Communication method and communication apparatus
By receiving task attributes and configuring dedicated communication resources through SAF, the problem of the network side being unable to provide differentiated services is solved, thereby improving user experience and communication efficiency.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2026-01-26
- Publication Date
- 2026-07-30
AI Technical Summary
The network side is unable to provide differentiated services for different tasks, resulting in a reduced user experience.
By receiving task attributes through Service Aware Network Elements (SAF), obtaining corresponding communication resource credentials, and configuring dedicated communication resources based on criteria such as task initiation frequency and terminal device priority, the user experience can be improved.
It enables differentiated services for different tasks on the network side, improving user experience and the flexibility and efficiency of the communication process.
Smart Images

Figure CN2026074932_30072026_PF_FP_ABST
Abstract
Description
A communication method and a communication device
[0001] This application claims priority to Chinese Patent Application No. 202510126631.6, filed on January 27, 2025, entitled "A Communication Method and Communication Device", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of wireless communication technology, and more specifically, to a communication method and a communication device. Background Technology
[0003] In scenarios where the terminal device initiates a task and sends a task to the network side based on different attribute combinations, the network side responds to the task based on the attribute combinations provided by the user equipment (UE). Currently, the network side cannot provide differentiated services for different tasks, which reduces the user experience. Summary of the Invention
[0004] This application provides a communication method and apparatus to provide differentiated services for different tasks, thereby enhancing the user experience.
[0005] Firstly, a method is provided that can be performed by an apparatus (e.g., a communication apparatus). The apparatus can be a device (such as a network device), or it can be a component of a device (e.g., a chip (such as a modem chip, also known as a baseband chip, or a system-on-a-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip), a chip system, or a circuit), which is not limited in this application. The following description primarily uses the first node as an example.
[0006] The first node is, for example, a service awareness function (SAF).
[0007] The method includes: receiving a first task; determining one or more attributes corresponding to the first task, wherein any two attributes correspond to the same or different communication resource credentials, and a communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credentials correspond one-to-one with the communication resources; and obtaining one or more communication resource credentials corresponding to one or more attributes.
[0008] Among them, communication resources refer to a form of dynamic and flexible organization of resources, and can also be understood as subnets.
[0009] Based on the above scheme, SAF can determine one or more attributes corresponding to the first task and obtain the corresponding communication resource credentials. In other words, for different tasks, SAF determines the attributes corresponding to the task according to the specific circumstances of the task. In this way, the network side can provide differentiated services for different tasks, thereby improving the user experience.
[0010] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: sending credentials for one or more communication resources to the terminal device; or sending credentials for a first communication resource to the terminal device, wherein the first communication resource is determined based on one or more communication resources.
[0011] Based on the above scheme, after obtaining credentials for one or more communication resources corresponding to one or more attributes, SAF sends one or more communication resource credentials to the terminal device; or, SAF obtains a first communication resource based on one or more communication resources and sends the credentials of the first communication resource to the terminal device. In other words, SAF configures dedicated communication resources for the terminal device, thereby further improving the user experience.
[0012] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the SAF determining whether to send credentials for the first communication resource based on a first criterion.
[0013] The first criterion includes one or more of the following: the frequency of initiation of the first task and the priority of the terminal device.
[0014] Based on the above scheme, SAF determines whether to configure dedicated communication resources for the terminal device based on a first criterion. This approach improves the user experience while making the communication process more flexible and efficient. For example, if the first task is initiated frequently, SAF configures dedicated first communication resources for the communication device, allowing the terminal device to access all communication resources corresponding to the first task using the credentials of the first communication resources.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: sending query information, wherein the query information includes one or more attributes, and the query information requests to obtain credentials for one or more communication resources.
[0016] Based on the above scheme, SAF obtains credentials for one or more communication resources by sending query information to other nodes (e.g., identity management function, IDM).
[0017] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: sending a first communication resource creation request, the first communication resource creation request including a first attribute, the first communication resource creation request being used to request the creation of a second communication resource, the credentials of the second communication resource corresponding to the first attribute, and the first attribute belonging to one or more attributes corresponding to the first task.
[0018] Based on the above scheme, if the second communication resource does not exist, SAF sends a first communication resource creation request to other nodes (e.g., resource management nodes) to request the creation of the second communication resource. In other words, based on the attribute that the network side cannot respond, SAF requests the creation of the corresponding communication resource, thereby improving the user experience.
[0019] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: sending a second communication resource creation request, the second communication resource creation request including information for creating a third communication resource, the second communication resource creation request being used to request the creation of a third communication resource, the credentials of the third communication resource corresponding to a second attribute, the second attribute belonging to one or more attributes corresponding to the first task.
[0020] Based on the above scheme, if the third communication resource does not exist, SAF sends a second communication resource creation request to other nodes (e.g., resource management nodes) to request the creation of the third communication resource. The second communication resource creation request includes information for creating the third communication resource. For example, SAF determines the information for creating the second communication resource based on the second attribute, thereby avoiding directly carrying the second attribute in the second communication resource creation request, thus improving the security of the communication process.
[0021] Secondly, a method is provided that can be performed by a device (e.g., a communication device). This device can be a network device, or it can be a component of a device (e.g., a chip (such as a modem chip, also known as a baseband chip, or a SoC chip or SIP chip containing a modem core) or a chip system or circuit), which is not limited in this application. The following description primarily uses the first node as an example.
[0022] The first node is, for example, SAF.
[0023] The method includes: obtaining one or more attributes of a terminal device; wherein any two attributes of the one or more attributes correspond to credentials for the same communication resource or credentials for different communication resources, a credential for a communication resource corresponds to at least one of the one or more attributes, and the credentials for the communication resources correspond one-to-one with the communication resources; determining whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes; and if the terminal device does not hold credentials for the communication resources corresponding to the first attribute, sending the credential for the communication resources corresponding to the first attribute to the terminal device, wherein the first attribute belongs to one or more attributes.
[0024] Based on the above scheme, SAF can perform attribute-aware evaluation on one or more attributes of the terminal device. In other words, SAF determines whether the terminal device holds credentials for communication resources corresponding to one or more attributes. Furthermore, SAF sends credentials for communication resources that the terminal device does not hold, thereby improving the user experience.
[0025] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: sending a first request message to a terminal device, the first request message requesting to obtain one or more attributes; and receiving a first request response message from the terminal device, the first request response message indicating one or more attributes.
[0026] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: one or more attributes are determined by the terminal device based on the first attribute criterion.
[0027] Optionally, the first attribute criterion includes one or more of the following: the privacy level of the attribute, the priority of the attribute.
[0028] Based on the above scheme, the terminal device sends one or more attributes to the SAF based on the SAF's request. Furthermore, the terminal device can selectively send one or more attributes, thereby improving the security of the communication process.
[0029] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: sending a second request message to a terminal device, the second request message requesting the terminal device to authorize the SAF to determine whether the terminal device holds credentials for communication resources corresponding to one or more attributes; receiving a second request response message from the terminal device, the second request response message indicating permission for the SAF to determine whether the terminal device holds credentials for communication resources corresponding to one or more attributes; and obtaining one or more attributes based on the second request response message.
[0030] Based on the above scheme, when the network side stores one or more attributes of the UE, the SAF can perform attribute-aware evaluation after obtaining authorization from the UE, making the communication process more flexible and efficient.
[0031] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: obtaining a credential for the first communication resource and the attributes corresponding to the credential for the first communication resource, wherein the terminal device holds the credential for the first communication resource; and determining whether the terminal device holds a credential for one or more attributes of the communication resource corresponding to the UE based on the credential for the first communication resource and the attributes corresponding to the credential for the first communication resource.
[0032] Optionally, the SAF obtains the credentials of the first communication resource and the attributes corresponding to the credentials of the first communication resource based on the stored data; or, the credentials of the first communication resource and the attributes corresponding to the credentials of the first communication resource are pre-configured; or, the SAF obtains the credentials of the first communication resource and the attributes corresponding to the credentials of the first communication resource from other nodes.
[0033] Based on the above scheme, the SAF can obtain the network-side issuance records on its own or from other nodes (such as the IDM) to determine the credentials of the first communication resource issued by the network side to the UE and its corresponding attributes. Based on this, the SAF can further determine whether the UE holds credentials for one or more communication resources corresponding to one or more attributes.
[0034] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: sending query information, the query information including one or more attributes, the query information being used to query whether the terminal device holds credentials for communication resources corresponding to one or more attributes.
[0035] Based on the above scheme, SAF sends query information to other nodes (e.g., IDM), and IDM queries whether the terminal device has issued credentials for one or more communication resources corresponding to one or more attributes. SAF can directly obtain the query results. In this way, the communication process becomes more flexible and efficient.
[0036] Thirdly, a method is provided that can be performed by a device (e.g., a communication device). This device can be an apparatus (such as a terminal device), or it can be a component of an apparatus (e.g., a chip (such as a modem chip, also known as a baseband chip, or a SoC chip or SIP chip containing a modem core) or a chip system or circuit), and this application does not limit this. The following description primarily uses a terminal device as an example.
[0037] The method includes: receiving first request information, the first request information requesting to obtain one or more attributes, wherein any two attributes among the one or more attributes correspond to the same communication resource credential or different communication resource credentials, a communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credentials correspond one-to-one with the communication resources; sending one or more attributes; and, if the terminal device does not hold a communication resource credential corresponding to the first attribute, receiving a communication resource credential corresponding to the first attribute, wherein the first attribute belongs to one or more attributes.
