Communication method, node, communication system, storage medium and program product
By introducing an authorization mechanism during the data collection process, the problem of unauthorized data collection is solved, ensuring that the third node requests data from the second node only under authorization, thus achieving secure and efficient data collection.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2025-01-26
- Publication Date
- 2026-07-30
AI Technical Summary
In existing technologies, the lack of authorization mechanisms in the data collection process leads to problems of unauthorized data collection, especially in service networks that are not trusted by users, which may result in data security and resource waste.
The first node receives information sent by the second node and authorizes the third node to request data from the second node, ensuring the legality and security of the data collection process, including verification mechanisms for data type and purpose.
It enables secure data collection under authorized conditions, improving the probability of business success and avoiding resource waste.
Smart Images

Figure CN2025075313_30072026_PF_FP_ABST
Abstract
Description
Communication methods, nodes, communication systems, storage media, and software products Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to communication methods, nodes, communication systems, storage media, and program products. Background Technology
[0002] Data collection plays a crucial role in the field of communications. For example, both Artificial Intelligence (AI) services and sensing services heavily rely on data collection processes. Examples include sensing data collection processes and training data collection processes. Summary of the Invention
[0003] This disclosure provides communication methods, nodes, communication systems, storage media, and program products.
[0004] According to a first aspect of the present disclosure, a communication method is proposed, the method comprising: receiving first information sent by a second node, the first information being used to authorize a third node to request data from the second node.
[0005] According to a second aspect of the present disclosure, a communication method is proposed, the method comprising: sending first information to a first node, the first information being used to authorize a third node to request data from a second node.
[0006] According to a third aspect of the present disclosure, a communication method is proposed, the method comprising: sending second information to a first node, the second information including a third data type and / or a first purpose.
[0007] According to a fourth aspect of the present disclosure, a first node is provided, comprising: a transceiver module for receiving first information sent by a second node, the first information being used to authorize the third node to request data from the second node.
[0008] According to a fifth aspect of the embodiments of this disclosure, a second node is proposed, comprising: a second node.
[0009] According to a sixth aspect of the present disclosure, a third node is proposed, comprising: a transceiver module for sending second information to a first node, the second information including a third data type and / or a first purpose.
[0010] According to a seventh aspect of the present disclosure, a first node is provided, comprising: one or more processors; wherein a terminal is configured to execute the first aspect and any one of the communication methods in the first aspect.
[0011] According to an eighth aspect of the present disclosure, a second node is provided, comprising: one or more processors; wherein a network device is configured to perform the second aspect and any of the communication methods in the second aspect.
[0012] According to a ninth aspect of the present disclosure, a third node is provided, comprising: one or more processors; wherein a network device is configured to perform the third aspect and any of the communication methods in the third aspect.
[0013] According to a tenth aspect of the present disclosure, a communication system is proposed, including a first node, a second node, and a third node, wherein the first node is configured to implement the first aspect and any one of the communication methods in the first aspect, the second node is configured to implement the second aspect and any one of the communication methods in the second aspect, and the third node is configured to implement the third aspect and any one of the communication methods in the third aspect.
[0014] According to the eleventh aspect of the present disclosure, a storage medium is provided that stores instructions, which, when executed on a communication device, cause the communication device to perform a communication method as described in the first aspect and any one of the first aspects, or the second aspect and any one of the third aspect and any one of the third aspects.
[0015] According to a twelfth aspect of the present disclosure, a program product is provided, comprising at least one of a program and instructions, wherein when the program and instructions are executed by a communication device, they implement a communication method comprising the first aspect and any one of the first aspect, or the second aspect and any one of the second aspect, or the third aspect and any one of the third aspect.
[0016] This disclosure allows a first node to receive first information sent by a second node, thereby authorizing a third node to request data from the second node. In other words, the method described in this disclosure enables a third node to request data from a second node with authorization, thereby achieving secure data collection, increasing the success rate of business operations, and avoiding resource waste. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.
[0018] Figure 1a is a schematic diagram of the system architecture of a data collection service according to an embodiment of the present disclosure.
[0019] Figure 1b is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.
[0020] Figure 2 is a schematic diagram of a communication method interaction according to an embodiment of the present disclosure.
[0021] Figure 3 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0022] Figure 4 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0023] Figure 5 is a flowchart illustrating a communication method according to an embodiment of the present disclosure.
[0024] Figure 6a is a schematic diagram of the communication method interaction according to an embodiment of the present disclosure.
[0025] Figure 6b is a schematic diagram of the communication method interaction according to an embodiment of the present disclosure.
[0026] Figure 7a is a schematic diagram of the structure of the first node proposed in an embodiment of this disclosure.
[0027] Figure 7b is a schematic diagram of the structure of the second node proposed in an embodiment of this disclosure.
[0028] Figure 7c is a schematic diagram of the structure of the third node proposed in an embodiment of this disclosure.
[0029] Figure 8a is a schematic diagram of the structure of a communication device proposed in an embodiment of this disclosure.
[0030] Figure 8b is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation
[0031] This disclosure provides communication methods, nodes, communication systems, storage media, and program products.
[0032] In a first aspect, embodiments of this disclosure propose a communication method, the method comprising: receiving first information sent by a second node, the first information being used to authorize a third node to perform the following action: requesting data from the second node.
[0033] In some alternative embodiments of the first aspect, the first information includes at least one of the following: a first data type, the first data type being associated with a first licensable use and / or a first unlicensable use; a second data type, the second data type not being associated with any licensable use or unlicensable use; a first licensable use; a first unlicensable use; a second licensable use, the second licensable use not being associated with any data type; a second unlicensable use, the second unlicensable use not being associated with any data type; first authorization verification information corresponding to each of the first data types; second authorization verification information corresponding to each of the second data types; and third authorization verification information corresponding to each of the second licensable use.
[0034] In some alternative embodiments of the first aspect, the method further includes: receiving second information sent by the third node, the second information including a third data type and / or a first purpose.
[0035] In some alternative embodiments of the first aspect, the method further includes sending at least one of the following to the third node: first authorization verification information corresponding to the third data type, wherein the third data type belongs to the first data type and the first use belongs to a first authorized use associated with the third data type; second authorization verification information corresponding to the third data type, wherein the third data type belongs to the second data type; and third authorization verification information corresponding to the first use, wherein the first use belongs to the second authorized use.
[0036] In some alternative embodiments of the first aspect, the method further includes: sending the identifier of at least one node to the third node, the at least one node including the second node.
[0037] In some optional embodiments of the first aspect, the second information includes the third data type, and the third data type belongs to the first data type. The method further includes: receiving third information sent by the third node, the third information including the identifier of the second node, the third data type, and a first purpose; sending first authorization verification information corresponding to the third data type to the third node, wherein the first purpose belongs to a first authorized purpose associated with the third data type.
[0038] In some alternative embodiments of the first aspect, the second information includes the first purpose, the first purpose belonging to the first authorized purpose, and the method further includes: receiving third information sent by the third node, wherein the third information includes the identifier of the second node, the first purpose, and a third data type; sending first authorization verification information corresponding to the third data type to the third node, wherein the third data type belongs to the first data type associated with the first purpose.
[0039] In some alternative embodiments of the first aspect, the second information includes the third data type and the first purpose, and the third data type belongs to the first data type, and the first purpose belongs to a first authorized purpose associated with the third data type. The method further includes: receiving third information sent by the third node, the third information including the identifier of the second node, the first purpose, and the third data type; and sending first authorization verification information corresponding to the third data type to the third node.
[0040] In some alternative embodiments of the first aspect, the first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); the second node includes at least one of the following: Terminal Equipment; Access Network Equipment; Network Function (NF); the third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
[0041] In a second aspect, a communication method is provided, the method comprising: sending first information to a first node, the first information being used to authorize a third node to perform the following action: requesting data from the second node.
[0042] In some alternative embodiments of the second aspect, the first information includes at least one of the following: a first data type, the first data type being associated with a first licensable use and / or a first unlicensable use; a second data type, the second data type not being associated with any licensable use or unlicensable use; a first licensable use; a first unlicensable use; a second licensable use, the second licensable use not being associated with any data type; a second unlicensable use, the second unlicensable use not being associated with any data type; first authorization verification information corresponding to each of the first data types; second authorization verification information corresponding to each of the second data types; and third authorization verification information corresponding to each of the second licensable uses.
[0043] In some optional embodiments of the second aspect, the method further includes: receiving fourth information sent by the third node, the fourth information being used to request data; sending fifth information to the third node, the fifth information including the data, the fifth information being sent under at least one of the following conditions: the fourth information includes a third data type, a first purpose, and first authorization verification information corresponding to the third data type, and the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type; the fourth data type is any one of the first data types, and the third data type is the same as the fourth data type, and the first purpose belongs to a first authorized purpose associated with the fourth data type; the fourth information includes a third data type, a first purpose, and second authorization verification information corresponding to the third data type, and the second authorization verification information corresponding to the third data type is the same as the second authorization verification information corresponding to the fifth data type, the fifth data type is any one of the second data types, and the third data type is the same as the fifth data type; the fourth information includes a third data type, a first purpose, and third authorization verification information corresponding to the first purpose, and the third authorization verification information corresponding to the first purpose is the same as the third authorization verification information corresponding to the second purpose, the second purpose is any one of the second authorized purposes, and the first purpose is the same as the second purpose.
[0044] In some alternative embodiments of the second aspect, the first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); the second node includes at least one of the following: Terminal Equipment; Access Network Equipment; Network Function (NF); the third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
[0045] Thirdly, a communication method is provided, the method comprising: sending second information to a first node, the second information including a third data type and / or a first purpose.
[0046] In some optional embodiments of the third aspect, the method further includes: receiving at least one of the following sent by the first node: first authorization verification information corresponding to a third data type, wherein the third data type belongs to a first data type in first information, and the first use belongs to a first authorized use associated with the third data type; second authorization verification information corresponding to a third data type, wherein the third data type belongs to a second data type in first information; third authorization verification information corresponding to a first use, wherein the first use belongs to a second authorized use in first information; wherein the first information is sent by the second node to the first node.
