal.

[0155] SEAF network elements initiate an authentication process for the terminal via NAS messages, carrying authentication parameters RAND and AUTN, as well as Network Key Security Information (ngKSI).

[0156] 7. Terminal calculation of RES*.

[0157] After receiving RAND and AUTN, the terminal verifies the freshness of the received AUTN. If the verification is successful, the terminal calculates RES*.

[0158] 8. The terminal sends a NAS authentication response message to the SEAF network element.

[0159] The NAS authentication response message includes RES*.

[0160] 9. SEAF network elements calculate HRES* and compare HRES* with HXRES*.

[0161] The SEAF network element calculates HRES* based on the RES* sent by the terminal. SEAF compares HRES* and HXRES*. If they match, the terminal is considered to have successfully authenticated with the currently visited network device.

[0162] 10. The SEAF network element sends an authentication request message (Nausf_UEAuthentication_Authenticate_Request) to the AUSF network element.

[0163] SEAF network element sends an authentication request message to the home network authentication center (AUSF) network element, and the authentication request message includes RES*.

[0164] 11. AUSF network elements compare and verify RES* and XRES*.

[0165] After receiving the authentication request message, the AUSF network element first determines whether the AV has expired. If it has expired, the authentication is considered to have failed. Otherwise, it compares RES* and XRES*. If they are equal, the authentication is considered to have succeeded from the perspective of the home network device.

[0166] 12. The AUSF network element sends an authentication response message (Nausf_UEAuthentication_Authenticate_Response) to the SEAF network element.

[0167] The authentication response message includes the authentication result of the terminal on the home network device, and the SEAF network element is notified of the authentication result of the terminal on the home network device through the authentication response message.

[0168] In the 5G AKA protocol, the AUSF network element requests an authentication vector from the UDM network element. Upon receiving the authentication vector, the AUSF network element returns it to the SEAF network element. The SEAF network element then returns the authentication vector to the terminal. The terminal authenticates the network device based on the authentication vector and sends RES* back to the visited network device. The visited network device uses RES* to authenticate the terminal. After successful authentication by the visited network device, RES* is sent to the home network device. The home network device verifies RES* to determine if the terminal is legitimate.

[0169] From the above steps, it can be seen that in the current 5G AKA process, the access control management of the terminal by the visited network device depends on the RES* generated by the authentication vector sent to the terminal by the home network device. The visited network device manages the access control of the terminal by comparing the RES* with the locally calculated HXRES* (based on the authentication vector of the home network device). The home network device verifies the RES* and authenticates the terminal.

[0170] In the above process, the access control of the terminal by the visited network device relies on the authentication vector provided by the home network device during the primary authentication process, making it overly dependent on the home network device. With the development of communication technology, to meet the diverse service needs of various scenarios, future 6G networks will adopt a decentralized hierarchical network with centralized and distributed collaboration. 6G networks will be organized through centralized and distributed collaboration and distributed autonomy, which can meet the diverse heterogeneous access scenarios and network performance requirements of air, land, and sea. In a distributed network, a logical node may be deployed on multiple physical entities or implemented by different software modules depending on the node's functions. Facing 6G distributed networks, there is plug-and-play functionality for distributed subnets. If a terminal on a home network device wants to access a distributed visited network device, according to 5G mechanisms, the home network device needs to sign a roaming agreement offline with the visited network device, which is inefficient. Furthermore, the dynamic network topology of 6G distributed networks leads to an increase in the number of subnets and frequent changes. From the terminal's perspective, this requires the terminal to frequently adjust the visited network list via NAS signaling, and the list also needs to maintain too many network device names and access technology categories.

[0171] In the architecture of a 6G distributed network, devices are located in different management domains. Within the same management domain, they are considered trusted. In order to establish trust between devices located in different management domains, the participating devices need to perform mutual authentication across management domains without involving trusted third parties, so as to manage the access permissions of the terminals.

[0172] The process can be seen in Figure 2, which is a schematic diagram of authentication management under a 6G network provided by an embodiment of this disclosure. As shown in Figure 2, it illustrates how devices under two different management domains (domain A and domain B) can perform cross-management domain mutual authentication.

[0173] Each management domain includes the following components:

[0174] Proxy Server: The proxy server is a node in the blockchain, serving the key generation center and periodically updating and uploading device public keys and system information. Each key generation center in the management domain needs to build a node to maintain the global ledger of the blockchain.

[0175] Key Generation Center: Generates private keys for corresponding devices based on the identity information and system information sent by devices within this management domain. The public key serves as the device's identity information, which is a temporary identifier generated by the device and needs to be updated periodically. It does not require signatures from authoritative institutions or digital certificates, simplifying the complexity of key system management. The Key Generation Center uploads the device's public key and system information to the blockchain through a proxy server and updates it periodically.

[0176] Authentication server: A device used for authentication. It can request the system information and public key information required for authentication of cross-domain devices in the blockchain from the proxy server in this management domain, and perform authentication of cross-domain devices on behalf of the requesting device.

[0177] When a device needs to perform authentication, it sends its identity information to a key generation center to generate a device private key. Blockchain, as an immutable distributed ledger, can provide trust endorsement for device public keys and system information across different management domains. When a device performs cross-domain authentication, it downloads the public key stored in the blockchain and uses it to verify the authentication message sent by the cross-domain device.

[0178] As shown in Figure 2, for domain A, the devices under domain A include proxy server 201, key generation center 202, device 203 and authentication server 204; for domain B, the devices under domain B include proxy server 211, key generation center 212, device 213 and authentication server 214.

[0179] Taking device 203 in domain A accessing domain B as an example, device 203 first needs to send an authentication request to the authentication server 214. The authentication request includes device 203's signature information. This signature information is generated based on device 203's private key, which is generated by the key generation center 202 based on device 203's identity information.

[0180] After receiving the authentication request from device 203, authentication server 214 obtains the signature information of device 203, downloads the public key and system information of domain A from the blockchain through proxy server 211, and then verifies the signature information using the public key of domain A to confirm the legitimacy of the authentication request. If legitimate, device 203 is allowed to access domain B; otherwise, device 203 is not allowed to access domain B. The authentication process for device 213 is similar and will not be described further here.

[0181] However, the aforementioned cross-domain authentication mechanism based on identity information mainly targets the authentication of terminals, i.e. whether the terminal is a registered user. It does not include access control of the terminal by the visiting network device. That is, if the visiting network device authenticates the terminal, it considers the terminal registered on the blockchain network to be a legitimate terminal, but it fails to implement further access control over the terminal registered on the blockchain network.

[0182] Based on this, the present disclosure provides an access permission management method, which introduces a first functional network element to manage the digital identity and structured information of the terminal. When the terminal needs to access the first network device, access permission management of the terminal is achieved through the interaction between the first functional network element and the first network device. This eliminates the need for frequent signaling interactions to access the visited network list, thereby enabling access permission management based on digital identity and structured information in roaming scenarios with high efficiency.

[0183] Figure 3 is a signaling diagram of the access control method provided in this embodiment of the present disclosure. As shown in Figure 3, the method includes:

[0184] S31, the terminal sends a first access request message to the first network device, the first access request message including the terminal's digital identity identifier.

[0185] In all embodiments of this disclosure, the terminal is registered with the first functional network element. The registration process can be offline registration or the terminal can send a registration request to the first functional network element to complete the terminal registration.