[0038] Based on the above scheme, the terminal device sends one or more attributes to the network side based on the first request information. The network side performs attribute awareness evaluation on the one or more attributes sent by the UE, and the terminal device can obtain the credential of the communication resource corresponding to the first attribute, that is, the communication device can access the first communication resource, thereby improving the user experience.
[0039] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the terminal device determining one or more attributes based on the first attribute criterion.
[0040] Optionally, the first attribute criterion includes one or more of the following: the privacy level of the attribute, the priority of the attribute.
[0041] Based on the above scheme, the terminal device can selectively report one or more attributes for attribute awareness assessment. For example, for some attributes with high privacy levels, the terminal device can choose not to report them, which can improve the security of user privacy data. For another example, for some high-priority attributes, the terminal device can choose to report them and obtain the corresponding communication resource credentials, thereby improving the user experience.
[0042] Fourthly, a method is provided that can be performed by an apparatus (e.g., a communication apparatus). The apparatus can be a device (such as a network device), or it can be a component of a device (e.g., a chip (such as a modem chip, also known as a baseband chip, or a SoC chip or SIP chip containing a modem core) or a chip system or circuit), which is not limited in this application. The following description primarily uses the first node as an example.
[0043] The first node is, for example, SAF.
[0044] The method includes: receiving a first task, the first task including credentials for one or more communication resources, wherein the credentials for the communication resources correspond one-to-one with the communication resources; obtaining a first communication resource based on the first task, the first communication resource being used to execute the first task, wherein the first communication resource does not belong to one or more communication resources corresponding to the first task; and sending the credentials for the first communication resource to a terminal device.
[0045] Based on the above scheme, SAF has the function of parsing the first task. Furthermore, SAF can configure the first communication resources for the first task, thereby further improving the user experience.
[0046] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: sending a first communication resource creation request, the first communication resource creation request being used to request the creation of a first communication resource; and receiving a first communication resource creation request response, the first communication resource creation request response indicating the credentials of the first communication resource.
[0047] As one possible implementation, the method also includes: SAF calling the first communication resource from other nodes.
[0048] Based on the above scheme, multiple implementation methods for SAF to acquire the first communication resource are provided, making the scheme of this application applicable to more application scenarios.
[0049] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: sending a first task response to a terminal device, the first task response indicating whether the communication resources corresponding to the credentials of one or more communication resources have been configured.
[0050] Fifthly, a communication apparatus is provided for performing the method provided in any one of the first to fourth aspects. Specifically, the apparatus may include units and / or modules for performing the method provided in any one of the above implementations of the first to fourth aspects, such as processing units and / or communication units.
[0051] In one implementation, the device is a communication device (such as a terminal device or a network device). When the device is a communication device, the communication unit can be a transceiver or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.
[0052] In another implementation, the device is a chip, chip system, or circuit used in a communication device. When the device is a chip, chip system, or circuit used in a communication device, the communication unit can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip, chip system, or circuit; the processing unit can be at least one processor, processing circuit, or logic circuit.
[0053] A sixth aspect provides a communication device comprising: a memory for storing a program; and at least one processor for executing the computer program or instructions stored in the memory to perform the method provided by any of the above-described implementations of any of the first to fourth aspects.
[0054] In one implementation, the device is a communication device (such as a terminal device or a network device).
[0055] In another implementation, the device is a chip, chip system, or circuit used in a communication device.
[0056] In a seventh aspect, this application provides a processor for performing the methods provided in the foregoing aspects.
[0057] Unless otherwise specified, or if it does not contradict its actual function or internal logic in the relevant description, the transmission and acquisition / reception operations involved in the processor can be understood as processor output and input operations, or as transmission and reception operations performed by radio frequency circuits and antennas. This application does not limit them in this regard.
[0058] Eighthly, a computer-readable storage medium is provided for program code executed by a device, the program code including a method for performing any of the above-described implementations of any of the first to fourth aspects.
[0059] Ninth aspect, a computer program product comprising instructions is provided, which, when executed by a processor on a computer, causes the computer to perform the method provided by any of the above-described implementations of any of the first to fourth aspects.
[0060] In a tenth aspect, a chip is provided, the chip including a processor and a communication interface, wherein the processor reads instructions stored in a memory through the communication interface and executes the method provided by any of the above-described implementations of any of the first to fourth aspects.
[0061] Optionally, as one implementation, the chip also includes a memory storing computer programs or instructions. The processor is used to execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the processor is used to execute the method provided by any of the above implementations of any of the first to fourth aspects.
[0062] Eleventhly, a communication system is provided, comprising a first communication device and a second communication device. The first communication device is used to execute the method provided in any implementation of the first, second, and fourth aspects, and the second communication device is used to execute the method provided in any implementation of the third aspect.
[0063] The beneficial effects of aspects five through eleven and their possible implementations can be found in the descriptions of any of the aforementioned aspects, and will not be repeated here. Attached Figure Description
[0064] Figure 1 is a schematic diagram of a wireless communication system applicable to an embodiment of this application.
[0065] Figure 2 shows a schematic diagram of a basic 5G system 200 architecture.
[0066] Figure 3 is a schematic diagram of the communication method 300 proposed in an embodiment of this application.
[0067] Figure 4 is a schematic diagram of the communication method 400 proposed in an embodiment of this application.
[0068] Figure 5 is a schematic diagram of the communication method 500 proposed in an embodiment of this application.
[0069] Figure 6 is a schematic diagram of the communication method 600 proposed in an embodiment of this application.
[0070] Figure 7 is a schematic diagram of the communication method 700 proposed in an embodiment of this application.
[0071] Figure 8 is a schematic block diagram of a communication device 800 provided in an embodiment of this application.
[0072] Figure 9 is a schematic diagram of another communication device 900 provided in an embodiment of this application.
[0073] Figure 10 is a schematic block diagram of a chip system 1000 provided in an embodiment of this application. Detailed Implementation
[0074] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0075] Before introducing the scheme of this application, the following points should be noted.
[0076] (1) In this application, "instruction" can include direct instruction, indirect instruction, explicit instruction, implicit instruction, etc. When describing an instruction information as indicating A, it can be understood that the instruction information carries A, carries the identifier of A, carries B which is associated with A, carries the identifier of B which is associated with A, etc. In other words, if the receiving side of an instruction information can determine A based on the instruction information, it can be described as the instruction information indicating A, and the specific method of determination is not limited. When it is understood that the instruction information carries A, "instruction" can be replaced with "includes". In this case, a statement such as "send / receive instruction information, the instruction information indicates A" can be replaced with "send / receive A".
[0077] In this application, the information indicated by the instruction information is called the information to be instructed. In specific implementations, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly indicate the information to be instructed by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. Furthermore, the information to be instructed can be sent as a whole or divided into multiple sub-information pieces, and the sending period and / or timing of these sub-information pieces can be the same or different.
[0078] (2) In this application, the expression " / " is used to indicate that the objects before and after are in an "or" relationship; for example, A / B can mean: A or B. The expression "and / or" is used to indicate that the objects before and after are in a relationship of either "and" or "or"; for example, A and / or B can mean the following: A exists alone, B exists alone, A and B exist simultaneously, where A and B can be single or multiple. "At least one of the following" or similar expressions are used to indicate any combination of the listed items; for example, at least one of A, B and / or C can mean the following: A exists alone, B exists alone, C exists alone, A and B exist simultaneously, B and C exist simultaneously, A and C exist simultaneously, A, B and C exist simultaneously, where A, B, and C can be single or multiple.
[0079] (3) In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which may include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receive information from YY" can be understood as the source of the information being YY, which may include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.
[0080] (4) In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terms and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0081] (5) In this application, "first," "second," and "#1," "#2," and "#A" are merely for descriptive convenience and are used to distinguish objects, and are not intended to limit the scope of the embodiments of this application. They are not used to describe the order or sequence of features. It should be understood that such described objects can be interchanged where appropriate in order to describe solutions other than those in the embodiments of this application.
[0082] (6) In this application, "predefined" can mean a standard protocol predefined, or it can mean a pre-agreed or pre-negotiated agreement between devices. Here, "protocol" can refer to a standard protocol in the field of communications, for example, it may include fourth-generation (4G) protocols. th Generation 4G network, fifth generation (5G) network th This application does not limit the scope of network protocols such as generation (5G), new radio (NR) protocols, and related protocols applied in future communication networks.
[0083] (7) In this application, the words “exemplary,” “for example,” etc., are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as an “example” in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the term “example” is used to present concepts in a specific manner.
[0084] (8) In this application, “of”, “corresponding, relevant”, “corresponding”, and “related” can sometimes be used interchangeably. It should be noted that when the distinction is not emphasized, they have the same meaning.
[0085] (9) In this application, “when…”, “if” and “if” all refer to the device making a corresponding processing under certain objective circumstances, and are not limited to a time, nor do they require the device to make a judgment when it is implemented, nor do they mean that there are other limitations.
[0086] (10) In this application, “communication resources” refers to a form of dynamically and flexibly organized resources, and its name is not limiting. For example, “subnet” can also be used instead of the concept of “communication resources”. For ease of description, this application uses “subnet” for description, but it should be understood that this application is not limited thereto.