[0047] In some alternative embodiments of the third aspect, the method further includes: receiving an identifier of at least one node sent by the first node, the at least one node including a second node.
[0048] In some optional embodiments of the third aspect, the second information includes the third data type, and the third data type belongs to the first data type in the first information. The method further includes: sending third information to the first node, the third information including the identifier of the second node, the third data type, and a first purpose; receiving first authorization verification information corresponding to the third data type sent by the first node, wherein the first purpose belongs to a first authorized purpose associated with the third data type; wherein the first information is sent by the second node to the first node.
[0049] In some optional embodiments of the third aspect, the second information includes the first purpose, which belongs to a first authorized purpose in the first information. The method further includes: sending third information to the first node, the third information including the identifier of the second node, the first purpose, and a third data type; receiving first authorization verification information corresponding to the third data type sent by the first node, wherein the third data type is sent when it belongs to a first data type associated with the first purpose; wherein the first information is sent by the second node to the first node.
[0050] In some optional embodiments of the third aspect, the second information includes the third data type and the first purpose, and the third data type belongs to the first data type in the first information, and the first purpose belongs to the first authorized purpose associated with the third data type. The method further includes: sending third information to the first node, the third information including the identifier of the second node, the first purpose, and the third data type; receiving first authorization verification information corresponding to the third data type sent by the first node; wherein the first information is sent by the second node to the first node.
[0051] In some optional embodiments of the third aspect, the method further includes: sending fourth information to a second node, the fourth information being used to request data; receiving fifth information, the fifth information including the data, the fifth information being received under at least one of the following conditions: the fourth information includes a third data type, a first purpose, and first authorization verification information corresponding to the third data type, and the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type; the fourth data type is any data type among the first data types; the third data type and the fourth data type are the same; and the first purpose belongs to a first authorized purpose associated with the fourth data type; the fourth information includes a third data type, a first purpose, and a second authorization verification information corresponding to the third data type. The authorization verification information includes the third data type, the second authorization verification information corresponding to the third data type, and the second authorization verification information corresponding to the fifth data type. The fifth data type is any one of the second data types, and the third data type is the same as the fifth data type. The fourth information includes the third data type, the first purpose, and the third authorization verification information corresponding to the first purpose. The third authorization verification information corresponding to the first purpose and the third authorization verification information corresponding to the second purpose are the same. The second purpose is any one of the second authorized purposes, and the first purpose is the same as the second purpose. At least one of the first data type, the second data type, and the second authorized purpose is included in the first information, and the first information is sent by the second node to the first node.
[0052] In some alternative embodiments of the third aspect, the first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); the second node includes at least one of the following: Terminal Equipment; Access Network Equipment; Network Function (NF); the third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
[0053] Fourthly, a first node is provided, comprising: a transceiver module for receiving first information sent by a second node, the first information being used to authorize the third node to perform the following action: requesting data from the second node.
[0054] Fifthly, a second node is provided, comprising: a second node.
[0055] In a sixth aspect, a third node is provided, comprising: a transceiver module for sending second information to a first node, the second information including a third data type and / or a first purpose.
[0056] A seventh aspect provides a first node, comprising: one or more processors; wherein the terminal is configured to execute the first aspect and any one of the communication methods in the first aspect.
[0057] Eighth aspect, a second node is provided, comprising: one or more processors; wherein a network device is configured to perform the second aspect and any of the communication methods described therein.
[0058] A ninth aspect provides a third node, comprising: one or more processors; wherein a network device is configured to perform the third aspect and any of the communication methods described therein.
[0059] In a tenth aspect, a communication system is provided, comprising a first node, a second node, and a third node, wherein the first node is configured to implement the first aspect and any one of the communication methods in the first aspect, the second node is configured to implement the second aspect and any one of the communication methods in the second aspect, and the third node is configured to implement the third aspect and any one of the communication methods in the third aspect.
[0060] Eleventhly, a storage medium is provided that stores instructions, which, when executed on a communication device, cause the communication device to perform a communication method as described in the first aspect and any one of the first aspect, or the second aspect and any one of the third aspect and any one of the third aspect.
[0061] In a twelfth aspect, a program product is provided, comprising at least one of a program and instructions, wherein when the program and instructions are executed by a communication device, they implement the communication method of the first aspect and any one of the first aspect, or the second aspect and any one of the second aspect, or the third aspect and any one of the third aspect.
[0062] In a thirteenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in an optional implementation of the first or second aspect.
[0063] In a fourteenth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the method described in an optional implementation of the first or second aspect above.
[0064] It is understood that the terminals, access network devices, first network elements, other network elements, core network devices, communication systems, storage media, program products, computer programs, chips, or chip systems involved in the embodiments of this disclosure are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0065] This disclosure provides communication methods, nodes, communication systems, storage media, and program products. In some embodiments, the terms "communication method" and "information processing method" can be used interchangeably, as can the terms "communication device" and "information processing device" and "communication device," and the terms "information processing system" and "communication system" can be used interchangeably.
[0066] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0067] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. The technical environments of different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0068] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0069] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0070] In the embodiments disclosed herein, "multiple" refers to two or more.
[0071] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0072] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0073] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0074] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0075] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0076] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0077] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0078] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.
[0079] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.
[0080] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."
[0081] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.
[0082] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0083] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0084] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0085] AI services and perception services are key features of future networks. Since both services heavily rely on data collection processes (e.g., perception data collection, training data collection), data collection becomes a cornerstone of future networks.
[0086] Figure 1a is a schematic diagram of the system architecture of a data collection service according to an embodiment of the present disclosure. As shown in Figure 1a, the system architecture is mainly divided into a control plane and a user plane. The boxes in Figure 1a represent nodes in the system, and the lines connecting the nodes represent the interfaces between them. To distinguish between the control plane interfaces and the user plane interfaces, the dark connecting lines in Figure 1a represent the control plane interfaces, and the light-colored lines represent the user plane interfaces. The nodes include: 6G Service Management Function (SMF), 6G Network Repository Function (NRF), Data Collection Function (DCF), Unified Data Management (UDM) / Unified Data Repository (UDR), Network Element Function (NEF), Third-Party Server, Network Data Analytics Function (NWDAF), Location Management Function (LMF), 6G Training Network Function 2 (6G Training NF2), 6G Access and Mobility Management Function (AMF), 6G Radio Access Network (RAN), and 6G UE.
[0087] DCF can also be referred to as a data consumer. The data collection function is defined as a function to collect and manage different types of data collected from different entities (e.g., UE, NWDAF, LMF, UDM, Application Function (AF), Analytic Data Repository Function (ADRF), etc.).
[0088] Among them, 6G NRF / UDM is enhanced to store and manage UE data capability information associated with the UE, so that DCF can discover and select appropriate UEs with the required data capabilities.
[0089] In some embodiments, UE data capability information may include the following parameters:
[0090] Device capabilities, such as cameras and sensors;
[0091] Data types, such as video data, sensor data, and location data;
[0092] Data format, for example, 3K, 4K; where K represents kilopixels, for example, 3K means 3 kilopixels;
[0093] User permission, for example, indicates whether user permission is required for the purpose of each type of data or all data.
[0094] Data transmission capabilities, such as the user plane and / or control plane.
[0095] However, while DCF can be used to collect and manage data, it lacks an authorization mechanism for the data collection process. For example, DCF may reside in the serving network, while NRF / UDM resides in the home network. If the serving network where DCF resides is not trusted by the UE, meaning that DCF may collect data without authorization, it can easily lead to problems such as unauthorized data collection.
[0096] Therefore, this disclosure provides a communication method in which a first node receives first information sent by a second node, thereby authorizing a third node to request data from the second node. In other words, the method of this disclosure allows a third node to request data from a second node when authorized, and the second node can verify whether the third node has obtained the relevant authorization, thereby achieving secure data collection, improving the success rate of business operations, and avoiding resource waste.
[0097] Figure 1b is a schematic diagram of a communication system architecture according to an embodiment of the present disclosure.
[0098] As shown in Figure 1b, the communication system 100 includes a first node 101, a second node 102, and a third node 103.
[0099] In some embodiments, the first node 101 may be an NRF or a UDM, but is not limited thereto.
[0100] In some embodiments, the first node 101 may be a network function for managing authorization information or a network function for managing privacy protection information, but is not limited thereto.
[0101] In some embodiments, the second node 102 may be a data provider, also known as a data source, i.e., a node that provides data. For example, the second node 102 may be a terminal or a network device, but is not limited thereto. Among them, network devices include base stations, NFs, etc.
[0102] In some embodiments, the third node 103 can be a data consumer, that is, a node that requests other nodes to collect data for it. For example, the third node 103 can be a UE, NF, AF, etc., but is not limited to this.
[0103] In some embodiments, the terminal includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.
[0104] In some embodiments, the network device may include at least one of an access network device and a core network device.
[0105] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0106] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0107] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0108] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
[0109] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0110] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1b, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1b are illustrative. The communication system may include all or some of the main bodies in FIG1b, or it may include other main bodies outside of FIG1b. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0111] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 6th generation mobile communication system (6G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future Generation Radio Access (FX), Global System for Mobile Communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0112] Figure 2 is a schematic diagram of a communication method interaction according to an embodiment of the present disclosure. As shown in Figure 2, this embodiment of the present disclosure relates to a communication method for a communication system 100, the method including:
[0113] Step S2101: The second node 102 sends the first information to the first node 101.
[0114] In some embodiments, the first node 101 receives first information sent by the second node 102.
[0115] In some embodiments, the second node is the node that collects data. The third node is the node that requests data from the second node; that is, the third node requests the second node to collect data for it. The first node is the node that authorizes the third node's data request. In other words, before requesting data from the second node, the third node can request authorization from the first node, and only after obtaining authorization can it request data from the second node, thus ensuring secure data collection, data reliability, and increasing the success rate of the business. For the first node, how to determine whether to authorize the third node, and how to authorize it, are problems that need to be solved. Therefore, the second node can send first information to the first node, and the first node receives the first information to authorize the third node based on the first information. The first information is used to authorize the third node for the following action: requesting data from the second node.
