Information processing method, communication device, communication system and storage medium

WO2026165955A1PCT designated stage Publication Date: 2026-08-13BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2026-08-13

Smart Images

  • Figure CN2025076736_13082026_PF_FP_ABST
    Figure CN2025076736_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present disclosure are an information processing method, a communication device, a communication system and a storage medium. The information processing method is executed by a first device, and comprises: sending first information to a second device or a third device, wherein the first information is configured to trigger the verification of whether a user is associated with an avatar, the first information comprises a first identifier and a second identifier, the first identifier is configured to indicate the avatar, and the second identifier is configured to indicate the user.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing methods, communication equipment, communication systems and storage media Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to an information processing method, communication device, communication system and storage medium. Background Technology

[0002] In the field of communication technology, digital assets can be used across various applications and / or platforms, and digital assets can be represented by virtual identities (avatars). Summary of the Invention

[0003] The embodiments disclosed herein aim to address the problem of authorizing and verifying the virtual identities of users and their representatives in communication systems.

[0004] According to a first aspect of the present disclosure, an information processing method is proposed, executed by a first device, comprising: sending first information to a second device or a third device, wherein the first information is used to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0005] According to a second aspect of the present disclosure, an information processing method is proposed, executed by a second device, comprising: receiving first information sent by a first device, wherein the first information is used to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0006] According to a third aspect of the present disclosure, an information processing method is proposed, executed by a third device, comprising: receiving a first identifier and an image of a virtual identity sent by one of a first device, a second device, and a fourth device, wherein the first identifier is used to indicate the virtual identity; and determining whether the image of the virtual identity is real based on the first identifier and the image of the virtual identity.

[0007] According to a fourth aspect of the present disclosure, an information processing method is proposed, executed by a fourth device, comprising: receiving second information sent by a second device or seventh information sent by a third device; wherein the second information includes: a first identifier and an image of a virtual identity, the first identifier being used to indicate the virtual identity; the second information is used to obtain authorization information; the authorization information includes at least one of the following: first authorization information and second authorization information; the seventh information includes a first identifier and a second identifier, the second identifier being used to indicate a user; the seventh information is used to obtain the second authorization information.

[0008] According to a fifth aspect of the present disclosure, an information processing method is proposed, executed by a communication system, the communication system including a first device, a second device, and a third device; the information processing method includes: the first device sending first information to the second device or the third device, wherein the first information is used to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate a virtual identity, and the second identifier is used to indicate a user.

[0009] According to a sixth aspect of the present disclosure, a first device is provided, comprising: a first transceiver module configured to send first information to a second device or a third device, wherein the first information is used to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate a virtual identity, and the second identifier is used to indicate a user.

[0010] According to a seventh aspect of the present disclosure, a second device is provided, comprising: a second transceiver module configured to receive first information sent by a first device, wherein the first information is used by the second device to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate a virtual identity, and the second identifier is used to indicate a user.

[0011] According to an eighth aspect of the present disclosure, a third device is provided, comprising: a third transceiver module configured to receive a first identifier and an image of a virtual identity sent by one of a first device, a second device, and a fourth device, wherein the first identifier is used to indicate the virtual identity; and determining whether the image of the virtual identity is real based on the first identifier and the image of the virtual identity.

[0012] According to a ninth aspect of the present disclosure, a fourth device is provided, comprising: a fourth transceiver module configured to receive second information sent by a second device or seventh information sent by a third device; wherein the second information includes: a first identifier and an image of a virtual identity, the first identifier being used to indicate the virtual identity; the second information is used to obtain authorization information; the authorization information includes at least one of the following: first authorization information and second authorization information; the seventh information includes a first identifier and a second identifier, the second identifier being used to indicate a user; the seventh information is used to obtain the second authorization information.

[0013] According to a tenth aspect of the present disclosure, a communication device is provided, which is used to perform an optional implementation of the first aspect, the second aspect, the third aspect, the fourth aspect, or the first aspect, the second aspect, the third aspect, and the fourth aspect.

[0014] According to an eleventh aspect of the present disclosure, a communication system is provided, comprising: a first device, a second device, a third device, and a fourth aspect; wherein the first device is configured to perform a method as described in an optional implementation of the first aspect, the second device is configured to perform a method as described in an optional implementation of the second aspect, the third device is configured to perform a method as described in an optional implementation of the third aspect, and the fourth device is configured to perform a method as described in an optional implementation of the fourth aspect.

[0015] According to a twelfth aspect of the present disclosure, a storage medium is provided that stores instructions which, when executed on a communication device, cause the communication device to perform the method described in the first aspect, second aspect, third aspect, fourth aspect, or optional implementations of the first aspect, second aspect, third aspect, and fourth aspect.

[0016] According to a thirteenth aspect of the present disclosure, a program product is provided, including at least one of a program and instructions, wherein the program and instructions, when executed by a communication device, implement the method described in the first aspect, second aspect, third aspect, fourth aspect, or optional implementations of the first aspect, second aspect, third aspect, and fourth aspect.

[0017] The embodiments disclosed herein enable the authorization verification of users and virtual identities representing users in a communication system. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.

[0019] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0020] Figure 2A is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0021] Figure 2B is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0022] Figure 2C is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0023] Figure 2D is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0024] Figure 3 is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure.

[0025] Figure 4A is a schematic diagram illustrating a digital asset service architecture supporting metaverse applications according to an embodiment of this disclosure.

[0026] Figure 4B is a schematic diagram of a CAPIF functional model of a third-party API provider according to an embodiment of the present disclosure.

[0027] Figure 4C is a schematic flowchart illustrating an information processing method according to an embodiment of the present disclosure.

[0028] Figure 4D is a schematic flowchart illustrating an information processing method according to an embodiment of the present disclosure.

[0029] Figure 4E is a schematic flowchart illustrating an information processing method according to an embodiment of the present disclosure.

[0030] Figure 5A is a schematic diagram of the structure of a first device according to an embodiment of the present disclosure.

[0031] Figure 5B is a schematic diagram of the structure of a second device according to an embodiment of the present disclosure.

[0032] Figure 5C is a schematic diagram of the structure of a third device according to an embodiment of the present disclosure.

[0033] Figure 5D is a schematic diagram of the structure of a fourth device according to an embodiment of the present disclosure.

[0034] Figure 6A is a schematic diagram of the structure of a communication device provided according to an embodiment of the present disclosure.

[0035] Figure 6B is a schematic diagram of the structure of a chip provided according to an embodiment of the present disclosure. Detailed Implementation

[0036] This disclosure provides an information processing method, a communication device, a communication system, and a storage medium.

[0037] In a first aspect, embodiments of this disclosure propose an information processing method, executed by a first device, comprising: sending first information to a second device or a third device, wherein the first information is used to trigger verification of whether a user and a virtual identity are associated; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0038] In the above embodiments, authorization verification of the user and the virtual identity representing the user can be realized, thereby ensuring the legitimacy of the user using the virtual identity, reducing the occurrence of attackers impersonating authorized users to use virtual identities, and improving network communication security.

[0039] Furthermore, mapping the second device to the Common API Framework (CAPIF) can also accommodate the implementation of authorized users when using the CAPIF framework.

[0040] In conjunction with some embodiments of the first aspect, in some embodiments, verifying whether a user is associated with a virtual identity includes at least one of the following: verifying whether the virtual identity is used on behalf of the user; verifying whether the user is authorized to use the virtual identity.

[0041] In the above embodiments, it is possible to enable virtual identities to represent real users and / or for users to allow the use of virtual identities for verification, thereby reducing the possibility of attackers impersonating authorized users to use virtual identities.

[0042] In conjunction with some embodiments of the first aspect, in some embodiments, the first information further includes the image of the virtual identity; the first information is also used to trigger the authenticity of the image of the virtual identity.

[0043] In the above embodiments, the authenticity of the virtual identity image can be verified, thereby reducing the possibility that attackers can create their own virtual identity or virtual identity image by obtaining the virtual identity identifier, making it impossible for the other party to verify. This also reduces the possibility that the victim can access the virtual identity by forging the virtual identity image, thus improving the security of network communication.

[0044] In conjunction with some embodiments of the first aspect, in some embodiments, the first information further includes at least one of the following: a third identifier, wherein the third identifier is used to indicate the first device; a fourth identifier, wherein the fourth identifier is used to indicate the application requesting access; and location information, wherein the location information is used to indicate the location of the first device.

[0045] In the above embodiments, if the first information also includes a third identifier, the caller can be verified, reducing the possibility of the caller being impersonated; and / or if the first information also includes a fourth identifier, the application to be accessed can be verified, reducing the possibility of virtual identities being used in unauthorized applications.

[0046] Secondly, this disclosure provides an information processing method executed by a second device, comprising: receiving first information sent by a first device, wherein the first information is used by the second device to trigger verification of whether a user and a virtual identity are associated; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0047] In conjunction with some embodiments of the second aspect, in some embodiments, verifying whether a user is associated with a virtual identity includes at least one of the following: verifying whether the virtual identity is used on behalf of the user; verifying whether the user is authorized to use the virtual identity.

[0048] In conjunction with some embodiments of the second aspect, in some embodiments, the first information further includes at least one of the following: an image of a virtual identity; a third identifier, wherein the third identifier is used to indicate the first device; a fourth identifier, wherein the fourth identifier is used to indicate the application requesting access; and location information, wherein the location information is used to indicate the location of the first device.

[0049] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: sending second information to a fourth device, wherein the second information includes: a first identifier and an image of a virtual identity; the second information is used to obtain authorization information.

[0050] In the above embodiments, obtaining authorization information is beneficial for accurately determining whether the requested user, application, etc. are allowed based on the authorization information.

[0051] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: receiving third information sent by a fourth device, wherein the third information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; and first indication information, wherein the first indication information is used to indicate the reason for failure to obtain authorization information.

[0052] In conjunction with some embodiments of the second aspect, in some embodiments the method further includes: determining the authenticity of the virtual identity image based on a certificate from a third device.

[0053] In the above embodiments, the authenticity of the virtual identity can be verified in the second device without having to go to the third or fourth device for verification, thereby saving transmission resources that would otherwise be wasted by verifying the virtual identity through the third or fourth device.