[0087] Next, we will introduce the communication system to which this application applies.
[0088] The technical solutions provided in this application can be applied to various communication systems, such as 5th generation (5G) or new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, and LTE time division duplex (TDD) systems. The technical solutions provided in this application can also be applied to future communication networks. Furthermore, the technical solutions provided in this application can be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), and Internet of Things (IoT) communication systems. The technical solutions provided in this application can also be applied to non-terrestrial network (NTN) systems such as inter-satellite communication and satellite communication.
[0089] As an example, a satellite communication system includes a satellite base station and terminal equipment. The satellite base station provides communication services to the terminal equipment. Satellite base stations can also communicate with each other. A satellite can act as a base station or as a terminal device. Here, "satellite" can refer to drones, hot air balloons, low-Earth orbit satellites, medium-Earth orbit satellites, high-Earth orbit satellites, etc. "Satellite" can also refer to non-terrestrial base stations or non-terrestrial equipment.
[0090] As an example, V2X communication can include: vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, and vehicle-to-network (V2N) communication.
[0091] In a communication system, a device can send signals to or receive signals from another device. These signals can include information, signaling, or data. The device can also be replaced by an entity, network entity, communication equipment, communication module, node, communication node, etc. This application uses a device as an example for description.
[0092] Figure 1 is a schematic diagram of a wireless communication system applicable to an embodiment of this application. As shown in Figure 1, the wireless communication system includes a wireless access network 100. The wireless access network 100 can be a future or higher version of the wireless access network, or a traditional (e.g., 5G, 4G, 3G, or 2G) wireless access network. One or more terminal devices (120a-120j, collectively referred to as 120) can be interconnected or connected to one or more network devices (110a, 110b, collectively referred to as 110) in the wireless access network 100. Network elements in the wireless communication system are connected through interfaces (e.g., NG, Xn) or air interfaces.
[0093] Figure 1 is just a schematic diagram. The wireless communication system may also include other devices, such as core network devices, wireless relay devices and / or wireless backhaul devices, which are not shown in Figure 1.
[0094] The 5G system will be briefly described below with reference to Figure 2. It should be understood that the 5G system described herein is merely an example and should not constitute any limitation on this application.
[0095] Figure 2 illustrates a basic architecture diagram of a 5G system 200. As shown in Figure 2, system 200 includes: PCF, AMF, Session Management Function (SMF), Radio Access Network (RAN), Unified Data Management (UDM), Data Network (DN), User Plane Function (UPF), UE, Application Function (AF), and / or Unified Data Storage (UDR). Optionally, Figure 2 may also include the following functions (not shown in Figure 2): Network Slice Selection Function (NSSF), Authentication Server Function (AUSF), Network Open Function (NEF), or Network Storage Function (NRF).
[0096] The main functions of each network element are described below:
[0097] 1. Terminal equipment
[0098] The terminal device in this application embodiment may be: UE, mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user equipment, etc.
[0099] Terminal devices can be devices that provide voice / data connectivity to users, such as handheld devices with wireless connectivity, in-vehicle devices, etc. Currently, examples of terminals include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving or autopilot systems, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to wireless modems, in-vehicle devices, wearable devices, terminal devices in future 5G networks, or future evolved public land mobile communication networks. Terminal devices in a mobile network (PLMN), etc., are not limited to this in the embodiments of this application.
[0100] By way of example and not limitation, in this embodiment, the terminal device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices worn directly on the body or integrated into a user's clothing or accessories. Wearable devices are not merely hardware devices; they achieve powerful functions through software support, data interaction, and cloud interaction. Broadly defined, wearable smart devices include those with comprehensive functions, large size, and the ability to achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those focused on a specific application function that require cooperation with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring. Furthermore, in this embodiment, the terminal device can also be a terminal device in an Internet of Things (IoT) system.
[0101] 2. Wireless access network
[0102] A radio access network (RAN) is an access network that implements network access functions based on wireless communication technology. RAN manages radio resources, provides wireless or air interface access services to terminals, and facilitates the forwarding of control signals and user data between terminals and the core network.
[0103] As an example and not a limitation, the radio access network can be an evolved NodeB (eNB or eNodeB) in an LTE system, a radio controller in a cloud radio access network (CRAN) scenario, or the access device can be a relay station, access point, vehicle-mounted equipment, wearable device, or access device in a 5G network or an access device in a future evolved PLMN network, etc. It can be an access point (AP) in a WLAN, or a gNB in an NR system. This application embodiment is not limited.
[0104] 3. Access and Mobility Management (AMF) network element: mainly used for mobility management and access management, such as mobility restrictions, initial registration of terminal devices, mobility registration updates, deregistration, and registration management.
[0105] 4. Security Anchor Function (SEAF): This network element is currently part of the AMF and is mainly responsible for initiating authentication requests to the AUSF and completing the network side's authentication of the UE during the EPS-AKA authentication process.
[0106] 5. Authentication server function (AUSF) network element: mainly used for user authentication, etc.
[0107] 6. Authentication Repository and Processing Function (ARPF) network element: mainly used to store long-term key K; receive authentication vector requests from AUSF; calculate authentication vector using K; and send authentication vector to AUSF, etc.
[0108] 7. Unified Data Management (UDM) Network Element: Used for unified data management, 5G user data management, processing user identification, access authentication, registration, or mobility management, etc.
[0109] For example, UDM can perform security authentication during the mobility registration process of terminal devices, interact with AMF to exchange subscription data, and update the context of terminal devices.
[0110] 8. Session Management Function (SMF) network element: mainly used for session management, allocation and management of Internet Protocol (IP) addresses for terminal devices, selection and management of user plane functions, policy control and charging function interface endpoints, and downlink data notification, etc.
[0111] 9. User Plane Function (UPF) Network Element: Used for packet routing and forwarding, as well as Quality of Service (QoS) processing of user plane data. User data can access the data network (DN) through this network element. In the embodiments of this application, it can be used to implement the functions of the user plane network element.
[0112] 10. Policy control function (PCF) network element: A unified policy framework used to guide network behavior, providing policy rule information to network elements (such as AMF, SMF, etc.) or terminal devices.
[0113] For example, the PCF can provide access and mobility policy control services to the AMF, including providing the AMF with mobility-related policy rules and updating the mobility-related policy rules.
[0114] 11. Application function (AF) network element: used for data routing affected by applications, accessing network open function network elements, and interacting with the policy framework for policy control, etc.
[0115] 12. Network Repository Function (NRF) Network Element: Used to store network function entities and their description information, as well as support functions such as service discovery and network element entity discovery.
[0116] 13. Network Exposure Function (NEF) element: Used to securely expose services and capabilities provided by 3GPP network functions to the outside world.
[0117] 14. Data Network
[0118] A data network refers to a specific data service network that a UE accesses. For example, typical data networks include the Internet and the IP Multimedia Subsystem (IPMS).
[0119] In the above architecture, the functions of each interface are described as follows:
[0120] N7: The interface between PCF and SMF, used to issue PDU session granularity and business data flow granularity control policies.
[0121] N15: The interface between PCF and AMF, used to issue UE policies and access control related policies.
[0122] N5: The interface between AF and PCF, used for issuing application service requests and reporting network events.
[0123] N4: The interface between SMF and UPF, used to transmit information between the control plane and the user plane, including the distribution of forwarding rules, QoS control rules, traffic statistics rules, etc. from the control plane to the user plane, as well as the reporting of information from the user plane.
[0124] N11: The interface between SMF and AMF, used to transmit PDU session tunnel information between RAN and UPF, transmit control messages sent to UE, and transmit radio resource control information sent to RAN, etc.
[0125] N2: The interface between AMF and RAN, used to transmit radio bearer control information from the core network side to the RAN.
[0126] N1: The interface between AMF and UE, access-independent, used to transmit QoS control rules to UE, etc.
[0127] N8: The interface between AMF and UDM, used by AMF to obtain access and mobility management related subscription data and authentication data from UDM, as well as by AMF to register UE's current mobility management information with UDM.
[0128] N10: The interface between SMF and UDM, used by SMF to obtain session management-related subscription data from UDM, and by SMF to register UE current session-related information with UDM.
[0129] N35: The interface between UDM and UDR, used by UDM to obtain user subscription data information from UDR.
[0130] N36: The interface between PCF and UDR, used by PCF to obtain policy-related contract data and application data related information from UDR.
[0131] N52: The interface between UDM and NEF, used by NEF to open network capabilities to third-party application functions, such as third-party application functions subscribing to reachability events of all users in a specific group through NEF to UDM.
[0132] In addition, NEF has direct interfaces with AMF and SMF, corresponding to the N29 interface and N51 interface respectively (not shown in the diagram above for simplification). These interfaces are used to open up operator network capabilities to third-party application function entities. The former can be used by NEF to directly subscribe to corresponding network events and update user configuration information from AMF, while the latter can be used to update application configuration data on SMF / UPF, such as packet flow description (PFD) information corresponding to the Application ID.
[0133] It should be understood that the network architecture described above in the embodiments of this application is merely an example of a network architecture described from the perspective of a traditional point-to-point architecture and a service-oriented architecture. The network architecture applicable to the embodiments of this application is not limited to this, and any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of this application.