[0116] The first information includes at least one of the following: a first data type, which is associated with a first authorized use and / or a first unauthorized use; a second data type, which is not associated with any authorized use or unauthorized use; a first authorized use; a first unauthorized use; a second authorized use, which is not associated with any data type; a second unauthorized use, which is not associated with any data type; a first authorization verification information corresponding to each first data type; a second authorization verification information corresponding to each second data type; and a third authorization verification information corresponding to each second authorized use.
[0117] It is understood that there are many types of data, such as video data, sensory data, location data, etc. This disclosure does not exhaustively list all data types, but is not limited to the examples given. The second node can report the data types it supports collecting through the first information. For example, the first information may include at least one of a first data type and a second data type. Both the first and second data types are data types supported by the second node for collection. The first data type is associated with a first authorized use and / or a second unauthorized use. The second data type is not associated with any authorized or unauthorized use. The first authorized use refers to the data use supported or agreed to by the second node among the data uses corresponding to the first data type, and the first unauthorized use refers to the data use not supported or agreed to by the second node among the data uses corresponding to the first data type. That is, for the first data type, the second node may support or agree to some of the data uses corresponding to it. For the second data type, the second node may support or agree to all of its corresponding data uses. Alternatively, for the second data type, the second node may not support or agree to all of its corresponding data uses.
[0118] Optionally, the first information includes a first data type. If the data type of the data requested by the third node is of the first data type, the first node can authorize the third node. Since the first data type is associated with a first authorizable use and / or a first unauthorizable use, the first information may also include at least one of the first authorizable use and the first unauthorizable use. For example, if the data type of the data requested by the third node is of the first data type, and the data use of the requested data is of the first authorizable use, then the first node can authorize the third node. As another example, if the data type of the data requested by the third node is of the first data type, but the data use of the requested data is of the first unauthorizable use, then the first node may not authorize the third node.
[0119] Optionally, the first information may include a first authorized use. If the data use requested by the third node falls under the first authorized use, then the third node can be authorized. If the data use requested by the third node does not fall under the first authorized use, then the data use requested by the third node can be considered to fall under the first unauthorized use, and therefore the third node will not be authorized.
[0120] Optionally, the first information may include a first unauthorized use. If the data use requested by the third node falls under the first unauthorized use, then the third node is not authorized. If the data use requested by the third node does not fall under the first unauthorized use, then the data use requested by the third node can be considered to fall under the first authorized use, and the third node can be authorized.
[0121] Optionally, the first information includes a second data type. If the data type requested by the third node is a second data type, the first node can authorize the third node. For example, if the second node supports or agrees to all data uses corresponding to the second data type, then the first node can authorize the third node when the data type requested by the third node is a second data type.
[0122] Optionally, the first information includes a second data type. If the data type requested by the third node is a second data type, the first node may not authorize the third node. For example, if the second node does not support or agrees with all data types corresponding to the second data type, the first node may not authorize the third node.
[0123] It is understood that data can be used for many purposes, such as model training, providing functionality to third-party applications, and inference. This disclosure does not exhaustively list all uses, but is not limited to the examples given. The second node can report data uses that it supports and / or does not support through the first information. For example, the first information may include at least one of a first authorized use, a first unauthorized use, a second authorized use, and a second unauthorized use. The first authorized use and the first unauthorized use are data uses associated with a first data type. The second authorized use and the second unauthorized use are data uses not associated with any data type. The case where the first information includes a first authorized use and a first unauthorized use is as described in the above embodiments and will not be repeated here.
[0124] Optionally, the first information may include a second authorized use. If the data use requested by the third node falls under the second authorized use, then the third node can be authorized. If the data use requested by the third node does not fall under the second authorized use, then the data use requested by the third node can be considered to fall under the second unauthorized use, and therefore the third node can not be authorized.
[0125] Optionally, the first information may include a second unauthorized use. If the data purpose requested by the third node falls under the second unauthorized use, then authorization may not be granted to the third node. If the data purpose requested by the third node does not fall under the second unauthorized use, then the data purpose requested by the third node may be considered to fall under the second authorized use, and authorization may be granted to the third node.
[0126] Understandably, if the first node does not authorize the third node, it can simply send a message denying authorization to the third node. If the first node authorizes the third node, it needs to send authorization verification information to the third node so that the third node can request data from the second node, and the second node can verify the authorization verification information carried by the third node. If the verification passes, the request is accepted and data is collected for the third node; if the verification fails, the request is rejected and no data is collected for the third node. Therefore, the second node can report the authorization verification information in the first message so that the first node can send the authorization verification information to the third node. The authorization verification information includes at least one of the following: first authorization verification information corresponding to a first data type, second authorization verification information corresponding to a second data type, and third authorization verification information corresponding to a second authorized purpose.
[0127] Optionally, the authorization verification information includes first authorization verification information corresponding to the first data type and the first authorized use.
[0128] Optionally, the first information includes first authorization verification information corresponding to the first data type. For example, if the data type of the data requested by the third node is a first data type, and the purpose of the data requested by the third node is a first authorized purpose, then the first node can send the first authorization verification information corresponding to the first data type in the first information to the third node to authorize the third node. As another example, if the data type of the data requested by the third node is a first data type, and the purpose of the data requested by the third node is not a first unauthorized purpose, then the first node can send the first authorization verification information corresponding to the data type in the first information to the third node to authorize the third node.
[0129] Optionally, the first information includes second authorization verification information corresponding to the second data type. For example, if the data type requested by the third node is a second data type, the first node can send the second authorization verification information corresponding to the second data type in the first information to the third node to authorize the third node.
[0130] Optionally, the first information includes third authorization verification information corresponding to the second authorized use. For example, if the data requested by the third node is for a second authorized use, the first node can send the third authorization verification information corresponding to the second authorized use in the first information to the third node to authorize the third node.
[0131] In some embodiments, the authorization verification information (at least one of the first authorization verification information, the second authorization verification information, and the third authorization verification information) may be an authorization code, a random number, a token, an assertion message, a hash value, etc., and this disclosure does not limit it.
[0132] In some embodiments, the first node may send a response message to the second node. The response message indicates that the first node successfully received the first message, or it indicates that the first node failed to receive the first message. For example, if the response message indicates that the first node failed to receive the first message, the second node may attempt to send the first message again after a certain interval. As another example, if the response message indicates that the first node failed to receive the first message, it may also include the reason for the failure.
[0133] In some embodiments, the second node receives a response message sent by the first node. The response message indicates that the first node successfully received the first information, or it indicates that the first node failed to receive the first information. For example, if the response message indicates that the first node failed to receive the first information, the second node can attempt to send the first information again after a certain interval. As another example, if the response message indicates that the first node failed to receive the first information, it may also include the reason for the failure.
[0134] In some embodiments, the first node includes at least one of the following: NRF; UDM;
[0135] In some embodiments, the second node includes at least one of the following: a terminal; an access network device; an NF;
[0136] In some embodiments, the third node includes at least one of the following: DCF; AF; NF.
[0137] In some embodiments, the name of the first information is not limited, and it may be, for example, "authorization information", "authorization policy", "user consent information", "privacy profile", etc.
[0138] In step S2102, the third node 103 sends the second information to the first node 101.
[0139] In some embodiments, the first node 101 receives second information sent by the third node 103.
[0140] In some embodiments, the second information includes a third data type and / or a first purpose. The third data type is the data type of the data requested by the third node. The first purpose is the data purpose for which the third node requests the data.
[0141] Optionally, the second information includes a third data type to indicate the data type of the data requested by the first node, so that the first node can determine whether to authorize the third type and how to authorize it.
[0142] For example, if the third data type belongs to the first data type, and the second information includes a first purpose, then authorization to the third node is determined based on whether the first purpose belongs to the first authorizable purpose associated with the third data type. The second information includes the first purpose to indicate to the first node the data purpose for which it requests data. For example, if the first purpose belongs to the first authorizable purpose associated with the third data type, the first node can authorize the third node. If the first purpose belongs to the first unauthorizable purpose associated with the third data type, the first node may not authorize the third node. For example, authorizing the third node could involve sending the first authorization verification information corresponding to the third data type to the third node. It is understood that since the third data type belongs to the first data type, the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to a data type within the first data type.
[0143] For example, suppose the first data type includes type A, type B, and type C, where type A corresponds to first authorization verification information a, type B corresponds to first authorization verification information b, and type C corresponds to first authorization verification information c. If the third data type is type A, then the third data type belongs to the first data type. Suppose the first authorized uses corresponding to type A include uses 1, uses 2, and uses 3. If the first use is use 1, then the first use belongs to the first authorized uses associated with type A, and authorization can be granted to the third node. If the first use is use 4, then the first use does not belong to the first authorized uses associated with type A, and authorization to the third node is not required. Authorizing the third node can be done by sending the first authorization verification information a to the third node. It is understood that if the third data type is type A, the first authorization verification information corresponding to the third data type is the first authorization verification information corresponding to type A, i.e., first authorization verification information a. This disclosure uses types A, B, and C as examples, but is not limited to them.
[0144] For example, if the third data type belongs to the first data type, and the second information does not include the first purpose, the first node cannot determine whether the data purpose requested by the third node belongs to the first authorized purpose, and therefore cannot accurately determine whether to authorize the third node. In this case, the first node can send the identifier of at least one node to the third node. This at least one node is one that supports collecting the third data type. Since the third data type belongs to the first data type, it means the second node supports the third data type; therefore, the at least one node includes the second node. It is understood that the second node can report the data types it supports collecting through the first information, and other nodes can also report the data types they support collecting. Therefore, the first node can identify at least one node that supports collecting the third data type and send the identifier of this at least one node to the third node. The third node can then select one node and request authorization carrying the node's identifier, the first purpose, and the third data type. For example, if the third node carries the second node's identifier, the first purpose, and the third data type, and requests authorization, since the third node carries the second node's identifier, the first node can determine whether to authorize the third node based on the first information sent by the second node and the first purpose carried by the third node. For example, if the first use belongs to the first authorizable use associated with the third data type, then the first node can authorize the third node. If the first use belongs to the first unauthorizable use associated with the third data type, then the first node may not authorize the third node. Specific implementation details are as described above and will not be repeated here.