[0054] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes one of the following: if it is determined that the image of the virtual identity is real, sending fourth information to a third device, the fourth information including a first identifier, a second identifier, and a fourth identifier, the fourth information being used to obtain authorization information; if it is determined that the image of the virtual identity is not real, sending second indication information to a first device, the second indication information being used to indicate verification failure; if it is impossible to determine whether the image of the virtual identity is real, sending fourth information to a third device, the fourth information including the image of the virtual identity, the fourth information also being used to request verification of whether the image of the virtual identity is real.

[0055] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes: receiving fifth information sent by a third device, wherein the fifth information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; first indication information, wherein the first indication information is used to indicate the reason for failure to obtain authorization information.

[0056] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes at least one of the following: verifying whether a user and a virtual identity are associated based on authorization information; and verifying whether the virtual identity is permitted to be used in the application indicated by the fourth identifier based on authorization information.

[0057] Thirdly, this disclosure provides an information processing method executed by a third device, comprising: receiving a first identifier and an image of a virtual identity and a fourth identifier sent by one of a first device, a second device, and a fourth device, wherein the first identifier is used to indicate the virtual identity; and determining whether the image of the virtual identity is real based on the first identifier and the image of the virtual identity.

[0058] In conjunction with some embodiments of the third aspect, in some embodiments, receiving the image of the first identifier and virtual identity sent by one of the first device, the second device, and the fourth device includes one of the following: receiving first information sent by the first device, wherein the first information includes the image of the first identifier and the virtual identity; receiving fourth information sent by the second device, wherein the fourth information includes the image of the first identifier and the virtual identity; receiving sixth information sent by the fourth device, wherein the sixth information includes the image of the first identifier and the virtual identity.

[0059] In conjunction with some embodiments of the third aspect, in some embodiments, the first information further includes at least one of the following: a second identifier and a fourth identifier; the second identifier is used to indicate a user; the fourth identifier is used to indicate an application requesting access; the first information is also used to request at least one of the following: verifying whether the user and the virtual identity are associated, and whether the virtual identity is allowed to use the application indicated by the fourth identifier; or, the fourth information further includes the second identifier and the fourth identifier; the fourth information is also used to obtain authorization information, the authorization information including first authorization information and second authorization information, the first authorization information being stored in a third device, and the second authorization information being stored in a fourth device; or, the sixth information is also used to obtain the first authorization information.

[0060] In conjunction with some embodiments of the third aspect, in some embodiments, the fourth information is sent when the second device determines that the image of the virtual identity is real; or, the fourth information is sent when the second device cannot determine whether the image of the virtual identity is real; or, the sixth information is sent when the fourth device cannot determine that the image of the virtual identity is real; or, the sixth information is sent when the fourth device determines that the second authorization information is unavailable.

[0061] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes: sending first authorization information to a fourth device.

[0062] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes: sending seventh information to a fourth device, wherein the seventh information includes a first identifier, a second identifier, and a fourth identifier, and the seventh information is used to obtain second authorization information; and receiving the second authorization information sent by the fourth device.

[0063] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes: sending fifth information to a second device, wherein the fifth information is determined based on the fourth information; the fifth information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is authentic; first indication information, wherein the first indication information is used to indicate the reason for failure to obtain authorization information.

[0064] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes at least one of the following: verifying whether a user and a virtual identity are associated based on authorization information; and verifying whether the virtual identity is permitted to use an application indicated by a fourth identifier based on authorization information.

[0065] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes: the user is associated with a virtual identity, and sending first information to a second device.

[0066] Fourthly, this disclosure provides an information processing method executed by a fourth device, comprising: receiving second information sent by a second device or seventh information sent by a third device; wherein the second information includes: a first identifier and an image of a virtual identity and a fourth identifier, the first identifier being used to indicate the virtual identity; the second information is used to obtain authorization information; the authorization information includes at least one of the following: first authorization information and second authorization information; the seventh information includes a first identifier and a second identifier, the second identifier being used to indicate the user; the seventh information is used to obtain the second authorization information.

[0067] In conjunction with some embodiments of the fourth aspect, in some embodiments, the method further includes one of the following: determining whether the image of the virtual identity is real based on the certificate of the third device; if it is impossible to determine whether the image of the virtual identity is real, sending sixth information to the third device, the sixth information including a first identifier, the image of the virtual identity, and a fourth identifier, the sixth information being used to request at least one of the following: first authorization information, and verification of whether the image of the virtual identity is real; if the second authorization information is unavailable, sending sixth information to the third device, the sixth information including a first identifier, the image of the virtual identity, and a fourth identifier, the sixth information being used to obtain the first authorization information.

[0068] In conjunction with some embodiments of the fourth aspect, in some embodiments, the method further includes: receiving first authorization information sent by a third device.

[0069] In conjunction with some embodiments of the fourth aspect, in some embodiments, the method further includes: sending third information to the second device, wherein the third information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; first indication information, wherein the first indication information is used to indicate the reason for the failure to obtain authorization information.

[0070] In conjunction with some embodiments of the fourth aspect, in some embodiments the method further includes: sending second authorization information to a third device.

[0071] Fifthly, this disclosure provides an information processing method executed by a communication system, the communication system including a first device, a second device, and a third device; the information processing method includes: the first device sending first information to the second device or the third device, wherein the first information is used to trigger verification of whether a user and a virtual identity are associated; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0072] In a sixth aspect, embodiments of this disclosure provide a first device, comprising: a first transceiver module configured to send first information to a second device or a third device, wherein the first information is used to trigger verification of whether a user and a virtual identity are associated; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0073] In a seventh aspect, embodiments of this disclosure provide a second device, comprising: a second transceiver module configured to receive first information sent by a first device, wherein the first information includes a first identifier and a second identifier; the first identifier is used to indicate a virtual identity, and the second identifier is used to indicate a user; wherein the first information is used by the second device to trigger verification of whether the user and the virtual identity are associated.

[0074] Eighthly, embodiments of this disclosure provide a third device, including: a third transceiver module configured to receive a first identifier and an image of a virtual identity sent by one of a first device, a second device, and a fourth device, wherein the first identifier is used to indicate the virtual identity; and based on the first identifier and the image of the virtual identity, determining whether the image of the virtual identity is real.

[0075] In a ninth aspect, embodiments of this disclosure provide a fourth device, comprising: a fourth transceiver module configured to receive second information sent by a second device or seventh information sent by a third device; wherein the second information includes: a first identifier and an image of a virtual identity, the first identifier being used to indicate the virtual identity; the second information is used to obtain authorization information; the authorization information includes at least one of the following: first authorization information and second authorization information; the seventh information includes a first identifier and a second identifier, the second identifier being used to indicate a user; the seventh information is used to obtain the second authorization information.

[0076] In a tenth aspect, embodiments of this disclosure provide a communication device for performing the first aspect, the second aspect, the third aspect, the fourth aspect, or optional implementations of the first aspect, the second aspect, the third aspect, and the fourth aspect.

[0077] Eleventhly, embodiments of this disclosure provide a communication system, including: a first device, a second device, a third device, and a fourth aspect; wherein the first device is configured to perform the method described in the optional implementation of the first aspect, the second device is configured to perform the method described in the optional implementation of the second aspect, the third device is configured to perform the method described in the optional implementation of the third aspect, and the fourth device is configured to perform the method described in the optional implementation of the fourth aspect.

[0078] In a twelfth aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect, second aspect, third aspect, fourth aspect, or optional implementations of the first aspect, second aspect, third aspect, and fourth aspect.

[0079] In a thirteenth aspect, embodiments of this disclosure provide a program product including at least one of a program and instructions, wherein the program and instructions, when executed by a communication device, implement the method described in the first aspect, second aspect, third aspect, fourth aspect, or optional implementations of the first aspect, second aspect, third aspect, and fourth aspect.

[0080] In a fourteenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the information processing method as described in the first aspect, second aspect, third aspect, fourth aspect, or optional implementations of the first aspect, second aspect, third aspect, and fourth aspect.

[0081] In a fifteenth aspect, embodiments of this disclosure provide a chip or chip system including processing circuitry configured to perform the methods described according to the first, second, third, and fourth aspects, or alternative implementations of the first, second, third, and fourth aspects.

[0082] It is understood that the aforementioned devices (such as the first device, second device, third device, fourth aspect, etc.), communication systems, storage media, program products, etc., are all used to execute the methods provided in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0083] This disclosure provides an information processing method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "information processing method" and "information processing method" may be used interchangeably.

[0084] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments. In all embodiments of this disclosure, unless otherwise specified or logically conflicting, the terminology and / or descriptions between the embodiments are consistent and can be mutually utilized. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0085] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0086] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.

[0087] In the embodiments disclosed herein, "multiple" refers to two or more.

[0088] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0089] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.

[0090] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.

[0091] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0092] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0093] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.

[0094] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.

[0095] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0096] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.

[0097] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).

[0098] In some embodiments, the terms "access network device (AN device)," "radio access network device (RAN device)," "base station (BS)," "radio base station," "fixed station," "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," and "bandwidth part (BWP)" can be used interchangeably.

[0099] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.

[0100] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.

[0101] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.

[0102] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0103] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0104] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0105] Figure 1 is a schematic diagram of the architecture of a communication system 100 according to an embodiment of the present disclosure. As shown in Figure 1, the communication system 100 includes: a terminal 101, an access network device 102, and a core network device 103.

[0106] In some embodiments, terminal 101 includes, for example, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home, but is not limited thereto.

[0107] In some embodiments, the access network device 102 may be a node or device that connects a terminal to a wireless network. The access network device may include at least one of the following in a 5G communication system: an evolved Node B (eNB), a next-generation eNB (ng-eNB), a next-generation Node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open RAN, a cloud RAN, a base station in other communication systems, and an access node in a Wi-Fi system, but is not limited thereto.

[0108] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0109] In some embodiments, the technical solutions of this disclosure can be applied to a service-based RAN architecture. In this case, the interfaces between access network devices or between access network devices and core network devices involved in the embodiments of this disclosure can be service-based interfaces. The processes and information interactions between these interfaces can be implemented by software or programs that call one or more corresponding services.

[0110] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0111] In some embodiments, terminal 101 may include a first device 1031 or other devices.