[0134] It should be understood that the interface names between the various network elements in Figure 2 are merely examples, and the interface names in actual implementations may be different. This application does not impose any specific limitations on them. Furthermore, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0135] It should be noted that the aforementioned network element may also be referred to as an entity, device, apparatus, or module, etc., and this application does not specifically limit it. Furthermore, in this application, for ease of understanding and explanation, the description of network element is omitted in some descriptions. For example, the SMF network element is abbreviated as SMF. In this case, "SMF" should be understood as the SMF network element. The following descriptions of the same or similar cases are omitted.
[0136] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualization function instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network element or function can be implemented by one device, multiple devices working together, or a functional module within a single device; this application embodiment does not specifically limit this.
[0137] It should also be understood that in the communication system shown in Figure 2, the functions of each component network element are merely exemplary, and not all functions of each component network element are required when applied to the embodiments of this application.
[0138] Furthermore, the names of the various network elements (such as PCF, AMF, etc.) included in Figure 2 are merely names and do not limit the function of the network element itself. In 5G networks and other future networks, the aforementioned network elements may also have other names, and this application embodiment does not specifically limit this. For example, in future communication networks, some or all of the aforementioned network elements may use the terminology from 5G, or they may have other names, etc. This is explained uniformly here and will not be elaborated further below.
[0139] It should also be noted that the communication between the various network elements of the control plane function in Figure 2 is described using non-service interfaces as an example, but this does not limit the scope of protection of the embodiments of this application. Those skilled in the art will understand that the various network elements of the control plane function in Figure 2 can also communicate through service interfaces. For example, the service interface provided by the AMF can be Namf; the service interface provided by the SMF can be Nsmf; the service interface provided by the UDM can be Nudm; the service interface provided by the AF can be Naf; the service interface provided by the PCF can be Npcf, and so on.
[0140] The network elements in Figure 2 above are based on a reference point architecture and do not constitute a limitation on the embodiments of this application.
[0141] To facilitate understanding of the embodiments of this application, the terms used in this application will be briefly explained.
[0142] 1. Service awareness function (SAF): mainly used to parse tasks initiated by UE and assist in configuring subnets, etc.
[0143] 2. Identity Management Function (IDM): Primarily used to store subnet credentials and subnet credential issuance records.
[0144] It should be understood that the network elements (SAF, IDM, NF, AF, NRF, NEF, etc.) involved in the embodiments of this application are only examples, and their names do not limit the scope of protection of this application. This application does not exclude the possibility of using other names to replace the above network elements in future protocols to achieve their same or similar functions.
[0145] In existing solutions, the UE, as the task initiator, can initiate tasks to the network side based on different attribute combinations. The network side responds to the task based on the attribute combinations provided by the UE. However, under this solution, the network side cannot provide differentiated services for different tasks. In some possible situations, such as when the network side cannot respond to the attributes provided by the UE (e.g., the network side cannot provide the corresponding subnet to execute the task), the network side provides default resources to the UE, thereby reducing the user experience.
[0146] In view of this, this application proposes a method that enables the network side to parse tasks, thereby providing differentiated services for different tasks and improving the user experience.
[0147] The method proposed in this application is described below with reference to Figures 3 to 7.
[0148] Figure 3 is a schematic diagram of the communication method 300 proposed in an embodiment of this application. Method 300 briefly describes the process of creating a subnet and the process of resource registration.
[0149] Figure 3 includes UE, SAF, IDM, resource storage node, and resource management node.
[0150] In this embodiment, the resource storage node may be a network function (NF) or an application function (AF). In other words, the resources involved in this application embodiment may be internal network resources or external application resources, and are not limited thereto.
[0151] Among them, the resource management node is, for example, a network repository function (NRF); or, for example, a network exposure function (NEF); or there is a new resource management node (NRMF), which is not limited.
[0152] The following is a brief description of the process of creating a subnet.
[0153] S301, the UE sends a subnet creation request, and the resource management node receives the subnet creation request accordingly.
[0154] The subnet creation request is used to request the creation of a subnet.
[0155] Specifically, the subnet creation request includes administrator credentials (e.g., the UE's ID), subnet parameters, and the corresponding verification attributes (claim) for the subnet. These parameters are briefly described below.
[0156] ●Administrator credentials: A unique identifier used to distinguish and verify the identity of an administrator.
[0157] ● Subnet parameters: Used to ensure the normal operation of the network. Subnet parameters include, for example, subnet mask, IP address, etc.
[0158] ● Authentication attributes corresponding to the subnet: that is, the attributes corresponding to the credentials of the subnet, such as user identity attributes, service identification attributes, communication attributes, and location attributes and visual attributes mentioned later.
[0159] It should be understood that the credentials for a subnet are used to access the subnet, and there is a one-to-one correspondence between the credentials for a subnet. The credentials for a subnet correspond to (or include, or require verification) one or more attributes. The credentials for a subnet are briefly introduced in S304.
[0160] S302, the resource management node sends a resource request message, and the corresponding resource storage node receives the resource request message.
[0161] Specifically, the resource management node sends resource request information to the resource storage node based on the subnet creation request. The resource request information is used to obtain resources for creating the subnet.
[0162] S303, the resource storage node configures the resources used to create the subnet to the resource management node.
[0163] S304, the resource management node sends the subnet's credentials, and correspondingly, the IDM receives the subnet's credentials.
[0164] Specifically, the resource management node creates a subnet, generates the corresponding subnet credentials, and then registers the subnet credentials with the IDM.
[0165] The subnet credentials represent the permissions to access the subnet. Optionally, the subnet credentials may include one or more of the following: subnet parameters, attributes corresponding to the subnet credentials, and the signature of the resource management node.
[0166] ●In this context, the credentials for a subnet correspond to one or more attributes.
[0167] ● The signature of the resource management node is used to verify the authenticity of the subnet credentials.
[0168] S305, IDM sends a subnet credential registration response, and correspondingly, the resource management node receives the subnet credential registration response.
[0169] Specifically, after receiving the subnet credentials sent by the resource management node, the IDM registers (or stores) them and sends a subnet credential registration response to the resource management node. The subnet credential registration response is used to indicate that the IDM has successfully received the subnet credentials.
[0170] S306, the resource management node sends a subnet creation request response, and the UE receives the subnet creation request response accordingly.
[0171] The subnet creation request response includes subnet credentials and indicates that the subnet was created successfully.
[0172] The following is a brief description of the resource registration process.
[0173] S307, the resource management node sends resource registration information, and correspondingly, the IDM receives the resource registration information.
[0174] The resource registration information includes credentials for one or more subnets, which are used to register resources associated with the credentials of the subnets with the IDM.
[0175] Here, a resource is a resource associated with a credential of a subnet. In other words, a resource corresponds one-to-one with a credential of a subnet. For example, credential A is associated with resource #1, credential B is associated with resource #2, and credential C is associated with resource #3.
[0176] S308, IDM sends resource registration response information, and correspondingly, the resource management node receives the resource registration response information.
[0177] The resource registration response information indicates that IDM has successfully registered the resource.
[0178] S309, the resource management node sends task registration information, and correspondingly, the SAF receives the task registration information.
[0179] The task registration information includes the resources associated with the task, that is, the resources used to execute the task.
[0180] Specifically, since a task can correspond to one or more attributes, and further, an attribute corresponds to a credential of a subnet, and any two attributes correspond to the same credential of a subnet, or any two attributes correspond to credentials of different subnets, that is, a task corresponds to credentials of one or more subnets, then a task corresponds to one or more resources.
[0181] For example, a task (let's call it task #1) corresponds to two attributes (let's call them attribute A and attribute B). Taking the credential of the same subnet as attribute A and attribute B (let's call it credential #1) as an example, then task #1 corresponds to credential #1. Furthermore, credential #1 corresponds to resource #1, so task #1 corresponds to resource #1. In other words, resource #1 is used to execute task #1.
[0182] For another example, task #1 corresponds to two attributes (e.g., attribute A and attribute B). Taking the example that attributes A and attribute B correspond to credentials of different subnets, for example, attribute A corresponds to credential #1 and attribute B corresponds to credential #2, then task #1 corresponds to two credentials (i.e., credential #1 and credential #2). Furthermore, credential #1 corresponds to resource #1 and credential #2 corresponds to resource #2, then task #1 corresponds to two resources (i.e., resource #1 and resource #2). In other words, resources #1 and resource #2 are used to execute task #1.
[0183] S310, SAF sends task registration response information, and correspondingly, the resource management node receives the task registration response information.
[0184] The task registration response information indicates that SAF has successfully registered the task.
[0185] Figure 4 is a schematic diagram of the communication method 400 proposed in an embodiment of this application.
[0186] S401, IDM performs pre-configuration.
[0187] For example, the specific process of IDM performing pre-configuration may include the following:
[0188] ● The IDM and UE complete registration and establish a secure connection.
[0189] ● The IDM stores the subnet credentials that the network side has sent to the UE, such as those mentioned in step S306 above.
[0190] ●IDM stores verifiable credentials (VCs) for each node. In other words, IDM can verify the authenticity of each node based on its VCs, thereby improving communication security.
[0191] ● Establish a secure connection between the IDM and the service provider (SP).
[0192] ●IDM maintains a list of attribute requests for each app.
[0193] S402, UE sends task #2, and correspondingly, SAF receives task #2.
[0194] Task #2 includes the UE's ID.
[0195] Optionally, Task #2 also includes a dynamic credential for Task #2, which SAF can use to determine the authenticity of Task #2.