[0145] For example, if the third data type belongs to the second data type, then the first node can authorize the third node. For instance, if the second node supports or agrees to all data uses corresponding to the second data type, then when the third node requests to collect a data type that belongs to the second data type, the first node can authorize the third node. For example, authorizing the third node could involve sending the second authorization verification information corresponding to the third data type to the third node. It can be understood that since the third data type belongs to the second data type, the second authorization verification information corresponding to the third data type is the same as the second authorization verification information corresponding to a data type within the second data type.
[0146] For example, suppose the second data type includes types D, E, and F, where type D corresponds to the second authorization verification information d, type E corresponds to the second authorization verification information e, and type F corresponds to the second authorization verification information f. If the third data type is type E, then the third data type belongs to the second data type. The first node can send the second authorization verification information e to the third node. It is understood that the third data type is type E, and the second authorization verification information corresponding to the third data type is the second authorization verification information corresponding to type E, i.e., the second authorization verification information e. This disclosure uses types D, E, and F as examples, but is not limited to them.
[0147] For example, if the third data type belongs to the second data type, the first node may not grant authorization to the third node. Similarly, if the second node does not support or agrees with all data types corresponding to the second data type, the first node may not grant authorization to the third node.
[0148] For example, if the third data type belongs to the second data type, but the first node does not have the second authorization verification information corresponding to the third data type, then the first node may not authorize the third node. This is understandable because the third data type belongs to the second data type, and the second authorization verification information corresponding to the third data type is the authorization verification information corresponding to one data type within the second data type.
[0149] For example, assuming the second data type includes types D, E, and F, if the third data type is type D, then the third data type belongs to the second data type. If the first node does not have second authorization verification information corresponding to type D, then the first node does not have second authorization verification information corresponding to the third data type. The first node not having second authorization verification information corresponding to the third data type could be because the first information sent by the second node to the first node does not include the second authorization verification information corresponding to the third data type, or it could be because the second authorization verification information corresponding to the third data type has expired, etc. This disclosure does not limit the scope of such cases.
[0150] For example, suppose the second data type includes types D, E, and F, where type D has no corresponding second authorization verification information. If the third data type is type D, then the third data type belongs to the second data type. Since the first node does not have second authorization verification information corresponding to type D, the first node does not authorize the third node.
[0151] For example, if the third data type belongs to the second data type, but the second data type does not support or agree to all its corresponding data uses, the first node may not authorize the third node. In other words, if some data types in the second data type support or agree to all their corresponding data uses, and the third data type belongs to these second data types, then the first node may authorize the third node. The specific method can be found in the above embodiment. If some data types in the second data type do not support or agree to all their corresponding data uses, and the third data type belongs to these second data types, then the first node may not authorize the third node.
[0152] For example, suppose the second data type includes types D, E, and F. Type D supports or agrees to all its corresponding data uses, while types E and F do not support or agree to all their corresponding data uses. If the third data type belongs to the second data type and is type D within the second data type, then the first node can authorize the third node. If the third data type belongs to the second data type and is type E or type F within the second data type, then the first node may not authorize the third node.
[0153] Optionally, the second information includes a first purpose to indicate to the first node the data purpose for which it requests the data, so that the first node can determine whether to authorize the third party and how to authorize it.
[0154] For example, if the first purpose belongs to the second authorized purpose, then the first node can authorize the node. For example, authorizing the third node can be done by sending the third authorization verification information corresponding to the first purpose to the third node.
[0155] For example, suppose the second authorizable use includes use A, use B, and use C. Use A corresponds to third authorization verification information a, use B corresponds to third authorization verification information b, and use C corresponds to third authorization verification information c. If the first use is use C, then the first use belongs to the second authorizable use. The first node can send the third authorization verification information c to the third node. It is understood that if the first use is use C, the third authorization verification information corresponding to the first use is the same as the third authorization verification information corresponding to use C, i.e., the third authorization verification information c. This disclosure uses use A, use B, and use C as examples, but is not limited thereto. For another example, if the first use belongs to the first authorizable use, and the second information includes a third data type, then the above embodiments can be referred to, and will not be repeated here.
[0156] For example, suppose the second authorizable uses include uses A, B, and C. Use A corresponds to third authorization verification information a, use B corresponds to third authorization verification information b, and use C has no corresponding authorization verification information. If the first use is use C, then the first node does not authorize the third node.
[0157] For example, if the first purpose belongs to the first authorized purpose, and the second information does not include the third data type, then the first node cannot determine whether the data type requested by the third node belongs to the first data type associated with the first authorized purpose. Therefore, it cannot accurately determine whether to authorize the third node. In this case, the first node can send the identifier of at least one node to the third node. This at least one node is at least one node that supports the first purpose. Since the first purpose belongs to the first authorized purpose, it means that the second node supports the first purpose; therefore, the at least one node includes the second node. It is understood that the second node can report its supported data purposes through the first information, and other nodes can also report their supported data purposes. Therefore, the first node can identify at least one node that supports the first purpose and send the identifier of this at least one node to the third node. The third node can select one of these nodes and request authorization carrying the node's identifier, the first purpose, and the third data type. For example, if the third node requests authorization carrying the second node's identifier, the first purpose, and the third data type, since the third node carries the second node's identifier, the first node can determine whether to authorize the third node based on the first information sent by the second node and the third data type carried by the third node. For example, if the third data type belongs to the first data type associated with the first purpose, then the first node can authorize the third node. If the third data type does not belong to the first data type associated with the first purpose, then the first node may not authorize the third node. Specific implementation details are as described above and will not be repeated here.
[0158] Optionally, the second information includes a third data type and a first purpose. As in the above optional embodiments, the first node may authorize the third node if the third data type belongs to the first data type and the first purpose belongs to the first authorized purpose associated with the third data type, or if the first purpose belongs to the first authorized purpose and the third data type belongs to the first data type associated with the first purpose. For example, the first node sends the first authorization verification information corresponding to the third data type to the third node. In another optional embodiment, if the first node satisfies the above conditions (i.e., the third data type belongs to the first data type and the first purpose belongs to the first authorized purpose associated with the third data type, or if the first purpose belongs to the first authorized purpose and the third data type belongs to the first data type associated with the first purpose), it may send the identifier of at least one node to the third node, wherein the at least one node includes the second node. That is, although the data type and data purpose requested by the third node are data types and data purposes agreed upon or supported by the second node, the first node may not directly authorize the third node, but instead send the identifier of at least one node, including the second node, to the third node to inform the third node that these at least one node all support or agree to the data type and data purpose requested. A third node may select one of at least one nodes and request authorization from the first node, carrying the node's identifier, a third data type, and a first purpose. For example, if the third node sends the identifier of a second node to the first node, the first node may send the first authorization verification information reported in the first information to the third node. It is understood that if the third node sends the identifier of another node to the first node, the implementation method is similar to that of the second node, and will not be described in detail here.
[0159] In some embodiments, the name of the second information is not limited, and it may be, for example, "authorization request information", "instruction information", etc.
[0160] In some embodiments, the second information may be carried in the authorization request message, and this disclosure does not limit this.
[0161] In step S2103, the first node 101 sends the identifier of at least one node to the third node 103.
[0162] In some embodiments, the third node 103 receives the identifier of at least one node sent by the first node 101.
[0163] In some embodiments, if the second information includes only a third data type, and the third data type belongs to the first data type, then the first node may send the identifier of at least one node to the third node. For details, please refer to the embodiment of step S2102 above, which will not be repeated here.
[0164] In some embodiments, if the second information only includes the first purpose, and the first purpose belongs to a first licenable purpose, then the first node may send the identifier of at least one node to the third node. For details, please refer to the embodiment of step S2102 above, which will not be repeated here.
[0165] In step S2104, the third node 103 sends third information to the first node 101.
[0166] In some embodiments, the first node 101 receives third information sent by the third node 103.
[0167] In some embodiments, the third information includes the identifier of the second node, the third data type, and the first purpose.
[0168] Optionally, if the second information only includes a third data type, and the third data type belongs to the first data type, then after receiving the third information, the first node can determine whether the first use belongs to the first authorized use associated with the third data type. If the first use belongs to the first authorized use associated with the third data type, then authorization can be granted to the third node. If the first use does not belong to the first authorized use associated with the third data type, then authorization can be denied to the third node. It is understandable that since the third data type belongs to the first data type, the first authorized use associated with the third data type is the same as the first authorized use associated with a data type within the first data type. The principle is similar to the first authorization verification information corresponding to the third data type, and will not be elaborated further.
[0169] Optionally, if the second information only includes the first purpose, and the first purpose belongs to the first authorized purpose, then after receiving the third information, the first node can determine whether the third data type belongs to the first data type associated with the first purpose. If the third data type belongs to the first data type associated with the first purpose, then authorization can be granted to the third node. If the third data type does not belong to the first data type associated with the first purpose, then authorization can be denied to the third node. It is understandable that since the first purpose belongs to the first authorized purpose, the first data type associated with the first purpose is the same as the first data type associated with one of the authorized purposes in the first authorized purpose. The principle is similar to the first authorization verification information corresponding to the third data type, and will not be elaborated further.
[0170] Optionally, if the second information includes a third data type and a first purpose, and the third data type belongs to the first data type, and the first purpose belongs to the first authorized purpose associated with the third data type, then after receiving the third information, the first node does not need to determine whether the first purpose belongs to the first authorized purpose or whether the third data type belongs to the first data type. It can authorize the third node based on the identifier in the third information. For example, if the identifier in the third information is the identifier of the second node, then the first node can send the first authorization verification information corresponding to the third data type in the first information sent by the second node to the first node to authorize the third node.
[0171] It is understandable that, since the third information includes the identifier of the second node, the first node determines whether to authorize the third node based on the first information sent by the second node. If the third information includes the identifiers of other nodes, the implementation method is similar, and this disclosure will not provide examples of each.
[0172] In step S2105, the first node 101 sends authorization verification information to the third node 103.
[0173] In some embodiments, the third node 103 receives authorization verification information sent by the first node 101.
[0174] In some embodiments, the authorization verification information includes at least one of first authorization verification information, second authorization verification information, and third authorization verification information.