[0112] In some embodiments, the core network device 103 may be a single device, including a second device 1032, a third device 1033, a fourth device 1034, or a fifth device 1035, or it may be multiple devices or a group of devices, including all or some of the aforementioned second device 1032, third device 1033, fourth device 1034, and fifth device 1035. The devices may be virtual or physical. The core network may include, for example, at least one of the following: Evolved Packet Core (EPC), 5G Core Network (5GCN), Next Generation Core (NGC), and 6G Core Network (6GCN). At least two of the first device 1031, second device 1032, third device 1033, fourth device 1034, and fifth device 1035 may be interconnected, and the connection between the first device 1031, second device 1032, third device 1033, fourth device 1034, and fifth device 1035 may not be limited to the connection shown in FIG1.

[0113] In some embodiments, the first device 1031 may refer to an API invoker, API requester, or application client.

[0114] In some embodiments, the first device 1031 is used to request or invoke a service API to perform corresponding operations or request application services, and the name is not limited thereto.

[0115] For example, the first device 1031 may be at least one of the following: a caller or requester or client in the UE client, a caller or requester of the Metaverse Application Service API in the UE, a Metaverse Application Service client in the UE, etc.

[0116] Exemplary API callers can be terminals or user interfaces (UEs), or applications (such as browsers) running on terminals or UEs, or public accounts or mini-programs, or application functions, or application servers, or servers belonging to third parties (such as Company A, operator B, or platform C).

[0117] In some embodiments, the second device 1032 is, for example, a Vertical Application Layer (VAL) server.

[0118] In some embodiments, the second device 1032 is used for API opening functions or for providing application services, and the name is not limited thereto.

[0119] For example, the second device 1032 may be an application server or a metaverse application server.

[0120] For example, the second device 1032 can be mapped to an API Invoker within the Common API Framework (CAPIF) architecture.

[0121] For example, the second device 1032 can be mapped to an API Exposing Function (AEF) within the Common API Framework (CAPIF) architecture.

[0122] In some embodiments, the third device 1033 is a Service Enabler Architecture Layer (SEAL) or a server related to digital assets (DA), etc., and the name is not limited thereto.

[0123] For example, the third device 1033 may be a DA server, etc.

[0124] For example, the third device 1033 can be mapped to an API Exposing Function (AEF) within the Common API Framework (CAPIF) architecture.

[0125] In some embodiments, the fourth device 1034 may be a Universal Application Programming Interface Framework core function (CAPIF core function, CCF) or a licensing function, etc.

[0126] In some embodiments, the fourth device 1034 is any network element, function, or entity in the core network of the CAPIF system, or it may be any network element, function, or entity in the core network used for functions such as authorization, etc., and the name is not limited thereto.

[0127] In some embodiments, the fifth device 1035 is used for authentication and / or authorization, etc., and the name is not limited thereto.

[0128] In some embodiments, the fifth device 1035 may be an authentication server, an authorization server, or a network management function, etc.

[0129] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions provided in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in this disclosure are also applicable to similar technical problems.

[0130] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. ​​The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0131] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future generation Radio Access (FX), Global System for Mobile Communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0132] In some embodiments, virtual identities (avatars) are digital representations of a user's interactions with the metaverse and other users. The Service Enablement Architecture Layer (SEAL) enables the creation, discovery, and / or management of users' virtual identity profiles to offload applications and implement core network functionality across service and vertical application layers (VALs). The metaverse support service provides mechanisms for creating, updating, acquiring, and / or discovering virtual identities as digital assets. Most metaverse applications require avatars for users to interact with the application. Furthermore, users can seamlessly move between metaverse applications using the same virtual identity, taking into account the constraints of the applications accessed.

[0133] Without verification of virtual identities, attackers can forge them to impersonate users represented by legitimate virtual identities. For example, an attacker can download another user's avatar or generate their own by copying and pasting another user's avatar, and use the avatar to impersonate themselves when interacting with the metaverse and other users. Such attacks cannot be detected as long as the association between the virtual identity and the user represented by it cannot be verified within the mobile metaverse service. The attacker can then manipulate the forged / copied virtual identity within the mobile metaverse service to launch further types of attacks. Even though the unique identifier of the legitimate virtual identity may change from time to time, attackers can still launch such attacks within the identifier's validity period.

[0134] Authentication and authorization of digital representations (e.g., virtual identities) with their unique identifiers. Communication systems are required to provide means to support the verification of digital representations on behalf of users in mobile metaverse services, and to provide means to support the authorization of users using digital representations (virtual identities) in mobile metaverse services. Therefore, it is necessary to investigate a method for mobile communication systems to verify digital representations (virtual identities) on behalf of users and to authorize users when using virtual identities representing them.

[0135] In some embodiments, the UE can be a terminal, or the terminal can be a UE.

[0136] Figure 2A is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 2A, this embodiment of the present disclosure relates to an information processing method used in a communication system 100, the method comprising:

[0137] Step S2101: The first device sends first information to the second or third device.

[0138] In some embodiments, the first device sends first information to the second device.

[0139] In some embodiments, the second device receives the first information sent by the first device.

[0140] In some embodiments, the first device sends first information to the third device.

[0141] In some embodiments, the third device receives the first information sent by the first device.

[0142] Optionally, the first information includes at least one of the following: a first identifier, a second identifier, the image of the virtual identity, a third identifier, a fourth identifier, a fifth identifier, and location information.

[0143] For example, a first identifier is used to indicate a virtual identity. For instance, a first identifier is used to indicate a virtual identity for which verification is requested. For example, a virtual identity (avatar) can be replaced by a digital asset, a digitally represented virtual character, a virtual image, an avatar, a substitute, a user representative image, or an online profile picture, etc. Here, there can be one or more first identifiers, with one first identifier indicating one virtual identity; or the first identifier can be replaced by a list of virtual identity identifiers or a list of first identifiers, both of which can include one or more first identifiers; thus, one or more virtual identities associated with or corresponding to a user can be verified.

[0144] For example, the second identifier is used to indicate a user. For instance, the second identifier is used to indicate a user requesting verification. Here, there can be one or more second identifiers, with one second identifier indicating one user; or the second identifier can be replaced by a first user identifier list or a second identifier list, both of which can include one or more second identifiers; thus, one or more users associated with or corresponding to a virtual identity can be verified.

[0145] For example, the first information including the image of the virtual identity can be replaced with: the first information including information indicating or describing the image of the virtual identity; or, the first information can be used to indicate the image of the virtual identity.

[0146] For example, the image of a virtual identity can be replaced by an avatar object, a digital asset object, an avatar object, a virtual character object, a replacement object, a user representative image object, or an online avatar object, etc. For example, the image of a virtual identity can be a cartoon virtual photo or multimedia animation, or a virtual photo, avatar, or multimedia animation that can represent the user, etc. Here, the first information may not include the image of the virtual identity or may include the image of the virtual identity; when the first information does not include the image of the virtual identity, if the second device or the third device receives the first information, it can obtain the image of the virtual identity corresponding to the virtual identity based on the first identifier. For example, the first information may include a cartoon photo, a virtual identity avatar, or a multimedia animation, etc.

[0147] For example, a third identifier is used to indicate a first device. For instance, a third identifier is used to indicate a first device requesting application services or authorization verification. For instance, a third identifier is used by a requester client requesting application services or authorization verification. For instance, a third identifier is used by a caller client requesting application services or authorization verification. Here, there can be one or more third identifiers, with one third identifier indicating one first device; or the third identifier can be replaced by a list of first client identifiers or a list of third identifiers, where either a client list or a list of third identifiers may include one or more third identifiers.

[0148] For example, the third identifier is used to indicate a client, caller, or requester in the first device.

[0149] For example, the fourth identifier is used to indicate the application requesting access or verification. For instance, the application can be a metaverse app, a metaverse service API, or an application other than a metaverse app; the metaverse service API is an API related to a metaverse app or metaverse service, etc. Here, there can be one or more fourth identifiers, with one fourth identifier indicating one application; or, the fourth identifier can be replaced by a first application identifier list or a fourth identifier list, both of which can include one or more fourth identifiers; thus, a virtual identity management system or one or more corresponding applications can be verified. In some embodiments of this disclosure, metaverse apps and metaverse services can be interchangeable. Metaverse apps or metaverse services can be services provided by the application layer, etc.

[0150] For example, the fifth identifier is used to indicate a business API. For instance, this business API could be a metaverse business API. For instance, the fifth identifier is used to indicate a business API used for authorization or verification. Here, there can be one or more fifth identifiers, with one fifth identifier indicating one business API; or, the fifth identifier can be replaced by a first list of business API identifiers or a list of fifth identifiers, both of which can include one or more fifth identifiers; this allows verification that a virtual identity can be invoked or used through one or more business APIs.

[0151] For example, location information is used to indicate the location of a first device. For instance, location information can be used to indicate the location of a first device requesting authorization or verification; if the location indicated by the location information is successfully authorized or verified, the first device is permitted to use the virtual object while at the location indicated by the location information.

[0152] Optionally, the first information includes a first identifier and a second identifier, and the first information is used to trigger verification of whether the user and the virtual identity are associated. For example, verifying whether the user and the virtual identity are associated may include one of the following: verifying that the user and the virtual identity are associated, or verifying that the user and the virtual identity are not associated.

[0153] For example, the first information is used to request verification of whether the user is associated with the virtual identity.

[0154] For example, the first information is used to request a determination of whether the user is associated with the virtual object.

[0155] For example, verifying whether a user and a virtual identity are associated includes at least one of the following: verifying whether the virtual identity is used to represent the user; verifying whether the user is authorized to use the virtual identity. For instance, first information is used to trigger verification of at least one of the following: verifying whether the virtual identity is used to represent the user; verifying whether the user is authorized to use the virtual identity. For instance, verifying whether the virtual identity is used to represent the user may include one of the following: verifying that the virtual identity can be used to represent the user, or verifying that the virtual identity cannot represent the user. For instance, verifying whether the user is authorized to use the virtual identity may include one of the following: verifying that the user is authorized to use the virtual identity, or verifying that the user is not authorized to use the virtual identity.

[0156] For example, verifying whether a user is authorized to use a virtual identity can be replaced by verifying whether the user is authorized to use a virtual identity.