[0196] This application does not limit the specific form of the dynamic certificate. As one possible implementation, the dynamic certificate is in VC form and is signed by SAF based on its own public key.
[0197] This application does not limit the implementation method of the UE obtaining dynamic credentials. As one possible implementation method, the UE obtains dynamic credentials from the IDM.
[0198] Optionally, task #2 also includes information #A, which describes task #2 and helps SAF determine one or more attributes corresponding to task #2.
[0199] For example, if task #2 is "family member care", and information #A includes: task #2 is used to locate family members in real time, then SAF can determine, based on information #A, that task #2 corresponds to at least the location attribute (an example of an attribute) and the visual attribute (an example of an attribute). Furthermore, SAF determines the credentials of the communication sensing subnet (an example of a subnet) corresponding to task #2.
[0200] It should be understood that the above is only an illustrative example. The embodiments of this application do not limit the specific form of task #2A or the specific method by which the UE obtains information #A. As one possible implementation, the network service provider distributes information #A to the UE and SAF through service discovery.
[0201] S403, SAF determines one or more attributes corresponding to task #2.
[0202] Optionally, S403 also includes: SAF determining the authenticity of Task #2 based on the dynamic credentials of Task #2.
[0203] This application does not limit the specific method by which the SAF determines one or more attributes corresponding to task #2. In one possible implementation, the SAF can determine one or more attributes corresponding to task #2 based on stored data; in another possible implementation, the SAF can determine one or more attributes corresponding to task #2 based on instruction information.
[0204] S404, SAF sends query information, and IDM receives the query information accordingly.
[0205] The query information includes one or more attributes, and is used to query the credentials of the subnet corresponding to one or more attributes.
[0206] S405, IDM sends query response information, and SAF receives query response information accordingly.
[0207] The query response information includes the subnet credentials obtained by IDM based on one or more attributes.
[0208] This application does not limit the specific implementation method of IDM obtaining subnet credentials. Several possible scenarios are given below.
[0209] One possible scenario: The IDM retrieves the subnet credentials based on stored data. For example, the IDM queries the issuance record and retrieves the subnet credentials issued to the UE based on the issuance record.
[0210] Another possible scenario: IDM obtains the subnet credentials from the resource management node, i.e., S405a.
[0211] For example, S405a may include the following two possible implementations.
[0212] (1) If the IDM fails to find the credentials (e.g., credential #A) of the subnet (e.g., subnet #A) based on the stored data, the IDM queries the resource management node to see if subnet #A has been created. If subnet #A has been created, the IDM sends the UE's ID to subnet #A and obtains the credentials of the subnet.
[0213] (2) If the IDM fails to find the subnet credentials based on the stored data and the subnet has not been created, the IDM sends a subnet creation request to the resource management node and obtains the subnet credentials.
[0214] This application embodiment does not limit the specific content of the subnet creation request sent by the IDM.
[0215] For example, if the subnet corresponding to attribute #1 has not been created, attribute #1 belongs to one or more attributes corresponding to task #2. If the subnet creation request includes attribute #1, the resource management node can determine to create the subnet corresponding to attribute #1 based on the subnet creation request.
[0216] In another possible implementation, method 400 further includes: SAF sending a subnet creation request to the resource management node based on the query response information and obtaining the subnet's credentials.
[0217] Specifically, taking the example of the subnet corresponding to attribute #1 not being created, attribute #1 belongs to one or more attributes corresponding to task #2. If IDM fails to find the credential of the subnet corresponding to attribute #1 based on the stored data, and the subnet corresponding to attribute #1 has not been created, SAF cannot obtain the credential of the subnet corresponding to attribute #1 based on the query response information. In this case, SAF sends a subnet creation request to the resource management node.
[0218] This application does not limit the specific content of the subnet creation request sent by the SAF.
[0219] In one possible scenario, if the subnet creation request includes attribute #1, the resource management node can determine the subnet corresponding to attribute #1 to be created based on the subnet creation request.
[0220] In another possible scenario, the subnet creation request includes information #B, where information #B is determined by SAF based on attribute #1. Information #B is used to create the subnet corresponding to attribute #1. In this case, the resource management node can create the subnet corresponding to attribute #1 based on information #B.
[0221] The embodiments of this application do not limit the specific content of information #B, so that the resource management node can create the subnet corresponding to attribute #1 based on information #B.
[0222] The specific process for creating a subnet by the resource management node can be found in Method 300, and will not be repeated here.
[0223] S406, the SAF sends credentials for one or more subnets, and the UE receives credentials for one or more subnets accordingly.
[0224] As one possible implementation, method 400 also includes S407-S408.
[0225] S407, SAF determines the generation of subnet #1 based on one or more subnets.
[0226] Furthermore, SAF determines, based on criterion #1 (an example of the first criterion), to generate subnet #1 from one or more subnets, and further, SAF obtains credentials for subnet #1.
[0227] The embodiments of this application do not limit the specific content of guideline #1, but the following are exemplary descriptions.
[0228] (1) Criterion #1 is the frequency of task #2 initiation. Specifically, when the frequency of task #2 initiation is greater than or equal to the first threshold, it indicates that the frequency of task #2 is high. SAF then determines to generate subnet #1 based on one or more subnets, thereby improving the user experience.
[0229] The embodiments of this application do not limit the specific value of the first threshold or the specific method by which the SAF obtains the first threshold. Optionally, the first threshold may be configured, indicated, or predefined.
[0230] (2) Criterion #1 is the priority of the UE. Specifically, when the UE is a high-priority UE, the SAF can determine to generate subnet #1 based on one or more subnets. In other words, it creates a dedicated subnet for the UE, thereby improving the user experience.
[0231] Among them, high-priority UE and low-priority UE are two relative concepts. For example, if the priority of UE#1 is higher than that of UE#2, then UE#1 is a high-priority UE and UE#2 is a low-priority UE.
[0232] The embodiments of this application do not limit the specific method of generating subnet #1 based on one or more subnets. Optionally, SAF sends a subnet creation request to the resource management node. The subnet creation request is used to request the creation of subnet #1 and obtain the credentials of subnet #1, i.e., S407a.
[0233] S408, SAF sends the credential for subnet #1, and correspondingly, UE receives the credential for subnet #1.
[0234] S406 and S407-S408 are parallel steps, and only one of them needs to be executed.
[0235] S409, the UE sends a task #2 execution request, and the resource storage node receives the task #2 execution request accordingly.
[0236] The task #2 execution request is used to access the resources corresponding to the subnet, thereby executing task #2.
[0237] Specifically, the task #2 execution request includes credentials for one or more subnets in S406; or, the task #2 execution request includes credentials for subnet #1 in S408.
[0238] As one possible implementation, method 400 further includes: the UE generating credential #3 based on the attributes corresponding to the credentials of one or more subnets in S406. For example, the attributes corresponding to the credentials of one or more subnets are recombined to generate credential #3, wherein credential #3 corresponds to one or more subnets. In other words, the UE can access one or more corresponding subnets based on credential #3, thereby reducing communication overhead.
[0239] As mentioned above, for tasks initiated by the UE, the SAF has the function of parsing tasks. The SAF can parse the attributes corresponding to the task itself and send the subnet credentials corresponding to the attributes to the UE, thereby realizing differentiated services for different tasks.
[0240] Figure 5 is a schematic diagram of the communication method 500 proposed in an embodiment of this application.
[0241] S501, IDM performs pre-configuration.
[0242] S501 can be referenced from the content in S401, and will not be repeated here.
[0243] S502, UE sends task #3, and correspondingly, SAF receives task #3.
[0244] Task #3 includes the UE's ID and also includes credentials for one or more subnets (e.g., subnet #2), where subnet #2 is used to execute task #3.
[0245] Optionally, task #3 also includes information #C, which describes task #3 and helps the SAF determine one or more subnets corresponding to task #3. Further, based on information #C, the SAF can determine whether the credentials of subnet #2 included in task #3 are compatible with task #3.
[0246] The specific content and acquisition method of information #C can be found in the description of information #A in S402.
[0247] S503, SAF determines one or more subnets corresponding to task #3 based on task #3 (for example, denoted as subnet #3).
[0248] In one possible scenario, the subnet #3 determined by SAF is the same subnet as the one whose credentials correspond to subnet #2 included in task #3 in S502.
[0249] Another possible scenario is that the subnet #3 determined by SAF is different from the subnet corresponding to the credentials of subnet #2 included in task #3 in S502.
[0250] S504, SAF sends query information, and IDM receives the query information accordingly.
[0251] The query information includes the credentials for subnet #3, and the query information is used to query the issuance records of credentials for subnet #3.
[0252] S505, IDM sends query response information, and SAF receives query response information accordingly.
[0253] The query response information includes the credentials for subnet #4.
[0254] Specifically, the IDM obtains the credential for subnet #3 in S504. Further, the IDM queries the issuance record of the credential for subnet #3. In other words, the IDM queries whether the credential for subnet #3 has been issued to the UE, and sends the credential for the subnet with the issuance record (denoted as subnet #4) to the SAF.
[0255] S506, SAF determines the credentials for subnet #5.
[0256] Among them, the credential for subnet #5 is a subnet credential for which there is no issuance record.
[0257] Specifically, SAF can determine the subnet credential (i.e., the subnet credential) that does not have an issuance record based on the credential of subnet #3 and the credential of subnet #4.