[0186] Taking a terminal sending a registration request to a first functional network element as an example, the registration request includes the terminal's identity information, which is used to uniquely identify the terminal. After receiving the terminal's identity information, the first functional network element generates a digital identity identifier for the terminal and corresponding structured information.

[0187] The terminal's digital identity can be a universal identity identifier used across different platforms to uniquely identify the terminal. Optionally, the first functional network element can perform calculations or encryption on the terminal's identity information to obtain the terminal's digital identity. Optionally, the registration request may also include a configuration file, which indicates the terminal's home network device and the network devices the terminal is allowed to access. The first functional network element can perform calculations or encryption on the terminal's identity information, as well as the identifiers of the home network device and the network devices the terminal is allowed to access, to obtain the terminal's digital identity.

[0188] The structured information of a terminal is a detailed description of the terminal's digital identity, and there is a one-to-one relationship between the digital identity and the structured information. For example, the structured information may indicate the terminal's home network device and / or the network devices that the terminal is allowed to access. For example, the structured information may include key credential information to indicate the terminal's public key. For example, if the terminal's digital identity is generated based on a certain encryption mechanism, the structured information may indicate that encryption mechanism, and so on.

[0189] When a terminal needs to access a first network device, the terminal sends a first access request message to the first network device, which is the visited network device of the terminal. The first access request message includes the digital identity identifier of the terminal.

[0190] S32, the first network device sends a digital identity identifier to the first functional network element.

[0191] The first network device receives a first access request message sent by the terminal, and can obtain the terminal's digital identity from the first access request message. Since the terminal's digital identity and structured information are managed uniformly by the first functional network element, the first network device sends the digital identity to the first functional network element to request the terminal's structured information.

[0192] S33, the first functional network element determines the structured information of the terminal based on the digital identity identifier.

[0193] The first functional network element is used to manage the digital identity identifiers of different terminals. The digital identity identifiers and structured information are in one-to-one correspondence. Therefore, after receiving the digital identity identifier sent by the first network device, the first functional network can determine the structured information of the terminal based on the digital identity identifier and the one-to-one correspondence between the digital identity identifier and the structured information.

[0194] S34, the first functional network element sends structured information to the first network device.

[0195] After determining the structured information of the terminal, the first functional network sends the structured information to the first network device, and the first network device receives the structured information accordingly.

[0196] S35, the first network device determines whether the terminal has access rights to the first network device based on the structured information.

[0197] After receiving the structured information sent by the first functional network element, the first network device uses the structured information to determine whether the terminal has access rights to the first network device, that is, whether the terminal is allowed to access the first network device.

[0198] For example, if the structured information can be used to indicate the network devices that the terminal is allowed to access, and the first network device is included among the network devices that the terminal is allowed to access, then it is determined that the terminal has access rights to the first network device; if the first network device is not included among the network devices that the terminal is allowed to access, then it is determined that the terminal does not have access rights to the first network device.

[0199] For example, when the structured information can be used to indicate the home network device of the terminal, the first network device can send the home network device information to the first functional network element. The first functional network element determines whether the terminal has access rights to the first network device based on the home network device information, and then the first functional network element instructs the first network device whether the terminal has access rights to the first network device.

[0200] The access permission management method provided in this disclosure involves a terminal sending a first access request message to the first network device when it needs to access a first network device. The first access request message includes the terminal's digital identity identifier. The first network device then sends the digital identity identifier to a first functional network element. The first functional network element determines the terminal's structured information based on the digital identity identifier and sends the structured information back to the first network device. This solution uses a first functional network element to uniformly manage the terminal's digital identity identifier and structured information. When a terminal requests access to the first network device, the first functional network element sends the terminal's structured information to the first network device, enabling the first network device to determine whether the terminal has access rights to the first network device based on the digital identity identifier and structured information. This method achieves high efficiency in roaming scenarios by eliminating the need for the terminal's home network device and the first network device to sign a roaming agreement offline or to engage in frequent signaling interactions.

[0201] The solutions of the embodiments of this disclosure will be further described below with reference to the accompanying drawings.

[0202] First, the connection relationship between the first functional network element, the terminal, and the network device is described with reference to Figure 4. Figure 4 is a schematic diagram of a connection relationship provided by an embodiment of this disclosure. As shown in Figure 4, the connection relationship between terminal A, the first network device, the second network device, and the first functional network element is illustrated.

[0203] The first functional network element, also known as the digital identity management platform, identity management platform, digital identity management server, etc., is used to manage the digital identity identifiers and structured information of all terminals, and can also be used to manage the identifiers of all network devices.

[0204] The terminal is a user registered with the first functional network element. After registering with the first functional network element, the terminal can obtain the services provided by the first functional network element. The connection between the terminal and the first functional network element can be a wired connection or a wireless connection. As shown in Figure 4, after terminal A completes its registration on the first functional network element side, terminal A establishes a connection with the first functional network element and can obtain the services provided by the first functional network element.

[0205] The first network device is the visited network device for terminal A. The first network device can also register with the first functional network element. After registering with the first functional network element, the first network device can obtain the services provided by the first functional network element. The connection between the first network device and the first functional network element can be a wired connection or a wireless connection.

[0206] The second network device is the home network device of terminal A, and the second network device can also register with the first functional network element. After registering with the first functional network element, the second network device can obtain the services provided by the first functional network element. The connection between the second network device and the first functional network element can be a wired connection or a wireless connection.

[0207] For any given network device, it may include one or more network elements. Establishing a connection between the network device and the first functional network element can mean that each network element in the network device establishes a connection with the first functional network element, or it can mean that a certain proxy network element in the network device establishes a connection with the first functional network element.

[0208] As shown in Figure 4, the first network device includes three network elements, namely network function 1, network function 2 and network function 3. The establishment of a connection between the first network device and the first functional network element means that network function 1, network function 2 and network function 3 are all connected to the first functional network element.

[0209] As shown in Figure 4, the second network device includes three network elements: a proxy network element, network function 2, and network function 3. The connection between the second network device and the first function network element indicates that the proxy network element has established a connection with the first function network element.

[0210] For example, for any network device, if all network elements in the network device establish a connection with the first functional network element, then subsequent information interaction between the network device and the first functional network element is achieved through the interaction between the corresponding network element in the network device and the first functional network element; if only the proxy network element in the network device establishes a connection with the first functional network element, then subsequent information interaction between the network device and the first functional network element is achieved through the interaction between the proxy network element and the first functional network element. It is understood that the interaction process between the first network device and the first functional network element, and the interaction process between the second network device and the first functional network element in Figure 4, are merely examples and do not constitute a limitation on the interaction process. In the following embodiments, interactions between network devices and other devices are described using actions such as "network device sends A" or "network device receives B". "Network device sends A" can mean "network function 1 sends A / network function 2 sends A / network function 3 sends A...", and "network device receives B" can mean "network function 1 receives B / network function 2 receives B / network function 3 receives B...". Alternatively, "network device sends A" can mean "a proxy network element in the network device sends A", and "network device receives B" can mean "a proxy network element in the network device receives B".