[0157] Optionally, the first information includes a first identifier and the image of the virtual identity, and the first information is used to trigger verification of the authenticity of the image of the virtual identity. Here, verifying the authenticity of the image of the virtual identity means verifying whether the image of the virtual identity is real.

[0158] For example, the first information is used to request the authenticity of the virtual identity's image.

[0159] For example, the first information is used to request the verification of the authenticity of the virtual identity.

[0160] For example, verifying or determining the authenticity of a virtual identity image means: verifying or determining that the virtual identity image was created by an entity authorized to create virtual identities, or created by an entity authorized to create virtual identities; or verifying or determining whether the received virtual identity image is consistent with or associated with the real virtual identity image; or verifying or determining that the digital signature of the virtual identity image is valid. For example, the authenticity of a virtual identity image may include one of the following: verifying that the virtual identity image is real, or verifying that the virtual identity image is not real. For example, the authenticity of a virtual identity image may include one of the following: verifying that the digital signature of the virtual identity image indicated by the first identifier is valid, verifying that the virtual identity indicated by the first identifier is associated with the virtual identity image, or verifying that the virtual identity indicated by the first identifier is not associated with the virtual identity image.

[0161] Optionally, the first information may also include a fourth identifier, which is used to trigger verification of whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0162] For example, the first information is used to request verification of whether the virtual identity is allowed to be used in the application indicated by the fourth identity.

[0163] For example, the first information is used to determine whether the virtual identity is permitted to be used in the application indicated by the fourth identity.

[0164] For example, verifying or determining whether a virtual identity is permitted for use in an application indicated by a fourth identity may be done by verifying or determining whether the application indicated by the fourth identity is permitted or authorized to use a virtual identity replacement.

[0165] For example, verifying or determining whether a virtual identity is permitted to be used in the application indicated by the fourth identity includes one of the following: verifying or determining that the virtual identity is permitted to be used in the application indicated by the fourth identity, or verifying or determining that the virtual identity is not permitted to be used in the application indicated by the fourth identity.

[0166] Optionally, the first information may include a fifth identifier, which is used to request authorization to invoke a business API. For example, invoking a business API to perform operations related to the virtual identity.

[0167] Optionally, the first device sends first information to the second device. The first information includes a first identifier and a second identifier. The first information is used to trigger verification of whether the user and the virtual identity are associated. Optionally, the first information may also include the image of the virtual identity. The first information is also used to trigger verification of the authenticity of the image of the virtual identity.

[0168] Optionally, the first device sends first information to the third device. The first information includes a first identifier and a second identifier. The first information is used to trigger verification of whether the user and the virtual identity are associated. Optionally, the first information may also include the image of the virtual identity. The first information is also used to trigger verification of the authenticity of the image of the virtual identity.

[0169] In some embodiments, the first information may be an API call request message, an API call request, or a metaverse service API invocation request message, etc.; the API call request may be a metaverse service API invocation request. Alternatively, the first device sends an API call request message to a second or third device, and the API call request message includes the first information.

[0170] In some embodiments, the first information, the first identifier, the second identifier, the image of the virtual identity, the third identifier, the fourth identifier, and the fifth identifier can all be a string; the string may include one or more letters, numbers, and / or symbols, etc.

[0171] In some embodiments, the names of the first information, the first identifier, the second identifier, the image of the virtual identity, the third identifier, the fourth identifier, and the fifth identifier are not limited; for example, the first information may be business API call request information or authorization request information, etc.; the first identifier may be a user identifier; the second identifier may be a virtual identity identifier; the third identifier may be a client identifier, a requester identifier, or a caller identifier, etc.; the fourth identifier may be an application identifier; and the fifth identifier may be a business API identifier, etc.

[0172] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transfer,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.

[0173] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "bit", and "data" can be used interchangeably.

[0174] In some embodiments, terms such as "certain", "preset", "specified", "default", "set", "indicated", "a certain", "any", and "first" can be used interchangeably. "Certain A", "preset A", "specified A", "default A", "set A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, specified A, a certain A, any A, or first A, but are not limited thereto.

[0175] In step S2102, the second device sends the second information to the fourth device.

[0176] In some embodiments, the fourth device receives second information sent by the second device.

[0177] Optionally, the second information may include: the first identifier and the image of the virtual identity. Optionally, the second information may also include at least one of the following: a second identifier, a fifth identifier, a third identifier, a fourth identifier, and location information.

[0178] Optionally, the second information includes the first identifier and the image of the virtual identity, and the second information is used to obtain authorization information. Here, the authorization information is sent by the fourth device after determining that the image of the virtual identity is real. For example, the second information is used to request authorization information.

[0179] For example, the authorization information may include at least one of the following: first authorization information and second authorization information. Here, the first authorization information may be stored on a third device or obtained by the third device from other devices; the second authorization information may be stored on a fourth device or obtained by the fourth device from other devices.

[0180] Optionally, the second information may be an authorization information request or an authorization information request message, etc. Alternatively, the second device may send an authorization information request message to the fourth device, and the authorization information request message may include the second information.

[0181] Optionally, the name of the second information is not limited; it may be, for example, authorization information or request information.

[0182] In some alternative embodiments, the fourth device verifies or determines whether the virtual identity is real based on a certificate.

[0183] In some alternative embodiments, the fourth device verifies or determines whether the virtual identity is authentic based on the certificate of the third device. Here, the fourth device can obtain the certificate from the third device, or the certificate can be configured for it.

[0184] Optionally, determining whether the virtual identity's appearance is real includes: determining that the virtual identity's appearance is real, and determining that the virtual identity's appearance is not real. Optionally, the fourth device verifies whether the virtual identity's appearance is real based on a certificate.

[0185] Optionally, the certificate can be generated by a third device; for example, when the third device determines the image of the virtual identity associated with the first identifier, it can generate a certificate to verify the association between the first identifier and the image of the virtual identity (i.e., generate a certificate to verify whether the image of the virtual identity is real).

[0186] Optionally, the fourth device determines that the image of the virtual identity is real based on the first identifier and the image of the virtual identity included in the certificate and the second information; or, the fourth device determines that the image of the virtual identity is not real based on the first identifier and the image of the virtual identity included in the certificate and the second information.

[0187] In some embodiments, the fourth device sends a first message to the third device, the first message being used to request a certificate; the fourth device receives a first response from the third device, the first response including a certificate.

[0188] Optionally, the names of the first message and the first response can be unrestricted; for example, the first message may be a certificate request; or the first response may be a certificate response.

[0189] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomously implementing, among other meanings.

[0190] In step S2103, the fourth device sends the sixth information to the third device.

[0191] In some embodiments, the third device receives sixth information sent by the fourth device.

[0192] Optionally, the sixth information may include the first identifier. Optionally, the sixth information may also include at least one of the following: the image of the virtual identity, the second identifier, the fifth identifier, the third identifier, the fourth identifier, and location information.

[0193] Optionally, the sixth information includes a first identifier, and the sixth information is used to obtain the first authorization information. For example, the sixth information is used to request the first authorization information.

[0194] Optionally, the sixth information includes the first identifier and the image of the virtual identity, and the sixth information is used to request at least one of the following: first authorization information, and to verify whether the image of the virtual identity is real.

[0195] Optionally, the name of the sixth piece of information is not limited; it may be, for example, authorization request information or verification request information.

[0196] In some embodiments, if the fourth device determines that the image of the virtual identity is real, it sends sixth information to the third device. Optionally, the sixth information includes the first identifier and the image of the virtual identity, and the sixth information is used to obtain the first authorization information. Here, the fourth device only obtains the authorization information when it determines that the virtual identity is real; otherwise, if it determines that the virtual identity is not real, there is no need to return the authorization information to the second device.

[0197] In some embodiments, the third device receives a sixth message sent by the fourth device, the sixth message being the fourth device's determination that the virtual identity of the first identifier is real.

[0198] In some embodiments, if the fourth device cannot determine whether the image of the virtual identity is genuine, it sends a sixth message to the third device. Optionally, the sixth message includes a first identifier and the image of the virtual identity; the sixth message is used to request: first authorization information, and to verify whether the image of the virtual identity is genuine. Here, if the fourth device has not obtained the certificate sent by the third device or the certificate has expired, it may be unable to determine whether the image of the virtual identity is genuine.

[0199] In some embodiments, the third device receives a sixth message sent by the fourth device, the sixth message being sent when the fourth device cannot determine whether the image of the virtual identity is real.

[0200] In some embodiments, if the second authorization information is unavailable, the fourth device sends sixth information to the third device. Optionally, the sixth information includes a first identifier and an image of the virtual identity, and is used to obtain the first authorization information. Optionally, the sixth information can also be used to request verification of whether the image of the virtual identity is real. Here, when its own second authorization information is unavailable, the fourth device may request the third device to store the first authorization information; typically, the second authorization information stored by the fourth device may include the first authorization information stored in the third device; of course, in some cases, the content included in the first authorization information and the second authorization information may be at least partially the same or at least partially different.

[0201] In step S2104, the third device sends the first authorization information to the fourth device.

[0202] In some embodiments, the fourth device receives first authorization information sent by the third device.

[0203] In some alternative embodiments, prior to step S2104, the method may further include: a third device determining whether the image of the virtual identity is real.

[0204] Optionally, the third device determines whether the image of the virtual identity is real based on the image of the first identifier and the virtual identity included in the sixth information, as well as the stored local information. The third device may be the image of the first identifier and the corresponding or associated virtual identity stored when the image of the first identifier and the virtual identity were generated. Here, since the third device itself generates or stores the image of the first identifier and the corresponding or associated virtual identity, it can directly determine whether the image of the virtual identity in the sixth information is real without verification.

[0205] Optionally, if the third device determines that the image of the virtual identity in the sixth information is real, it sends the first authorization information to the fourth device.

[0206] Optionally, after determining that the virtual identity is authentic, the third device further determines, based on the fourth identifier included in the sixth information, whether the application indicated by the fourth identifier is an allowed application; if it determines that the application indicated by the fourth identifier is an allowed application, it sends the first authorization information to the fourth device. For example, the third device can determine whether the application indicated by the fourth identifier is an allowed application based on the fourth identifier and the content shown in Table 1. Optionally, if the third device determines that the application indicated by the fourth identifier is not an allowed application, it may not send the first authorization information to the fourth device.

