Communication method and apparatus
By using private key signing and public key verification methods in the control plane network elements, terminals can directly access the private network, solving the problem of inflexible access in existing technologies and achieving a more efficient and secure access method.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2026-01-20
- Publication Date
- 2026-07-30
AI Technical Summary
In existing technologies, terminal access to enterprise private networks requires operator administrators to pre-add network information to the terminal's subscription data, resulting in inflexible access.
By receiving the terminal's signature credentials through the control plane network element, and using private key signing and public key verification, the terminal is allowed to directly access the private network, reducing reliance on operator administrators.
It improves the flexibility and efficiency of terminal access to dedicated networks, and enhances the security and flexibility of access.
Smart Images

Figure CN2026073802_30072026_PF_FP_ABST
Abstract
Description
A communication method and apparatus
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese Patent Application No. 202510125805.7, filed on January 26, 2025, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology
[0004] Within an enterprise, a dedicated network is typically deployed. The process for a terminal to access this dedicated network is usually as follows: The enterprise's users inform the operator's administrator of the dedicated network information through the operator's business hall; the operator's administrator adds the dedicated network information to the terminal's subscription data on the communication network equipment; the terminal sends the dedicated network information to the communication network equipment to request access to the dedicated network; the communication network equipment determines whether the dedicated network information is stored in the terminal's subscription information; if it is, the terminal is allowed to access the dedicated network and its resources.
[0005] This shows that for a terminal to successfully access a dedicated network, the operator's administrator needs to add the dedicated network information to the terminal subscription data of the communication network equipment in advance, which is very inflexible. Summary of the Invention
[0006] This application provides a communication method and apparatus to improve the flexibility of terminal access to a dedicated network.
[0007] Firstly, this application provides a communication method applied to a first communication device. The first communication device includes, but is not limited to, a control plane network element, or a communication module within a control plane network element, or a processor, circuit, or chip within a control plane network element responsible for communication functions. It can also be a logical node, logical module, or software capable of implementing all or part of the control plane network element. Taking the application of this method to a control plane network element as an example: A first request is received from a first terminal. The first request is for the first terminal to request the use of services from a first subnet. The first request includes a first credential, which is a credential allowing the first terminal to use the services of the first subnet. The first credential includes a signature of first information using the private key of the first network element. The first information includes information from the first subnet. If the signature verification using the public key of the first network element is successful, a communication connection is established between the first terminal and a first device providing services to the first subnet.
[0008] In this method, the first terminal sends a credential allowing the use of the services of the first subnet to the control plane network element. This credential includes a signature of the information of the first subnet using the private key of the first network element. The control plane network element trusts the first network element. If the signature is verified successfully using the public key of the first network element, the control plane network element can allow the first terminal to access the first subnet. This eliminates the need for the operator's administrator to pre-add the information of the first subnet to the first terminal's subscription data, thereby improving the flexibility of terminal access to the first subnet and also improving access efficiency.
[0009] In one possible implementation, the first information may also include the identifier of the first terminal.
[0010] In this implementation, the first credential is determined based on the identifier of the first terminal. The first credentials of each first terminal are different, which can improve the security of the first terminal accessing the first subnet.
[0011] In one possible implementation, the first credential may further include: the identifier of the first terminal and / or information about the first subnet.
[0012] In one possible implementation, the information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a condition identifier; wherein the condition identifier is used to identify a first condition satisfied by a terminal using the services of the first subnet.
[0013] In one possible implementation, the information of the first device includes: the identifier of the user plane device, or the access address or identifier of the application server.
[0014] In one possible implementation, establishing a communication connection between a first terminal and a first device serving a first subnet includes: sending second information to an access network device serving the first terminal, the second information being used to establish a communication connection between the access network device serving the first terminal and the first device; or, sending third information to the first terminal, the third information being used to establish a communication connection between the first terminal and the first device.
[0015] In one possible implementation, the first device is a user plane device, the second information is the access address of the user plane device; the first device is an application server, and the third information is a token used to access the application server.
[0016] In one possible implementation, the token may include: a primary credential, or a string generated by the application server.
[0017] In one possible implementation, the method further includes: receiving a second request for requesting the creation of a subnet; and sending information about the first subnet.
[0018] This implementation eliminates the need for operator administrators to create subnets, improving both the flexibility and efficiency of subnet creation.
[0019] In one possible implementation, the second request includes information about a first condition satisfied by the terminal using the services of the first subnet.
[0020] In one possible implementation, the information for the first condition is: terminals using the services of the first subnet are associated with the same generic public subscription identifier (GPSI).
[0021] In this implementation, only terminals associated with the same GPSI can access the first subnet, which improves the security of the subnet.
[0022] Secondly, this application provides a communication method applied to a terminal side. This terminal side includes, but is not limited to: a terminal device, or a communication module within the terminal device, or a processor, circuit, or chip (such as a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip or system-in-package (SIP) chip containing a modem core) responsible for communication functions within the terminal device. It can also be a logical node, logical module, or software capable of implementing all or part of the terminal's functions. Taking the application of this method to a first terminal as an example: a first request is sent to a control plane network element. The first request is used by the first terminal to request the use of services from a first subnet. The first request includes a first credential, which is a credential allowing the first terminal to use the services of the first subnet. The first credential includes a signature of first information using the private key of the first network element. The first information includes information from the first subnet. If the signature verification using the public key of the first network element is successful, a communication connection is established between the first terminal and a first device serving the first subnet.
[0023] In one possible implementation, the first information may also include the identifier of the first terminal.
[0024] In one possible implementation, the first credential may further include: the identifier of the first terminal and / or information about the first subnet.
[0025] In one possible implementation, the information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a condition identifier; wherein the condition identifier is used to identify a first condition satisfied by a terminal using the services of the first subnet.
[0026] In one possible implementation, the information of the first device includes: the identifier of the user plane device, or the access address or identifier of the application server.
[0027] In one possible implementation, establishing a communication connection between a first terminal and a first device serving a first subnet includes: receiving third information, the third information being used to establish a communication connection between the first terminal and the first device; and establishing a communication connection between the first terminal and the first device based on the third information.
[0028] In one possible implementation, the first device is an application server, and the third information is a token used to access the application server.
[0029] The technical effects of the second aspect can be referenced from those of the first aspect, and will not be elaborated further.
[0030] Thirdly, this application provides a communication method applied to a terminal side. This terminal side includes, but is not limited to, a terminal device, or a communication module within the terminal device, or a processor, circuit, or chip (such as a modem chip, also known as a baseband chip, or a SoC chip containing a modem core, or a system-in-package (SIP) chip) responsible for communication functions within the terminal device. It can also be a logical node, logical module, or software capable of implementing all or part of the terminal functions. Taking the application of this method to a second terminal as an example: a second request is sent to a control plane network element, the second request being used to request the creation of a subnet; information about a first subnet is received from the control plane network element; a third request is sent to the first network element, the third request being used to request the acquisition of a first credential, the first credential being a credential allowing the first terminal to use the services of the first subnet; the third request includes information about the first subnet; the first credential includes a signature of the first information using the private key of the first network element, the first information including information about the first subnet.
[0031] In one possible implementation, the third request also includes the identifier of the first terminal; the first information also includes the identifier of the first terminal.
[0032] In one possible implementation, the first credential may further include: the identifier of the first terminal and / or information about the first subnet.
[0033] In one possible implementation, the information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a condition identifier; wherein the condition identifier is used to identify a first condition satisfied by a terminal using the services of the first subnet.
[0034] In one possible implementation, the information of the first device includes: the identifier of the user plane device, or the access address or identifier of the application server.
[0035] In one possible implementation, it also includes: receiving a first credential; sending the first credential to a first terminal.
[0036] The technical effects of the third aspect can be referenced from those of the first aspect, and will not be elaborated further.
[0037] Fourthly, a communication device is provided. The communication device can be a control plane network element as described in the first aspect, and the communication device possesses the functions of the control plane network element. The communication device may be, for example, a functional module within the control plane network element, such as a baseband device or a chip system. Alternatively, the communication device can be a first terminal as described in the second aspect, and the communication device possesses the functions of the first terminal. The communication device may be, for example, a functional module within the first terminal, such as a baseband device or a chip system. Alternatively, the communication device can be a second terminal as described in the third aspect, and the communication device possesses the functions of the second terminal. The communication device may be, for example, a functional module within the second terminal, such as a baseband device or a chip system.
[0038] In one optional implementation, the communication device includes a baseband device and a radio frequency device. In another optional implementation, the communication device includes a processing unit (sometimes also called a processing module) and a transceiver unit (sometimes also called a transceiver module). The transceiver unit is capable of both transmitting and receiving functions. When the transceiver unit performs the transmitting function, it can be called a transmitting unit (sometimes also called a transmitting module), and when it performs the receiving function, it can be called a receiving unit (sometimes also called a receiving module). The transmitting unit and the receiving unit can be the same functional module, which is called the transceiver unit and can perform both transmitting and receiving functions; or, the transmitting unit and the receiving unit can be different functional modules, and the transceiver unit is a collective term for these functional modules.
[0039] In one possible implementation, the communication device further includes a storage unit (sometimes also called a storage module), and a processing unit is used to couple with the storage unit and execute programs or instructions in the storage unit to enable the communication device to perform the functions of the control plane network element of the first aspect, or the functions of the first terminal of the second aspect, or the functions of the second terminal of the third aspect.
[0040] Fifthly, a communication device is provided, including an interface circuit and one or more processors, optionally including a memory, with the one or more processors coupled to the memory. The memory stores a computer program, and the processors are coupled to the memory and the interface circuit. When the processor reads the computer program or instructions, it causes the communication device to execute the method executed by the control plane network element in the first aspect, or the method executed by the first terminal in the second aspect, or the method executed by the second terminal in the third aspect. For example, the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor, or to send signals from the processor to other communication devices outside the communication device. The processor, through logic circuits or executable code instructions, implements the method executed by the control plane network element in the first aspect, or the method executed by the first terminal in the second aspect, or the method executed by the second terminal in the third aspect.
[0041] In one possible implementation, the communication device is a chip or chip system.
[0042] In a sixth aspect, a communication device is provided, including a processor, and optionally, a memory; the processor and the memory are coupled; the memory is used to store computer programs or instructions; the processor is used to execute part or all of the computer programs or instructions in the memory, and when part or all of the computer programs or instructions are executed, it is used to implement the function of the control plane network element in the first aspect, or to implement the function of the first terminal in the second aspect, or to implement the function of the second terminal in the third aspect.
[0043] In one possible implementation, the apparatus may further include a transceiver for transmitting signals processed by the processor or receiving signals input to the processor. The transceiver may perform the transmitting or receiving actions performed by the control plane network element in the first aspect, or the transceiver may perform the transmitting or receiving actions performed by the first terminal in the second aspect, or the transceiver may perform the transmitting or receiving actions performed by the second terminal in the third aspect.
[0044] In one possible implementation, the processing unit in the fourth aspect can be implemented by a processor, the storage unit in the fourth aspect can be implemented by a memory, and the transceiver unit in the fourth aspect can be implemented by a transceiver.
[0045] In one possible implementation, the communication device is a chip or chip system.
[0046] A seventh aspect provides a communication system comprising a control plane network element as described in the first aspect, a first terminal as described in the second aspect, and a second terminal as described in the third aspect. For example, the first terminal, the second terminal, and the control plane network element can be implemented using the communication devices of the fifth and sixth aspects.
[0047] Eighthly, a communication system is provided, including a first network element and a control plane network element as described in the first aspect, wherein the first network element is used to determine the first credential.
[0048] In one possible implementation, the first network element is further configured to: receive a third request, the third request being for requesting to obtain the first credential, the third request including information about the first subnet; the first network element is further configured to: send the first credential.
[0049] In one possible implementation, the third request may also include the identifier of the first terminal.
[0050] In one possible implementation, the first network element is specifically used to: receive the third request from the second terminal; and, if the second terminal allows the creation of a subnet, determine or send a first credential.
[0051] In one possible implementation, the control plane element trusts the first element.
[0052] Ninth aspect, a computer-readable storage medium is provided for storing a computer program or instructions that, when executed, cause the methods of the first, second, or third aspects described above to be implemented.