[0211] The above embodiments, in conjunction with Figure 4, illustrate the connection relationship between the first functional network element, the terminal, and the network device. The terminal can register with the first functional network element through a registration process. The first functional network element generates the terminal's digital identity and structured information, and sends the terminal's digital identity to the terminal. The network device can also register with the first functional network element through a registration process. The first functional network element generates the network device's identifier (which can be the network device's digital identity) and the network device's structured information. The terminal's digital identity and structured information will be described below with reference to the accompanying drawings.

[0212] With the widespread adoption of mobile internet, each user has several accounts, collectively known as digital identities. A digital identity serves as a marker in a user's virtual life and forms the basis for their online activities, allowing them to continuously connect with other devices. As digital identity technology and blockchain technology advance, blockchain's private key encryption and distributed storage ensure end-to-end data traceability. Furthermore, the continuous improvement of user digital identity information can fundamentally address the existing blockchain problem of ensuring authenticity on the chain but failing to detect forgery, while effectively promoting the flow and sharing of blockchain information, thereby improving overall authentication efficiency.

[0213] After the terminal registers with the first functional network element, the first functional network element generates the terminal's digital identity and structured information. During the registration process, the terminal sends its identity information and configuration file to the first functional network element. This configuration file indicates the terminal's home network device and the network devices the terminal is allowed to access. Based on the terminal's identity information and configuration file, the first functional network element generates the terminal's digital identity and structured information.

[0214] For example, the digital identity of a terminal can be, for instance, the terminal's decentralized identity (DID).

[0215] DID is a new type of identifier, a decentralized identification protocol released by the World Wide Web Consortium (W3C) to identify any entity (such as an individual, organization, abstract entity, virtual entity, etc.). DIDs are platform-independent; a single DID can be used to log in to multiple different platforms. Even if one platform is shut down, it will not affect the ability to log in to other platforms (provided that the platform supports DIDs).

[0216] DID places greater emphasis on decentralization, requiring each terminal in the identity system to achieve point-to-point interaction through DID identification, so that no single node or group of nodes can control all the data generated in the process; DID requires that all aspects of the identity system architecture be decentralized, including data storage, verification, and transaction, all of which are carried out on the blockchain or distributed ledger, achieving decentralization from the underlying protocol to the upper-layer application.

[0217] Figure 5 is a schematic diagram of the composition of a DID identifier provided in an embodiment of this disclosure. As shown in Figure 5, the DID identifier mainly consists of three parts: scheme identifier, DID method identifier, and specific identifier in the DID method.

[0218] The scheme identifier is the first part of the DID identifier and is used to distinguish the different schemes to which the DID identifier belongs. The scheme identifier is fixed and usually begins with "did:" (as shown in the example "did:" in Figure 5), indicating that the DID identifier follows the DID specification.

[0219] The DID method identifier is the second part of the DID identifier (as shown in the example in Figure 5). It is used to indicate that the DID identifier is generated using a specific DID method in the DID specification, representing the method and rules used by the DID identifier.

[0220] The specific identifier in the DID method is a string generated by the method identifier (as shown in the example "123456789abcdefghi" in Figure 5), which is used to uniquely represent the corresponding device.

[0221] There is a one-to-one relationship between the DID identifier and the DID document; the DID document is a detailed description of the DID identifier. Figure 6 is a schematic diagram of the composition of the DID document provided in an embodiment of this disclosure. As shown in Figure 6, the DID document mainly consists of two parts: DID metadata and DID public key.

[0222] The DID public key can be used for digital signatures or encryption operations. The DID identifier can be stored on the terminal, while the DID document can be stored in data such as a blockchain (indexed by the DID identifier) ​​to ensure the correctness of the DID document. Since the DID document does not contain any content related to real information, authentication is required through a Verifiable Credential (VC) in the DID application layer.

[0223] A VC is a descriptive statement issued by a DID to endorse certain attributes of another DID, and is accompanied by its own digital signature to prove the authenticity of these attributes. It can be considered a type of digital certificate.

[0224] Figure 7 is a schematic diagram of the composition of the VC provided in the embodiment of this disclosure. As shown in Figure 7, the VC mainly includes the following information:

[0225] VC metadata mainly includes information such as the issuer, release date, and type of declaration.

[0226] Declaration: One or more descriptions of the subject, which may include information such as name, gender, date of birth, etc.;

[0227] Proof: This is usually the issuer's digital signature, which ensures that the VC can be verified, prevents the VC content from being tampered with, and verifies the issuer of the VC.

[0228] Because the DID document corresponding to the DID does not contain the actual terminal information, the terminal needs to provide proof, i.e., a VC (Publisher Document), when performing a certain operation. The DID identifier can be obtained through the Uniform Resource Identifier (URI) field in the VC, and then its public key can be obtained from the corresponding DID document. Verifying the signature of the VC using the public key verifies whether the VC was issued by the publisher.

[0229] In one possible implementation, the terminal's digital identity includes at least one of the following: 1.1 to 1.3

[0230] 1.1 Identifiers for digital identity schemes.

[0231] The identifier of a digital identity scheme is used to identify the corresponding digital identity scheme. If the digital identity identifier of a terminal includes the identifier of a digital identity scheme, it means that the digital identity identifier follows the corresponding digital identity scheme specification, or it can mean that the digital identity identifier is compatible with other systems that follow the same digital identity scheme specification.

[0232] In some embodiments, if the digital identity of the terminal is the terminal's DID identifier, then the identifier of the digital identity scheme can be the scheme identifier in the DID identifier.

[0233] 1.2 Identifiers for digital identity methods.

[0234] The identifier of the digital identity method is used to identify the corresponding digital identity method. If the digital identity identifier of the terminal includes the identifier of the digital identity method, then the identifier of the digital identity method indicates which digital identity method in the digital identity scheme specification was used to generate the digital identity identifier.

[0235] In some embodiments, if the digital identity of the terminal is the terminal's DID identifier, then the identifier of the digital identity method can be the DID method identifier in the DID identifier.

[0236] 1.3 String identifier of the terminal in the digital identity method.

[0237] The string identifier is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0238] In some embodiments, if the digital identity of the terminal is the terminal's DID identifier, then the string identifier of the terminal in the digital identity method can be a specific identifier in the DID method.

[0239] For example, a digital identity for a terminal can take the following form:

[0240] DID: <did-xxmobile>:<H(SUCI||PLMN)>

[0241] In the aforementioned digital identity identifier, "DID:" is the identifier of the digital identity scheme, used to identify the corresponding digital identity scheme as DID. "did-XXmobile" is the identifier of the digital identity method, used to identify the corresponding digital identity method as "did-XXmobile", where did-XXmobile represents the encryption of the terminal's SUCI and PLMN. "H(SUCI||PLMN)" is the string identifier in the terminal's digital identity method "did-XXmobile", where SUCI is the terminal's SUCI, PLMN is the terminal's home network device information (i.e., the identifier of the second network device, which is the terminal's home network device), and H represents the encryption mechanism of the digital identity identifier.

[0242] In one possible implementation, the terminal's structured information includes at least one of the following 2.1 to 2.5:

[0243] 2.1 Type information, used to indicate that the digital identity is a terminal type digital identity.

[0244] For the structured information of a terminal, if the structured information includes type information, then the type information is used to indicate that the corresponding digital identity is a digital identity of the terminal type, and is used to identify the terminal.