[0207] Optionally, the first authorization information can be a configuration file of a third device, such as a DA service profile or asset configuration file. The first authorization information may be as shown in Table 1, including at least one of the following: digital asset owner identifier, digital asset type, list of metaverse service provider identifiers, access control list, list of allowed users, allowed operations, list of prediction models, spatial conditions, current location, list of allowed applications, related accessories, and expiration time. Optionally, the first authorization information, second authorization information, and authorization information may include at least some of the information shown in Table 1, as well as other information not shown in Table 1.

[0208] Table 1

[0209] Optionally, the first authorization information, the second authorization information, and the authorization information may each include at least one of the following: the sixth identifier, the seventh identifier, the eighth identifier, and the operation instructions.

[0210] For example, the sixth identifier is used to indicate a permitted (or authorized) client, requester, or caller, etc. There can be one or more sixth identifiers; one sixth identifier indicates a client, requester, or caller. Alternatively, the sixth identifier can be replaced by a second list of client identifiers, which includes one or more sixth identifiers.

[0211] For example, the seventh identifier is used to indicate an authorized (or permitted) user. There can be one or more seventh identifiers, with one seventh identifier indicating one user; or, the seventh identifier can be replaced by a second list of user identifiers, which includes one or more seventh identifiers.

[0212] For example, the eighth identifier is used to indicate a permitted (or authorized) application. There can be one or more eighth identifiers, with one eighth identifier indicating an application (e.g., a metaverse application); or, the eighth identifier can be replaced by a second list of application identifiers, which may include one or more application identifiers.

[0213] For example, an operation instruction is used to indicate an operation. There can be one or more operation instructions, with one operation instruction indicating one operation. Operations may include: discovering, obtaining, updating, deleting, reading, retrieving, and / or invoking virtual identities.

[0214] Optionally, the sixth identifier, the seventh identifier, the eighth label, and the operation instruction can all be a string; the string may include one or more letters, numbers, and / or symbols, etc.

[0215] Optionally, the names of the sixth, seventh, and eighth identifiers, as well as the operation instructions, are not restricted; for example, the sixth identifier can be a client identifier, a requester identifier, or a caller identifier, etc.; the seventh identifier can be a user identifier, etc.; and the eighth identifier can be an application identifier, etc.

[0216] In step S2105, the fourth device sends the third information to the second device.

[0217] In some embodiments, the second device receives third information sent by the fourth device.

[0218] In some embodiments, the third information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; and first indication information, wherein the first indication information is used to indicate the reason for the failure to obtain the authorization information. Optionally, the first indication information is sent after the fourth device determines that the image of the virtual identity is not real, and the first indication information is sent by the fourth device after determining that the image of the virtual identity is not real through the third device.

[0219] Optionally, the name of the first indication information is not limited, and it may be, for example, an indication of failure to obtain authorization information or an indication of the reason for failure.

[0220] Optionally, the name of the third information is not limited; it may be, for example, authorization information, response information, or verification response information.

[0221] Optionally, the fourth device verifies that the image of the virtual identity is real, or determines that the image of the virtual identity is real through the third device, and sends third information to the second device, which includes authorization information.

[0222] Optionally, the second device receives third information sent by the fourth device. The third information includes authorization information and is sent by the fourth device after determining that the image of the virtual identity is real or after the third device has determined that the image of the virtual identity is real.

[0223] Optionally, if the fourth device verifies that the image of the virtual identity is not real, or if the third device determines that the image of the virtual identity is not real, it sends third information to the second device, the third information including the first instruction information.

[0224] Optionally, the second device receives third information sent by the fourth device. The third information includes the first indication information. The third information is sent by the fourth device after determining that the image of the virtual identity is not real or after the third device determines that the image of the virtual identity is not real.

[0225] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values ​​(e.g., a comparison with a predetermined value), but is not limited thereto.

[0226] In some alternative embodiments, the second device verifies or determines the authenticity of the virtual identity based on a certificate.

[0227] In some alternative embodiments, the second device verifies or determines the authenticity of the virtual identity based on the certificate of the third device. Here, the second device can obtain the certificate from the third device, or the certificate can be configured for it.

[0228] Optionally, determining the authenticity of a virtual identity can mean: determining that the image of the virtual identity is real.

[0229] Optionally, the certificate can be generated by a third device. Here, the second device can act as an API caller or requester, and can directly request the certificate from the third device.

[0230] Optionally, the second device determines that the image of the virtual identity is real based on the certificate, the first identifier included in the second information, and the image of the virtual identity; or, the second device determines that the image of the virtual identity is not real based on the certificate, the first identifier included in the second information, and the image of the virtual identity.

[0231] In some embodiments, the second device sends a second message to the third device, the second message being used to request a certificate; the second device receives a second response from the third device, the second response including the certificate.

[0232] Optionally, the names of the second message and the second response are not restricted; for example, the second message is a certificate request; for example, the second response is a certificate response.

[0233] In step S2106, the second device sends the fourth information to the third device.

[0234] In some embodiments, the third device receives fourth information sent by the second device.

[0235] Optionally, the fourth information includes the first identifier and the second identifier. Optionally, the fourth information may also include at least one of the following: the image of the virtual identity, the third identifier, the fourth identifier, the fifth identifier, the ninth identifier, and location information. For example, the ninth identifier is used to indicate the DA service API; the ninth identifier is used to indicate the service API of the invoked digital asset (DA).

[0236] Optionally, the fourth information includes the first identifier and the second identifier, and the fourth information is used to obtain authorization information. For example, the authorization information may include at least one of the following: first authorization information and second authorization information.

[0237] Optionally, the fourth information includes the first identifier and the image of the virtual identity, and the fourth information is used to request verification of whether the image of the virtual identity is real.

[0238] Optionally, the fourth information may be an authorization information request or an authorization information request message, a DA service API call request or a DA service API call request message, etc. Alternatively, the second device may send a DA service API call request message to the third device, and the DA service API call request message may include the fourth information.

[0239] Optionally, the name of the fourth piece of information is not limited; it may be, for example, authorization information request information or DA service API call request information.

[0240] In some embodiments, if the second device determines that the image of the virtual identity is real, it sends fourth information to the third device. The fourth information includes the first identifier and the second identifier, and is used to obtain authorization information.

[0241] In some embodiments, the third device receives fourth information sent by the second device. The fourth information includes a first identifier and a second identifier, and is used to obtain authorization information. The fourth information is sent by the second device when it determines that the image of the virtual identity is real.

[0242] In some embodiments, if the second device cannot determine whether the image of the virtual identity is real, it sends fourth information to the third device. The fourth information includes a first identifier, a second identifier, and the image of the virtual identity. The fourth information is used to request at least one of the following: authorization information and verification of whether the image of the virtual identity is real.

[0243] In some embodiments, the third device receives fourth information sent by the second device. The fourth information includes a first identifier, a second identifier, and an image of the virtual identity. The fourth information is used to request at least one of the following: authorization information and verification of whether the image of the virtual identity is real. The fourth information is sent by the second device when it is unable to determine whether the image of the virtual identity is real.

[0244] In some alternative embodiments, the second device sends a second instruction message to the first device.

[0245] In some alternative embodiments, the first device receives second instruction information sent by the second device.

[0246] Optionally, the second indication information is used to indicate verification failure. For example, the second indication information is used to indicate that the authenticity of the virtual identity's image failed, or the second indication information is used to indicate that the verification of whether the virtual identity's image is associated with the virtual identity's image failed.

[0247] Optionally, if the second device determines that the virtual identity is not real, it sends a second instruction message to the first device, which is used to indicate that the verification failed.

[0248] Optionally, the first device receives a second indication message sent by the second device, the second indication message being used to indicate verification failure; the second indication message is sent by the second device after determining that the image of the virtual identity is not genuine.

[0249] Optionally, the name of the second indication information is not limited; it may be, for example, a verification failure indication.

[0250] In step S2107, the third device sends the seventh message to the fourth device.

[0251] In some embodiments, the fourth device receives the seventh information sent by the third device.

[0252] Optionally, the seventh information may include the first identifier and the second identifier. Optionally, the seventh information may also include at least one of the following: a third identifier, a fourth identifier, and location information.

[0253] Optionally, the seventh information includes a first identifier and a second identifier, and the seventh information is used to obtain the second authorization information. For example, the seventh information is used to request the second authorization information.

[0254] Optionally, the name of the seventh information is not limited, and it may be, for example, authorization information, request information, etc.

[0255] Optionally, if the third device needs to obtain more authorization information, the third device may send a seventh message to the fourth device; wherein the seventh message includes a first identifier and a second identifier, and the seventh message is used to obtain the second authorization information.

[0256] Optionally, if the third device determines that the first authorization information is unavailable, the third device sends a seventh message to the fourth device; wherein the seventh message includes a first identifier and a second identifier, and the seventh message is used to obtain the second authorization information.

[0257] Optionally, the fourth device receives the seventh information sent by the third device. The seventh information includes the first identifier and the second identifier. The seventh information is used to obtain the second authorization information. The seventh information is sent by the third device when it needs to obtain more authorization information, or when the third device determines that the first authorization information is unavailable.

[0258] In step S2108, the fourth device sends the second authorization information to the third device.

[0259] In some embodiments, the third device receives second authorization information sent by the fourth device.

[0260] Optionally, the second authorization information is sent by the fourth device after receiving the seventh information sent by the third device.

[0261] Optionally, the second authorization information can be the second authorization information in the previous embodiments; for example, the second authorization information may include the contents in Table 1, etc.

[0262] In step S2109, the third device sends the fifth information to the second device.

[0263] In some embodiments, the second device receives fifth information sent by the third device.

[0264] In some embodiments, the fifth information includes at least one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; and first indication information, wherein the first indication information is used to indicate the reason for the failure to obtain the authorization information. Optionally, the first indication information is sent after the third device determines that the image of the virtual identity is not real.

[0265] Optionally, the name of the fifth piece of information is not limited; it may be, for example, authorization information, response information, etc.

[0266] In some alternative embodiments, prior to step S2109, the method further includes: a third device determining the authenticity of the virtual identity's image based on the first identifier and the image of the virtual identity included in the fourth information.

[0267] Optionally, the third device verifies that the virtual identity is real and sends a fifth piece of information to the second device, which includes authorization information.