[0175] Optionally, if the second information includes a third data type and a first purpose, and the third data type belongs to the first data type, and the first purpose belongs to the first authorized purpose associated with the third data type, then the first node can send the first authorization verification information corresponding to the third data type to the third node. Specific examples can be found in the above embodiments, and will not be repeated here.
[0176] Optionally, if the second information includes a third data type, and the third data type belongs to the second data type, then the first node can send the second authorization verification information corresponding to the third data type to the third node. Specific examples can be found in the above embodiments, and will not be repeated here.
[0177] Optionally, if the second information includes the first purpose, and the first purpose belongs to the second authorized purpose, then the first node can send the third authorization verification information corresponding to the first purpose to the third node. Specific examples can be found in the above embodiments, and will not be repeated here.
[0178] Optionally, if the second information includes a third data type, and the third data type belongs to the first data type, and the first node sends at least one node's identifier to the third node and receives the third information, wherein the third information includes the second node's identifier, the third data type, and a first purpose, and the first purpose belongs to a first authorized purpose associated with the third data type, then the first node may send the first authorization verification information corresponding to the third data type to the third node. Specific examples can be found in the above embodiments and will not be repeated here.
[0179] Optionally, if the second information includes a first purpose, and the first purpose belongs to a first authorized purpose, and the first node sends at least one node's identifier to the third node and receives third information, the third information including the second node's identifier, a third data type, and the first purpose, and the third data type belongs to a first data type associated with the first purpose, then the first node can send the first authorization verification information corresponding to the first purpose to the third node. Specific examples can be found in the above embodiments and will not be repeated here.
[0180] In step S2106, the third node 103 sends the fourth message to the second node 102.
[0181] In some embodiments, the second node 102 receives fourth information sent by the third node 103.
[0182] In some embodiments, the fourth information is used to request data.
[0183] In some embodiments, the fourth information includes a third data type, a first purpose, and authorization verification information. The third data type represents the data type requested by the third node, the first purpose represents the intended use of the requested data, and the authorization verification information may include at least one of first authorization verification information, second authorization verification information, and third authorization verification information. The second node can determine whether the data is authorized by the third node based on its supported data types, data purposes, and the authorization verification information it stores. For a specific method, refer to the embodiment of step S2107 below.
[0184] In some embodiments, the name of the fourth information is not limited, and it may be, for example, "request information" or "instruction information".
[0185] In some embodiments, the fourth information may be carried in a data collection request message, but this disclosure does not limit this.
[0186] In step S2107, the second node 102 sends the fifth message to the third node 103.
[0187] In some embodiments, the third node 103 receives the fifth information sent by the second node 102.
[0188] In some embodiments, the fifth information includes the data requested by the third node.
[0189] Optionally, the authorization verification information included in the fourth information is the first authorization verification information corresponding to the third data type. The fifth information is sent if: the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type, and the third and fourth data types are the same, and the first purpose belongs to the first authorized purpose associated with the fourth data type; then the fifth information is sent to the third node. Here, the fourth data type can be any data type from the first data types.
[0190] For example, the first data type is a data type that the second node supports collecting, and the fourth data type is any one of the first data types, which can be understood as the fourth data type being a data type that the second node supports collecting. The first authorized use associated with the fourth data type can be understood as the use that the second node supports among the uses corresponding to the fourth data type. If the third data type and the fourth data type are the same, it means that the data type of the data requested by the third node is a data type supported by the second node. If the first use belongs to the first authorized use associated with the fourth data type, it means that the data use of the data requested by the third node is a use supported by the second node. If the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type, it means that the third node has obtained authorization from the first node or that the third node has obtained authorization from the second node. Under the above conditions, the second node can collect data for the third node, that is, collect data of the third data type, and send the collected data to the third node through the fifth information so that the third node can use the data to complete the first use. If any of the above conditions are not met, the second node may not collect data for the third node, for example, it may send a message rejecting the data request to the third node.
[0191] Optionally, the authorization verification information included in the fourth information is the second authorization verification information corresponding to the third data type. The fifth information is sent if the second authorization verification information corresponding to the third data type and the second authorization verification information corresponding to the fifth data type are the same, and the third data type and the fifth data type are the same, then the fifth information is sent to the third node. The fifth data type can be any one of the second data types.
[0192] For example, the second data type is a data type that the second node supports collecting, and the fifth data type is any one of the second data types, which can be understood as the fifth data type being a data type that the second node supports collecting. If the third data type and the fifth data type are the same, it means that the data type requested by the third node is a data type supported by the second node. If the second authorization verification information corresponding to the third data type is the same as the second authorization verification information corresponding to the fifth data type, it means that the third node has obtained authorization from the first node or that the third node has obtained authorization from the second node. Under the above conditions, the second node can collect data for the third node, that is, collect data of the third data type, and send the collected data to the third node through the fifth information so that the third node can use the data to complete the first purpose. If any of the above conditions are not met, the second node may not collect data for the third node, for example, it may send a message rejecting the data request to the third node.
[0193] Optionally, the authorization verification information included in the fourth information is the third authorization verification information corresponding to the first purpose. The fifth information is sent if the third authorization verification information corresponding to the first purpose is the same as the third authorization verification information corresponding to the second purpose, and the first purpose and the second purpose are the same, then the fifth information is sent to the third node. Here, the second purpose is any one of the second authorizable purposes.
[0194] For example, the second authorized use is a data use supported by the second node. The second use can be any one of the second authorized uses, which can be understood as a data use supported by the second node. If the first use and the second use are the same, it means that the data use for which the third node requests data is a data use supported by the second node. If the third authorization verification information corresponding to the first use is the same as the third authorization verification information corresponding to the second use, it means that the third node has obtained authorization from the first node or that the third node has obtained authorization from the second node. Under these conditions, the second node can collect data for the third node, that is, collect data of the third data type, and send the collected data to the third node through the fifth information so that the third node can use the data to complete the first use. If any of the above conditions are not met, the second node may not collect data for the third node; for example, it may send a message rejecting the data request to the third node.
[0195] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2107. For example, step S2101 may be implemented as a standalone embodiment, but is not limited thereto. For example, steps S2101, S2102, and S2105 may be implemented as standalone embodiments, but are not limited thereto. For example, steps S2101 to S2105 may be implemented as standalone embodiments, but are not limited thereto. For example, steps S2101, S2102, and S2105 to S2107.
[0196] In some embodiments, steps S2102 to S2107 are optional and may be omitted or replaced in different embodiments.
[0197] In some embodiments, other optional implementations described before or after the specification corresponding to FIG2 may be referred to.
[0198] Figure 3 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 3, this embodiment of the present disclosure relates to a communication method executed by a first node 101, the method including:
[0199] Step S3101: Obtain the first information.
[0200] The optional implementation of step S3101 can be found in the optional implementation of step S2101 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0201] In some embodiments, the first node 101 receives first information sent by the second node 102, but is not limited thereto; it may also receive first information sent by other entities.
[0202] In some embodiments, the first node 101 obtains first information as defined by the protocol.
[0203] In some embodiments, the first node 101 obtains first information from the upper layer(s).
[0204] In some embodiments, the first node 101 performs processing to obtain the first information.
[0205] In some embodiments, step S3101 is omitted, and the first node 101 autonomously implements the function indicated by the first information, or the above function is default or default.
[0206] Step S3102: Obtain the second information.
[0207] The optional implementation of step S3102 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0208] In some embodiments, the first node 101 receives second information sent by the third node 103, but is not limited thereto; it may also receive second information sent by other entities.
[0209] In some embodiments, the first node 101 obtains second information as defined by the protocol.
[0210] In some embodiments, the first node 101 obtains second information from the upper layer(s).
[0211] In some embodiments, the first node 101 processes the information to obtain the second information.
[0212] In some embodiments, step S3102 is omitted, and the first node 101 autonomously implements the function indicated by the second information, or the above function is defaulted or set to default.
[0213] Step S3103: Send the identifier of at least one node.
[0214] The optional implementation of step S3103 can be found in the optional implementation of step S2103 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0215] In some embodiments, the first node 101 sends the identifier of at least one node to the third node 103, but is not limited thereto; it may also send the identifier of at least one node to other entities.
[0216] Step S3104: Obtain third information.
[0217] The optional implementation of step S3104 can be found in the optional implementation of step S2104 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0218] In some embodiments, the first node 101 receives third information sent by the third node 103, but is not limited thereto; it may also receive third information sent by other entities.
[0219] In some embodiments, the first node 101 obtains third information as defined by the protocol.
[0220] In some embodiments, the first node 101 obtains third information from the upper layer(s).
[0221] In some embodiments, the first node 101 processes the information to obtain the third information.
[0222] In some embodiments, step S3104 is omitted, and the first node 101 autonomously implements the function indicated by the third information, or the above function is defaulted or set to default.
[0223] Step S3105: Send authorization verification information.
[0224] The optional implementation of step S3105 can be found in the optional implementation of step S2105 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0225] In some embodiments, the first node 101 sends authorization verification information to the third node 103, but it is not limited to this and may also send authorization verification information to other entities.
[0226] The communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3105. For example, step S3101 may be implemented as a standalone embodiment, but is not limited thereto. For example, steps S3101, S3102, and S3105 may be implemented as standalone embodiments, but are not limited thereto. For example, steps S3101 to S3105 may be implemented as standalone embodiments, but are not limited thereto. For example, steps S3101, S3102, and S3105.
[0227] In some embodiments, steps S3102 to S3105 are optional and may be omitted or replaced in different embodiments.
[0228] In some embodiments, other optional implementations may be described before or after the specification corresponding to FIG3.
[0229] Figure 4 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 4, this embodiment of the present disclosure relates to a communication method executed by a second node 102, the method comprising:
[0230] Step S4101: Send the first message.
[0231] The optional implementation of step S4101 can be found in the optional implementation of step S2101 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0232] In some embodiments, the second node 102 sends the first information to the first node 101, but it is not limited to this and may also send the first information to other entities.
[0233] Step S4102: Obtain the fourth information.
[0234] The optional implementation of step S4102 can be found in the optional implementation of step S2106 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0235] In some embodiments, the second node 102 receives fourth information sent by the third node 103, but is not limited thereto; it may also receive fourth information sent by other entities.