[0245] 2.2 Encryption Mechanism Identifier, used to indicate the encryption mechanism of the digital identity identifier.

[0246] If the terminal's digital identity includes a string identifier in the digital identity method, this string identifier is obtained by encrypting the terminal's SUCI and the identifier of the second network device using an encryption mechanism. Therefore, this encryption mechanism identifier is used to uniquely identify the encryption mechanism. The corresponding encryption mechanism can be determined through this encryption mechanism, allowing the decryption of the string identifier in the digital identity method to obtain the terminal's SUCI and the identifier of the second network device.

[0247] 2.3 Key credential information, used to indicate the terminal's public key.

[0248] The terminal's public and private keys are paired. The private key can be used to generate digital signature information, while the terminal's public key can be used to verify the digital signature information.

[0249] 2.4 Home network device information, used to indicate the home network device of the terminal.

[0250] The terminal's home network device is the second network device. Therefore, the home network device information can be the identifier of the second network device, such as the device identifier of the second network device, the digital identity identifier of the second network device (such as the DID identifier of the second network device), etc.

[0251] 2.5 Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0252] The network devices that a terminal is allowed to access can be network devices that have pre-signed a roaming agreement with the terminal's home network device. If a network device has signed a roaming agreement with the terminal's home network device, the terminal is allowed to access that network device. If the network devices that the terminal is allowed to access include network device A, the access information for the network device can include the identifier of network device A, such as the device identifier of network device A, the digital identity identifier of network device A (such as the DID identifier of network device A), etc.

[0253] In one possible implementation, the network device can also register at the first functional network element side, whereby the first functional network element generates the network device's digital identity and structured information. The network device's digital identity may include at least one of the following: an identifier for a digital identity scheme, an identifier for a digital identity method, and a string identifier for the network device within the digital identity method. The string identifier for the network device within the digital identity method is obtained by encrypting the network device's device identifier using an encryption mechanism. The components of the digital identity can be found in the relevant descriptions in sections 1.1-1.3 of the above embodiments, and will not be repeated here.

[0254] For example, the digital identity of a network device can take the following form:

[0255] DID: <did-xxmobile>:<H(device ID||PLMN)>

[0256] In the aforementioned digital identity identifier, "DID:" is the identifier of the digital identity scheme, used to identify the corresponding digital identity scheme as DID. "did-XXmobile" is the identifier of the digital identity method, used to identify the corresponding digital identity method as "did-XXmobile", where did-XXmobile represents the encryption of the network device's device ID and PLMN. "H(device ID||PLMN)" is the string identifier in the network device's digital identity method "did-XXmobile", where device ID is the network device's device identifier, PLMN is the network device information to which the network device belongs, and H represents the encryption mechanism of the digital identity identifier.

[0257] For example, the structured information of a network device may include at least one of the following: type information, indicating that the digital identity is a network device type; encryption mechanism identifier, indicating the encryption mechanism of the digital identity; and key credential information, indicating the public key of the network device.

[0258] During the registration of network devices with the first functional network element, the first functional network element also needs to maintain the access control information corresponding to the network devices.

[0259] Taking the second network device as an example, the second network device sends access control information corresponding to the second network device to the first functional network element. The access control information corresponding to the second network device is used to indicate the network devices that at least one terminal is allowed to access. The network devices to which at least one terminal belongs are the second network device.

[0260] Optionally, the access control information corresponding to the second network device can be represented by the correspondence between the identifier of the second network device, the SUCI of each of at least one terminal, and the identifiers of the network devices that each terminal is allowed to access.

[0261] Table 1 below illustrates an example of access control information. As shown in Table 1, the access control information corresponding to the first network device and the second network device are illustrated respectively.

[0262] For the first network device, it includes terminal A and terminal B (i.e., the home network device of terminal A and terminal B is the first network device). The SUCI of terminal A is SUCI1, and the SUCI of terminal B is SUCI2. The network devices that terminal A is allowed to access include network device 2 and network device 3, and the network devices that terminal B is allowed to access include network device 2 and network device 4. For the second network device, it includes terminal C and terminal D (i.e., the home network device of terminal C and terminal D is the first network device). The SUCI of terminal C is SUCI3, and the SUCI of terminal D is SUCI4. The network devices that terminal C is allowed to access include network device 1 and network device 3, and the network devices that terminal D is allowed to access include network device 1 and network device 3.

[0263] Table 1

[0264] In the above embodiments, digital identity identifiers, structured information, and access control information have been described. The access permission management method provided by the embodiments of this disclosure will be further described below with reference to the accompanying drawings.

[0265] Figure 8 is a signaling diagram of the access control method provided in this embodiment of the present disclosure. As shown in Figure 8, the method may include:

[0266] S801, the terminal sends a first access request message to the first network device.

[0267] When a terminal needs to access a first network device, the terminal sends a first access request message to the first network device, and the first network device receives the first access request message accordingly. The first access request message includes the terminal's digital identity identifier, which is generated by the first functional network element when the terminal registers with it. The first functional network element generates the terminal's digital identity identifier and structured information, and sends the terminal's digital identity identifier to the terminal. The first functional network element stores the digital identity identifiers and structured information of different terminals, with a one-to-one correspondence between the digital identity identifier and the structured information.

[0268] Optionally, the first access request message may also include the terminal's digital signature information, which is generated based on the terminal's private key.

[0269] Optionally, the first access request message may also include a request plaintext, which may be used to indicate, for example, the content requested by the first access request message, or other possible information.

[0270] S802, the first network device sends a digital identity identifier to the first functional network element.

[0271] Upon receiving the first access request message, the first network device can obtain the terminal's digital identity and learn that the terminal wants to access the first network device. Since the terminal's digital identity and structured information are uniformly managed by the first functional network element, the first network device sends the digital identity to the first functional network element to obtain the terminal's structured information.

[0272] S803, the first functional network element determines the structured information of the terminal based on the digital identity identifier.

[0273] On the first functional network element side, the digital identity identifiers and structured information of multiple different terminals can be stored and managed. After the first functional network element receives the digital identity identifier sent by the first network device, it can determine the structured information of the terminal from the structured information of multiple different terminals based on the digital identity identifier of the terminal.

[0274] S804, the first functional network element sends structured information to the first network device.

[0275] After determining the structured information of the terminal, the first functional network element sends the structured information to the first network device. The terminal's digital identity and structured information are used to determine whether the terminal has access rights to the first network device.

[0276] S805, the first network device verifies the digital signature information based on the terminal's public key and obtains the verification result.

[0277] In some embodiments, the structured information of the terminal includes key credential information, which indicates the terminal's public key. After receiving the structured information of the terminal, the first network device can determine the terminal's public key based on the key credential information in the structured information, and then verify the digital signature information in the first access request message according to the terminal's public key to obtain the verification result.

[0278] S806, the first network device determines whether the verification result is successful. If not, proceed to S807; if yes, proceed to S808.

[0279] The process of verifying digital signature information is the process of verifying whether the digital signature information was generated based on the terminal's private key.

[0280] S807, the first network device sends the first notification message to the terminal.

[0281] If the verification fails, it indicates that the terminal is not a registered terminal of the first functional network element, and the digital signature information may have been tampered with during transmission. In this case, the first network device will send a first notification message to the terminal. The first notification message is used to inform the terminal that it is not a registered terminal of the first functional network element and therefore does not have access to the first network device.