[0268] Optionally, the second device receives the fifth information sent by the third device. The fifth information includes authorization information and is sent by the third device after determining that the image of the virtual identity is real.

[0269] Optionally, if the third device determines that the virtual identity is not real, it sends a fifth message to the second device, which includes the first instruction message.

[0270] Optionally, the second device receives a fifth message sent by the third device. The fifth message includes the first instruction message and is sent by the third device after determining that the image of the virtual identity is not real.

[0271] In some optional embodiments, before step S2109, the method further includes: after determining that the virtual identity image is real, the third device further determines whether the application indicated by the fourth identifier is an allowed application based on the fourth identifier included in the fourth information; if the application indicated by the fourth identifier is determined to be an allowed application, the third device sends authorization information to the second device. Optionally, if the third device determines that the application indicated by the fourth identifier is not an allowed application, it may not send authorization information to the second device.

[0272] In step S2110, the second or third device determines, based on the authorization information, at least one of the following: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0273] In some alternative embodiments, before step S2110, the method further includes: a third device determining the authenticity of the virtual identity image based on the first identifier and the image of the virtual identity included in the first information.

[0274] In some embodiments, the second device determines, based on authorization information, at least one of the following: verifying whether the user is associated with the virtual identity, and verifying whether the virtual identity is permitted to be used in the application indicated by the fourth identifier.

[0275] Optionally, after receiving the authorization information sent by the third or fourth device, the second device, based on the authorization information, determines at least one of the following: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier. Here, when the authorization information is sent by the fourth device, the authorization information may be carried in the third information; when the authorization information is sent by the third device, the authorization information may be carried in the fifth information.

[0276] Optionally, after receiving the authorization information, and determining that the first information received from the first device includes the first identifier and the second identifier, the second device verifies whether the user and the virtual identity are associated based on the authorization information, the first identifier, and the second identifier.

[0277] Optionally, after receiving the authorization information, and determining that the first information received from the first device includes the first identifier, the second identifier, and the fourth identifier, the second device verifies whether the user and the virtual identity are associated based on the authorization information, the first identifier, and the second identifier, and verifies whether the virtual identity is allowed to be used in the application indicated by the fourth identifier based on the authorization information, the first identifier, and the third identifier.

[0278] In some embodiments, the third device determines, based on authorization information, at least one of the following: verifying whether the user is associated with the virtual identity, and verifying whether the virtual identity is permitted to be used in the application indicated by the fourth identifier.

[0279] Optionally, after receiving the first information, the third device determines at least one of the following based on the authorization information (such as the first authorization information stored locally by the third device and / or the second authorization information obtained from the fourth device): verifying whether the user is associated with the virtual identity, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0280] Optionally, after receiving the first information, if the third device determines that the first information includes the first identifier and the second identifier, it verifies whether the user and the virtual identity are associated based on the authorization information, the first identifier, and the second identifier.

[0281] Optionally, after receiving the first information, if the second device determines that the first information includes a first identifier, a second identifier, and a fourth identifier, it verifies whether the user and the virtual identity are associated based on the authorization information, the first identifier, and the second identifier, and verifies whether the virtual identity is allowed to be used in the application indicated by the fourth identifier based on the authorization information, the first identifier, and the third identifier.

[0282] In some embodiments, the second device or the third device performs at least one of the following operations based on the first information and the authorization information:

[0283] If the user indicated by the second identifier in the first information is any user allowed in the authorization information, it is determined that the user indicated by the second identifier is associated with the virtual identity;

[0284] If the user indicated by the second identifier in the first information is not any user allowed in the authorization information, it is determined that the user indicated by the second identifier is not associated with the virtual identity;

[0285] If the first device indicated by the third identifier in the first information is any client of the clients allowed in the authorization information, it is determined that the client indicated by the first identifier is allowed to use the virtual identity;

[0286] If the first device indicated by the third identifier in the first information is not any client of the clients allowed in the authorization information, it is determined that the client indicated by the first identifier is not allowed to use the virtual identity;

[0287] If the application indicated by the fourth identifier in the first information is any application allowed in the authorization information, then the virtual identity is determined to be allowed to be used in the application indicated by the fourth identifier.

[0288] If the application indicated by the fourth identifier in the first information is not any of the applications allowed in the authorization information, it is determined that the virtual identity is not allowed to be used in the application indicated by the fourth identifier.

[0289] Optionally, any number of users can be one or more. For example, any user can be one or more users; any application can be one or more applications.

[0290] In some alternative embodiments, the third device sends the first information to the second device.

[0291] In some alternative embodiments, the second device receives the first information sent by the third device.

[0292] In some alternative embodiments, the third device receives the first information sent by the first device; the third device sends the first information to the second device after determining that the image of the virtual identity in the first information is real and that the user indicated by the second identifier in the first information is associated with the virtual identity.

[0293] In some alternative embodiments, the second device receives first information sent by the third device. The first information is received by the third device from the first device. The first information is sent by the third device after determining that the image of the virtual identity in the first information is real and that the user indicated by the second identifier in the first information is associated with the virtual identity.

[0294] In some alternative embodiments, the second device sends an eighth message to the fifth device.

[0295] In some alternative embodiments, the fifth device receives the eighth information sent by the second device.

[0296] Optionally, the eighth information includes at least one of the following: a first identifier, a second identifier, the image of the virtual identity, a third identifier, a fourth identifier, and location information.

[0297] Optionally, the eighth information is used to request at least one of the following: verifying whether the user is associated with the virtual identity, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier. For example, when the eighth information includes the first identifier and the second identifier, the eighth information is used to request the fifth device to verify whether the user is associated with the virtual identity. For example, when the eighth information includes both the first identifier and the fourth identifier, the eighth information is used to request the fifth device to verify whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0298] In some alternative embodiments, the fifth device verifies, based on authorization information, at least one of the following: whether the user is associated with the virtual identity, and whether the virtual identity is permitted to be used in the application indicated by the fourth identifier.

[0299] In some embodiments, the fifth device may perform at least one of the following: verifying the authenticity of the virtual identity image based on the certificate of the third device; verifying whether the user and the virtual identity are associated based on authorization information; verifying whether the virtual identity is permitted to be used in the application indicated by the fourth identifier based on authorization information; and obtaining authorization information from the third device or the fourth device. Furthermore, the implementation of the above operations performed by the fifth device is similar to the implementation of the corresponding operations performed by the second device; embodiments of the above operations performed by the fifth device can be found in embodiments of the corresponding operations performed by the second device.

[0300] For example, the fifth device's verification of whether a user and a virtual identity are associated based on authorization information and whether the virtual identity is allowed to be used in the application indicated by the fourth identifier are similar to the implementation of the second device's verification of whether a user and a virtual identity are associated based on authorization information and whether the virtual identity is allowed to be used in the application indicated by the fourth identifier. For the embodiments of the fifth device's verification of whether a user and a virtual identity are associated based on authorization information and whether the virtual identity is allowed to be used in the application indicated by the fourth identifier, please refer to the embodiments of the second device's verification of whether a user and a virtual identity are associated based on authorization information and whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0301] In this embodiment of the disclosure, if the fifth device verifies whether the user and the virtual identity are associated and / or verifies whether the virtual identity is allowed to be used in the application indicated by the fourth identifier based on the authorization information, then step S2110 may not be performed.

[0302] In some alternative embodiments, the eighth information may also include authorization information. Thus, the fifth device can obtain the authorization information from the second device. Alternatively, in other embodiments, the fifth device stores the authorization information itself for verification or obtains the authorization information from other devices such as the fourth or third device.

[0303] In some alternative embodiments, the fifth device sends a third indication message to the second device. This third indication message is used to verify at least one of the following verification failures: verifying whether the user is associated with the virtual identity, or verifying whether the virtual identity is permitted to be used in the application indicated by the fourth identifier. Optionally, the third indication message may also indicate the reason for the verification failure.

[0304] In some alternative embodiments, the second device receives fourth instruction information sent by the fifth device.

[0305] Optionally, the fifth device may also send a fourth indication message to the third device, the fourth indication message being used to indicate that at least one of the following verifications was successful: verifying whether the user is associated with the virtual identity, verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identification.

[0306] In some embodiments, both the third and fourth indication information can be one or more bits; for example, both can be a string; the string can include one or more letters, numbers, and / or symbols, etc.

[0307] In some embodiments, the names of the eighth information, the third indication information, and the fourth indication information are not limited; for example, the eighth information may be a verification request information, the third indication information may be a verification failure indication, and the fourth indication information may be an authentication success indication.

[0308] The information processing method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2110. For example, step S2101 can be implemented as an independent embodiment; step S2102 can be implemented as an independent embodiment; step S2103 can be implemented as an independent embodiment; step S2104 can be implemented as an independent embodiment; step S2105 can be implemented as an independent embodiment; step S2106 can be implemented as an independent embodiment; step S2107 can be implemented as an independent embodiment; step S2108 can be implemented as an independent embodiment; step S2109 can be implemented as an independent embodiment; step S2110 can be implemented as an independent embodiment; the combination of steps S2101 and S2102 can be implemented as an independent embodiment; the combination of steps S2103 and S2104 can be implemented as an independent embodiment; step S2102 and step S2104 can be implemented as an independent embodiment; The combination of steps S2105 can be implemented as an independent embodiment; the combination of steps S2102 to S2105 can be implemented as an independent embodiment; the combination of steps S2101 to S2105 can be implemented as an independent embodiment; the combination of steps S2101 and S2106 can be implemented as an independent embodiment; the combination of steps S2107 and S2108 can be implemented as an independent embodiment; the combination of steps S2106 and S2109 can be implemented as an independent embodiment; the combination of steps S2106 to S2110 can be implemented as an independent embodiment; the combination of steps S2101 and steps S2106 to S2109 can be implemented as an independent embodiment; the combination of steps S2101 and S2110 can be implemented as an independent embodiment.

[0309] In some embodiments, steps S2102 and S2106 may be performed in an alternate order or simultaneously.

[0310] In some embodiments, steps S2106 to S2109 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0311] In some embodiments, steps S2102 to S2105 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0312] In some embodiments, steps S2102 to S2109 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0313] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0314] Figure 2B is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 2B, this embodiment of the present disclosure relates to an information processing method used in a communication system 100, the method comprising:

[0315] Step S2201: The first device sends the first information to the second device.