[0053] In a tenth aspect, a computer program product containing instructions is provided, which, when run on a computer, causes the methods of the first, second, or third aspects described above to be implemented. Attached Figure Description
[0054] Figure 1 is a schematic diagram of the architecture of the communication system provided in this application;
[0055] Figures 2 to 4, 6 and 7 are schematic diagrams of the communication method provided in this application;
[0056] Figures 5a, 5b and 5c are schematic diagrams of the identity identifier provided in this application;
[0057] Figures 8 and 9 are structural diagrams of the communication device provided in this application. Detailed Implementation
[0058] The technical solution of this application can be applied to various wireless communication systems, including but not limited to fourth-generation (4G) mobile communication technology systems (also known as long term evolution (LTE) systems), fifth-generation (5G) mobile communication technology systems (also known as new radio (NR) systems), or future mobile communication systems, etc., without any specific limitations.
[0059] Furthermore, the technical solutions provided in this application can be applied to device-to-device (D2D) scenarios, such as NR-D2D scenarios, or to vehicle-to-everything (V2X) communication scenarios, such as NR-V2X scenarios. For example, they can be used in fields such as intelligent driving, assisted driving, or intelligent connected vehicles. As another example, the technical solutions provided in this application can also be applied to factory manufacturing scenarios.
[0060] Furthermore, the technical solutions provided in this application can be applied to scenarios including but not limited to: terrestrial cellular communication, non-terrestrial network (NTN), satellite communication, high altitude platform station (HAPS) communication, integrated access and backhaul (IAB) communication, and reconfigurable intelligent surface (RIS) communication.
[0061] Figure 1 is a schematic diagram of a communication system provided in this application, including: 1) a terminal device, 2) a radio access network (RAN), and 3) a core network, wherein the terminal device accesses the core network through the RAN. Optionally, it also includes: 4) a data network (DN), wherein the core network communicates with the DN. A detailed description follows:
[0062] 1) Terminal Equipment: In this application embodiment, any device capable of data communication with network equipment can be considered a terminal equipment. Terminal equipment is also called a terminal, terminal device, user equipment (UE), user terminal, mobile station, or mobile terminal, etc. Terminal equipment can be widely used in various scenarios. For example, terminal equipment can be: mobile phones, computers, mobile internet devices (MID), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, stations (STA), robotic arms, cameras, robots, vehicles, drones, helicopters, airplanes, ships, or smart home devices (such as televisions, air conditioners, robot vacuums, speakers, set-top boxes), relays, customer premises equipment (CPE), etc.
[0063] Furthermore, in this embodiment, the terminal device can also be a terminal device in an IoT system, such as a water meter or electricity meter. IoT is an important component of future information technology development. Its main technical characteristic is connecting objects to networks through communication technology, thereby realizing an intelligent network that enables human-machine interconnection and object-to-object interconnection.
[0064] When the terminal device is applied to V2X, it can also be called a V2X device, such as a smart car, digital car, unmanned car, driverless car, pilotless car, autonomous car, pure electric vehicle, hybrid electric vehicle (HEV), range-extended electric vehicle (REEV), plug-in hybrid electric vehicle (PHEV), new energy vehicle, and RSU.
[0065] The various terminal devices described above, if located on a vehicle (e.g., placed / installed inside the vehicle), can all be considered in-vehicle terminal devices. In-vehicle terminal devices can be built into a vehicle's in-vehicle module, in-vehicle component, in-vehicle chip, or in-vehicle unit as one or more components or units. The vehicle can implement the methods of this application through the built-in in-vehicle module, in-vehicle component, in-vehicle chip, or in-vehicle unit. In-vehicle terminal devices can be vehicle equipment, in-vehicle modules, vehicles, in-vehicle units (on-board units, OBUs), remote sensing units (RSUs), in-vehicle infotainment systems (or in-vehicle transmission units) (telematics boxes, T-boxes), chips, or systems on a chip (SOCs), etc. These chips or SOCs can be installed in the vehicle, OBU, RSU, or T-box.
[0066] In the embodiments of this application, the device for implementing the functions of the terminal device can be the terminal device itself, or a device capable of supporting the terminal device in implementing the functions, such as a chip system or a combination of devices or components capable of implementing the functions of the terminal device. This device can be installed in the terminal device. The embodiments of this application do not limit the specific technology or specific device form used in the terminal device.
[0067] 2) Radio Access Network (RAN): Provides connectivity between terminal equipment and the core network. The RAN can be a 3GPP-related cellular system, such as a 5G / NR mobile communication system, or a future-oriented evolution system. The RAN can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), a virtualized RAN (vRAN), a non-terrestrial network (NTN), etc. The RAN can also be a communication system that integrates two or more of the above systems. The radio access network can include at least one access network device. Access network devices can also be called RAN nodes, RAN entities, or access nodes, etc.
[0068] In one possible scenario, a RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), or a base station in a future mobile communication system. RAN nodes can also be macro base stations, micro base stations, indoor stations, relay nodes, donor / host nodes, or radio controllers. RAN nodes can also be servers, wearable devices, vehicles, or in-vehicle equipment. For example, in V2X technology, the RAN node can be a roadside unit (RSU).
[0069] In another possible scenario, the RAN node can be a module or unit that performs some of the functions of the base station; or multiple RAN nodes can cooperate to assist terminal equipment in achieving wireless access, with different RAN nodes performing some of the functions of the base station. For example, the RAN node can include, but is not limited to, a centralized unit (CU), a distributed unit (DU), or a radio unit (RU). The function of the CU can be implemented by a single entity or by different entities. For example, the function of the CU can be further divided, that is, the control plane and the user plane can be separated and implemented by different entities, namely the control plane CU entity (i.e., CU-control plane (CP) entity) and the user plane CU entity (i.e., CU-user plane (UP) entity). The CU-CP entity and the CU-UP entity can be coupled with the DU to jointly complete the function of the RAN node. The CU and DU can be set up separately or included in the same network element, such as in the baseband unit (BBU). Any of the units among the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by software modules, hardware modules, or a combination of software modules and hardware modules.
[0070] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an O-RAN system, CU can also be called O-CU (Open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples.
[0071] The CU and DU can be configured according to the protocol layer functions of the wireless network they implement: for example, the CU is responsible for handling non-real-time protocol stack functions and is typically located in a data center or edge cloud. The CU is configured to implement protocol layers at or above the Packet Data Convergence Protocol (PDCP) layer (e.g., Radio Resource Control (RRC) layer and / or Service Data Adaptation Protocol (SDAP) layer); the DU handles real-time protocol stack functions and is configured to implement protocol layers below the PDCP layer (e.g., Radio Link Control (RLC), Media / Medium Access Control (MAC) layer, and / or Physical (PHY) layer). The DU can be deployed close to the base station to reduce latency. For detailed descriptions of the above protocol layers, please refer to the relevant 3GPP technical specifications or the technical specifications of other applicable communication protocols.
[0072] The above division of CU and DU processing functions according to protocol layers is merely an example; other division methods are also possible, and this application does not limit this. For example, in one design, the CU or DU can be further divided into processing functions with protocol layers. In one design, some functions of the RLC layer and the functions of the protocol layer above the RLC layer are located in the CU, while the remaining functions of the RLC layer and the functions of the protocol layer below the RLC layer are located in the DU. For example, the RU performs lower-layer physical layer functions, is directly connected to the antenna, and performs radio frequency signal transmission and reception.
[0073] In another possible design, the DU and RU collaborate to implement the PHY layer functionality, or, more specifically, a portion of the PHY layer functionality of the DU can be moved to the RU. A DU can be connected to one or more RUs. The functions of the DU and RU can be configured in various ways depending on the design. For example, the DU may be configured to implement baseband functions, and the RU may be configured to implement mid-RF functions. Alternatively, the DU may be configured to implement higher-level functions in the PHY layer, and the RU may be configured to implement lower-level functions in the PHY layer, or both lower-level and RF functions. Higher-level functions in the physical layer may include a portion of the physical layer's functionality closer to the MAC layer, and lower-level functions may include another portion of the physical layer's functionality closer to the mid-RF side. This application does not limit the specific functions of the DU and RU. The interface between the DU and RU can be called a fronthaul interface. In one design, the CU may not have a PDCP layer; for example, the CU may only include an RRC layer. The CU-CP may not have PDCP-C. The CU-UP may not have PDCP-U, or may not have a CU-UP. In one design, the DU may not have an RLC layer; for example, the DU may only have a MAC and a higher PHY layer.
[0074] When the RAN is O-RAN, it can also have artificial intelligence (AI) capabilities. For example, O-RAN includes a RAN intelligent controller (RIC). The RIC is an innovative element in the ORAN architecture, divided into xAPPs (applications for near real-time control) and rApps (applications for non-real-time optimization). The RIC provides adaptive management and optimization of the wireless network. The RIC includes non-real-time RAN intelligent controllers (non-real-time RIC / non-RT RIC / NRT RIC) and near-real-time RAN intelligent controllers (near-real-time RIC / nRT RIC). Non-real-time RICs can be used to implement non-real-time intelligent management of RAN functions, enabling workflows including model training and model updates, and guiding applications / functions in the nRT RIC based on policies. Near-real-time RICs can be used to implement near-real-time intelligent management of the RAN. Through data collection and related operations on the E2 interface, near-real-time control and optimization of O-RAN modules and resources are achieved.
[0075] The ORAN system includes: a cloud platform, RAN network functions, and a service management and orchestration (SMO) framework. RAN network functions include: O-CU, O-DU, and O-RU; optional, RIC may also be included, as detailed above. O-Cloud is an open cloud infrastructure platform consisting of physical resources that meet the functional requirements of O-RAN and software components that support O-RAN management and orchestration. This platform hosts and runs all software entities related to O-RAN network functions, while providing the necessary management and orchestration capabilities. The SMO not only assumes the responsibilities of a traditional network management system but also emphasizes its highly intelligent and service-oriented characteristics. It can integrate products and services from multiple vendors, thereby providing users with more flexible and customized solutions.
[0076] In the embodiments of this application, the device used to implement the function of the access network device can be the access network device itself, or it can be a device that supports the access network device in implementing the function, such as a chip system or a combination device or component that can implement the function of the access network device. The device can be installed in the access network device. The embodiments of this application do not limit the specific technology or specific device form used in the access network device.
[0077] 3) Core network (CN): It mainly provides user connections, user management, and service delivery, and serves as the interface to external networks.
[0078] The core network includes one or more of the following network elements:
[0079] The access management network element (also known as the mobility management network element) is a control plane network element provided by the operator's network. It is responsible for access control and mobility management of terminal devices accessing the operator's network, including functions such as mobility state management, allocation of temporary user identities, authentication, and user management. In 5G communication systems, this access management network element can be an access and mobility management function (AMF) network element. In future communication systems, the access management network element can still be an AMF network element, or it can have other names; this application does not limit its scope.
[0080] The session management network element is primarily responsible for session management in mobile networks, such as session establishment, modification, and release. Specific functions include assigning IP addresses to users and selecting user plane network elements that provide packet forwarding capabilities. In 5G communication systems, this session management network element can be a session management function (SMF) network element. In future communication systems, the session management network element may still be an SMF network element, or it may have other names; this application does not impose any limitations on this.
[0081] User plane network elements are responsible for forwarding and receiving user data in terminal devices. They can receive user data from the data network and transmit it to the terminal device through the access network equipment; user plane network elements can also receive user data from the terminal device through the access network equipment and forward it to the data network. The transmission resources and scheduling functions that provide services to the terminal device in the user plane network element are managed and controlled by the SMF network element. In 5G communication systems, this user plane network element can be a user plane function (UPF) network element. In future communication systems, the user plane network element can still be a UPF network element, or it can have other names; this application does not limit this.
[0082] The data management network element is used for generating authentication credentials, processing user identifiers (such as storing and managing permanent user identities), and managing access control and subscription information. In 5G communication systems, this data management network element can be a unified data management (UDM) network element. In future communication systems, the data management network element can still be a UDM network element, or it can have other names; this application does not limit this.
[0083] An identity management network element is used to determine verifiable credentials for users, which prove that the user possesses a specific identity and / or is authorized to access specific services. In 5G communication systems, this identity management network element can be an independent network function (NF), such as an identity management function (IDM) network element, or it may be part of other network functions, such as an authentication server function (AUSF) or a UDM. In future communication systems, the identity management network element may still be an IDM network element, or it may have other names, or it may be part of other network functions; this application does not impose any limitations.
[0084] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). One possible implementation is that the aforementioned network element or function can be implemented by a single device, multiple devices working together, or a functional module within a single device; this application does not specifically limit this.