[0258] If subnet #5 includes one or more subnets, method 500 further includes: SAF obtaining subnet #5, and / or, credentials for subnet #5.
[0259] This application does not limit the specific implementation of SAF obtaining subnet #5, and / or the credentials of subnet #5. The following is an exemplary description.
[0260] In one possible scenario, if subnet #5 already exists, the SAF obtains subnet #5 and / or its credentials from other nodes. For example, if subnet #5 is a subnet provided to other UEs by the network side, the SAF can access subnet #5 and obtain its credentials.
[0261] In another possible scenario, SAF sends a subnet creation request to the resource management node. The subnet creation request is used to request the creation of subnet #5, i.e., S507.
[0262] S507, SAF sends a subnet creation request to the resource management node, requesting the creation of subnet #5.
[0263] Subnet #5 includes one or more subnets.
[0264] This application does not limit the specific content of the subnet creation request.
[0265] In one possible scenario, SAF obtains one or more attributes (e.g., attribute #5) corresponding to the credentials of subnet #5 based on the credentials of subnet #5. Then, the subnet creation request includes attribute #5. Furthermore, SAF creates subnet #5 based on attribute #5 in the subnet creation request.
[0266] In another possible scenario, the subnet creation request includes information #B, where information #B is determined by SAF based on attribute #5. Information #B is used to create subnet #5, and the resource management node can create subnet #5 based on information #B.
[0267] The specific content of information #B is not limited in this embodiment, so that the resource management node can create the subnet corresponding to attribute #5 based on information #B.
[0268] S508, SAF sends Task #3 response, and correspondingly, UE receives Task #3 response.
[0269] Among them, Task #3 indicates whether subnet #2 has been configured.
[0270] If S507 is executed, method 500 also includes S509.
[0271] S509, the resource storage node sends the creation result of subnet #5 to the UE.
[0272] Optionally, if S507 is performed, method 500 further includes: the SAF sending the credential of subnet #5 to the UE.
[0273] In the above, SAF parses the tasks initiated by the UE and configures the UE with the credentials of subnet #5. In this way, it assists the UE in expanding the functions of the tasks, thereby improving the user experience.
[0274] Figure 6 is a schematic diagram of the communication method 600 proposed in an embodiment of this application.
[0275] S601, IDM performs pre-configuration.
[0276] S601 can be referenced from the content in S401, and will not be repeated here.
[0277] S602, SAF sends first request information, and correspondingly, UE receives first request information.
[0278] The first request information request retrieves one or more attributes.
[0279] S603, the UE sends a first request response information, and correspondingly, the SAF receives the first request response information.
[0280] The first request response information includes the UE's ID, and also includes one or more attributes (e.g., attribute #2).
[0281] In one possible implementation, the UE determines attribute #2 based on criterion #2 (an example of the first attribute criterion). The specific content of criterion #2 is not limited in the embodiments of this application. The following is an exemplary description.
[0282] (1) Criterion #2 is the privacy level of the attribute. Specifically, for communication security reasons, if the privacy level of an attribute is low, the UE can send the attribute to the SAF; if the privacy level of an attribute is high, the UE can choose not to send the attribute.
[0283] This application does not limit the specific implementation method for measuring the privacy level of attributes in the embodiments.
[0284] (2) Criterion #2 is the priority of attributes. Specifically, if an attribute is a high-priority attribute, the UE can send the attribute to the SAF; if an attribute is a low-priority attribute, the UE can choose not to send the attribute.
[0285] This application does not limit the specific implementation method for measuring the priority of attributes. In one possible implementation, the priority is determined based on the importance of the attribute relative to the task. For example, if attribute #A is more important than a certain task (e.g., task #4), in other words, attribute #A is an indispensable attribute for performing task #4, then attribute #A is a high-priority attribute. As another example, if attribute #B is less important than task #4, in other words, attribute #B is an optional attribute relative to task #4, then attribute #B is a low-priority attribute.
[0286] S604, SAF performs attribute-aware evaluation.
[0287] Specifically, the SAF determines whether there is one or more attributes (e.g., attribute #C) in attribute #2, and the UE does not hold the credential for the subnet corresponding to attribute #C (or, in other words, the IDM has not sent the credential for the subnet corresponding to attribute #C to the UE).
[0288] Among them, attribute #C may be a service pre-activated by the UE, or attribute #C may be a core function of the UE, without limitation.
[0289] The specific implementation method of attribute-aware evaluation of SAF in this application embodiment is not limited, but the following is an exemplary description.
[0290] Example 1: SAF sends a query message to IDM to check whether attribute #C, i.e., S605-S606, exists in attribute #2.
[0291] Two possible implementation methods are given below.
[0292] Implementation Method 1
[0293] S605, SAF sends query information, and IDM receives the query information accordingly.
[0294] The query information includes the UE's ID, which is used to query the subnet credentials issued by the IDM to the UE.
[0295] S606, IDM sends query response information, and SAF receives query response information accordingly.
[0296] The query response information includes a credential issued by the IDM to the UE for a subnet (e.g., denoted as subnet #6), where subnet #6 includes one or more subnets.
[0297] Optionally, the query response information may also include one or more attributes corresponding to the credential of subnet #6 (e.g., attribute #3); or, SAF may obtain attribute #3 based on the credential of subnet #6, for example, SAF may obtain attribute #3 based on stored data, etc., without limitation.
[0298] Furthermore, based on the credentials of subnet #6 and attribute #3, SAF can determine whether attribute #C exists in attribute #2, where attribute #C does not belong to attribute #3.
[0299] Implementation Method Two
[0300] S605, SAF sends query information, and IDM receives the query information accordingly.
[0301] The query information includes attribute #2. The query information is used to check whether attribute #C exists in attribute #2. In other words, the query information is used to check whether the IDM has issued the subnet credential corresponding to attribute #2 to the UE.
[0302] S606, IDM sends query response information, and SAF receives query response information accordingly.
[0303] The query response information includes attribute #C, meaning that IDM did not find any credentials issued to the UE for the subnet corresponding to attribute #C.
[0304] Based on the query response information, SAF can determine that the UE does not hold credentials for the subnet corresponding to attribute #C.
[0305] Example 2: SAF obtains the correspondence between the credentials of subnet #6 and attribute #3, and determines whether attribute #C exists in attribute #2 based on the correspondence between the credentials of subnet #6 and attribute #3.
[0306] This application embodiment does not limit the specific implementation method of SAF obtaining the credential of subnet #6 and the correspondence of attribute #3.
[0307] One possible scenario is that the SAF obtains the correspondence between the credential of subnet #6 and attribute #3 based on the stored data. For example, the SAF stores data on the subnet credentials issued by the IDM to the UE.
[0308] Another possible scenario is that the correspondence between the credentials for subnet #6 and attribute #3 is pre-configured.
[0309] S607, SAF retrieves the subnet credential corresponding to attribute #C.
[0310] This application does not limit the specific implementation of SAF obtaining the subnet credential corresponding to attribute #C. The following is an exemplary description.
[0311] Example 1: SAF retrieves the subnet credentials corresponding to attribute #C based on stored data. For example, SAF stores subnet credentials held by other UEs.
[0312] Example 2: SAF retrieves the subnet credentials corresponding to attribute #C from other nodes. For example, SAF queries IDM for the credentials for the subnet corresponding to attribute #C.
[0313] Example 3: If the subnet corresponding to attribute #C has not been created, the SAF or IDM sends a subnet creation request to the resource storage node to request the creation of the subnet corresponding to attribute #C and to obtain the subnet credential corresponding to attribute #C, i.e., S607a.
[0314] S608, the SAF sends the credential of the subnet corresponding to attribute #C (for example, denoted as credential #C), and the UE receives credential #C accordingly.
[0315] S609, the UE sends access information, and the resource storage node receives the access information accordingly.
[0316] The access information includes the UE's ID and credential #C. The access information is used to access the subnet resources corresponding to credential #C.
[0317] Figure 7 is a schematic diagram of the communication method 700 proposed in an embodiment of this application.
[0318] S701, IDM performs pre-configuration.
[0319] S701 can be referenced from the content in S401, and will not be repeated here.
[0320] S702, SAF sends authorization request information, and correspondingly, UE receives authorization request information.
[0321] The authorization request information requests the UE to authorize the SAF to perform attribute-aware evaluation on one or more attributes of the UE (e.g., attribute #4). In other words, the authorization request information requests the UE to authorize the SAF to determine whether the UE holds the credential for the subnet corresponding to attribute #4.
[0322] S703, the UE sends an authorization request response information, and the SAF receives the authorization request response information accordingly.
[0323] The authorization request response information includes the UE's ID and is used to indicate whether the UE authorizes SAF to perform attribute-aware evaluation on the UE's attribute #4.
[0324] Optionally, the authorization request response information may also include authorization credentials, which are used to prove the authenticity of the UE's authorization.
[0325] S704, SAF sends query information, and IDM receives the query information accordingly.
[0326] The query information includes the UE's ID and authorization credentials. The query information is used to query the subnet credentials issued by the IDM to the UE, as well as attribute #4.
[0327] S705, IDM queries the UE's subnet credential issuance record and the UE's attribute #4.
[0328] S706, IDM sends query response information, and SAF receives query response information accordingly.