[0282] S808, the first network device determines whether the access network device information includes the identifier of the first network device.

[0283] If the verification result is successful, it indicates that the digital signature information was generated based on the terminal's private key. This means the terminal is a registered terminal of the first functional network element, and the digital signature information has not been tampered with during transmission. In this case, it is necessary to further determine whether the terminal has access rights to the first network device.

[0284] The first network device can obtain the terminal's access network device information from the terminal's structured information. This access network device information could be, for example, the identifier of a network device that the terminal is allowed to access. Then, the first network device can determine whether the terminal's access network device information includes the identifier of the first network device. If so, the first network device determines that the terminal has access rights to the first network device.

[0285] S809, if the access network device information includes the identifier of the first network device, the first network device sends a query request message to the terminal.

[0286] If the terminal's access network device information includes the identifier of the first network device, the first network device sends a query request message to the terminal. This query request message is used to request a query of the terminal's SUCI, and the terminal receives the query request message accordingly.

[0287] S810, in response to the query request message received from the first network device, the terminal sends the terminal's SUCI to the first network device.

[0288] After receiving the query request message, the terminal sends its SUCI to the first network device, and the first network device receives the terminal's SUCI accordingly.

[0289] S811, the first network device sends a second access request message to the second network device based on the terminal's SUCI.

[0290] The second access request message is used for the terminal to perform initial registration on a second network device, which is the terminal's home network device. The second access request message includes at least one of the terminal's digital identity, digital signature information, and SUCI. Specifically, after receiving the second access request message, the second network device sends the terminal's SUCI (which may also include digital signature information and the terminal's digital identity) to the first network device's AUSF network element through the second network device's SEAF network element. Then, the AUSF network element in the first network device sends the terminal's SUCI to the UDM network element in the first network device, thus proceeding with subsequent processes (see the flowchart in the embodiment of Figure 1 for details, which will not be repeated here).

[0291] In summary, the solution of this embodiment, through the unified management of the terminal's digital identity and structured information by the first functional network element, allows the terminal to send a first access request message to the first network device when it needs to access the first network device. This first access request message includes the terminal's digital identity and digital signature information. The first network device then sends the terminal's digital identity to the first functional network element to obtain the terminal's structured information. The first network device verifies the digital signature information using the terminal's public key in the structured information, thereby confirming whether the terminal is registered with the first functional network element. Once the terminal is confirmed to be registered with the first functional network element, the first network device can determine whether the terminal has access rights to the first network device by checking whether the access network device information in the structured information includes the identifier of the first network device. This eliminates the need for the terminal's home network device and the first network device to sign a roaming agreement offline, and also avoids frequent signaling interactions, resulting in high efficiency in access control management.

[0292] The above embodiments, in conjunction with Figure 8, illustrate the process of managing terminal access permissions when the access network device information includes the identifier of the first network device. The following, in conjunction with Figure 9, illustrates the process of managing terminal access permissions when the access network device information does not include the identifier of the first network device.

[0293] Figure 9 is a signaling diagram of the access control method provided in this embodiment of the present disclosure. As shown in Figure 9, the method may include:

[0294] S901, the terminal sends a first access request message to the first network device.

[0295] S902, the first network device sends a digital identity identifier to the first functional network element.

[0296] S903, the first functional network element determines the structured information of the terminal based on the digital identity identifier.

[0297] S904, the first functional network element sends structured information to the first network device.

[0298] S905, the first network device verifies the digital signature information based on the terminal's public key and obtains the verification result.

[0299] S906, verify whether the verification result is successful. If not, proceed to S907; if yes, proceed to S908.

[0300] S907, the first network device sends the first notification message to the terminal.

[0301] S908, the first network device determines whether the access network device information includes the identifier of the first network device.

[0302] The implementation process of S901 to S908 can be found in the implementation process of S801 to S808 in the above embodiments, and will not be repeated here.

[0303] S909, if the identifier of the first network device is not included in the accessed network device information, the first network device sends the home network device information to the first functional network element.

[0304] If the identifier of the first network device is not included in the access network device information, it does not necessarily mean that the terminal is not allowed to access the first network device. Because the network architecture in a distributed network system is dynamically changing, the terminal may already have access rights to the first network device, but the access network device information in the terminal's structured information has not yet been updated. In this case, the first functional network element needs to determine whether the terminal has access rights to the first network device.

[0305] Therefore, if the identifier of the first network device is not included in the access network device information, the first network device sends the home network device information to the first functional network element.

[0306] S910: The first functional network element determines whether the terminal has access rights to the first network device based on the information of the network device to which it belongs.

[0307] The first functional network element can determine the terminal's structured information based on the terminal's digital identity identifier, thereby obtaining the encryption mechanism identifier from the terminal's structured information and determining the encryption mechanism of the terminal's digital identity identifier. After receiving the home network device information, the first functional network element decrypts the terminal's digital identity identifier according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device, which is the terminal's home network device.

[0308] Then, the first functional network element determines the access control information corresponding to the second network device based on the home network device information, and determines whether the terminal has access rights to the first network device based on the terminal's SUCI and the access control information corresponding to the second network device.

[0309] The access control information corresponding to the second network device is used to indicate the network devices that each of the at least one terminal is allowed to access. The home network device of each of these at least one terminal is the second network device. The access control information corresponding to the second network device can be seen in the example in Table 1 above. In Table 1, at least one terminal includes terminal C and terminal D, and the second network device is the home network device of terminal C and terminal D. If the terminal's SUCI is SUCI3, it can be determined that the network devices the terminal is allowed to access include network device 1 and network device 3. If the first network device is network device 1 or network device 3, the first functional network element can determine that the terminal has access rights to the first network device. If the first network device is not network device 1 or network device 3, the first functional network element can determine that the terminal does not have access rights to the first network device.

[0310] S911, the first functional network element sends a response message to the first network device.

[0311] After the first functional network element determines whether the terminal has access rights to the first network device, the first functional network element sends a response message to the first network device. Correspondingly, the first network device receives the response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.

[0312] Optionally, if the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI. Therefore, after the first network device receives the response message, it can obtain the terminal's SUCI from the response message.

[0313] S912, the first network device determines whether the response message is used to indicate that the terminal has access rights to the first network device. If not, proceed to S913; if yes, proceed to S914.

[0314] S913, the first network device sends a second notification message to the terminal.

[0315] If the response message indicates that the terminal does not have access to the first network device, the first network device sends a second notification message to the terminal, which is used to notify the terminal that it does not have access to the first network device.

[0316] S914, the first network device sends a second access request message to the second network device based on the terminal's SUCI.

[0317] If the response message indicates that the terminal has access to the first network device, the first network device sends a second access request message to the second network device based on the terminal's SUCI, and the second network device receives the second access request message accordingly. The second access request message includes at least one of the terminal's digital identity, the terminal's digital signature information, and the terminal's SUCI. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device. The implementation process of S914 can be found in the relevant description of S811 in the above embodiments, and will not be repeated here.