[0085] 4) Data Network (DN): This network can deploy various services and provide data and / or voice services to terminal devices. For example, the DN can be a private network in a smart factory. Sensors installed in the workshop can serve as terminal devices. The DN can also house sensors and a control server, which can provide services to the sensors. Sensors can communicate with the control server, receive instructions, and transmit collected sensor data to the control server accordingly. Another example is the DN can be an internal office network for a company. Employees' mobile phones or computers can serve as terminal devices, allowing them to access information and data resources on the company's internal network. The application server in this application can be deployed within the data network.
[0086] Access Point Name (APN) or Data Network Name (DNN) is a key parameter for a terminal to access a network. APN / DNN is typically stored as part of the subscription data in the Home Subscriber Server (HSS) or UDM. When a terminal initiates a packet service, it provides the APN / DNN to the communication network device (e.g., AMF). The communication network device determines whether the APN / DNN is stored in the terminal's subscription data in the HSS / UDM. If so, the communication network device can perform domain name resolution on the APN / DNN through a domain name server. Based on the resolution result, it connects the terminal to the specific network resource corresponding to the APN / DNN. Therefore, it can be seen that successful terminal access to a dedicated network requires the addition of the dedicated network's information (e.g., APN / DNN) to the terminal's subscription data, which is highly inflexible.
[0087] Based on this, this application provides a communication method in which a first terminal (e.g., a terminal of an enterprise) sends a first request to a control plane network element. The first request is used by the first terminal to request the use of services of a first subnet (e.g., a private network of an enterprise). The first request includes a first credential, which is a credential that allows the first terminal to use the services of the first subnet. The first credential includes a signature of first information using the private key of the first network element. The first information includes information of the first subnet. If the signature is verified successfully using the public key of the first network element, the control plane network element can establish a communication connection between the first terminal and a first device that provides services for the first subnet.
[0088] In this method, the first terminal sends a credential allowing the use of the services of the first subnet to the control plane network element. This credential includes a signature of the information of the first subnet using the private key of the first network element. The control plane network element trusts the first network element. If the signature is verified using the public key of the first network element, the control plane network element can allow the first terminal to access the first subnet. This eliminates the need for the operator to add the information of the first subnet to the first terminal's subscription data, thereby improving the flexibility of terminal access to the first subnet and also improving access efficiency.
[0089] The relevant terms used in the embodiments of this application will be explained below. It should be noted that these explanations are for the purpose of making the embodiments of this application easier to understand, and should not be regarded as a limitation on the scope of protection claimed by this application.
[0090] (1) A subnetwork is a logically independent part of a physical network. A subnetwork can be a portion of a mobile communication network, a third-party network connected to a mobile communication network, or a virtual private network provided by an operator to a specific individual, family, or organization. A subnetwork can also be called a logical network, a private network, or a virtual network.
[0091] (2) The first terminal is any terminal that requests access to the first subnet (or requests to use the services of the first subnet); the second terminal is the terminal that requests to create the first subnet; the first terminal and the second terminal may be the same or different.
[0092] Optionally, the second terminal can manage the first terminal. Optionally, the generic public subscription identifier (GPSI) associated with the first terminal is the GPSI of the second terminal. The first terminal can be referred to as a member terminal or user terminal of the first subnet; the second terminal can be referred to as the administrator terminal of the first subnet.
[0093] The control plane network element can establish a communication connection between the first terminal and the first device serving the first subnet. The control plane network element can be an SMF or a communication and computing integrated control network element, etc.
[0094] The first network element can determine the credentials for the first terminal to access the first subnet. The first network element can be an IDM, an authentication service function (AUSF), or a UDM, etc. AUSF can implement 3GPP and non-3GPP access authentication.
[0095] The “credential” in this application embodiment can also be called a “verifiable credential (VC)”.
[0096] In this embodiment of the application, the interaction between the terminal (e.g., the first terminal, the second terminal) and the core network elements (e.g., the control plane network elements, the first network element, the UDM, etc.) can be carried out through the access network equipment and AMF that serve the terminal.
[0097] (3) Private key signing and public key verification:
[0098] Device A generates a key pair, a public key and a private key. Device A uses its private key to encrypt the digest of information m, forming a signature.
[0099] Device B obtains the information m, the signature, and the public key of device A. It then uses device A's public key to decrypt the signature, obtaining a digest. Device B calculates the digest of information m and compares it with the decrypted digest. If they match, it means information m has not been tampered with, and the signature verification passes; otherwise, the signature verification fails.
[0100] (4) In the embodiments of this application, "when," "if," and "if" all refer to the device making a corresponding processing under certain objective circumstances, and are not limited to a time, nor do they require the device to perform a judgment action, nor do they imply any other limitations. Unless otherwise specified, "if" and "if" can be substituted, and "when" and "in the case of" can be substituted. "When" and "if" / "if" can be substituted.
[0101] In this application embodiment, the number of nouns, unless otherwise specified, refers to "singular nouns or plural nouns," that is, "one or more." "At least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A or B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. For example, A / B means: A or B. Expressions such as "at least one of the following" or "one or more of them" refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c, or one or more of a, b, or c, means: a, b, c, a and b, a and c, b and c, or a and b and c. Each of a, b, and c can be single or multiple.
[0102] The ordinal numbers such as "first" and "second" mentioned in the embodiments of this application are used to distinguish multiple objects, and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. Furthermore, such names do not indicate differences in the content, sending / receiving end, sending order, size, application scenario, priority, or importance of the two pieces of information. Additionally, the numbering of steps in the various embodiments described in this application is only to distinguish different steps and is not used to limit the order of steps.
[0103] The naming of each message / information in this application is merely illustrative and limits the names of each message / information.
[0104] (5) The methods executed by the terminal device (e.g., the first terminal or the second terminal) in the embodiments of this application can also be implemented by the communication module in the terminal device, or by the circuit or chip responsible for communication functions in the terminal device (e.g., a modem chip (also known as a baseband chip), or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip). The methods executed by the control plane network element in the embodiments of this application can also be implemented by the module in the control plane network element (e.g., a circuit, a chip, or a chip system), or by the logic node, logic module, or software that can implement all or part of the functions of the control plane network element. The methods executed by the first network element in the embodiments of this application can also be implemented by the module in the first network element (e.g., a circuit, a chip, or a chip system), or by the logic node, logic module, or software that can implement all or part of the functions of the first network element.
[0105] To better illustrate the embodiments of this application, the methods provided by the embodiments of this application are described below with reference to the accompanying drawings. Unless otherwise specified below, the steps indicated by dashed lines in the accompanying drawings corresponding to the various embodiments of this application are optional steps. It should be noted that the technical details of the multiple embodiments provided in this application can be referenced to each other, each embodiment described below can exist independently, and multiple embodiments can also be combined with each other as an embodiment in the absence of logical errors.
[0106] Figure 2 is a flowchart illustrating a communication method provided in an embodiment of this application.
[0107] Step 201: The first terminal sends a first request to the control plane network element; correspondingly, the control plane network element receives the first request.
[0108] The first request is used by the first terminal to request the use of the services of the first subnet; in other words, the first request is used by the first terminal to request access to the first subnet; the first request includes a credential that allows the first terminal to use the services of the first subnet (for ease of subsequent description, the credential that allows the first terminal to use the services of the first subnet will be referred to as the first credential); in other words, the first credential is a credential that allows the first terminal to access the first subnet).
[0109] The first credential includes: a signature of first information using the private key of the first network element, wherein the first information includes: information of the first subnet and / or the identifier of the first terminal. Optionally, the first credential may also include the identifier of the first terminal and / or the information of the first subnet; or, the identifier of the first terminal and / or the information of the first subnet may be located in the first request and not in the first credential.
[0110] The identifier of the first terminal can be a subscription permanent identifier (SUPI), GPSI, or subscription concealed identifier (SUCI), or a unique string assigned to the first terminal by the control plane network element or the first network element (e.g., IDM) that identifies the first terminal (this string can be in a globally uniform format), etc.
[0111] The information of the first subnet includes, but is not limited to, one or more of the following: 1) information of the device serving the first subnet (for ease of description, the device serving the first subnet will be referred to as the first device), 2) a condition identifier; wherein the condition identifier is used to identify the first condition satisfied by the terminal using the service of the first subnet, or 3) the identifier of the first subnet.
[0112] Regarding point 1) above, the first device can be a user plane device, such as a UPF, router, etc.; or the first device can be an application server, which can be an application server within a mobile communication network (or operator network), or an application server outside a mobile communication network (e.g., an application server provided by an enterprise or a third party). The information of the first device can be the identifier of the user plane device, the identifier of the application server device, or the access address of the application server, etc.
[0113] The information of the first device serving the first subnet can also be replaced with: the name of the service that the terminal is allowed to access the first subnet to call (or use), the application service identifier (APP ID), or the uniform resource identifier (URI). The URI can also be replaced with the uniform resource locator (URL).
[0114] Regarding condition 2) above, the first condition can be that terminals using the services of the first subnet are associated with the same GPSI; the same GPSI can be the first GPSI, such as the GPSI of the second terminal, or other GPSIs. The condition identifier can include: the first GPSI and / or a condition identifier other than the first GPSI that can uniquely identify the first condition, for example, #001.
[0115] Regarding point 3) above, the identifier of the first subnet can be: information of the device serving the first subnet (or APP ID, or URL, or URI), or condition identifier, or other identifiers that can uniquely identify the first subnet.
[0116] Step 202: If the signature is verified using the public key of the first network element, the control plane network element establishes a communication connection between the first terminal and the first device serving the first subnet.
[0117] If the signature is verified using the public key of the first network element, it indicates that the first terminal has permission to access the first subnet. The control plane network element allows the first terminal to access the first subnet, and can then establish a communication connection between the first terminal and the first device. If the verification fails, it indicates that the first terminal does not have permission to access the first subnet, and the control plane network element can reject the first request. A trust relationship can exist between the control plane network element and the first network element; for example, the control plane network element trusts the first network element, without limiting whether the first network element trusts the control plane network element.
[0118] The following is an example of verifying the signature in the first credential:
[0119] Example 1: The control plane network element obtains the first information and the public key of the first network element; based on the public key of the first network element and the first information, it verifies the signature in the first credential to determine whether the verification is successful.
[0120] Example 2: The control plane network element sends the signature and first information to other devices. Additionally, the control plane network element can send the public key of the first network element to other devices, or other devices may have the public key of the first network element stored therein. Other devices verify the signature based on the public key of the first network element and the first information, and send the verification result (i.e., verification passed or failed) to the control plane network element. The control plane network element can determine whether the signature in the first credential has been successfully verified based on the verification result from other devices. Other devices can be the first network element or any device with signature verification functionality.
[0121] The following describes a possible implementation for a control plane network element to establish a communication connection between a first terminal and a first device: The control plane network element determines second information based on information from a first subnet (which may come from a first credential or a first request). This second information is used to establish a communication connection between the access network device serving the first terminal and the first device. The control plane network element then sends the second information to the access network device serving the first terminal. Alternatively, the control plane network element determines third information based on information from the first subnet (which may come from a first credential or a first request). This third information is used to establish a communication connection between the first terminal and the first device. The control plane network element then sends the third information to the first terminal.
[0122] One possible implementation for determining the second / third information is that the information of the first subnet is associated with the first device, and the control plane network element determines the first device based on the information of the first subnet; the control plane network element interacts with the first device to determine the second / third information.
[0123] One example of identifying the first device is that the information of the first subnet includes information about the first device, such as the identifier of the user plane device, the identifier of the application server, and the access address of the application server; the control plane network element can directly identify the first device based on the information of the first subnet. Another example of identifying the first device is that the information of the first subnet does not include the information of the first device, but the control plane network element stores the association between the information of the first subnet and the information of the first device; the control plane network element identifies the first device based on this association and the information of the first subnet.
[0124] The first device is a user plane device (e.g., UPF, router), and the third information can be the access address information of the user plane device. The access network device serving the terminal device establishes a communication connection with the user plane device based on the access address information of the user plane device, and establishes a communication connection between the first terminal and the access network device.
[0125] The first device is an application server, and the second information can be a token for accessing the application server; the token can be a first credential, for example, the first credential includes: a signature of the application server's access address (or identifier) using the private key of the first network element, or a signature of the application server's access address (or identifier) and the identifier of the first terminal using the private key of the first network element.