[0236] In some embodiments, the second node 102 obtains fourth information as defined by the protocol.
[0237] In some embodiments, the second node 102 obtains fourth information from the upper layer(s).
[0238] In some embodiments, the second node 102 processes the information to obtain the fourth information.
[0239] In some embodiments, step S4102 is omitted, and the second node 102 autonomously implements the function indicated by the fourth information, or the above function is defaulted or set to default.
[0240] Step S4103: Send the fifth message.
[0241] The optional implementation of step S4103 can be found in the optional implementation of step S2107 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0242] In some embodiments, the second node 102 sends the fifth information to the third node 103, but it is not limited to this and may also send the fifth information to other entities.
[0243] The communication method involved in the embodiments of this disclosure may include at least one of steps S4101 to S4103. For example, step S4101 may be implemented as a standalone embodiment, but is not limited thereto.
[0244] In some embodiments, steps S4102 to S4103 are optional and may be omitted or replaced in different embodiments.
[0245] In some embodiments, other optional implementations may be described before or after the specification corresponding to Figure 4.
[0246] Figure 5 is a flowchart illustrating a communication method according to an embodiment of the present disclosure. As shown in Figure 5, this embodiment of the present disclosure relates to a communication method executed by a third node 103, the method comprising:
[0247] Step S5101: Send the second message.
[0248] The optional implementation of step S5101 can be found in the optional implementation of step S2102 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0249] In some embodiments, the third node 103 sends the second information to itself, but it is not limited to this; the second information may also be sent to other entities.
[0250] Step S5102: Obtain the identifier of at least one node.
[0251] The optional implementation of step S5102 can be found in the optional implementation of step S2103 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0252] In some embodiments, the third node 103 receives the identifier of at least one node sent by the first node 101, but is not limited thereto, and may also receive the identifier of at least one node sent by other entities.
[0253] In some embodiments, the third node 103 acquires the identifier of at least one node as defined by the protocol.
[0254] In some embodiments, the third node 103 obtains the identifier of at least one node from the upper layer(s).
[0255] In some embodiments, the third node 103 processes the data to obtain the identifier of at least one node.
[0256] In some embodiments, step S5102 is omitted, and the third node 103 autonomously implements the function indicated by the identifier of at least one node, or the above function is default or default.
[0257] Step S5103: Send the third message.
[0258] The optional implementation of step S5103 can be found in the optional implementation of step S2104 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0259] In some embodiments, the third node 103 sends third information to the first node 101, but it is not limited to this and may also send third information to other entities.
[0260] Step S5104: Obtain authorization verification information.
[0261] The optional implementation of step S5104 can be found in the optional implementation of step S2105 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0262] In some embodiments, the third node 103 receives authorization verification information sent by the first node 101, but is not limited thereto; it may also receive authorization verification information sent by other entities.
[0263] In some embodiments, the third node 103 obtains the authorization verification information specified by the protocol.
[0264] In some embodiments, the third node 103 obtains authorization verification information from the upper layer(s).
[0265] In some embodiments, the third node 103 processes the information to obtain authorization verification information.
[0266] In some embodiments, step S5104 is omitted, and the third node 103 autonomously implements the function indicated by the authorization verification information, or the above function is defaulted or set to default.
[0267] Step S5105: Send the fourth message.
[0268] The optional implementation of step S5105 can be found in the optional implementation of step S2106 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0269] In some embodiments, the third node 103 sends fourth information to the second node 102, but is not limited thereto; it may also send fourth information to other entities.
[0270] Step S5106: Obtain the fifth piece of information.
[0271] The optional implementation of step S5106 can be found in the optional implementation of step S2107 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.
[0272] In some embodiments, the third node 103 receives the fifth information sent by the second node 102, but is not limited thereto; it may also receive the fifth information sent by other entities.
[0273] In some embodiments, the third node 103 obtains the fifth information specified by the protocol.
[0274] In some embodiments, the third node 103 obtains the fifth information from the upper layer(s).
[0275] In some embodiments, the third node 103 processes the information to obtain the fifth information.
[0276] In some embodiments, step S5106 is omitted, and the third node 103 autonomously implements the function indicated by the fifth information, or the above function is defaulted or set to default.
[0277] The communication method involved in the embodiments of this disclosure may include at least one of steps S5101 to S5106. For example, step S5101 may be implemented as a standalone embodiment, but is not limited thereto. For example, steps S5101 and S5104 may be implemented as standalone embodiments, but are not limited thereto. For example, steps S5101 to S5104 may be implemented as standalone embodiments, but are not limited thereto.
[0278] In some embodiments, steps S5102 to S5105 are optional and may be omitted or replaced in different embodiments.
[0279] In some embodiments, other optional implementations described before or after the specification corresponding to Figure 5 may be referred to.
[0280] This disclosure provides a communication method as follows:
[0281] Figure 6a is a schematic diagram of a communication method interaction according to an embodiment of the present disclosure. As shown in Figure 6a, the present disclosure relates to a communication method, which includes:
[0282] In step S6101, the data provider (i.e., UE) sends an authorization information configuration request to NF1 (e.g., NRF, UDM).
[0283] In some embodiments, the core network uses authorization information to authorize data consumers (e.g., network functions (NF), application functions (AF), base stations, UEs) to request data from data providers.
[0284] In some embodiments, the authorization information includes a data provider ID (e.g., GPSI, AF-specific identifier, SUPI), a data type that can be provided by the UE (e.g., location information, camera information), permitted / disallowed uses for this data type (e.g., model training, exposure to a third-party AF), and authorization verification information associated with the data type and intended use. Based on the authorization information provided by the UE, the UE uses the authorization verification information to check whether the data consumer is authorized.
[0285] In some embodiments, there is no definition of authorization verification information in the current 3GPP system. Authorization verification information can be an authorization code, a random number, a token, an assertion message, a hash value, etc.
[0286] In some embodiments, there is no definition of authorization information in the current 3GPP system. Authorization information may be referred to as authorization policies, user consent information, privacy profiles, etc.
[0287] In step S6102, NF1 (e.g., UDM, NRF) sends an authorization information configuration response to the data provider.
[0288] In some embodiments, the response indicates that NF1 has successfully received the authorization information.
[0289] In step S6103, the data consumer (e.g., NF, AF) sends a data provider discovery request to NF1. This request includes the data type and the purpose associated with the data type.
[0290] In some embodiments, the data provider may also be referred to as the data source.
[0291] In step S6104, NF1 authorizes the data consumer based on the authorization information provided by the data consumer.
[0292] In some embodiments, if the data provider is a UE and the requested data type and purpose are consistent with the authorization information provided by the data provider, then NF1 sends the data provider identifier and the corresponding authorization verification information to the data consumer.
[0293] In step S6105, the data consumer sends a data request to the data provider.
[0294] In some embodiments, the request includes the requested data type, the purpose of the request, and the authorization verification information obtained in step 4.
[0295] In step S6106, the data provider sends a data request response to the data consumer.
[0296] In some embodiments, if locally stored authorization information indicates that the authorization verification information provided by the data consumer is associated with the requested data type and the requested purpose, the data provider sends the requested data to the data consumer. Otherwise, the data consumer rejects the data request. Rejection indicates that the purpose is not authorized.
[0297] This disclosure also provides an alternative communication method, the main difference of which is that the data consumer does not indicate the purpose of data collection during data provider discovery, but only the data type. Thus, NF1 cannot authorize a discovery request without a purpose, because the authorization information provided by the UE in step S6101 is purpose-bound. Then, when the data consumer is able to indicate the purpose of data collection to NF1, authorization must be granted to the data consumer after discovery.
[0298] Figure 6b is a schematic diagram of a communication method interaction according to an embodiment of the present disclosure. As shown in Figure 6b, the embodiments of the present disclosure relate to a communication method, which includes:
[0299] Steps S6201 to S6202 are the same as steps S6101 to S6102, and will not be described again in this disclosure.
[0300] In step S6203, the data consumer (e.g., NF, AF) sends a data provider discovery request to NF1. This request includes data types without a destination.
[0301] In step S6204, NF1 sends a data provider discovery response to the data consumer. This response includes a data provider identifier but does not contain corresponding authorization verification information.
[0302] In step S6205, the data consumer (e.g., NF, AF) sends an authorization request to NF1. This request includes the data provider identifier, data type, and purpose.
[0303] Step S6206, NF1 Authorizes Data Consumer.
[0304] Steps S6206 and S6104 are similar and will not be described again in this disclosure.
[0305] Steps S6207 to S6208 are the same as steps S6105 to S6106, and will not be described again in this disclosure.
[0306] In some embodiments, for the data provider:
[0307] Alternatively, the data provider can be a UE, a base station, or an NF.
[0308] Optionally, if the data provider is a UE, the data provider should be able to send authorization information to NF1. The authorization information includes permitted / disallowed purposes for using this data type (e.g., model training, exposure to a third-party AF), and authorization verification information associated with the data type and purpose. Based on the authorization information provided by the UE, the UE uses the authorization verification information to check whether the data consumer is authorized.
[0309] Optionally, if the data provider is not a UE, the data provider should be able to send authorization information to NF1. The authorization information includes the data type and the permitted / disallowed purposes for using that data type (e.g., model training, exposure to third-party AFs).
[0310] Optionally, the data provider should be able to receive data requests from data consumers. The request includes the requested data type, the purpose of the request, and token or authorization verification information.
[0311] Optionally, if the data provider is not a UE and the data request matches the token, the data provider should be able to send the requested data to the data consumer. Otherwise, the data consumer rejects the data request.
[0312] Optionally, if the data provider is a UE and the locally stored authorization information indicates that the authorization verification information provided by the data consumer is associated with the requested data type and the corresponding requested purpose, then the data provider should be able to send the requested data to the data consumer. Otherwise, the data consumer rejects the data request.
[0313] In some embodiments, for data consumers:
[0314] Alternatively, the data consumer can be an NF, a base station, or an AF.
[0315] Optionally, data consumers (e.g., NF, AF) should be able to send a data provider discovery request / authorization request to NF1. This request includes the data provider identifier, data type, and the purpose associated with the data type.