[0316] The optional implementations of step S2201 can be found in the optional implementations of step S2101 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0317] In step S2202, the second device sends the second information to the fourth device.

[0318] The optional implementations of step S2202 can be found in the optional implementations of step S2102 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0319] In some alternative embodiments, the fourth device verifies whether the virtual identity is real based on the certificate of the third device.

[0320] In step S2203, the fourth device sends the sixth message to the third device.

[0321] The optional implementation of step S2203 can be found in the optional implementation of step S2103 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0322] In step S2204, the third device sends the first authorization information to the fourth device.

[0323] The optional implementation of step S2204 can be found in the optional implementation of step S2104 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0324] In step S2205, the fourth device sends the third information to the second device.

[0325] The optional implementation of step S2205 can be found in the optional implementation of step S2105 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0326] Step S2206, Second Device Authorization Information, determines at least one of the following: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0327] The optional implementation of step S2206 can be found in the optional implementation of step S2110 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0328] The information processing method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2206. For example, step S2201 can be implemented as an independent embodiment; step S2202 can be implemented as an independent embodiment; step S2203 can be implemented as an independent embodiment; step S2204 can be implemented as an independent embodiment; step S2205 can be implemented as an independent embodiment; step S2206 can be implemented as an independent embodiment; a combination of steps S2201 and S2202 can be implemented as an independent embodiment; a combination of steps S2203 and S2204 can be implemented as an independent embodiment; a combination of steps S2202 and S2205 can be implemented as an independent embodiment; a combination of steps S2202 to S2205 can be implemented as an independent embodiment; a combination of steps S2201 and S2205 can be implemented as an independent embodiment; a combination of steps S2201 to S2206 can be implemented as an independent embodiment.

[0329] In some embodiments, steps S2203 and S2204 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0330] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0331] Figure 2C is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 2C, this embodiment of the present disclosure relates to an information processing method used in a communication system 100, the method comprising:

[0332] Step S2301: The first device sends the first information to the second device.

[0333] The optional implementation of step S2301 can be found in the optional implementation of step S2101 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0334] In step S2302, the second device sends the fourth information to the third device.

[0335] The optional implementation of step S2302 can be found in the optional implementation of step S2106 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0336] In some alternative embodiments, the second device sends a second instruction message to the first device.

[0337] In step S2303, the third device sends the seventh message to the fourth device.

[0338] The optional implementation of step S2303 can be found in the optional implementation of step S2107 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0339] In step S2304, the fourth device sends the second authorization information to the third device.

[0340] The optional implementation of step S2304 can be found in the optional implementation of step S2108 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0341] In some alternative embodiments, the third device determines whether the image of the virtual identity is real based on the first identifier and the image of the virtual identity included in the fourth information.

[0342] In step S2305, the third device sends the fifth message to the second device.

[0343] The optional implementation of step S2305 can be found in the optional implementation of step S2109 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0344] Step S2306, Second Device Authorization Information, determines at least one of the following: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0345] The optional implementation of step S2306 can be found in the optional implementation of step S2110 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0346] The information processing method involved in the embodiments of this disclosure may include at least one of steps S2301 to S2306. For example, step S2301 can be implemented as an independent embodiment; step S2302 can be implemented as an independent embodiment; step S2303 can be implemented as an independent embodiment; step S2304 can be implemented as an independent embodiment; step S2305 can be implemented as an independent embodiment; step S2306 can be implemented as an independent embodiment; a combination of steps S2301 and S2302 can be implemented as an independent embodiment; a combination of steps S2302 and S2305 can be implemented as an independent embodiment; a combination of steps S2301 and S2305 can be implemented as an independent embodiment; a combination of steps S2301 to S2306 can be implemented as an independent embodiment.

[0347] In some embodiments, steps S2303 and S2304 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0348] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0349] Figure 2D is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 2D, this embodiment of the present disclosure relates to an information processing method used in a communication system 100, the method comprising:

[0350] Step S2401: The first device sends the first information to the third device.

[0351] The optional implementation of step S2401 can be found in the optional implementation of step S2101 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0352] In some alternative embodiments, the third device determines whether the image of the virtual identity is real based on the first identifier and the image of the virtual identity included in the first information.

[0353] In step S2402, the third device, based on the authorization information, determines at least one of the following: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier.

[0354] The optional implementation of step S2402 can be found in the optional implementation of step S2110 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0355] In some alternative embodiments, the third device sends the first information to the second device.

[0356] The information processing method disclosed in this embodiment may include at least one of steps S2401 to S2402. For example, step S2401 may be implemented as a standalone embodiment; step S2402 may be implemented as a standalone embodiment; a combination of steps S2401 and S2402 may be implemented as a standalone embodiment.

[0357] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0358] Figure 3 is an interactive schematic diagram illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 3, this embodiment of the present disclosure relates to an information processing method for a communication system 100, the method including one of the following steps:

[0359] In step S3101, the first device sends first information to the second or third device, wherein the first information is used to trigger verification of whether the user and the virtual identity are associated. Optionally, the first information includes at least one of the following: a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

[0360] The optional implementations of step S3101 can be found in the optional implementations of step S2101 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0361] In some embodiments, verifying whether a user is associated with a virtual identity includes at least one of the following: verifying whether the virtual identity is used on behalf of the user; verifying whether the user is authorized to use the virtual identity.

[0362] In some embodiments, the first information further includes the image of the virtual identity; the first information is also used to trigger the authenticity of the image of the virtual identity.

[0363] In some embodiments, the first information further includes at least one of the following: a third identifier, wherein the third identifier is used to indicate the first device; a fourth identifier, wherein the fourth identifier is used to indicate the application requesting access; and location information, wherein the location information is used to indicate the location of the first device.

[0364] In some embodiments, the method further includes: the second device sending second information to the fourth device, wherein the second information includes: a first identifier and an image of a virtual identity, and the second information is used to obtain authorization information.

[0365] In some embodiments, the method further includes: the second device receiving third information sent by the fourth device, wherein the third information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; and first indication information, wherein the first indication information is used to indicate the reason for the failure to obtain authorization information.

[0366] In some embodiments, the method further includes: the second device determining the authenticity of the virtual identity image based on the certificate of the third device.

[0367] In some embodiments, the method further includes one of the following: if the second device determines that the image of the virtual identity is real, it sends fourth information to the third device, the fourth information including a first identifier, a second identifier, and a fourth identifier, the fourth information being used to obtain authorization information; if the second device determines that the image of the virtual identity is not real, it sends second indication information to the first device, the second indication information being used to indicate verification failure; if the second device cannot determine whether the image of the virtual identity is real, it sends fourth information to the third device, the fourth information including the image of the virtual identity, the fourth information also being used to request verification of whether the image of the virtual identity is real.

[0368] In some embodiments, the method further includes: the second device receiving fifth information sent by the third device, wherein the fifth information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; and first indication information, wherein the first indication information is used to indicate the reason for failure to obtain authorization information.

[0369] In some embodiments, the method further includes at least one of the following: the second device verifies, based on authorization information, whether the user and the virtual identity are associated; the second device verifies, based on authorization information, whether the virtual identity is permitted to be used in the application indicated by the fourth identifier.

[0370] In some embodiments, the method includes: a third device receiving a first identifier and an image of a virtual identity sent by one of a first device, a second device, and a fourth device, wherein the first identifier is used to indicate the virtual identity; and determining whether the image of the virtual identity is real based on the first identifier and the image of the virtual identity.

[0371] In some embodiments, the third device receiving a first identifier and virtual identity image sent by one of the first device, the second device, and the fourth device includes one of the following: the third device receiving first information sent by the first device, wherein the first information includes the first identifier and virtual identity image; the third device receiving fourth information sent by the second device, wherein the fourth information includes the first identifier and virtual identity image; the third device receiving sixth information sent by the fourth device, wherein the sixth information includes the first identifier and virtual identity image.

[0372] In some embodiments, the first information further includes at least one of the following: a second identifier and a fourth identifier; the second identifier is used to indicate a user; the fourth identifier is used to indicate an application requesting access; the first information is also used to request at least one of the following: verifying whether the user and the virtual identity are associated, and whether the virtual identity is allowed to use the application indicated by the fourth identifier; or, the fourth information further includes the second identifier and the fourth identifier; the fourth information is also used to obtain authorization information, the authorization information including first authorization information and second authorization information, the first authorization information being stored in a third device, and the second authorization information being stored in a fourth device; or, the sixth information is also used to obtain the first authorization information.

[0373] In some embodiments, the fourth information is sent when the second device determines that the image of the virtual identity is real; or, the fourth information is sent when the second device cannot determine whether the image of the virtual identity is real; or, the sixth information is sent when the fourth device cannot determine that the image of the virtual identity is real; or, the sixth information is sent when the fourth device determines that the second authorization information is unavailable.

[0374] In some embodiments, the method further includes: the third device sending first authorization information to the fourth device.

[0375] In some embodiments, the method further includes: a third device sending seventh information to a fourth device, wherein the seventh information includes a first identifier, a second identifier, and a fourth identifier, and the seventh information is used to obtain second authorization information; and receiving the second authorization information sent by the fourth device.

[0376] In some embodiments, the method further includes: a third device sending fifth information to a second device, wherein the fifth information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is authentic; and first indication information, wherein the first indication information is used to indicate the reason for failure to obtain authorization information.

[0377] In some embodiments, the method further includes at least one of the following: a third device verifies, based on authorization information, whether the user and the virtual identity are associated; or a third device verifies, based on authorization information, whether the virtual identity is permitted to use the application indicated by the fourth identifier.

[0378] In some embodiments, the method further includes: a third device sending first information to a second device after determining that the user indicated by the second identifier is associated with a virtual identity.

[0379] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0380] This disclosure relates to an information processing method that ensures a communication system can verify a digital representation (virtual identity, such as an avatar) on behalf of a user and authorize the user using a virtual identity based on the CAPIF framework.

[0381] Assume the user has been authenticated to download his / her virtual identity, and the virtual identity has been downloaded from the DA server to the UE he / she is using. The virtual identity can be created by the DA server and can be digitally signed by the DA server.