[0126] When a control plane network element sends second information to a first terminal, or sends third information to an access network device serving the first terminal, for example, the control plane network element sends a response message to the access network device serving the first terminal in response to a first request. This response message includes the second or third information, and is used to indicate that the first terminal is allowed to use the services of the first subnet (or to access the first subnet). The access network device then sends a response message to the first terminal in response to the first request, including the third information. The terminal device does not need to be aware of the second information (e.g., the access address information of the user plane device).
[0127] In this method, the first terminal sends a credential allowing the use of the services of the first subnet to the control plane network element. This credential includes a signature of the information of the first subnet using the private key of the first network element. The control plane network element trusts the first network element. If the signature is verified using the public key of the first network element, the control plane network element can allow the first terminal to access the first subnet. Therefore, the operator does not need to add the information of the first subnet to the first terminal's subscription data in advance, which can improve the flexibility of the terminal accessing the first subnet and also improve the access efficiency.
[0128] Before step 201, the process also includes creating a first subnet. For example, the terminal's owner goes to the operator's service center and informs the operator's administrator to create a first subnet. Alternatively, the first terminal or other device requests the creation of a first subnet from the control plane network element, without requiring the operator's administrator to create the first subnet.
[0129] In addition, prior to step 201, the process includes: the first network element determining a first credential that allows the first terminal to use the services of the first subnet.
[0130] Next, referring to Figure 3, we will introduce a flowchart of a communication method, taking the request of a control plane network element to create the first subnet as an example.
[0131] Optionally, in step 300: The second terminal successfully accesses the mobile network after network authentication; the second terminal's subscriber identity module (SIM) or user identity module (UIM) stores the second terminal's SUPI and a key, which is shared between the second terminal and the mobile network. The second terminal uses this key to calculate the challenge question issued by the mobile network; if the answer is correct, the mobile network can consider the second terminal a legitimate user and allow the second terminal to access the mobile network.
[0132] Step 301: The second terminal sends a second request to the control plane network element, the second request being used to request the creation of a subnet; correspondingly, the control plane network element receives the second request.
[0133] Optionally, the second request may include an identifier for the second terminal, such as the second terminal's SUPI, GPSI, or SUCI. The control plane network elements can determine which terminal is requesting the creation of the subnet based on the second terminal's identifier.
[0134] Optionally, the second request is used to request the creation of a subnet that satisfies the first constraint information (or the first description information). For example, the second request includes the first constraint information. For example, the first constraint information includes one or more of the following: the geographical location information of the subnet, the IP address segment information of the subnet, and information on the first conditions that the subnet can provide the first application service or that terminals using the services of the first subnet must meet.
[0135] The geographic location information of a subnet can include: location name, Global Positioning System (GPS) location information, etc.
[0136] The IP address information of a subnet can include: the subnet's IPv4 or IPv6 address range and subnet mask, etc.
[0137] The first application service can be represented by a URL or an application service identifier (APP ID).
[0138] The first condition can be: terminals using the services of the first subnet are associated with the same GPSI; the same GPSI can be the GPSI of the terminal requesting the creation of the subnet (i.e., the second terminal) or other GPSIs.
[0139] The second terminal can send the second request to the control plane network element through the AMF. Optionally, after receiving the second request, the AMF determines whether the second terminal is allowed to create a subnet; if allowed, it can send the second request to the control plane network element; if not allowed, it can reject the second request. Alternatively, the AMF can skip this determination and directly forward the second request to the control plane network element. Optionally, after receiving the second request, the control plane network element determines whether the second terminal is allowed to create a subnet, thus eliminating the need for the AMF to determine this; if allowed, subsequent steps can be executed; if not allowed, the second request can be rejected.
[0140] For example, the subscription information of the second terminal includes indication information on whether the creation of a subnet is allowed. The AMF or control plane network element can determine whether the second terminal is allowed to create a subnet based on the subscription information of the second terminal.
[0141] In one example, the AMF or control plane network element obtains (e.g., from the UDM / HSS) the subscription information of a second terminal; based on the subscription information of the second terminal, it determines whether the second terminal is allowed to create a subnet. For example, the AMF or control plane network element sends the identifier of the second terminal to the UDM / HSS, and the UDM / HSS searches for the subscription information corresponding to the identifier of the second terminal in its stored mapping relationship between terminal identifiers and subscription information, and sends the found subscription information to the AMF or control plane network element.
[0142] In another example, the AMF or control plane network element queries the UDM / HSS to determine whether the second terminal is permitted to create a subnet. For instance, the AMF or control plane network element sends a query message to the UDM / HSS, which includes the identifier of the second terminal. The UDM / HSS then searches its stored mapping between terminal identifiers and subscription information to find the subscription information corresponding to the second terminal's identifier and determines whether the subscription information includes an indication that subnet creation is permitted. If so, the UDM / HSS sends an indication that the second terminal is permitted to create a subnet to the AMF or control plane network element; otherwise, it sends an indication that the second terminal is not permitted to create a subnet to the AMF or control plane network element.
[0143] The identifier of the second terminal device sent by the AMF or control plane network element to the UDM / HSS can be the identifier of the second terminal included in the second request, or the identifier of another second terminal determined based on the identifier of the second terminal included in the second request. For example, the identifier of the second terminal included in the second request is SUCI, and the identifier of the other second terminal is SUPI or GPSI.
[0144] In one possible scenario, the second terminal receives the user's instruction; based on the user's instruction, the second terminal sends a second request to the control plane network element.
[0145] Step 302: The control plane network element sends the information of the first subnet to the second terminal; correspondingly, the second terminal receives the information of the first subnet.
[0146] Upon receiving the second request, the control plane network element can identify the first device serving the first subnet. The first device can be a user plane device, such as a UPF or router; or the first device can be an application server, which can be an application server for a mobile communication network (or an operator) or an application server for a non-mobile communication network.
[0147] For example, a control plane network element can determine a first device serving a first subnet based on first constraint information. For example, when the first constraint information includes the subnet's geographical location information, the control plane network element determines that a UPF (User Platform Provider) whose service area covers that geographical location provides subnet service, or determines that an application server whose network deployment location is at or near that geographical location provides subnet service. For example, when the first constraint information includes the subnet's IP address segment information, the control plane network element determines that a router provides subnet service, and the IP address of at least one interface of that router is within that IP address segment. For example, when the first constraint information includes that the subnet can provide a first application service, the control plane network element determines that an application server or specific resource that can provide the first application service provides subnet service, and that this specific resource connects to a user plane device, which is equivalent to determining a user plane device capable of providing service to that subnet. For example, if the first application service is represented by an APP ID, the application server providing subnet service can be determined based on that APP ID. For example, if the first application service is represented by a URL or URI, a UPF or application server providing subnet service can be determined based on that URL or URI.
[0148] For example, when the first constraint information is that the terminal using the service of the first subnet meets the first condition, the control plane network element determines a suitable UPF, or router, or application server to provide the subnet service.
[0149] If the second request includes information about the first condition, the control plane network element can also determine a condition identifier (also called a rule identifier or subnet rule identifier) that can uniquely identify the first condition based on the information about the first condition. For example, the information about the first condition is: terminals using the services of the first subnet are associated with the same GPSI, which can be the first GPSI, such as the GPSI of the second terminal, or other GPSIs. The condition identifier can include: the first GPSI (also called the associated GPSI) and / or a condition identifier other than the first GPSI that can uniquely identify the first condition, such as #001. Optionally, the control plane network element can also store the association relationship between the first GPSI and the condition identifier other than the first GPSI that can uniquely identify the first condition. Optionally, the control plane network element can also store the association relationship between the condition identifier and the information of the first device.
[0150] Optionally, after receiving the second request, the control plane network element can also determine the identifier of the first subnet. The control plane network element can determine the information (or APP ID, or URL, or URI) of the first device serving the first subnet as the identifier of the first subnet; or determine the condition identifier as the identifier of the first subnet; or generate a subnet identifier that uniquely identifies the first subnet. If the identifier of the first subnet does not include the information of the first device serving the first subnet, the control plane network element can also save the association between the identifier of the first subnet and the information of the first device. If the identifier of the first subnet does not include the condition identifier, the control plane network element can also save the association between the identifier of the first subnet and the condition identifier.
[0151] Based on the second request, the control plane network element determines the information of the first subnet and sends the information to the second terminal. The information of the first subnet informs the second terminal that the first subnet has been successfully created. Optionally, the control plane network element sends a response message to the second terminal for the second request. This response message indicates successful creation of the first subnet and includes the information of the first subnet. Optionally, the response message also includes the identifier of the second terminal, such as its SUPI, GPSI, or SUCI.
[0152] Step 303: The second terminal sends a third request to the first network element; correspondingly, the first network element receives the third request.
[0153] The third request is used to request credentials allowing access to the services of the first subnet. The third request includes information about the first subnet (i.e., the information obtained in step 302). The third request may not be specific to a particular terminal, or it may be specific to a particular terminal. Optionally, the third request may also include the identifier of the first terminal, such as its SUPI, GPSI, or SUCI. The number of first terminals in the third request can be one or more.
[0154] Optionally, the third request may include the identifier of the second terminal, such as the second terminal's SUPI, GPSI, or SUCI. The first network element can determine which terminal initiated the request based on the identifier of the second terminal.
[0155] The second terminal can send the third request to the first network element through the AMF. Optionally, after receiving the third request, the AMF determines whether the second terminal is allowed to create a subnet; if allowed, it can send the third request to the first network element; if not allowed, it can reject the third request. Alternatively, the AMF can skip this determination and directly forward the third request to the first network element. Optionally, after receiving the third request, the first network element determines whether the second terminal is allowed to create a subnet, thus eliminating the need for the AMF to determine this; if allowed, subsequent steps can be executed; if not allowed, the third request can be rejected. For example, if the second terminal's subscription information includes an indication of whether subnet creation is allowed, the subnet creation can be determined based on the subscription information. An example of the AMF or the first network element determining whether the second terminal is allowed to create a subnet can be found in step 301, and will not be elaborated further here.
[0156] Step 304: The first network element determines the first credential based on the third request.
[0157] For example, for each first terminal in the third request, the first network element signs the information of the first subnet and / or the identifier of the first terminal based on its own private key, and the first credential of the first terminal includes the signature. Optionally, the first credential also includes the information of the first subnet and / or the identifier of the first terminal. It is understood that if the third request includes multiple first terminals, and the first credential of each first terminal needs to be determined based on the identifier of the first terminal, then the first network element determines the credential corresponding to each first terminal separately for the multiple first terminals.
[0158] When the first network element determines the first credential corresponding to the first terminal, the identifier of the first terminal can be the identifier of the first terminal carried in the third request, or it can be a string that uniquely identifies the first terminal generated by the first network element or the control plane network element (e.g., generated based on the first terminal's SUPI, GPSI, or SUCI).
[0159] Step 305: The first terminal obtains the first credential from the first network element.
[0160] For example, the first network element sends the first credential to the second terminal, and the second terminal sends the first credential to the first terminal. For example, the second terminal sends the first credential to the first terminal via Bluetooth, access communication, or other means.
[0161] For example, the AMF pages the first terminal, triggering the terminal configuration update process, and obtains the first credential through the core network element.
[0162] Step 306: The first terminal sends a first request to the control plane network element. The first request is used by the first terminal to request the use of the services of the first subnet. The first request includes a first credential. Accordingly, the control plane network element receives the first request.
[0163] Step 307: If the signature verification in the first credential is successful using the public key of the first network element, the control plane network element establishes a communication connection between the first terminal and the first device.
[0164] Steps 306 and 307 can be referred to steps 201 and 202, and will not be described in detail here.
[0165] In this method, the second terminal requests the control plane network element to create the first subnet, eliminating the need for the operator's administrator to create the subnet, thus improving the flexibility and efficiency of subnet creation.
[0166] Referring to Figure 4, taking "the first device serving the first subnet as the user plane device" as an example, a flowchart of a communication method is introduced.
[0167] Step 400: The second terminal successfully accesses the mobile network after network authentication. Step 400 can be referred to as step 300, and will not be described in detail here.
[0168] Step 401: The second terminal sends a second request to the control plane network element, which is used to request the creation of a subnet; accordingly, the control plane network element receives the second request.
[0169] Optionally, the second request includes the identifier of the second terminal and the first constraint information. In this example, the first constraint information is: the geographical location information of the subnet, or the IP address information of the subnet, or the subnet's ability to provide a first application service or a first resource, wherein the first application service or the first resource is represented by a URL.