[0316] Optionally, the data consumer (e.g., NF, AF) should be able to receive a data provider discovery response or authorization response sent by NF1. This response includes the data type, purpose, data consumer identifier and data provider identifier, token, or authorization verification information.
[0317] Optionally, data consumers should be able to send data requests to data providers. These requests should include the requested data type, the purpose of the request, and tokens or authorization verification information.
[0318] Optionally, the data consumer should be able to receive the requested data or data request rejection information.
[0319] In some embodiments, for NF1:
[0320] Alternatively, NF1 can be NRF or UDM.
[0321] Optionally, NF1 should be able to receive authorization information from the data consumer.
[0322] Optionally, NF1 should be able to receive data provider discovery requests / authorization requests from the UE. This request includes the data provider identifier, data type, and the purpose associated with the data type.
[0323] Optionally, NF1 should be able to send a data provider discovery response or authorization response sent by NF1 to a data consumer (e.g., NF, AF). This response includes the data type, purpose, data consumer identifier and data provider identifier, and token or authorization verification information.
[0324] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.
[0325] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0326] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0327] Figure 7a is a schematic diagram of the structure of the first node proposed in an embodiment of this disclosure. As shown in Figure 7a, the first node 7100 may include at least one of a transceiver module 7101 and a processing module 7102. The transceiver module 7101 is used to receive first information sent by the second node, the first information being used to authorize the third node to perform the following action: requesting data from the second node.
[0328] In some embodiments, the first information includes at least one of the following: a first data type, the first data type being associated with a first licensable use and / or a first unlicensable use; a second data type, the second data type being not associated with any licensable use or unlicensable use; a first licensable use; a first unlicensable use; a second licensable use, the second licensable use being not associated with any data type; a second unlicensable use, the second unlicensable use being not associated with any data type; first authorization verification information corresponding to each of the first data types; second authorization verification information corresponding to each of the second data types; and third authorization verification information corresponding to each of the second licensable use.
[0329] In some embodiments, the transceiver module 7101 is further configured to: receive second information sent by the third node, the second information including a third data type and / or a first purpose.
[0330] In some embodiments, the transceiver module 7101 is further configured to: send at least one of the following to the third node: first authorization verification information corresponding to the third data type, wherein the third data type belongs to the first data type and the first use belongs to the first authorized use associated with the third data type; second authorization verification information corresponding to the third data type, wherein the third data type belongs to the second data type; and third authorization verification information corresponding to the first use, wherein the first use belongs to the second authorized use.
[0331] In some embodiments, the transceiver module 7101 is further configured to: send the identifier of at least one node to the third node, wherein the at least one node includes the second node.
[0332] In some embodiments, the second information includes the third data type, and the third data type belongs to the first data type. The transceiver module 7101 is further configured to: receive third information sent by the third node, the third information including the identifier of the second node, the third data type, and a first purpose; and send first authorization verification information corresponding to the third data type to the third node, wherein the first purpose belongs to a first authorized purpose associated with the third data type.
[0333] In some embodiments, the second information includes the first purpose, which belongs to the first authorized purpose. The transceiver module 7101 is further configured to: receive third information sent by the third node, wherein the third information includes the identifier of the second node, the first purpose, and a third data type; and send first authorization verification information corresponding to the third data type to the third node, wherein the third data type belongs to the first data type associated with the first purpose.
[0334] In some embodiments, the second information includes the third data type and the first purpose, and the third data type belongs to the first data type, and the first purpose belongs to the first authorized purpose associated with the third data type. The transceiver module 7101 is further configured to: receive the third information sent by the third node, the third information including the identifier of the second node, the first purpose, and the third data type; and send the first authorization verification information corresponding to the third data type to the third node.
[0335] In some embodiments, the first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); the second node includes at least one of the following: Terminal Device; Access Network Device; Network Function (NF); the third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
[0336] Figure 7b is a schematic diagram of the structure of the second node proposed in an embodiment of this disclosure. As shown in Figure 7b, the second node 7200 may include at least one of a transceiver module 7201 and a processing module 7202. The transceiver module 7201 is used to send first information to the first node, the first information being used to authorize the third node to request data from the second node.
[0337] In some embodiments, the first information includes at least one of the following: a first data type, which is associated with a first licensable use and / or a first unlicensable use; a second data type, which is not associated with any licensable or unlicensable use; a first licensable use; a first unlicensable use; a second licensable use, which is not associated with any data type; a second unlicensable use, which is not associated with any data type; first authorization verification information corresponding to each first data type; second authorization verification information corresponding to each second data type; and third authorization verification information corresponding to each second licensable use.
[0338] In some embodiments, the transceiver module 7201 is further configured to: receive fourth information sent by a third node, the fourth information being used to request data; send fifth information to the third node, the fifth information including data, the fifth information being sent under at least one of the following conditions: the fourth information includes a third data type, a first purpose, and first authorization verification information corresponding to the third data type, and the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type; the fourth data type is any one of the first data types, and the third data type is the same as the fourth data type, and the first purpose belongs to a first authorized purpose associated with the fourth data type; the fourth information includes a third data type, a first purpose, and second authorization verification information corresponding to the third data type, and the second authorization verification information corresponding to the third data type is the same as the second authorization verification information corresponding to the fifth data type, the fifth data type is any one of the second data types, and the third data type is the same as the fifth data type; the fourth information includes a third data type, a first purpose, and third authorization verification information corresponding to the first purpose, and the third authorization verification information corresponding to the first purpose is the same as the third authorization verification information corresponding to the second purpose, the second purpose is any one of the second authorized purposes, and the first purpose and the second purpose are the same.
[0339] In some embodiments, the first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); the second node includes at least one of the following: Terminal Equipment; Access Network Equipment; Network Function (NF); the third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
[0340] Figure 7c is a schematic diagram of the structure of the third node proposed in an embodiment of this disclosure. As shown in Figure 7c, the third node 7300 may include at least one of a transceiver module 7301 and a processing module 7302. The transceiver module 7301 is used to send second information to the first node, the second information including a third data type and / or a first purpose.
[0341] In some embodiments, the transceiver module 7301 is further configured to: receive at least one of the following sent by the first node: first authorization verification information corresponding to a third data type, wherein the third data type belongs to a first data type in first information, and the first use belongs to a first authorized use associated with the third data type; second authorization verification information corresponding to a third data type, wherein the third data type belongs to a second data type in first information; third authorization verification information corresponding to a first use, wherein the first use belongs to a second authorized use in first information; wherein the first information is sent by the second node to the first node.
[0342] In some embodiments, the method further includes: receiving an identifier of at least one node sent by the first node, the at least one node including a second node.
[0343] In some embodiments, the second information includes the third data type, and the third data type belongs to the first data type in the first information. The transceiver module 7301 is further configured to: send the third information to the first node, the third information including the identifier of the second node, the third data type, and a first purpose; receive the first authorization verification information corresponding to the third data type sent by the first node, wherein the first purpose belongs to the first authorized purpose associated with the third data type; wherein the first information is sent by the second node to the first node.
[0344] In some embodiments, the second information includes the first purpose, which belongs to the first authorized purpose in the first information. The transceiver module 7301 is further configured to: send third information to the first node, the third information including the identifier of the second node, the first purpose, and the third data type; receive first authorization verification information corresponding to the third data type sent by the first node, wherein the third data type is sent when it belongs to the first data type associated with the first purpose; wherein the first information is sent by the second node to the first node.
[0345] In some embodiments, the second information includes the third data type and the first purpose, and the third data type belongs to the first data type in the first information, and the first purpose belongs to the first authorized purpose associated with the third data type. The transceiver module 7301 is further configured to: send third information to the first node, the third information including the identifier of the second node, the first purpose, and the third data type; receive first authorization verification information corresponding to the third data type sent by the first node; wherein the first information is sent by the second node to the first node.
[0346] In some optional embodiments of the first aspect, the transceiver module 7301 is further configured to: send fourth information to the second node, the fourth information being used to request data; receive fifth information, the fifth information including the data, the fifth information being received under at least one of the following conditions: the fourth information includes a third data type, a first purpose, and first authorization verification information corresponding to the third data type, and the first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type; the fourth data type is any one of the first data types, and the third data type is the same as the fourth data type, and the first purpose belongs to a first authorized purpose associated with the fourth data type; the fourth information includes a third data type, a first purpose, and first authorization verification information corresponding to the third data type. The second authorization verification information includes the same second authorization verification information corresponding to the third data type and the same second authorization verification information corresponding to the fifth data type. The fifth data type is any one of the second data types, and the third data type is the same as the fifth data type. The fourth information includes the third data type, the first purpose, and the third authorization verification information corresponding to the first purpose. The third authorization verification information corresponding to the first purpose is the same as the third authorization verification information corresponding to the second purpose. The second purpose is any one of the second authorized purposes, and the first purpose is the same as the second purpose. At least one of the first data type, the second data type, and the second authorized purpose is included in the first information, which is sent by the second node to the first node.
[0347] In some embodiments, the first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); the second node includes at least one of the following: Terminal Device; Access Network Device; Network Function (NF); the third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
[0348] Figure 8a is a schematic diagram of the structure of a communication device according to an embodiment of this disclosure. The communication device 8100 can be a network device, a terminal, or a chip, chip system, or processor that supports the network device in implementing any of the above methods; alternatively, the network device can be an access network device, a core network device, etc. Optionally, the terminal can be a user equipment, etc. The communication device 8100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0349] As shown in Figure 8a, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control the communication device, execute programs, and process program data. The communication device 8100 is used to execute any of the above methods. Optionally, the communication device can be a base station, a baseband chip, a terminal, a terminal chip, a DU, or a CU, etc.
[0350] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may also be located outside the communication device 8100.
[0351] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceivers 8103 perform communication steps such as sending and / or receiving in the above-described method, such as steps S2101 and S2102, but are not limited thereto. The processor 8201 performs other steps, such as steps S2103 and S2104, but is not limited thereto.
[0352] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0353] In some embodiments, the communication device 8100 may include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0354] The communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in this disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG8a. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal, smart terminal, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0355] Figure 8b is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. For cases where the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the chip 8200 shown in Figure 8b, but it is not limited thereto.