[0318] In summary, the solution of this embodiment, through the unified management of the terminal's digital identity and structured information by the first functional network element, allows the terminal to send a first access request message to the first network device when it needs to access the first network device. This first access request message includes the terminal's digital identity and digital signature information. The first network device then sends the terminal's digital identity to the first functional network element to obtain the terminal's structured information. The first network device verifies the digital signature information using the terminal's public key in the structured information, thereby confirming whether the terminal is registered with the first functional network element. If the terminal is confirmed to be registered with the first functional network element, and the access network device information does not include the first network device's identifier, the first functional network element determines whether the terminal has access rights to the first network device. This eliminates the need for the terminal's home network device and the first network device to sign a roaming agreement offline, and also eliminates the need for frequent signaling interactions, resulting in high efficiency in access control management.

[0319] Figure 10 is a schematic diagram of the access control device provided in an embodiment of this disclosure. As shown in Figure 10, the device includes: a memory, a transceiver, and a processor.

[0320] The memory 1020 is used to store computer programs; the transceiver 1000 is used to send and receive data under the control of the processor 1010; the processor 1010 is used to read the computer program stored in the memory 1020 and perform the following operations:

[0321] Receives a digital identity identifier sent by the first network device, where the digital identity identifier is the terminal's digital identity identifier;

[0322] Based on the digital identity identifier, determine the terminal's structured information;

[0323] Structured information is sent to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.

[0324] In some embodiments, the structured information includes at least one of the following:

[0325] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0326] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0327] Key credential information, used to indicate the terminal's public key;

[0328] Home network device information, used to indicate the home network device of the terminal;

[0329] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0330] In some embodiments, a digital identity includes at least one of the following:

[0331] Identifiers for digital identity schemes;

[0332] Identifiers for digital identity methods;

[0333] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0334] In some embodiments, the processor 1010 is also configured to perform the following operations:

[0335] Receive home network device information sent by the first network device;

[0336] Determine whether the terminal has access to the first network device based on the network device information;

[0337] A response message is sent to the first network device, which indicates whether the terminal has access rights to the first network device.

[0338] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information includes:

[0339] The string identifier is decrypted according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device;

[0340] Based on the terminal's SUCI and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that each terminal is allowed to access. The home network devices of each terminal are the second network device.

[0341] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.

[0342] In Figure 10, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors (represented by a processor) and memories (represented by memory). The bus architecture can also link various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. The transceiver can be multiple components, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store data used by the processor 1010 during operation.

[0343] The processor can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.

[0344] The processor 1010 executes any of the methods provided in the embodiments of this disclosure by calling a computer program stored in memory, according to the obtained executable instructions. The processor 1010 and the memory 1020 may also be physically separated.

[0345] It should be noted that the access control device provided in this embodiment can implement all the method steps implemented in the above method embodiment and achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0346] Figure 11 is a second schematic diagram of the access control device provided in an embodiment of this disclosure. As shown in Figure 11, the device includes: a memory, a transceiver, and a processor.

[0347] The memory 1120 is used to store computer programs; the transceiver 1100 is used to send and receive data under the control of the processor 1110; the processor 1110 is used to read the computer program stored in the memory 1120 and perform the following operations:

[0348] The receiving terminal sends a first access request message, which includes the terminal's digital identity identifier.

[0349] Send a digital identity identifier to the first functional network element;

[0350] Receive structured information sent by the first functional network element;

[0351] Based on the structured information, determine whether the terminal has access rights to the first network device.

[0352] In some embodiments, the structured information includes at least one of the following:

[0353] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0354] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0355] Key credential information, used to indicate the terminal's public key;

[0356] Home network device information, used to indicate the home network device of the terminal;

[0357] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0358] In some embodiments, the first access request further includes the terminal's digital signature information. Based on the structured information, determining whether the terminal has access rights to the first network device includes:

[0359] The digital signature information is verified using the terminal's public key to obtain the verification result;

[0360] If the verification result is successful, determine whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.

[0361] In some embodiments, determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes:

[0362] If the network device access information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.

[0363] In some embodiments, the processor 1110 is also configured to perform the following operations:

[0364] Send a query request message to the terminal. The query request message is used to request the query terminal's SUCI.

[0365] SUCI sent by the receiving terminal;

[0366] According to SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0367] In some embodiments, determining whether a terminal has access to a first network device based on the home network device information and / or the access network device information includes:

[0368] If the identifier of the first network device is not included in the accessed network device information, send the home network device information to the first functional network element.

[0369] The terminal receives a response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.

[0370] In some embodiments, when the response message indicates that the terminal has access rights to the first network device, the response message also includes the terminal's SUCI, and the processor 1110 is further configured to perform the following operations:

[0371] According to SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0372] In some embodiments, the second access request message includes at least one of the following:

[0373] Digital identity;

[0374] Digital signature information;

[0375] SUCI of the terminal.

[0376] In some embodiments, a digital identity includes at least one of the following:

[0377] Identifiers for digital identity schemes;

[0378] Identifiers for digital identity methods;

[0379] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0380] In Figure 11, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors (represented by a processor) and memories (represented by memory). The bus architecture can also link various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. The transceiver can be multiple components, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store data used by the processor 1110 during operation.

[0381] The processor can be a CPU, ASIC, FPGA, or CPLD, and it can also adopt a multi-core architecture.

[0382] The processor 1110 executes any of the methods provided in the embodiments of this disclosure by calling a computer program stored in memory, according to the obtained executable instructions. The processor 1110 and the memory 1120 may also be physically separated.

[0383] It should be noted that the access control device provided in this embodiment can implement all the method steps implemented in the above method embodiment and achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0384] Figure 12 is a schematic diagram of the access control device provided in this embodiment of the present disclosure. As shown in Figure 12, the device includes: a memory, a transceiver, and a processor.

[0385] The memory 1220 is used to store computer programs; the transceiver 1200 is used to send and receive data under the control of the processor 1210; the processor 1210 is used to read the computer program stored in the memory 1220 and perform the following operations:

[0386] A first access request message is sent to a first network device. The first access request message includes the terminal's digital identity identifier. The digital identity identifier is used to obtain the terminal's structured information. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.

[0387] In some embodiments, the structured information includes at least one of the following:

[0388] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0389] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0390] Key credential information, used to indicate the terminal's public key;

[0391] Home network device information, used to indicate the home network device of the terminal;

[0392] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0393] In some embodiments, a digital identity includes at least one of the following:

[0394] Identifiers for digital identity schemes;

[0395] Identifiers for digital identity methods;

[0396] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0397] In some embodiments, the processor 1210 is also configured to perform the following operations:

[0398] In response to a query request message received from the first network device, the terminal sends its SUCI to the first network device.

[0399] In Figure 12, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1210 and memory represented by memory 1220. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver may be multiple components, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. For different user equipment, the user interface 1230 may also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.

[0400] The processor 1210 is responsible for managing the bus architecture and general processing, and the memory 1220 can store the data used by the processor 1210 when performing operations.

[0401] Optionally, the processor 1210 can be a CPU, ASIC, FPGA or CPLD, and the processor 1210 can also adopt a multi-core architecture.

[0402] The processor 1210 executes any of the methods provided in the embodiments of this disclosure according to the obtained executable instructions by calling the program stored in the memory 1220. The processor 1210 and the memory 1220 may also be physically separated.

[0403] It should be noted that the access control device provided in this embodiment can implement all the method steps implemented in the above method embodiment and achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0404] Figure 13 is a schematic diagram of the access control device provided in this embodiment of the present disclosure. As shown in Figure 13, the device includes: a memory, a transceiver, and a processor.