[0170] The second terminal can send a second request to the control plane network element through the AMF. If the AMF or the control plane network element determines that the second terminal is allowed to create a subnet, it will perform subsequent steps; otherwise, it will reject the second request.
[0171] Step 401 can be referred to step 301, and will not be described in detail here.
[0172] Step 402a: The control plane network element determines the user plane equipment serving the first subnet and the information of the first subnet.
[0173] For example, based on the second request, the control plane network element determines the user plane equipment serving the first subnet and the information of the first subnet.
[0174] In this example, the information for the first subnet includes one or more of the following: an identifier for the first subnet, or an identifier for a user plane device serving the first subnet. For example, a control plane element determines, based on the subnet's geographical location, which UPF (User Plane Provider) provides subnet services covering that geographical location. For example, a control plane element determines, based on the subnet's IP address segment information, that a router provides subnet services, wherein at least one interface of that router has an IP address within that IP address segment. For example, a control plane element determines, based on a URL, a user plane element connecting to that URL, and identifies that user plane element as a user plane device serving the first subnet.
[0175] If the information of the first subnet does not include the identifier of the user plane device serving the first subnet (or the information of the first application service), the control plane network element can also store the identifier of the first subnet and the identifier of the user plane device serving the first subnet, so that the subsequent control plane network element can find the user plane device serving the first subnet based on the information of the first subnet and the association relationship.
[0176] Step 402b: The control plane network element sends the information of the first subnet to the second terminal; correspondingly, the second terminal receives the information of the first subnet.
[0177] Steps 402a and 402b can be referred to step 302, and will not be described in detail here.
[0178] Step 403: The second terminal sends a third request to the first network element; correspondingly, the first network element receives the third request.
[0179] For example, the third request is used to request the determination of credentials that allow the use of services in the first subnet, or to request the determination of the identity of the first terminal in the first subnet, the identity including credentials that allow the first terminal to use services in the first subnet.
[0180] The third request includes the information of the first subnet obtained in step 402b and / or the identifier of the first terminal (e.g., the SUPI, GPSI, SUCI of the first terminal). The number of first terminals in the third request can be one or more.
[0181] Optionally, the third request may include the identifier of the second terminal, such as the SUPI, GPSI, or SUCI of the second terminal; the first network element may determine which terminal initiated the request based on the identifier of the second terminal.
[0182] The second terminal can send a third request to the first network element through the AMF. If the AMF or the first network element determines that the second terminal is allowed to create a subnet, it will execute the subsequent steps; otherwise, it will reject the third request.
[0183] Step 403 can be referred to step 303, and will not be described in detail here.
[0184] Step 404: The first network element determines the first credential of the first terminal or determines the identity identifier (user ID) of the first terminal in the first subnet.
[0185] The process of determining the first credential by the first network element can be referred to in step 304, and will not be described in detail here.
[0186] The following describes how the first network element determines the user ID of the first terminal in the first subnet:
[0187] As shown in Figure 5a, the identity of the first terminal in the first subnet includes two parts: A. a globally unique identifier of the first terminal, and B. a first credential that allows the first terminal to use the services of the first subnet. Optionally, the first credential can be located in the profile information.
[0188] A) The globally unique identifier of the first terminal includes, but is not limited to, one or more of the following: the SUPI, GPSI, SUCI of the first terminal, a string of unique identifiers of the first terminal generated by the first network element or control plane network element (e.g., generated based on the SUPI, GPSI or SUCI of the first terminal), etc.
[0189] B) The first credential includes: a signature of the globally unique identifier of the first terminal (i.e., A above) and / or information of the first subnet using the private key of the first network element; optionally, the first credential also includes: the globally unique identifier of the first terminal (i.e., A above) and / or information of the first subnet. When the information of the first subnet is the identifier of a user plane device, the information of the first subnet can be called the network element attribute information of the first subnet, and the first credential can be called the network element attribute credential. When the information of the first subnet is a subnet identifier generated by a control plane network element that uniquely identifies the first subnet, the information of the first subnet can be called the identifier attribute information of the first subnet, and the first credential can be called the subnet identifier attribute credential. If the signature is verified successfully based on the public key of the first network element, the first terminal with the user ID is allowed to use the services of the first subnet and access (or connect to) the network resources of the first subnet.
[0190] Optionally, the first network element stores the first credential of the first terminal or the identity identifier of the first terminal in the first subnet. If the globally unique identifier of the first terminal used to determine the first credential (i.e., the globally unique identifier of part A) is not a SUPI, but is, for example, the GPSI of the first terminal, or, for example, a string that uniquely identifies the first terminal generated by the first network element or control plane network element, the first network element may also store the association relationship between the first credential / identity identifier of the first terminal and the SUPI of the first terminal. Usually, the key stored in the SIM or UIM is associated with the SUPI. In this way, the key associated with the first credential / identity identifier of the first terminal can still be considered as the key stored in the SIM or UIM of the first terminal (the first terminal and the mobile network share this key).
[0191] Step 405: The first network element sends a response message for the third request to the second terminal; correspondingly, the second terminal receives the response message.
[0192] The response message is used to indicate that the identity of the first terminal in the first subnet has been determined, or that credentials have been determined to allow the use of the services of the first subnet.
[0193] Optionally, the response message includes: the user ID or first credential of the first terminal in the first subnet; further optionally, the response message also includes the identifier of the first terminal (e.g., the same as the identifier of the first terminal in the third request), such as SUPI or GPSI. If there are multiple first terminals, in this response message, the user ID / first credential of each first terminal in the first subnet corresponds one-to-one with the identifier of the first terminal. Optionally, after receiving the response message, the second terminal may send the user ID or first credential of the first terminal to the first terminal via Bluetooth, HFOR, or other means.
[0194] In another approach, a terminal configuration update process can be triggered via a paging terminal, informing the first terminal of the first credential or identity identifier. This will be described below:
[0195] Step 406: The first network element sends a message to the UDM; correspondingly, the UDM receives the message.
[0196] The message includes: the user ID of the first terminal in the first subnet, or the first credential of the first terminal; optionally, the message also includes the identifier of the first terminal (e.g., SUPI, GPSI, SUCI). If there are multiple first terminals, in this message, the user ID / credential of each first terminal in the first subnet corresponds one-to-one with the identifier of the first terminal.
[0197] Step 407: UDM saves the first terminal's identity identifier (user ID) or the first terminal's first credential in the first subnet.
[0198] Optionally, the UDM stores the association between the user ID of the first terminal in the first subnet and the SUPI of the first terminal; or, it stores the association between the first credential of the first terminal and the SUPI of the first terminal.
[0199] This information can be stored in the contract information on the first terminal.
[0200] Step 408: UDM sends a message to AMF serving the first terminal; correspondingly, AMF receives the message.
[0201] This message is used to indicate that the subscription information of the first terminal has changed. The message includes the identifier of the first terminal, such as the first terminal's SUPI.
[0202] For example, the AMF subscribes to the UDM for the following information: notifications of changes to subscription information of terminals accessing the AMF (including the first terminal). After determining that the subscription information of the first terminal has changed, the UDM sends a notification message to the AMF to notify the first terminal that its subscription information has changed. Optionally, the notification message includes the changed subscription information.
[0203] Step 409: Based on the identifier of the first terminal, the AMF pages the first terminal through the access network equipment serving the first terminal; after the first terminal responds to the paging, the AMF sends a notification message to the first terminal to instruct it to update the relevant information of the first terminal.
[0204] Step 410: The first terminal initiates a terminal configuration update process, connects to the UDM via AMF, and obtains the first terminal's identity identifier or first credential.
[0205] Step 411: The first terminal sends a first request to the control plane network element. The first request is used by the first terminal to request the use of the services of the first subnet; correspondingly, the control plane network element receives the first request.
[0206] The first request includes a first credential or the identity identifier of the first terminal in the first subnet; optionally, the first request may also include one or more of the following: the identifier of the first terminal, information of the first subnet, and time information of sending the first request (e.g., timestamp).
[0207] Optionally, the first request may also include: signing one or more of the above information using the key of the first terminal (a key stored in the SIM or UIM of the first terminal and shared with the mobile network); in order to distinguish it from the signature in the first credential, the signature of one or more of the above information using the key of the first terminal is referred to as signature A.
[0208] Other technical details of step 411 can be found in step 201, and will not be elaborated here.
[0209] Optionally, step 412: Control plane network element determination: The key pair signature A of the first terminal is verified.
[0210] If the first request includes signature A, then it is determined whether the signature A based on the key pair of the first terminal has been verified. If the signature A based on the key pair of the first terminal has been verified, it means that the first terminal is a legitimate terminal, and the subsequent steps are executed; if it has not been verified, it means that the first terminal is not a legitimate terminal, and the first request can be rejected.
[0211] The following is an example of verifying signature A:
[0212] Example 1: The control plane network element obtains the key of the first terminal, verifies the signature A based on the key of the first terminal, and determines whether the verification is successful.
[0213] The control plane network element can send the SUPI of the first terminal to the UDM. The UDM stores the SUPI and key of the first terminal (e.g., stored in the subscription information of the first terminal). The UDM retrieves the key of the first terminal based on the SUPI of the first terminal and sends it to the control plane network element. The first request may include the SUPI of the first terminal. Alternatively, after receiving the first request, the control plane network element sends a message to the first network element requesting to obtain the SUPI of the first terminal. The first network element stores the association relationship between the first terminal's first credential / identity identifier and the SUPI of the first terminal (refer to step 404). The first network element determines the SUPI of the first terminal based on this association relationship and sends it to the control plane network element.
[0214] Example 2: The control plane network element sends the key of the first terminal, the signature A to be verified, and information related to the signature A to other devices (such as AUSF, UDM, or the first network element). The other devices verify the signature A based on the key of the first terminal and send the verification result (i.e., verification passed or failed) to the control plane network element. The control plane network element can then determine whether the signature A has been verified based on the verification result from the other devices.
[0215] Example 3: The control plane network element sends the SUPI of the first terminal, the signature A to be verified, and information related to the signature A to the UDM. The UDM obtains the key of the first terminal based on the SUPI of the first terminal, verifies the signature A based on the key of the first terminal, and sends the verification result (i.e., verification passed or failed) to the control plane network element. Then the control plane network element can determine whether the signature A has been verified based on the verification results from other devices.
[0216] After step 411 or step 412, step 413 is executed: Control plane network element determination: The signature verification in the first credential is passed based on the public key of the first network element.
[0217] Step 413 can be referred to step 202, and will not be described in detail here.
[0218] After step 413, step 414 is executed: the control plane network element determines the access address information of the user plane equipment serving the first subnet.
[0219] Based on the information of the first subnet, the control plane network element determines the user plane equipment serving the first subnet; the control plane network element interacts with the user plane equipment to obtain the access address information of the user plane equipment, which is the access address serving the first subnet.
[0220] For example, if the information of the first subnet includes the identifier of the user plane device, then the user plane device identified by that identifier is the user plane device serving the first subnet. As another example, if the information of the first subnet includes the identifier of the first subnet, and the control plane network element stores the identifier of the first subnet and the identifier of the user plane device serving the first subnet (refer to step 402a), the control plane network element can determine the user plane device serving the first subnet based on the identifier of the first subnet and this association.
[0221] Step 415a: The control plane network element sends a response message for the first request to the access network device serving the first terminal; correspondingly, the access network device receives the response message.
[0222] The response message is used to indicate that the first terminal has successfully accessed the first subnet (another way to describe it: indicating that the first terminal is allowed to use the services of the first subnet). The response message includes the access address information of the user plane device serving the first subnet, or, in other messages, sends the access address information of the user plane device serving the first subnet to the access network device.
[0223] Step 415b: The access network device sends a response message for the first request to the first terminal; correspondingly, the first terminal receives the response message.
[0224] This response message is used to indicate that the first terminal has successfully accessed the first subnet (in other words, to indicate that the first terminal is allowed to use the services of the first subnet).
[0225] A communication connection is established between the access network equipment and the first terminal.
[0226] The remaining technical details of steps 414, 415a, and 415b can be found in the possible implementation of the communication connection between the control plane network element and the first device in step 202, and will not be elaborated here.
[0227] In subsequent communications, the first terminal can send data to the user plane network element through the access network equipment.
[0228] Referring to Figure 6, taking "the first device serving the first subnet as the application server" as an example, a flowchart of a communication method is introduced.
[0229] Step 600: The second terminal successfully accesses the mobile network after network authentication. Step 600 can be referred to as step 300, and will not be repeated here.