[0356] Chip 8200 includes one or more processors 8201, which are used to perform any of the above methods.
[0357] In some embodiments, chip 8200 further includes one or more interface circuits 8202. Optionally, the interface circuit 8202 is connected to memory 8203, and the interface circuit 8202 can be used to receive signals from memory 8203 or other devices, and the interface circuit 8202 can be used to send signals to memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in memory 8203 and send the instructions to processor 8201.
[0358] In some embodiments, the interface circuit 8202 performs communication steps such as sending and / or receiving in the above method, such as steps S2101 and S2102, but is not limited thereto. The processor 8201 performs other steps, such as steps S2103 and S2104, but is not limited thereto.
[0359] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
[0360] In some embodiments, chip 8200 further includes one or more memories 8203 for storing instructions. Optionally, all or part of the memories 8203 may be located outside of chip 8200.
[0361] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device 8100, cause the communication device 8100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0362] This disclosure also provides a program product that, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0363] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
Claims
1. A communication method, characterized in that, The method is executed by the first node, and the method includes: The third node receives a first message sent by the second node, the first message being used to authorize the third node to perform the following action: request data from the second node.
2. The method according to claim 1, characterized in that, The first information includes at least one of the following: A first data type, wherein the first data type is associated with a first authorized use and / or a first unauthorized use; The second data type is not associated with any authorized or unauthorized use; First authorized use; The first unauthorized use; Second authorized use, which is not associated with any data type; Second unauthorized use, which is not associated with any data type; The first authorization verification information corresponding to each of the first data types; Second authorization verification information corresponding to each of the second data types; Third authorization verification information corresponding to each of the second authorized uses.
3. The method according to claim 2, characterized in that, The method further includes: Receive second information sent by the third node, the second information including a third data type and / or a first purpose.
4. The method according to claim 3, characterized in that, The method further includes: Send at least one of the following to the third node: The first authorization verification information corresponding to the third data type, wherein the third data type belongs to the first data type, and the first use belongs to the first authorized use associated with the third data type; The second authorization verification information corresponding to the third data type, wherein the third data type belongs to the second data type; The third authorization verification information corresponding to the first purpose, wherein the first purpose belongs to the second authorized purpose.
5. The method according to claim 3, characterized in that, The method further includes: The identifier of at least one node, including the second node, is sent to the third node.
6. The method according to claim 5, characterized in that, The second information includes the third data type, and the third data type belongs to the first data type. The method further includes: Receive third information sent by the third node, the third information including the identifier of the second node, the third data type, and the first purpose; Send the first authorization verification information corresponding to the third data type to the third node, wherein the first purpose belongs to the first authorized purpose associated with the third data type.
7. The method according to claim 5, characterized in that, The second information includes the first purpose, which belongs to the first authorized purpose, and the method further includes: Receive third information sent by the third node, wherein the third information includes the identifier of the second node, the first purpose, and the third data type; Send the first authorization verification information corresponding to the third data type to the third node, wherein the third data type belongs to the first data type associated with the first purpose.
8. The method according to claim 5, characterized in that, The second information includes the third data type and the first purpose, wherein the third data type belongs to the first data type, and the first purpose belongs to the first authorized purpose associated with the third data type. The method further includes: Receive third information sent by the third node, the third information including the identifier of the second node, the first purpose, and the third data type; Send the first authorization verification information corresponding to the third data type to the third node.
9. The method according to any one of claims 1-8, characterized in that, The first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); The second node includes at least one of the following: terminal equipment; access network equipment; network function (NF); The third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
10. A communication method, characterized in that, The method is executed by the second node, and the method includes: Send a first message to the first node, the first message being used to authorize the third node to perform the following action: request data from the second node.
11. The method according to claim 10, characterized in that, The first information includes at least one of the following: A first data type, wherein the first data type is associated with a first authorized use and / or a first unauthorized use; The second data type is not associated with any authorized or unauthorized use; First authorized use; The first unauthorized use; Second authorized use, which is not associated with any data type; Second unauthorized use, which is not associated with any data type; The first authorization verification information corresponding to each of the first data types; Second authorization verification information corresponding to each of the second data types; Third authorization verification information corresponding to each of the second authorized uses.
12. The method according to claim 11, characterized in that, The method further includes: Receive the fourth information sent by the third node, the fourth information being used to request data; Send a fifth message to the third node, the fifth message including the data, the fifth message being sent under at least one of the following conditions: The fourth information includes a third data type, a first purpose, and a first authorization verification information corresponding to the third data type. The first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type. The fourth data type is any one of the first data types. The third data type is the same as the fourth data type. The first purpose belongs to the first authorized purpose associated with the fourth data type. The fourth information includes a third data type, a first purpose, and a second authorization verification information corresponding to the third data type. The second authorization verification information corresponding to the third data type is the same as the second authorization verification information corresponding to the fifth data type. The fifth data type is any one of the second data types, and the third data type is the same as the fifth data type. The fourth information includes a third data type, a first purpose, and third authorization verification information corresponding to the first purpose. The third authorization verification information corresponding to the first purpose is the same as the third authorization verification information corresponding to the second purpose. The second purpose is any one of the second authorized purposes, and the first purpose and the second purpose are the same.
13. The method according to any one of claims 10-12, characterized in that, The first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); The second node includes at least one of the following: terminal equipment; access network equipment; network function (NF); The third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
14. A communication method, characterized in that, The method is executed by a third node, and the method includes: Send a second message to the first node, the second message including a third data type and / or a first purpose.
15. The method according to claim 14, characterized in that, The method further includes: Receive at least one of the following sent by the first node: The third data type corresponds to the first authorization verification information, wherein the third data type belongs to the first data type in the first information, and the first use belongs to the first authorized use associated with the third data type; The third data type corresponds to the second authorization verification information, wherein the third data type belongs to the second data type in the first information; The third authorization verification information corresponding to the first purpose, wherein the first purpose belongs to the second authorized purpose in the first information; The first information is sent from the second node to the first node.
16. The method according to claim 14, characterized in that, The method further includes: The first node sends an identifier of at least one node, wherein the at least one node includes a second node.
17. The method according to claim 16, characterized in that, The second information includes the third data type, and the third data type belongs to the first data type in the first information. The method further includes: Send third information to the first node, the third information including the identifier of the second node, the third data type, and the first purpose; Receive the first authorization verification information corresponding to the third data type sent by the first node, wherein the first use belongs to the first authorized use associated with the third data type; The first information is sent from the second node to the first node.
18. The method according to claim 16, characterized in that, The second information includes the first purpose, which belongs to the first authorized purpose in the first information. The method further includes: Send third information to the first node, the third information including the identifier of the second node, the first purpose, and the third data type; Receive the first authorization verification information corresponding to the third data type sent by the first node, wherein the third data type is sent when it belongs to the first data type associated with the first purpose; The first information is sent from the second node to the first node.
19. The method according to claim 16, characterized in that, The second information includes the third data type and the first purpose, wherein the third data type belongs to the first data type in the first information, and the first purpose belongs to the first authorized purpose associated with the third data type. The method further includes: Send third information to the first node, the third information including the identifier of the second node, the first purpose, and the third data type; Receive the first authorization verification information corresponding to the third data type sent by the first node; The first information is sent from the second node to the first node.
20. The method according to any one of claims 14-19, characterized in that, The method further includes: Send a fourth message to the second node, the fourth message being used to request data; Receive fifth information, the fifth information including the data, the fifth information being received under at least one of the following conditions: The fourth information includes a third data type, a first purpose, and a first authorization verification information corresponding to the third data type. The first authorization verification information corresponding to the third data type is the same as the first authorization verification information corresponding to the fourth data type. The fourth data type is any one of the first data types. The third data type is the same as the fourth data type. The first purpose belongs to the first authorized purpose associated with the fourth data type. The fourth information includes a third data type, a first purpose, and a second authorization verification information corresponding to the third data type. The second authorization verification information corresponding to the third data type is the same as the second authorization verification information corresponding to the fifth data type. The fifth data type is any one of the second data types, and the third data type is the same as the fifth data type. The fourth information includes a third data type, a first purpose, and a third authorization verification information corresponding to the first purpose. The third authorization verification information corresponding to the first purpose is the same as the third authorization verification information corresponding to the second purpose. The second purpose is any one of the second authorized purposes, and the first purpose and the second purpose are the same. Wherein, at least one of the first data type, the second data type, and the second authorized use is included in the first information, which is sent by the second node to the first node.
21. The method according to any one of claims 15-20, characterized in that, The first node includes at least one of the following: Network Storage Function (NRF); Unified Data Management (UDM); The second node includes at least one of the following: terminal equipment; access network equipment; network function (NF); The third node includes at least one of the following: Data Collection Function (DCF); Application Function (AF); NF.
22. A first node, characterized in that, include: The transceiver module is used to receive first information sent by the second node, which is used to authorize the third node to perform the following action: request data from the second node.
23. A second node, characterized in that, include: The transceiver module is used to send first information to the first node, and the first information is used to authorize the third node to perform the following action: request data from the second node.
24. A third node, characterized in that, include: The transceiver module is used to send second information to the first node, wherein the second information includes a third data type and / or a first purpose.
25. A first node, characterized in that, include: One or more processors; The processor is used to execute the communication method according to any one of claims 1-9.
26. A second node, characterized in that, include: One or more processors; The processor is used to execute the communication method according to any one of claims 10-13.
27. A third node, characterized in that, include: One or more processors; The processor is used to execute the communication method according to any one of claims 14-21.
28. A communication system, characterized in that, It includes a first node, a second node, and a third node, wherein the first node is configured to implement the communication method of claims 1-9, the second node is configured to implement claims 10-13, and the third node is configured to implement the communication method of claims 14-21.
29. A storage medium, characterized in that, The storage medium stores instructions that, when executed on a communication device, cause the communication device to perform the communication method as described in any one of claims 1-9, 10-13, and 14-21.
30. A program product, characterized in that, It includes at least one of a program and instructions, wherein when the program and instructions are executed by a communication device, they implement the communication method according to any one of claims 1-9, 10-13, and 14-21.