[0405] The memory 1320 is used to store computer programs; the transceiver 1300 is used to send and receive data under the control of the processor 1310; the processor 1310 is used to read the computer program stored in the memory 1320 and perform the following operations:

[0406] The terminal receives a second access request message sent by a first network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0407] In some embodiments, the structured information includes at least one of the following:

[0408] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0409] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0410] Key credential information, used to indicate the terminal's public key;

[0411] Home network device information, used to indicate the home network device of the terminal;

[0412] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0413] In some embodiments, a digital identity includes at least one of the following:

[0414] Identifiers for digital identity schemes;

[0415] Identifiers for digital identity methods;

[0416] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0417] In some embodiments, the processor is also configured to perform the following operations:

[0418] Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the network devices to which at least one terminal belongs are the second network devices.

[0419] In Figure 13, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors (represented by a processor) and memories (represented by memory). The bus architecture can also link various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides the interface. The transceiver can be multiple components, including a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. The processor is responsible for managing the bus architecture and general processing, and the memory can store data used by the processor 1310 during operation.

[0420] The processor can be a CPU, ASIC, FPGA, or CPLD, and it can also adopt a multi-core architecture.

[0421] The processor 1310 executes any of the methods provided in the embodiments of this disclosure by calling a computer program stored in memory, according to the obtained executable instructions. The processor 1310 and the memory 1320 may also be physically separated.

[0422] It should be noted that the access control device provided in this embodiment can implement all the method steps implemented in the above method embodiment and achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0423] Figure 14 is a schematic diagram of the structure of the access control device provided in this embodiment of the present disclosure. As shown in Figure 14, the access control device 140 includes:

[0424] The first receiving module 141 is used to receive a digital identity identifier sent by the first network device, wherein the digital identity identifier is the digital identity identifier of the terminal.

[0425] The first processing module 142 is used to determine the structured information of the terminal based on the digital identity identifier;

[0426] The first sending module 143 is used to send structured information to the first network device. The digital identity and structured information are used to determine whether the terminal has access rights to the first network device.

[0427] In some embodiments, the structured information includes at least one of the following:

[0428] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0429] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0430] Key credential information, used to indicate the terminal's public key;

[0431] Home network device information, used to indicate the home network device of the terminal;

[0432] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0433] In some embodiments, a digital identity includes at least one of the following:

[0434] Identifiers for digital identity schemes;

[0435] Identifiers for digital identity methods;

[0436] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0437] In some embodiments,

[0438] The first receiving module 141 is further configured to receive home network device information sent by the first network device;

[0439] The first processing module 142 is further configured to determine whether the terminal has access rights to the first network device based on the home network device information.

[0440] The first sending module 143 is further configured to send a response message to the first network device, the response message being used to indicate whether the terminal has access rights to the first network device.

[0441] In some embodiments, the first processing module 142 is further configured to:

[0442] The string identifier is decrypted according to the encryption mechanism to obtain the terminal's SUCI and the identifier of the second network device;

[0443] Based on the terminal's SUCI and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that at least one terminal is allowed to access. The home network devices of at least one terminal are the second network device.

[0444] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.

[0445] It should be noted that the access control device 140 provided in this disclosure can implement all the method steps implemented by the first functional network element in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0446] Figure 15 is a schematic diagram of the structure of the access control device provided in this embodiment of the present disclosure. As shown in Figure 15, the access control device 150 includes:

[0447] The second receiving module 151 is used to receive a first access request message sent by the terminal, wherein the first access request message includes the digital identity identifier of the terminal.

[0448] The second sending module 152 is used to send a digital identity identifier to the first functional network element;

[0449] The third receiving module 153 is used to receive structured information sent by the first functional network element;

[0450] The second processing module 154 is used to determine whether the terminal has access rights to the first network device based on the structured information.

[0451] In some embodiments, the structured information includes at least one of the following:

[0452] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0453] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0454] Key credential information, used to indicate the terminal's public key;

[0455] Home network device information, used to indicate the home network device of the terminal;

[0456] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0457] In some embodiments, the first access request further includes the terminal's digital signature information, and the second processing module 154 is specifically used for:

[0458] The digital signature information is verified using the terminal's public key to obtain the verification result;

[0459] If the verification result is successful, determine whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.

[0460] In some embodiments, the second processing module 154 is specifically used for:

[0461] If the network device access information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.

[0462] In some embodiments,

[0463] The second sending module 152 is also used to send a query request message to the terminal, the query request message being used to request a query of the terminal's SUCI;

[0464] The third receiving module 153 is also used to receive SUCI sent by the terminal;

[0465] The second sending module 152 is further configured to send a second access request message to the second network device according to SUCI. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0466] In some embodiments, the second processing module 154 is specifically used for:

[0467] If the identifier of the first network device is not included in the accessed network device information, send the home network device information to the first functional network element.

[0468] The terminal receives a response message sent by the first functional network element. The response message is used to indicate whether the terminal has access rights to the first network device.

[0469] In some embodiments, where the response message indicates that the terminal has access to the first network device, the response message also includes the terminal's SUCI, and the second sending module 152 is further configured to:

[0470] According to SUCI, a second access request is sent to the second network device. The second access request is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0471] In some embodiments, the second access request message includes at least one of the following:

[0472] Digital identity;

[0473] Digital signature information;

[0474] SUCI of the terminal.

[0475] In some embodiments, a digital identity includes at least one of the following:

[0476] Identifiers for digital identity schemes;

[0477] Identifiers for digital identity methods;

[0478] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0479] It should be noted that the access control device 150 provided in this disclosure can implement all the method steps implemented by the first network device in the above method embodiment and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0480] Figure 16 is a schematic diagram of the access control device provided in an embodiment of this disclosure. As shown in Figure 16, the access control device 160 includes:

[0481] The first transceiver module 161 is used to send a first access request message to the first network device. The first access request message includes a digital identity identifier of the terminal. The digital identity identifier is used to obtain the structured information of the terminal. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.

[0482] In some embodiments, the structured information includes at least one of the following:

[0483] Type information, used to indicate that the digital identity is a terminal type digital identity;

[0484] Encryption mechanism identifier, used to indicate the encryption mechanism of the digital identity identifier;

[0485] Key credential information, used to indicate the terminal's public key;

[0486] Home network device information, used to indicate the home network device of the terminal;

[0487] Access network device information, used to indicate the network devices that the terminal is allowed to access.

[0488] In some embodiments, a digital identity includes at least one of the following:

[0489] Identifiers for digital identity schemes;

[0490] Identifiers for digital identity methods;

[0491] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0492] In some embodiments, the first transceiver module 161 is further configured to:

[0493] In response to a query request message received from the first network device, the terminal sends its SUCI to the first network device.

[0494] It should be noted that the access control device 160 provided in this disclosure can implement all the method steps implemented by the terminal in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0495] Figure 17 is a schematic diagram of the structure of the access control device provided in this embodiment of the present disclosure. As shown in Figure 17, the access control device 170 includes:

[0496] The second transceiver module 171 is used to receive a second access request message sent by the first network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

[0497] In some embodiments, the second access request includes at least one of the following:

[0498] Digital identity;

[0499] Digital signature information;

[0500] SUCI of the terminal.