[0329] The query response information includes the subnet credentials issued by the IDM to the UE, and the UE's attribute #4.
[0330] S707, SAF performs attribute-aware evaluation.
[0331] Specifically, the SAF determines whether there is one or more attributes (e.g., attribute #C) in attribute #4 based on the subnet credentials issued by the IDM to the UE and the UE's attribute #4, where the IDM has not sent the subnet credentials corresponding to attribute #C to the UE (or in other words, the UE does not hold the subnet credentials corresponding to attribute #C).
[0332] S708, SAF retrieves the credentials for the subnet corresponding to attribute #C.
[0333] One possible scenario is that the SAF retrieves the credentials for the subnet corresponding to attribute #C based on stored data. For example, the SAF stores subnet credentials held by other UEs.
[0334] Another possible scenario is that the SAF or IDM sends a subnet creation request to the resource storage node, requesting the creation of the subnet corresponding to attribute #C and obtaining the credential for the subnet corresponding to attribute #C, i.e., S708a.
[0335] S709, the SAF sends the credential of the subnet corresponding to attribute #C (e.g., denoted as credential #C), and the UE receives credential #C accordingly.
[0336] S710, the UE sends access information, and the resource storage node receives the access information accordingly.
[0337] The access information includes the UE's ID and credential #C. The access information is used to access the subnet resources corresponding to credential #C.
[0338] In summary, SAF performs attribute-aware evaluation on the UE's attributes. If the UE does not hold the subnet credentials corresponding to the attribute, it configures subnet credentials for the UE, enabling the UE to access the corresponding subnet based on the subnet credentials, thereby improving the user experience.
[0339] Figure 8 is a schematic block diagram of a communication device 800 provided in an embodiment of this application. The communication device includes a transceiver unit 810. The transceiver unit 810 can be used to implement corresponding communication functions. The transceiver unit 810 can also be referred to as a communication interface or a communication unit. Optionally, the device 800 further includes a processing unit 820. The processing unit 820 can be used to implement processing operations.
[0340] Optionally, the device 800 may further include a storage unit for storing instructions and / or data, and the processing unit 820 may read the instructions and / or data from the storage unit to enable the device to implement the aforementioned method embodiments.
[0341] Optionally, the transceiver unit 810 includes a sending unit and / or a receiving unit, wherein the sending unit is used to perform the sending operation in the above embodiments, and the receiving unit is used to perform the receiving operation in the above embodiments.
[0342] It should be noted that the communication device 800 may include a transmitting unit but not a receiving unit; or, the communication device 800 may include a receiving unit but not a transmitting unit. Specifically, it depends on whether the above-described scheme executed by the communication device 800 includes both transmitting and receiving actions. For example, the communication device 800 is used to execute the actions performed by each node (e.g., UE, SAF, IDM) in the embodiments shown in Figures 3 to 7. For details, please refer to the relevant descriptions in the embodiments shown in Figures 3 to 7, which will not be repeated here.
[0343] For example, communication device 800 is used to execute the following scheme.
[0344] In one possible design, the device 800 is a network device, or it can be a component of a network device (such as a chip, chip system, or circuit). The transceiver unit and the processing unit can be used to implement the relevant operations of the network device, which may be a service-aware network element.
[0345] In one possible implementation, the transceiver unit 810 is used to receive a first task; the processing unit 820 is used to determine one or more attributes corresponding to the first task, wherein any two attributes among the one or more attributes correspond to the same communication resource credential or different communication resource credentials, a communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credentials correspond one-to-one with the communication resources; the transceiver unit 810 is also used to obtain the one or more communication resource credentials corresponding to the one or more attributes.
[0346] Optionally, the transceiver unit 810 is further configured to send credentials for one or more communication resources; or, the transceiver unit 810 is further configured to send credentials for a first communication resource, wherein the first communication resource is determined based on one or more communication resources.
[0347] Optionally, the processing unit 820 is further configured to determine whether to send the credentials for the first communication resource based on a first criterion.
[0348] Optionally, the first criterion includes one or more of the following: the frequency of initiation of the first task, and the priority of the terminal device.
[0349] Optionally, the transceiver unit 810 is also used to send query information; wherein the query information includes one or more attributes, and the query information requests to obtain credentials for one or more communication resources.
[0350] Optionally, the transceiver unit 810 is further configured to send a first communication resource creation request, the first communication resource creation request including a first attribute, the first communication resource creation request being used to request the creation of a second communication resource, the credentials of the second communication resource corresponding to the first attribute, and the first attribute belonging to one or more attributes corresponding to the first task.
[0351] Optionally, the transceiver unit 810 is further configured to send a second communication resource creation request, the second communication resource creation request including information for creating a third communication resource, the second communication resource creation request being used to request the creation of a third communication resource, the credentials of the third communication resource corresponding to a second attribute, the second attribute belonging to one or more attributes corresponding to the first task.
[0352] In a second possible design, the device 800 is a network device, or it can be a component of a network device (such as a chip, chip system, or circuit). The transceiver unit and the processing unit can be used to implement the relevant operations of the network device. The network device is, for example, a service-aware network element.
[0353] In one possible implementation, the transceiver unit 810 is used to acquire one or more attributes of the terminal device; wherein any two attributes among the one or more attributes correspond to the same or different communication resource credentials, one communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credentials correspond one-to-one with the communication resources; the processing unit 820 is used to determine whether the terminal device holds the communication resource credential corresponding to one or more attributes; if the terminal device does not hold the communication resource credential corresponding to the first attribute, the transceiver unit 810 is further used to send the communication resource credential corresponding to the first attribute to the terminal device, wherein the first attribute belongs to one or more attributes.
[0354] Optionally, the transceiver unit 810 is further configured to send a first request message to the terminal device, the first request message requesting to obtain one or more attributes; the transceiver unit 810 is further configured to receive a first request response message from the terminal device, the first request response message indicating one or more attributes.
[0355] Optionally, the transceiver unit 810 is further configured to send a second request message to the terminal device, the second request message requesting the terminal device to authorize the SAF to determine whether the terminal device holds credentials for communication resources corresponding to one or more attributes; Optionally, the transceiver unit 810 is further configured to receive a second request response message from the terminal device, the second request response message indicating that the SAF is allowed to determine whether the terminal device holds credentials for communication resources corresponding to one or more attributes; Optionally, the transceiver unit 810 is further configured to obtain one or more attributes based on the second request response message.
[0356] Optionally, the transceiver unit 810 is further configured to obtain the credential of the first communication resource and the attribute corresponding to the credential of the first communication resource, wherein the terminal device holds the credential of the first communication resource; the processing unit 820 is further configured to determine whether the terminal device holds the credential of one or more attributes of the communication resource corresponding to the UE based on the credential of the first communication resource and the attribute corresponding to the credential of the first communication resource.
[0357] Optionally, the transceiver unit 810 is also used to send query information, which includes one or more attributes, and is used to query whether the terminal device holds credentials for communication resources corresponding to one or more attributes.
[0358] In a third possible design, the device 800 can be a terminal device, or a component of a terminal device (such as a chip, chip system, or circuit). The transceiver unit and processing unit can be used to implement the relevant operations of the terminal device.
[0359] In one possible implementation, the transceiver unit 810 is configured to receive first request information, which requests the acquisition of one or more attributes. Any two of the attributes correspond to credentials for the same or different communication resources, and a credential for one communication resource corresponds to at least one of the attributes. The credentials for communication resources are in one-to-one correspondence with the communication resources. The transceiver unit 810 is also configured to send one or more attributes. If the terminal device does not possess a credential for the communication resource corresponding to the first attribute, the transceiver unit 810 is further configured to receive a credential for the communication resource corresponding to the first attribute. The first attribute belongs to one or more attributes.
[0360] Optionally, the processing unit 820 is used to determine one or more attributes based on the first attribute criterion.
[0361] Optionally, the first attribute criterion includes one or more of the following: the privacy level of the attribute, the priority of the attribute.
[0362] The fourth possible design is that the device 800 is a network device, or it can be a component of a network device (such as a chip, chip system, or circuit). The transceiver unit and the processing unit can be used to implement the relevant operations of the network device. The network device is, for example, a service-aware network element.
[0363] In one possible implementation, the transceiver unit 810 is configured to receive a first task, the first task including credentials for one or more communication resources, wherein the credentials for the communication resources correspond one-to-one with the communication resources; the transceiver unit 810 is further configured to obtain a first communication resource according to the first task, the first communication resource being used to execute the first task, wherein the first communication resource does not belong to one or more communication resources corresponding to the first task; the transceiver unit 810 is further configured to send the credentials for the first communication resource.
[0364] Optionally, the transceiver unit 810 is further configured to send a first communication resource creation request, the first communication resource creation request being used to request the creation of a first communication resource; the transceiver unit 810 is further configured to receive a first communication resource creation request response, the first communication resource creation request response indicating the credentials of the first communication resource.
[0365] Optionally, the transceiver unit 810 is also used for a first task response, which indicates whether the communication resources corresponding to the credentials of one or more communication resources have been configured.
[0366] It is understood that the division of units in the above-described device is merely a logical functional division. Each function can correspond to a functional unit, or two or more functions can be integrated into one functional unit. In actual implementation, all or some units can be integrated into a single physical entity, or they can be distributed across different physical entities. Furthermore, the aforementioned functional units can be implemented in hardware, software, or a combination of both. Whether a function is executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0367] In one example, the functional unit in any of the above devices may be one or more integrated circuits configured to implement the above methods, such as: one or more application-specific integrated circuits (ASICs), or one or more central processing units (CPUs), one or more microcontroller units (MCUs), one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.