[0230] Step 601: The second terminal sends a second request to the control plane network element, which is used to request the creation of a subnet; correspondingly, the control plane network element receives the second request.
[0231] Optionally, the second request includes the identifier of the second terminal and first constraint information. In this example, the first constraint information is: information about the subnet's ability to provide the first application service, or geographical location information.
[0232] The second terminal can send a second request to the control plane network element through the AMF. If the AMF or the control plane network element determines that the second terminal is allowed to create a subnet, it will perform subsequent steps; otherwise, it will reject the second request.
[0233] Step 601 can be referred to step 301, and will not be described in detail here.
[0234] Step 602a: The control plane network element determines the application server serving the first subnet and the information of the first subnet.
[0235] For example, based on the second request, the control plane network element determines the application server serving the first subnet and the information of the first subnet.
[0236] In this example, the information for the first subnet includes one or more of the following: the identifier of the first subnet, or the access address (or identifier) of the application server serving the first subnet. For example, the control plane network element determines the application server capable of providing the first application service based on the information of the first application service (e.g., APP ID, URL, or URI), or determines that the application server whose network deployment location is at or near the geographical location provides the subnet service.
[0237] If the information of the first subnet does not include the access address (or identifier) of the application server serving the first subnet, the control plane network element can also save the association between the identifier of the first subnet and the access address (or identifier) of the application server serving the first subnet, so that the subsequent control plane network element can find the application server serving the first subnet based on the identifier of the first subnet and the association.
[0238] Step 602b: The control plane network element sends the information of the first subnet to the second terminal; correspondingly, the second terminal receives the information of the first subnet.
[0239] The information for the first subnet includes the identifier of the first subnet and / or the access address of the application server.
[0240] Steps 602a and 602b can be referred to step 302, and will not be described in detail here.
[0241] Step 603: The second terminal sends a third request to the first network element; correspondingly, the first network element receives the third request.
[0242] For example, the third request is used to request the determination of credentials that allow the use of services in the first subnet, or to request the determination of the identity of the first terminal in the first subnet, the identity including credentials that allow the first terminal to use services in the first subnet.
[0243] The third request includes the information of the first subnet obtained in step 602b and / or the identifier of the first terminal (e.g., the SUPI, GPSI, SUCI of the first terminal). The number of first terminals in the third request can be one or more.
[0244] Optionally, the third request may include the identifier of the second terminal, such as the SUPI, GPSI, or SUCI of the second terminal; the first network element may determine which terminal initiated the request based on the identifier of the second terminal.
[0245] The second terminal can send a third request to the first network element through the AMF. If the AMF or the first network element determines that the second terminal is allowed to create a subnet, it will execute the subsequent steps; otherwise, it will reject the third request.
[0246] Step 603 can be referred to step 303, and will not be described in detail here.
[0247] Step 604: The first network element determines the first credential of the first terminal or determines the identity identifier (user ID) of the first terminal in the first subnet.
[0248] The process of determining the first credential by the first network element can be referred to in step 304, and will not be described in detail here.
[0249] The following describes how the first network element determines the user ID of the first terminal in the first subnet:
[0250] As shown in Figure 5b, the identity identifier of the first terminal in the first subnet includes: 1) a globally unique identifier of the first terminal; 2) a first credential allowing the first terminal to use the services of the first subnet; optionally, it also includes 3) a public key attribute credential; optionally, the first credential and the public key attribute credential can be located in the profile information.
[0251] 1) The globally unique identifier of the first terminal includes, but is not limited to, one or more of the following: the SUPI, GPSI, SUCI of the first terminal, a string of unique identifiers of the first terminal generated by the first network element or control plane network element (e.g., generated based on the SUPI, GPSI or SUCI of the first terminal), etc.
[0252] 2) The first credential includes: a signature of the globally unique identifier of the first terminal (i.e., 1 above) and / or the information of the first subnet using the private key of the first network element; optionally, the first credential also includes: the globally unique identifier of the first terminal (i.e., 1 above) and / or the information of the first subnet. When the information of the first subnet is the access address (or identifier) of an application server, the information of the first subnet can be called the server attribute information of the first subnet, and the first credential can be called the server attribute credential. When the information of the first subnet is a subnet identifier generated by a control plane network element that uniquely identifies the first subnet, the information of the first subnet can be called the identifier attribute information of the first subnet, and the first credential can be called the subnet identifier attribute credential. When the information of the first subnet is the information of a first application service (e.g., APP ID, URL, or URI), the information of the first subnet can be called the service attribute information, and the first credential can be called the service attribute credential. If the signature is verified successfully based on the public key of the first network element, the first terminal with the user ID is allowed to use the services of the first subnet and access (or access) the network resources of the first subnet.
[0253] 3) The public key attribute certificate includes: a signature of the public key of the first terminal using the private key of the first network element; or, a signature of the globally unique identifier of the first terminal (i.e., 1 above) and the public key of the first terminal using the private key of the first network element. To distinguish it from other signatures, the signature included in the public key attribute certificate is referred to as signature B here. Optionally, the public key attribute certificate may also include: the globally unique identifier of the first terminal (i.e., 1 above) and / or the public key of the first terminal.
[0254] If the signature B is verified using the public key of the first network element, it can be determined that the public key of the first terminal can be used to verify the identity of the terminal user terminal identified by the globally unique identifier. In other words, the signature made by the first terminal using its private key can be verified for legitimacy using the public key attribute certificate of the first terminal.
[0255] Optionally, the first network element stores the first credential of the first terminal or the identity identifier of the first terminal in the first subnet.
[0256] Step 605: The first network element sends a response message for the third request to the second terminal; correspondingly, the second terminal receives the response message.
[0257] The response message is used to indicate that the identity of the first terminal in the first subnet has been determined, or that a first credential has been determined that allows the use of the services of the first subnet.
[0258] Optionally, the response message includes: the user ID or first credential of the first terminal in the first subnet; further optionally, the response message also includes the identifier of the first terminal (e.g., the same as the identifier of the first terminal in the third request), such as SUPI, GPSI, SUCI. If there are multiple first terminals, in the response message, the user ID / first credential of each first terminal in the first subnet corresponds one-to-one with the identifier of the first terminal.
[0259] Alternatively, as shown in Figure 4, a terminal configuration update process can be triggered via a paging terminal, informing the first terminal of the first credential or identity identifier. If the first terminal has a SIM or UIM installed, the first credential or identity identifier can be provided to the first terminal via paging or through a second terminal; if the first terminal does not have a SIM or UIM installed, it can be provided to the first terminal through a second terminal.
[0260] Step 606: The second terminal sends the first terminal's first credential or identity identifier to the first terminal.
[0261] For example, the second terminal can send the first terminal's first credential or identity identifier to the first terminal via near-field communication methods such as Bluetooth or local wireless LAN direct connection.
[0262] Step 607: The first terminal sends a first request to the control plane network element. The first request is used by the first terminal to request the use of the services of the first subnet; correspondingly, the control plane network element receives the first request.
[0263] The first request includes a first credential or the identity identifier of the first terminal in the first subnet; optionally, the first request may also include one or more of the following: the identifier of the first terminal, information of the first subnet, time information of sending the first request (e.g., timestamp), and the public key attribute credential of the first terminal.
[0264] Optionally, the first request may also include: signing one or more of the above information using the private key of the first terminal; in order to distinguish it from other signatures, the signature of one or more of the above information using the private key of the first terminal is referred to here as signature C.
[0265] Other technical details of step 607 can be found in step 201, and will not be elaborated here.
[0266] Optionally, in step 608a: if the first request includes the public key attribute credential of the first terminal, the control plane network element determines that the signature B in the public key attribute credential of the first terminal has been verified based on the public key of the first network element.
[0267] If the first request includes signature B, then it is determined whether signature B has been verified using the public key of the first network element. If signature B has been verified using the public key of the first network element, it can be determined that the public key of the first terminal can be used to verify the identity and legitimacy of the terminal user terminal identified by the globally unique identifier. In other words, the signature made by the first terminal using its private key can be verified for legitimacy using the public key attribute certificate of the first terminal.
[0268] In one possible implementation, the public key attribute certificate of the first terminal is included in the first certificate. The first certificate can then only include a signature of the information of the first subnet using the private key of the first network element, without needing to include the identifier of the first terminal. Only the first terminal holding the private key corresponding to the public key is authorized to access the first subnet. This eliminates the need for the operator to pre-add the first subnet information to the first terminal's subscription data, improving the flexibility and efficiency of terminal access to the first subnet.
[0269] The following is an example of verifying signature B:
[0270] Example 1: The control plane network element verifies the signature B in the public key attribute certificate of the first terminal based on the public key of the first network element.
[0271] Example 2: The control plane network element sends the signature B from the public key attribute certificate of the first terminal to other devices. These other devices verify the signature B based on the public key of the first network element and send the verification result (i.e., successful or unsuccessful) to the control plane network element. The control plane network element can determine whether the signature B has been successfully verified based on the verification result from the other devices. These other devices can be the first network element or any device with signature verification functionality.
[0272] Optionally, step 608b: Control plane network element determination: The signature C based on the public key of the first terminal is verified.
[0273] If the first request includes a signature C, then it is determined whether the signature C is verified using the first terminal's public key (the public key in the public key attribute certificate). If the signature C is verified using the first terminal's public key, it indicates that the first terminal is a legitimate terminal, and subsequent steps are executed; if the verification fails, it indicates that the first terminal is not a legitimate terminal, and the first request can be rejected.
[0274] The following is an example of verifying signature C:
[0275] Example 1: The control plane network element verifies the signature C based on the public key of the first terminal to determine whether the verification is successful.
[0276] Example 2: The control plane network element sends the public key and signature C of the first terminal to other devices. The other devices verify the signature C based on the public key of the first terminal and send the verification result (i.e., verification passed or failed) to the control plane network element. The control plane network element can determine whether the signature C has been successfully verified based on the verification result from the other devices. The other devices can be the first network element or any device with signature verification function.
[0277] After step 607 or step 608a or 608b, step 609 is executed: Control plane network element determination: The signature verification in the first credential is passed based on the public key of the first network element.
[0278] Step 609 can be referred to step 202, and will not be described in detail here.
[0279] After step 602a, step 610 is executed: the control plane network element and the application server interact to determine the token for the terminal accessing the application server in the first subnet.
[0280] In one example, the token is a string generated by the application server.
[0281] In another example, after determining the first credential (server attribute credential), the first network element sends the first credential to the control plane network element; the control plane network element can send the first credential to the application server; the control plane network element and the application server interact to determine the first credential as a token for accessing the application service.
[0282] The control plane element can determine the token after receiving the first request.
[0283] If the control plane element has already determined the token before receiving the first request, it can also store the association between the application server's access address (or identifier) and the token. Optionally, this association can also include the identifier of the first subnet. Then step 610 can be understood as: the control plane element searches for the already determined token for accessing the first application server. The control plane element determines the token for accessing the first application server based on the information of the first subnet.
[0284] For example, the information in the first subnet includes the access address (or identifier) of the application server. The control plane network element stores the association between the access address (or identifier) of the application server and the token. The control plane network element can determine the token based on this association.
[0285] For example, the information of the first subnet includes the identifier of the first subnet. The control plane network element stores the association between the identifier of the first subnet and the access address (or identifier) of the application server (refer to step 602a), and also stores the association between the access address (or identifier) of the application server and the token. The control plane network element can determine the token based on these associations.
[0286] Step 611: The control plane network element sends a response message for the first request to the first terminal; correspondingly, the first terminal receives the response message.
[0287] The response message is used to indicate that the first terminal has successfully accessed the first subnet. The response message includes the token, or the token is sent to the first terminal in other messages.
[0288] The remaining technical details of steps 610 and 611 can be found in step 202, and will not be elaborated here.
[0289] In subsequent communications, the first terminal uses the token to access the application server.
[0290] Referring to Figure 7, taking "the second terminal requests the creation of a subnet that meets the first condition" as an example, a flowchart of a communication method is introduced.
[0291] Step 700: The second terminal successfully accesses the mobile network after network authentication. Step 700 can be referred to as step 300, and will not be repeated here.
[0292] Step 701: The second terminal sends a second request to the control plane network element, which is used to request the creation of a subnet; accordingly, the control plane network element receives the second request.
[0293] The second request includes the identifier of the second terminal and first constraint information. In this example, the first constraint information is: information about terminals using the first subnet satisfying a first condition. The first condition may be: terminals using the services of the first subnet are associated with the same GPSI; the same GPSI may be the GPSI of the terminal requesting the creation of the subnet (i.e., the second terminal) or other GPSIs.