[0501] In some embodiments, a digital identity includes at least one of the following:

[0502] Identifiers for digital identity schemes;

[0503] Identifiers for digital identity methods;

[0504] The terminal's string identifier in the digital identity method is obtained by encrypting the terminal's SUCI and the identifier of the second network device through an encryption mechanism. The second network device is the terminal's home network device.

[0505] In some embodiments, the second transceiver module 171 is further configured to:

[0506] Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the network devices to which at least one terminal belongs are the second network devices.

[0507] It should be noted that the access control device 170 provided in this disclosure can implement all the method steps implemented by the second network device in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0508] It should be noted that the division of units in the embodiments of this disclosure is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.

[0509] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this disclosure.

[0510] It should be noted that the apparatus provided in this embodiment can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0511] This disclosure also provides a processor-readable storage medium storing a computer program for causing a processor to perform all the method steps described in the above method embodiments.

[0512] Non-transiently readable storage media can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).

[0513] This disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements any of the methods described in the above embodiments.

[0514] Processor-readable storage media can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MOs), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).

[0515] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0516] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.

[0517] These processor-executable instructions may also be stored in a processor-readable memory that can instruct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0518] Obviously, those skilled in the art can make various modifications and variations to this disclosure without departing from its spirit and scope. Therefore, if such modifications and variations fall within the scope of the claims of this disclosure and their equivalents, this disclosure is also intended to include such modifications and variations.

Claims

1. An access permission management method, applied to a first functional network element, the method comprising: Receive a digital identity identifier sent by a first network device, wherein the digital identity identifier is the digital identity identifier of the terminal; Based on the digital identity identifier, the structured information of the terminal is determined; The structured information is sent to the first network device, and the digital identity and the structured information are used to determine whether the terminal has access rights to the first network device.

2. The method according to claim 1, wherein, The structured information includes at least one of the following: Type information, used to indicate that the digital identity is a terminal type digital identity; An encryption mechanism identifier is used to indicate the encryption mechanism of the digital identity identifier; Key credential information, used to indicate the public key of the terminal; Home network device information, used to indicate the home network device of the terminal; Access network device information, used to indicate the network devices that the terminal is allowed to access.

3. The method according to claim 2, wherein, The digital identity identifier includes at least one of the following: Identifiers for digital identity schemes; Identifiers for digital identity methods; The string identifier of the terminal in the digital identity method is obtained by encrypting the terminal's subscription hidden identifier SUCI and the identifier of the second network device through the encryption mechanism. The second network device is the terminal's home network device.

4. The method according to claim 3, wherein, The method further includes: Receive the home network device information sent by the first network device; Determine whether the terminal has access to the first network device based on the home network device information; A response message is sent to the first network device, the response message indicating whether the terminal has access rights to the first network device.

5. The method according to claim 4, wherein, Determining whether the terminal has access to the first network device based on the home network device information includes: The string identifier is decrypted according to the encryption mechanism to obtain the SUCI of the terminal; Based on the SUCI of the terminal and the access control information corresponding to the second network device, it is determined whether the terminal has access rights to the first network device. The access control information is determined by the home network device information and is used to indicate the network devices that each of the at least one terminal is allowed to access. The home network devices of the at least one terminal are the second network device.

6. The method according to claim 4 or 5, wherein, If the response message indicates that the terminal has access to the first network device, the response message may also include the terminal's SUCI.

7. An access control method applied to a first network device, the method comprising: The receiving terminal sends a first access request message, the first access request message including the digital identity identifier of the terminal; Send the digital identity identifier to the first functional network element; Receive the structured information of the terminal sent by the first functional network element; Based on the structured information, it is determined whether the terminal has access rights to the first network device.

8. The method according to claim 7, wherein, The structured information includes at least one of the following: Type information, used to indicate that the digital identity is a terminal type digital identity; An encryption mechanism identifier is used to indicate the encryption mechanism of the digital identity identifier; Key credential information, used to indicate the public key of the terminal; Home network device information, used to indicate the home network device of the terminal; Access network device information, used to indicate the network devices that the terminal is allowed to access.

9. The method according to claim 8, wherein, The first access request also includes the digital signature information of the terminal. The step of determining whether the terminal has access rights to the first network device based on the structured information includes: The digital signature information is verified using the public key of the terminal to obtain the verification result; If the verification result is successful, it is determined whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information.

10. The method according to claim 9, wherein, The step of determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes: If the access network device information includes the identifier of the first network device, it is determined that the terminal has access rights to the first network device.

11. The method according to claim 10, wherein, The method further includes: Send a query request message to the terminal, the query request message being used to request a query of the terminal's SUCI; Receive the SUCI sent by the terminal; According to the SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

12. The method according to claim 9, wherein, The step of determining whether the terminal has access rights to the first network device based on the home network device information and / or the access network device information includes: If the identifier of the first network device is not included in the access network device information, the home network device information is sent to the first functional network element. The terminal receives a response message sent by the first functional network element, the response message being used to indicate whether the terminal has access rights to the first network device.

13. The method according to claim 12, wherein, If the response message indicates that the terminal has access rights to the first network device, and the response message also includes the terminal's SUCI, the method further includes: According to the SUCI, a second access request message is sent to the second network device. The second access request message is used for the terminal to perform initial registration on the second network device, which is the terminal's home network device.

14. The method according to claim 11 or 13, wherein, The second access request message includes at least one of the following: The digital identity identifier; The digital signature information; The terminal's SUCI.

15. The method according to any one of claims 8-14, wherein, The digital identity identifier includes at least one of the following: Identifiers for digital identity schemes; Identifiers for digital identity methods; The string identifier of the terminal in the digital identity method is obtained by encrypting the SUCI of the terminal and the identifier of the second network device through the encryption mechanism, wherein the second network device is the home network device of the terminal.

16. An access control method, applied to a terminal, the method comprising: A first access request message is sent to a first network device. The first access request message includes the digital identity identifier of the terminal. The digital identity identifier is used to obtain the structured information of the terminal. The digital identity identifier and the structured information are used to determine whether the terminal has access rights to the first network device.

17. The method according to claim 16, wherein, The method further includes: In response to the received query request message sent by the first network device, the terminal's SUCI is sent to the first network device.

18. An access control method applied to a second network device, the method comprising: The terminal receives a second access request message sent by a first network device, the second access request message being used for initial registration of the terminal on the second network device, the second network device being the terminal's home network device.

19. The method according to claim 18, wherein, The method further includes: Send access control information corresponding to the second network device to the first functional network element, wherein the access control information is used to indicate the network devices that at least one terminal is allowed to access, and the home network devices of the at least one terminal are the second network device.

20. An access control device, comprising a memory, a transceiver, and a processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 1-6.

21. An access control device, comprising a memory, a transceiver, and a processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 7-15.

22. An access control device, comprising a memory, a transceiver, and a processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 16-17.

23. An access control device, comprising a memory, a transceiver, and a processor: Memory, used to store computer programs; Transceiver, used to send and receive data under the control of the processor; A processor for reading a computer program from the memory and executing the access control method according to any one of claims 18-19.

24. A non-transitory readable storage medium storing a computer program for causing a processor to perform the method according to any one of claims 1 to 19.