[0368] In one example, the storage unit may include random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory and / or registers, etc.
[0369] Figure 9 is a schematic diagram of another communication device 900 provided in an embodiment of this application. The device 900 includes a processor 910, which is coupled to a memory 920. The memory 920 is used to store computer programs or instructions and / or data. The processor 910 is used to execute the computer programs or instructions stored in the memory 920, or to read the data stored in the memory 920, in order to execute the methods in the above method embodiments.
[0370] Optionally, there may be one or more processors 910.
[0371] Optionally, the memory 920 may be one or more.
[0372] Optionally, the memory 920 is integrated with the processor 910, or the memory 920 is built into the processor 910, or the memory 920 is set separately from the processor 910.
[0373] Optionally, as shown in FIG9, the device 900 further includes a transceiver 930 for receiving and / or transmitting signals. For example, the processor 910 is used to control the transceiver 930 to receive and / or transmit signals.
[0374] For example, processor 910 is used to execute computer programs or instructions stored in memory 920 to implement the relevant operations of terminal devices or network devices in the various method embodiments described above.
[0375] Optionally, the transceiver 930 includes a transmitter (or a transmitter module, a transmitting circuit, etc.) and / or a receiver (or a receiver module, a receiving circuit, etc.), wherein the transmitter is used to perform the transmitting operation in the above embodiments, and the receiver is used to perform the receiving operation in the above embodiments.
[0376] It should be noted that the communication device 900 may include a transmitter but not a receiver; or, the communication device 900 may include a receiver but not a transmitter. Specifically, it depends on whether the above-described scheme performed by the communication device 900 includes both transmitting and receiving actions. For example, the communication device 900 is used to perform the actions performed by various nodes (e.g., UE, SAF, IDM) in the embodiments shown in Figures 3 to 7. For details, please refer to the relevant descriptions in the embodiments shown in Figures 3 to 7, which will not be repeated here.
[0377] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0378] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0379] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0380] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0381] Figure 10 is a schematic block diagram of a chip system 1000 provided in an embodiment of this application. The chip system 1000 (or may also be referred to as a processing system) includes logic circuitry 1010 and an input / output interface 1020.
[0382] The logic circuit 1010 can be a processing circuit in the chip system 1000. The logic circuit 1010 can be coupled to a memory unit, calling instructions from the memory unit, enabling the chip system 1000 to implement the methods and functions of the embodiments of this application. The input / output interface 1020 can be an input / output circuit in the chip system 1000, outputting processed information from the chip system 1000, or inputting data or signaling information to be processed into the chip system 1000 for processing.
[0383] As one approach, the chip system 1000 is used to implement the operations performed by the communication device (such as a terminal device or a network device) in the various method embodiments described above.
[0384] For example, logic circuit 1010 is used to implement processing-related operations performed by a communication device (such as a terminal device or a network device) in the above method embodiments; input / output interface 1020 is used to implement sending and / or receiving-related operations performed by a communication device (such as a terminal device or a network device) in the above method embodiments.
[0385] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by a communication device (such as a terminal device or a network device) in the above-described method embodiments.
[0386] For example, when the computer program is executed by a computer, it enables the computer to implement the methods described in the embodiments of the above methods, which are executed by a communication device (such as a terminal device or a network device).
[0387] This application also provides a computer program product comprising instructions which, when executed by a computer, implement the methods described above as being performed by a communication device (such as a terminal device or a network device).
[0388] This application also provides a communication system, which includes the terminal devices and / or network devices described in the above embodiments.
[0389] The explanations and beneficial effects of the relevant contents in any of the devices provided above can be found in the corresponding method embodiments provided above, and will not be repeated here.
[0390] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of apparatus or units may be electrical, mechanical, or other forms.
[0391] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs). For example, the aforementioned available media include, but are not limited to, USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, and other media capable of storing program code.
[0392] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method, characterized in that, The method includes: Receive the first task; Determine one or more attributes corresponding to the first task, wherein any two of the one or more attributes correspond to the same communication resource credential or different communication resource credentials, and a communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credential corresponds one-to-one with the communication resource; Obtain credentials for one or more communication resources corresponding to the one or more attributes.
2. The method according to claim 1, characterized in that, The method further includes: Send credentials for the one or more communication resources; or, Send a certificate for a first communication resource, which is determined based on the one or more communication resources.
3. The method according to claim 2, characterized in that, The method further includes: The first criterion is used to determine whether to send the credentials for the first communication resource; The first criterion includes one or more of the following: the frequency of initiation of the first task, and the priority of the terminal device.
4. The method according to any one of claims 1 to 3, characterized in that, The credential for obtaining one or more communication resources corresponding to the one or more attributes includes: Send query information, the query information including one or more attributes, the query information requesting to obtain credentials for one or more communication resources.
5. The method according to any one of claims 1 to 3, characterized in that, The method for obtaining credentials for one or more communication resources corresponding to the one or more attributes further includes: Send a first communication resource creation request, the first communication resource creation request includes a first attribute, the first communication resource creation request is used to request the creation of a second communication resource, the credentials of the second communication resource correspond to the first attribute, and the first attribute belongs to one or more attributes.
6. The method according to any one of claims 1 to 3, characterized in that, The method for obtaining credentials for one or more communication resources corresponding to the one or more attributes further includes: Send a second communication resource creation request, the second communication resource creation request including information for creating a third communication resource, the second communication resource creation request being used to request the creation of the third communication resource, the credentials of the third communication resource corresponding to a second attribute, the second attribute belonging to one or more attributes.
7. A communication method, characterized in that, The method includes: Obtain one or more attributes of the terminal device, wherein any two of the one or more attributes correspond to the same or different communication resource credentials, and a communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credential corresponds one-to-one with the communication resource; Determine whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes; If the terminal device does not possess a credential for the communication resource corresponding to the first attribute, the credential for the communication resource corresponding to the first attribute is sent to the terminal device, wherein the first attribute belongs to one or more attributes.
8. The method according to claim 7, characterized in that, The acquisition of one or more attributes of the terminal device includes: Send a first request message to the terminal device, wherein the first request message requests to obtain one or more attributes; Receive a first request response message, wherein the first request response message indicates one or more attributes.
9. The method according to claim 7, characterized in that, The acquisition of one or more attributes of the terminal device includes: Send a second request message to the terminal device, the second request message requesting the terminal device to authorize the first node to determine whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes; Receive a second request response message, the second request response message indicating that the first node is allowed to determine whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes; The one or more attributes are obtained based on the second request response information.
10. The method according to any one of claims 7 to 9, characterized in that, The step of determining whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes includes: The terminal device obtains the credentials for the first communication resource and the attributes corresponding to the credentials for the first communication resource, and holds the credentials for the first communication resource. Based on the credentials of the first communication resource and the attributes corresponding to the credentials of the first communication resource, it is determined whether the terminal device holds the credentials of the communication resource corresponding to one or more attributes.
11. The method according to any one of claims 7 to 9, characterized in that, The step of determining whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes includes: Send query information, the query information including one or more attributes, the query information being used to query whether the terminal device holds credentials for the communication resources corresponding to the one or more attributes.
12. A communication method, characterized in that, The method is applied to a terminal device and includes: Receive a first request message, the first request message requests to obtain one or more attributes, any two of the one or more attributes correspond to the same communication resource credential or different communication resource credentials, a communication resource credential corresponds to at least one of the one or more attributes, and the communication resource credential corresponds one-to-one with the communication resource; Send one or more of the aforementioned attributes; If the terminal device does not possess a credential for the communication resource corresponding to the first attribute, it receives a credential for the communication resource corresponding to the first attribute, wherein the first attribute belongs to one or more attributes.
13. The method according to claim 12, characterized in that, include: The one or more attributes are determined based on the first attribute criterion; The first attribute criterion includes one or more of the following: the privacy level of the attribute, the priority of the attribute.
14. A communication method, characterized in that, The method includes: Receive a first task, the first task including one or more credentials for communication resources, wherein the credentials for the communication resources correspond one-to-one with the communication resources; Based on the first task, a first communication resource is obtained, the first communication resource is used to execute the first task, and the first communication resource does not belong to the one or more communication resources; Send the credentials for the first communication resource.
15. The method according to claim 14, characterized in that, The step of obtaining the first communication resource based on the first task includes: Send a first communication resource creation request, the first communication resource creation request being used to request the creation of the first communication resource; Receive a first communication resource creation request response, which indicates the credentials of the first communication resource.
16. The method according to any one of claims 1 to 15, characterized in that, The attributes include at least one of the following: user identity attribute, service identification attribute, communication attribute, location attribute, or visual attribute.
17. A communication device, characterized in that, include: A processor for executing computer programs or instructions stored in memory to cause the communication device to perform the method as described in any one of claims 1 to 16.
18. A computer program product, characterized in that, The computer program product includes programs or instructions for performing the method as described in any one of claims 1 to 16.
19. A computer-readable storage medium, characterized in that, include: The computer-readable storage medium stores a computer program that, when run on a computer, causes the computer to perform the method as described in any one of claims 1 to 16.