[0294] Step 701 can be referred to step 301, and will not be described in detail here.
[0295] Step 702a: The control plane network element determines the first device serving the first subnet and the information of the first subnet.
[0296] For example, based on a second request, a control plane network element determines a first device serving the first subnet and information about the first subnet. The first device may be a user plane device or an application server.
[0297] In this example, the information for the first subnet includes a condition identifier that uniquely identifies the first condition.
[0298] The control plane network element can also determine a condition identifier (also called a rule identifier or subnet rule identifier) that can uniquely identify the first condition based on the information of the first condition. The condition identifier can include: condition identifier a and / or second condition identifier b: where condition identifier a is a first GPSI (also called an associated GPSI), and second condition identifier b is a condition identifier other than the first GPSI that can uniquely identify the first condition, for example, #001. Optionally, the control plane network element can also store the association relationship between the first GPSI and the condition identifier other than the first GPSI that can uniquely identify the first condition. Optionally, the control plane network element can also store the association relationship between the condition identifier and the information of the first device.
[0299] The control plane network element can also store the association between the condition identifier and the information of the first device, so that the subsequent control plane network element can find the first device serving the first subnet based on the condition identifier and the association.
[0300] Step 702b: The control plane network element sends the information of the first subnet to the second terminal; correspondingly, the second terminal receives the information of the first subnet.
[0301] The information for the first subnet includes condition identifiers.
[0302] Steps 702a and 702b can be referred to step 302, and will not be described in detail here.
[0303] Step 703: The second terminal sends a third request to the first network element; correspondingly, the first network element receives the third request.
[0304] For example, the third request is used to request the determination of credentials that allow the use of services in the first subnet, or to request the determination of the identity of the first terminal in the first subnet, the identity including credentials that allow the first terminal to use services in the first subnet.
[0305] The third request includes the information of the first subnet obtained in step 702b and / or the identifier of the first terminal (e.g., the SUPI and GPSI of the first terminal). The number of first terminals in the third request can be one or more.
[0306] Optionally, the third request may include the identifier of the second terminal, such as the second terminal's SUPI, GPSI, or SUCI. The first network element can determine which terminal initiated the request based on the identifier of the second terminal.
[0307] The second terminal can send a third request to the first network element through the AMF. If the AMF or the first network element determines that the second terminal is allowed to create a subnet, it will execute the subsequent steps; otherwise, it will reject the third request.
[0308] The remaining technical details of step 703 can be found in step 303, and will not be elaborated here.
[0309] Step 704: The first network element determines the first credential of the first terminal or determines the identity identifier (user ID) of the first terminal in the first subnet.
[0310] The process of determining the first credential by the first network element can be referred to in step 304, and will not be described in detail here.
[0311] The following describes how the first network element determines the user ID of the first terminal in the first subnet:
[0312] As shown in Figure 5c, the identity identifier of the first terminal in the first subnet includes: 1) a globally unique identifier of the first terminal; 2) a first credential allowing the first terminal to use the services of the first subnet; optionally, it also includes 3) a credential with public key attributes; optionally, the first credential and the credential with public key attributes can be located in the profile information.
[0313] 1) The globally unique identifier of the first terminal includes, but is not limited to, one or more of the following: the SUPI, GPSI, SUCI of the first terminal, a string of unique identifiers of the first terminal generated by the first network element or control plane network element (e.g., generated based on the SUPI, GPSI or SUCI of the first terminal), etc.
[0314] 2) The first credential includes: a signature of the global unique identifier of the first terminal (i.e., 1 above) and / or the information of the first subnet using the private key of the first network element; optionally, the first credential may also include: the global unique identifier of the first terminal (i.e., 1 above) and / or the information of the first subnet.
[0315] The information of the first subnet includes: condition identifier a and / or condition identifier b, wherein condition identifier a is the first GPSI (also known as the associated GPSI), and the second condition identifier b is a condition identifier other than the first GPSI that can uniquely identify the first condition, for example, #001.
[0316] If the information of the first subnet includes condition identifier a and condition identifier b, then condition identifier a and condition identifier b can be regarded as a whole to determine the credential.
[0317] If the information of the first subnet includes condition identifier a and condition identifier b, corresponding credentials can be determined for condition identifier a and condition identifier b respectively. For example, the first credential includes credential a and credential b; credential a includes: a signature of the globally unique identifier of the first terminal (i.e., 1 above) and / or condition identifier a using the private key of the first network element; optionally, the first credential also includes: the globally unique identifier of the first terminal (i.e., 1 above) and / or condition identifier a; credential b includes: a signature of the globally unique identifier of the first terminal (i.e., 1 above) and / or condition identifier b using the private key of the first network element; optionally, the first credential also includes: the globally unique identifier of the first terminal (i.e., 1 above) and / or condition identifier b. The signatures in credential a and credential b are verified separately. If both are verified successfully, the signature verification in the first credential is successful.
[0318] When the information in the first subnet is condition identifier 'a', the information in the first subnet can be called associated GPSI attribute information, and the first credential can be called associated GPSI attribute credential. When the information in the first subnet is condition identifier 'b', the information in the first subnet can be called condition identifier attribute information, and the first credential can be called condition (rule) identifier attribute credential. If the signature verification of the first credential based on the public key of the first network element is successful, it can be confirmed that the first terminal with the identity identifier (user ID) is allowed to use the services of the first subnet and access (or connect to) the network resources of the first subnet.
[0319] 3) The public key attribute certificate includes: a signature of the public key of the first terminal using the private key of the first network element, or a signature of the globally unique identifier of the first terminal (i.e., 1 above) and the public key of the first terminal using the private key of the first network element. To distinguish it from other signatures, the signature included in the public key attribute certificate is referred to as signature B here. Optionally, the public key attribute certificate may also include: the globally unique identifier of the first terminal (i.e., 1 above) and / or the public key of the first terminal.
[0320] If the signature B is verified using the public key of the first network element, it can be determined that the public key of the first terminal can be used to verify the identity of the terminal user terminal identified by the globally unique identifier. In other words, the signature made by the first terminal using its private key can be verified for legitimacy using the public key attribute certificate of the first terminal.
[0321] Optionally, the first network element stores the first credential of the first terminal or the identity identifier of the first terminal in the first subnet.
[0322] Step 705: The first network element sends a response message for the third request to the second terminal; correspondingly, the second terminal receives the response message.
[0323] The response message is used to indicate that the identity of the first terminal in the first subnet has been determined, or that a credential (first credential) has been determined that allows the use of the services of the first subnet.
[0324] Optionally, the response message includes: the user ID or first credential of the first terminal in the first subnet; further optionally, the response message also includes the identifier of the first terminal (e.g., the same as the identifier of the first terminal in the third request), such as SUPI, GPSI, SUCI. If there are multiple first terminals, in the response message, the user ID / first credential of each first terminal in the first subnet corresponds one-to-one with the identifier of the first terminal.
[0325] Alternatively, as shown in Figure 4, a terminal configuration update process can be triggered via a paging terminal, informing the first terminal of the first credential or identity identifier. If the first terminal has a SIM or UIM installed, the first credential or identity identifier can be provided to the first terminal via paging or through a second terminal; if the first terminal does not have a SIM or UIM installed, it can be provided to the first terminal through a second terminal.
[0326] Step 706: The second terminal sends the first terminal's first credential or identity identifier to the first terminal.
[0327] For example, the second terminal can send the first terminal's first credential or identity identifier to the first terminal via near-field communication methods such as Bluetooth or local wireless LAN direct connection.
[0328] Step 707: The first terminal sends a first request to the control plane network element. The first request is used by the first terminal to request the use of the services of the first subnet; correspondingly, the control plane network element receives the first request.
[0329] The first request includes: a first credential or the identity identifier of the first terminal in the first subnet; optionally, the first request may also include one or more of the following: the identifier of the first terminal, information of the first subnet (condition identifier), and time information of sending the first request (e.g., timestamp).
[0330] Optionally, the first request may also include: signing one or more of the above information using the key of the first terminal (a key stored in the SIM or UIM of the first terminal and shared with the mobile network), in the same principle as signature A in step 411. The process of verifying the signature can be referred to step 412, and will not be described in detail here.
[0331] Alternatively, the first request may also include: a public key attribute credential of the first terminal, and a signature of one or more of the above information using the private key of the first terminal; the principle is the same as that of signature C in step 607. The specific verification process can be found in steps 608a and 608b, and will not be detailed here.
[0332] Execution step 708: Control plane network element determination: The signature verification in the first credential is passed based on the public key of the first network element.
[0333] Step 708 can be referred to step 202, and will not be described in detail here.
[0334] Step 709: The control plane network element sends a response message for the first request to the first terminal; correspondingly, the first terminal receives the response message.
[0335] This response message indicates that the first terminal has successfully accessed the first subnet.
[0336] Optionally, if the first device serving the first subnet is a user plane device, the response message includes the access address information of the user plane device serving the first subnet; alternatively, the access address information of the user plane device serving the first subnet is sent to the first terminal in another message. The process of determining the access address can be found in step 414, and will not be detailed here.
[0337] Optionally, if the first device serving the first subnet is an application server, the response message includes a token for accessing the application server, or the token is sent to the first terminal in another message. The process of determining the token can be referred to step 610, and will not be detailed here.
[0338] Optionally, step 710: The control plane network element acquires other first terminals.
[0339] If the first network element or UDM stores the GPSI information associated with the terminal's identity identifier, the control plane network element can send a message to the first network element or UDM to query the first terminal associated with the second terminal's GSPI (including the first terminal in step 709, and may also include other first terminals).
[0340] Optionally, in step 711, the control plane network element can send a message to other first terminals to inform them that the first terminal in step 709 has accessed the first subnet, or to request other first terminals to access the first subnet.
[0341] Alternatively, the access network device may page other first terminals, requesting them to access the first subnet. When other first terminals access the first subnet, the credentials of the other second terminals for using the services of the first subnet are verified. If the verification is successful, access to the first subnet is permitted.
[0342] In one possible scenario, the more terminals connected to a home subnet, the better the family's users can control these terminals, and the easier it is for multiple terminals to collaborate and complete family tasks.
[0343] It is understood that, in order to achieve the functions in the above embodiments, the first terminal, the second terminal, the control plane network element, and the first network element include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0344] Figures 8 and 9 are schematic diagrams of possible communication devices provided in embodiments of this application. These communication devices can be used to implement the functions of the first terminal, second terminal, control plane network element, and first network element in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.
[0345] As shown in Figure 8, the communication device 800 may include modules or units for implementing the methods described in the embodiments above. In one possible design, the communication device 800 includes a processing unit 810 and a transceiver unit 820. Optionally, the communication device 800 may further include a storage unit 830 for storing device program code and / or data.
[0346] The communication device 800 can be a device of the control plane network element in the above embodiments, such as a control plane network element, or a communication module in the control plane network element, or a circuit, chip, or chip system in the control plane network element responsible for communication functions.
[0347] The transceiver unit 820 can perform the receiving and transmitting actions performed by the control plane network element in the above method embodiment. The processing unit 810 can perform other actions besides the transmitting and receiving actions performed by the control plane network element in the above method embodiment.
[0348] For example, the transceiver unit 820 is configured to: receive a first request from a first terminal, the first request being for the first terminal to request the use of services of a first subnet, the first request including a first credential, the first credential being a credential allowing the first terminal to use services of the first subnet; the first credential including a signature of first information using the private key of a first network element, the first information including information of the first subnet; the processing unit 810 is configured to: establish a communication connection between the first terminal and a first device serving the first subnet if the signature is verified successfully using the public key of the first network element.
[0349] In one possible implementation, the first information may also include the identifier of the first terminal.
[0350] In one possible implementation, the first credential may further include: the identifier of the first terminal and / or information about the first subnet.
[0351] In one possible implementation, the information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a condition identifier; wherein the condition identifier is used to identify a first condition satisfied by a terminal using the services of the first subnet.
[0352] In one possible implementation, the information of the first device includes: the identifier of the user plane device, or the access address or identifier of the application server.
[0353] In one possible implementation, the transceiver unit 820 is further configured to: send second information to an access network device serving the first terminal, the second information being used to establish a communication connection between the access network device serving the first terminal and the first device; or, send third information to the first terminal, the third information being used to establish a communication connection between the first terminal and the first device.
[0354] In one possible implementation, the first device is a user plane device, the second information is the access address of the user plane device; the first device is an application server, and the third information is a token used to access the application server.
[0355] In one possible implementation, the token includes: the first credential.
[0356] In one possible implementation, the transceiver unit 820 is further configured to: receive a second request, the second request being for requesting the creation of a subnet; and send information about the first subnet.
[0357] In one possible implementation, the second request includes information on a first condition satisfied by the terminal using the services of the first subnet.
[0358] In one possible implementation, the information for the first condition is: terminals using the services of the first subnet are associated with the same General Public Subscription Identifier (GPSI).
[0359] The communication device 800 can be a device of the first terminal in the above embodiments, such as the first terminal, or the communication module in the first terminal, or the circuit, chip, or chip system in the first terminal responsible for communication functions.
[0360] The transceiver unit 820 can perform the receiving and sending actions performed by the first terminal in the above method embodiment. The processing unit 810 can perform other actions besides the sending and receiving actions performed by the first terminal in the above method embodiment.
[0361] For example, the transceiver unit 820 is configured to: send a first request to a control plane network element, the first request being used by a first terminal to request the use of services of a first subnet, the first request including a first credential, the first credential being a credential allowing the first terminal to use services of the first subnet; the first credential including a signature of first information using the private key of the first network element, the first information including information of the first subnet;
[0362] The processing unit 810 is configured to: establish a communication connection between the first terminal and the first device serving the first subnet if the signature verification using the public key of the first network element is successful.
[0363] In one possible implementation, the first information may also include the identifier of the first terminal.
[0364] In one possible implementation, the first credential may further include: the identifier of the first terminal and / or information about the first subnet.
[0365] In one possible implementation, the information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a condition identifier; wherein the condition identifier is used to identify a first condition satisfied by a terminal using the services of the first subnet.
[0366] In one possible implementation, the information of the first device includes: the identifier of the user plane device, or the access address or identifier of the application server.
[0367] In one possible implementation, the transceiver unit 820 is configured to: receive third information, the third information being used to establish a communication connection between the first terminal and the first device; and the processing unit 810 is configured to: establish a communication connection between the first terminal and the first device based on the third information.
[0368] In one possible implementation, the first device is an application server, and the third information is a token for accessing the application server.
[0369] The communication device 800 can be a device of the second terminal in the above embodiments, such as the second terminal, or the communication module in the second terminal, or the circuit, chip, or chip system in the second terminal responsible for communication functions.
[0370] The transceiver unit 820 can perform the receiving and sending actions performed by the second terminal in the above method embodiments. The processing unit 810 can perform other actions performed by the second terminal in the above method embodiments besides the sending and receiving actions.
[0371] For example, the transceiver unit 820 is configured to: send a second request to a control plane network element, the second request being used to request the creation of a subnet; receive information about the first subnet from the control plane network element; send a third request to a first network element, the third request being used to request the acquisition of a first credential, the first credential being a credential allowing a first terminal to use the services of the first subnet; the third request including information about the first subnet; the first credential including a signature of the first information using the private key of the first network element, the first information including information about the first subnet.
[0372] In one possible implementation, the third request may also include the identifier of the first terminal; the first information may also include the identifier of the first terminal.
[0373] In one possible implementation, the first credential may further include: the identifier of the first terminal and / or information about the first subnet.
[0374] In one possible implementation, the information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a condition identifier; wherein the condition identifier is used to identify a first condition satisfied by a terminal using the services of the first subnet.
[0375] In one possible implementation, the information of the first device includes: the identifier of the user plane device, or the access address or identifier of the application server.
[0376] In one possible implementation, the transceiver unit 820 is further configured to: receive the first credential; and send the first credential to the first terminal.
[0377] For a more detailed description of the above-mentioned processing unit 810 and transceiver unit 820, please refer directly to Figures 2 to 4. The relevant descriptions in the method embodiments shown in Figures 6 and 7 are directly obtained and will not be repeated here.
[0378] It is understood that the division of units in the above-described device is merely a logical functional division. One function can correspond to one functional unit, or two or more functions can be integrated into one functional unit. In actual implementation, all or some units can be integrated onto a single physical entity, or distributed across different physical entities. Furthermore, the aforementioned functional units can be implemented in hardware, software, or a combination of both. Whether a function is executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for specific applications, but such implementations should not be considered beyond the scope of this application.
[0379] In one example, the functional unit in any of the above devices may be one or more integrated circuits configured to implement the above methods, such as: one or more application-specific integrated circuits (ASICs), or one or more central processing units (CPUs), one or more microcontroller units (MCUs), one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.
[0380] In one example, storage unit 830 may include random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, and / or registers, etc. Processing unit 810 can be implemented by a processor, and transceiver unit 820 can be implemented by a transceiver.
[0381] As shown in Figure 9, the communication device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It is understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the communication device 900 may also include a memory 930 for storing instructions executed by the processor 910, or storing input data required for the processor 910 to execute instructions, or storing data generated after the processor 910 executes instructions. Sometimes, the interface circuit 920 can also be understood as part of the processor 910, in which case the communication device 900 includes the processor 910.
[0382] When the communication device 900 is used to implement the above-mentioned method of the first terminal, the second terminal, the control plane network element and the first network element, the processor 910 is used to implement the function of the above-mentioned processing unit 810, the interface circuit 920 is used to implement the function of the above-mentioned transceiver unit 820, and the memory 930 is used to implement the function of the above-mentioned storage unit 830.
[0383] When the aforementioned communication device is a chip applied to a terminal device, the terminal device chip implements the functions of the terminal device in the above method embodiments. The terminal device chip receives information from a network device, which can be understood as the information being first received by other modules (such as an RF module or antenna) in the terminal device, and then sent to the terminal device chip by these modules. The terminal device chip sends information to a network device, which can be understood as the information being first sent to other modules (such as an RF module or antenna) in the terminal device, and then sent to the network device by these modules.
[0384] When the aforementioned communication device is a chip applied to a network device, the network device chip implements the functions of the network device in the above method embodiments. The network device chip receives information from the terminal device, which can be understood as the information being first received by other modules (such as radio frequency modules or antennas) in the network device, and then sent to the network device chip by these modules. The network device chip sends information to the terminal device, which can be understood as the information being sent down to other modules (such as radio frequency modules or antennas) in the network device, and then sent to the terminal device by these modules. Here, the network device module can be the baseband chip of the network device, or a DU (Digital Unit) or other modules. The DU here can be a DU under the Open Radio Access Network (O-RAN) architecture.
[0385] In this application, entity A sends information to entity B, either directly or indirectly through other entities. Similarly, entity B receives information from entity A, either directly or indirectly through other entities. Entities A and B can be network devices or terminal devices, or modules within network devices or terminal devices. The sending and receiving of information can be between network devices and terminal devices, between two network devices (e.g., CU and DU), or between different modules within a single device (e.g., a terminal device chip and other modules within the terminal device, or a network device chip and other modules within the network device).
[0386] It is understood that the processor in the embodiments of this application may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.
[0387] This application also provides a computer-readable storage medium storing a computer program that, when executed by a computer, enables the computer to perform the aforementioned communication method. Alternatively, the computer program includes instructions for implementing the aforementioned communication.
[0388] This application also provides a computer program product, including: computer program code, which, when run on a computer, enables the computer to execute the communication method provided above.
[0389] This application also provides a communication system, which includes at least two of the following: a first terminal, a second terminal, a control plane network element, and a first network element, all of which perform the above-described communication method.
[0390] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, compact disc read-only memory (CD-ROM), or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a base station or terminal. Of course, the processor and storage medium can also exist as discrete components in the base station or terminal.
[0391] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a first control plane network element, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both types of storage media.
Claims
1. A communication method characterized by comprising: Comprising: receiving a first request from a first terminal, the first request being used for the first terminal to request to use a service of a first subnet, the first request comprising a first credential, the first credential being a credential allowing the first terminal to use the service of the first subnet, the first credential comprising a signature of first information using a private key of a first network element, the first information comprising information of the first subnet; establishing a communication connection between the first terminal and a first device serving the first subnet in a case that the signature is verified using a public key of the first network element.
2. The method of claim 1, wherein, The first information further comprises an identifier of the first terminal.
3. The method of claim 1 or 2, wherein, The first credential further comprises: the identifier of the first terminal and / or the information of the first subnet.
4. The method according to any one of claims 1 to 3, characterized in that, The information of the first subnet comprises one or more of: an identifier of the first subnet, information of the first device, or a conditional identifier; wherein the conditional identifier is used to identify a first condition met by a terminal using the service of the first subnet.
5. The method of claim 4, wherein, The information of the first device comprises: an identifier of a user plane device, or an access address or an identifier of an application server.
6. The method according to any one of claims 1 to 5, wherein, The establishing the communication connection between the first terminal and the first device serving the first subnet comprises: sending second information to an access network device serving the first terminal, the second information being used for establishing a communication connection between the access network device serving the first terminal and the first device; or, sending third information to the first terminal, the third information being used for establishing a communication connection between the first terminal and the first device.
7. The method of claim 6, wherein, The first device is a user plane device, and the second information is an access address of the user plane device. The first device is an application server, and the third information is a token used for accessing the application server.
8. The method of claim 7, wherein, The token comprises the first credential.
9. The method according to any one of claims 1 to 8, wherein, Further comprising: receiving a second request, the second request being used for requesting to create a subnet; sending the information of the first subnet.
10. The method of claim 9, wherein, The second request comprises information of a first condition met by a terminal using the service of the first subnet.
11. The method of claim 10, wherein, The information of the first condition is that the terminal using the service of the first subnet is associated with a same general public subscription identifier GPSI.
12. A communication system, characterized by Comprising: a first network element and a control plane network element performing the method according to any one of claims 1-11, the first network element being used to determine the first credential.
13. The system of claim 12, wherein, The first network element is further used to: receive a third request, the third request being used for requesting to obtain the first credential, the third request comprising the information of the first subnet; and send the first credential.
14. The system of claim 13, wherein, The third request further comprises an identifier of a first terminal.
15. The system of claim 13 or 14, wherein, The first network element is specifically used to: receive the third request from a second terminal; in a case that the second terminal allows to create a subnet, determine or send the first credential.
16. The system of any of claims 12-15, wherein, The control plane network element trusts the first network element.
17. A method of communication, comprising: Comprising: sending a first request, the first request being used for a first terminal to request a service using a first subnet, the first request including a first credential, the first credential being a credential allowing the first terminal to use the service of the first subnet, the first credential including a signature of first information using a private key of a first network element, the first information including information of the first subnet; in a case where the signature is verified using a public key of the first network element, establishing a communication connection between the first terminal and a first device serving the first subnet.
18. The method of claim 17, wherein, The first information further includes an identifier of the first terminal.
19. The method of claim 17 or 18, wherein, The first credential further includes the identifier of the first terminal and / or the information of the first subnet.
20. The method of any one of claims 17-19, wherein, The information of the first subnet includes one or more of the following: an identifier of the first subnet, information of the first device, or a conditional identifier, wherein the conditional identifier is used to identify a first condition met by a terminal using the service of the first subnet.
21. The method of claim 20, wherein, The information of the first device includes an identifier of a user plane device, or an access address or identifier of an application server.
22. The method of any one of claims 17-21, wherein, The establishing the communication connection between the first terminal and the first device serving the first subnet includes: receiving third information, the third information being used for establishing the communication connection between the first terminal and the first device; based on the third information, establishing the communication connection between the first terminal and the first device.
23. The method of claim 22, wherein, The first device is an application server, and the third information is a token used for accessing the application server.
24. A communications device, characterized by comprising a module for performing the method of any one of claims 1-11, or the method of any one of claims 17-23.
25. A communications device, characterized by comprising a processor coupled to a memory; the memory is configured to store computer programs or instructions; the processor is configured to execute part or all of the computer programs or instructions in the memory, when the part or all of the computer programs or instructions are executed, to implement the method of any one of claims 1-11, or the method of any one of claims 17-23.
26. A computer readable storage medium, characterized in that, the storage medium stores computer programs or instructions, when the computer programs or instructions are executed by a communication device, to implement the method of any one of claims 1-11, or the method of any one of claims 17-23.
27. A computer program product, characterised in that, the computer program product comprises computer instructions, when the computer instructions are run on a computer, to cause the method of any one of claims 1-11 to be implemented, or the method of any one of claims 17-23 to be implemented.