[0382] Mobile metaverse applications can benefit from shared digital assets used by different mobile metaverse services / applications (e.g., consistent user digital representations across different applications), allowing users to benefit from having this information available when accessing mobile metaverse applications. This means that digital assets, including avatars, need to be uniquely identifiable to maintain consistency across different mobile metaverse services / applications. Therefore, virtual identities downloaded in the UE should be shareable by multiple metaverse VAL clients within the UE.

[0383] Since a UE can be used by multiple users, the currently logged-in user may not have downloaded and registered his / her virtual identity earlier. Furthermore, it is assumed that a user can own multiple digital assets (1:n) and can use more than one digital asset (1:n); while a digital asset can be used by multiple authorized users (1:m). This means that multiple users are allowed to use virtual identities downloaded in the UE to represent themselves and access metaverse applications via the corresponding metaverse VAL client in the UE. The metaverse VAL client needs to ensure that the virtual identity being used is legitimately associated with the user using it as a digital representation.

[0384] Figure 4A is a schematic diagram illustrating a digital asset service architecture supporting metaverse applications according to an embodiment of this disclosure. As shown in Figure 4A, the architecture may include a Vertical Application Layer (VAL) and a Service Enabler Architecture Layer (SEAL). The architecture includes a User Equipment (UE) and a server; the UE connects to the server through a network system. The UE includes a VAL client and a Digital Asset (DA) client; the server may include a VAL server and a DA server. The VAL client connects to the VAL server via a VAL-UU interface; the DA client connects to the DA server via a DA-UU interface; the network system connects to the DA server via an N33 interface; the N33 interface is a service-oriented interface. Here, the UE can refer to a DA client (DA-C); the server can refer to a DA server (DA-S).

[0385] Figure 4B illustrates a CAPIF functional model for a third-party API provider according to an embodiment of this disclosure. CAPIF is a north-bound API framework for authorizing API callers (e.g., third-party application functions (AFs)) to access a communication system. The CAPIF framework may include a CCF and an AEF. API callers can send service APIs to the AEF via the CCF; the CAPIF framework may also include an API publishing function (APF) and / or an API management function, etc. The AEF can use authorization information provided by the CCF to authorize API call requests from API callers; here, API callers may include API caller 1, API caller 2, and API caller 3. CAPIF-1e, CAPIF-2e, CAPIF-3e, CAPIF-4e, CAPIF-5e, and CAPIF-6e are interfaces between devices in different domains (e.g., API provider domain 1 and API provider domain 2); CAPIF-1, CAPIF-2, CAPIF-3, CAPIF-4, and CAPIF-5 are interfaces between devices in the same domain.

[0386] In Figure 4A, the DA server is a type of SEAL server. The VAL server can be a metaverse application server. When CAPIF is used to support metaverse-enabled services, Figure 4B proposes that the DA server can be mapped to an AEF in a PLMN trusted domain (e.g., API Provider Domain 1). The VAL server (i.e., the metaverse application server) can be mapped to an AEF in a third-party trusted domain (e.g., API Provider Domain 2). The VAL client above the DA client in the VAL UE, which is the API caller of the VAL server, can be mapped to the API caller in Figure B.

[0387] If a metaverse service request is sent directly from the VAL client in the UE to the metaverse application server (i.e., the VAL server) for verifying the virtual identity and authorizing the user based on the CAPIF framework, then the metaverse application server can act as an AEF (see Example 1) that provides the metaverse service API in a third-party trusted domain or as an API caller that requests metaverse support services (i.e., DA services) (see Example 2).

[0388] Example 1: The Metaverse Application Server acts as an AEF that provides Metaverse business APIs.

[0389] When the Metaverse Application Server is used as a third-party AEF, CAPIF acts as the framework for the northbound API that provides services to the Metaverse Application Provider.

[0390] Figure 4C is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 4C, the present disclosure relates to an information processing method, which includes:

[0391] Step S4101: The API caller sends a metaverse service API invocation request to the metaverse application server.

[0392] Optionally, the API caller can be a Metaverse service API caller in the UE; the service API call request may include at least one of the following: caller ID, virtual identity (avatar) identifier and the corresponding virtual identity image (i.e., virtual identity object), user identifier, and Metaverse service API identifier.

[0393] In step S4102, the Metaverse application server sends an Authorization info request to the CCF.

[0394] Optionally, as the AEF providing the Metaverse business API, the Metaverse Application Server sends an authorization information request to the CCF. This authorization information request requests the information required for authorization (i.e., authorization information). The authorization information request includes at least a virtual identity identifier and the corresponding virtual identity image; and optionally, it includes a user identifier and a business API identifier. When the virtual identity image is created and signed by the DA server, the CCF verifies the authenticity of the virtual identity image by using the DA server's certificate to verify the signature (i.e., whether the virtual identity indicated by the virtual identity identifier matches or is associated with the virtual identity image). Only when the virtual identity image is authentic will the CCF send the required authorization information to the Metaverse Application Server in step S4104; otherwise, the CCF returns a failure message to the Metaverse Application Server in step S4104.

[0395] Step S4103: CCF obtains authorization information from the DA server.

[0396] Optionally, if the CCF determines that the authorization information within the CCF is unavailable, it obtains the required authorization information from the DA service by sending a virtual identity identifier to the DA server. If the CCF cannot verify the authenticity of the virtual identity's image, it can also send the corresponding virtual identity's image to the DA server for verification. Only when the virtual identity's image is authentic will the DA server return the required authorization information to the CCF. The required authorization information can indicate the association between the virtual identity, the user, and the metaverse application; this authorization information can be as shown in Table 1 above.

[0397] In step S4104, CCF sends an authorization info response to the Metaverse application server.

[0398] Optionally, the authorization information response may include the required authorization information or the reason for failure.

[0399] In step S4105, the Metaverse application server verifies whether the virtual identity is associated with the user and the Metaverse application.

[0400] Optionally, if the Metaverse application server receives the required authorization information, it indicates that the authenticity verification of the virtual identity has been successful, meaning that the virtual identity has been implicitly authenticated. The Metaverse application server verifies the virtual identity identifier, user identifier, and Metaverse business API identifier by comparing the authorization information; that is, it verifies the relationship between the virtual identity, the user, and the Metaverse application, such as verifying whether the virtual identity can be used to represent the user indicated by the identifier, and / or whether the user is allowed to use the virtual identity.

[0401] Step S4106: The Metaverse application server sends a Metaverse business API call response to the API caller.

[0402] Optionally, the Metaverse business API call response may include: a success indication and / or the result of the business API call, or a failure indication.

[0403] In some embodiments, the API caller can be the first device in the previous embodiments, the metaverse application server can be the second device in the previous embodiments, the DA server can be the third device in the previous embodiments, and the CCF can be the fourth device in the previous embodiments. The virtual identity identifier can be the first identifier in the previous embodiments; the user identifier can be the second identifier in the previous embodiments; the caller identifier can be the third identifier in the previous embodiments; and the metaverse business API identifier can be the fifth identifier in the previous embodiments. The authorization information request can be the second information in the previous embodiments; and the authorization information response can be the third information in the previous embodiments.

[0404] The information processing method involved in the embodiments of this disclosure may include at least one of steps S4101 to S4106. For example, step S4101 can be implemented as an independent embodiment; step S4102 can be implemented as an independent embodiment; step S4103 can be implemented as an independent embodiment; step S4104 can be implemented as an independent embodiment; step S4105 can be implemented as an independent embodiment; step S4106 can be implemented as an independent embodiment; a combination of steps S4101 and S4102 can be implemented as an independent embodiment; a combination of steps S4102 and S4103 can be implemented as an independent embodiment; a combination of steps S4103 and S4104 can be implemented as an independent embodiment; a combination of steps S4102 to S4104 can be implemented as an independent embodiment; a combination of steps S4101 to S4104 can be implemented as an independent embodiment; a combination of steps S4101 to S4105 can be implemented as an independent embodiment; a combination of steps S4101 to S4106 can be implemented as an independent embodiment.

[0405] In some embodiments, step S4103 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0406] Example 2: The Metaverse Application Server, acting as an API caller, requests the DA Server.

[0407] Assuming a DA client is implemented in the Metaverse Application Server, the DA client in the Metaverse Application Server can act as an API caller requesting DA services provided by the PLMN operator. In this case, CAPIF acts as the framework for the northbound API of the DA services provided by the DA server.

[0408] Figure 4D is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 4D, the present disclosure relates to an information processing method, which includes:

[0409] Step S4201: The API caller sends a metaverse service API invocation request to the metaverse application server.

[0410] Optionally, the API caller can be a Metaverse business API caller in the UE; the business API call request may include at least one of the following: caller ID, virtual identity identifier and the corresponding virtual identity image (i.e., virtual identity object), user identifier, and Metaverse business API identifier.

[0411] Optionally, when the virtual identity image is created and signed by the DA server, if the DA server's certificate is available in the Metaverse application server, the Metaverse application server can verify the authenticity of the virtual identity image by verifying the signature of the virtual identity image. Only when the virtual identity image is verified as authentic will the Metaverse application server execute the following steps; otherwise, the Metaverse application server returns a failure message to the UE (i.e., the API caller).

[0412] In step S4202, the Metaverse application server sends a DA server API call request to the DA server.

[0413] Optionally, the API caller in the Metaverse application server sends a service API call request to the DA server. The service API call request includes at least one of the following: caller ID, the DA server API identifier to be called, the requested operation, and the virtual identity identifier. If the Metaverse application server cannot verify the authenticity of the virtual identity's appearance, it will also send the virtual identity's appearance to the DA server for verification.

[0414] Step S4203: The DA server obtains authorization information.

[0415] Optionally, if the DA server receives a virtual identity image, it verifies the authenticity of the image. Only when the virtual identity image is verified as authentic will the DA server accept DA service API call requests. The DA server can obtain more authorization information from the CCF as needed.

[0416] In step S4204, the DA server sends a DA server call response to the metaverse application server.

[0417] Optionally, the authorization information response may include the required authorization information (i.e., the DA file) or the reason for failure.

[0418] Step S4205: The Metaverse application server verifies whether the virtual identity is associated with the user and the Metaverse application.

[0419] Optionally, if the Metaverse application server receives the DA file, it implies that the authenticity of the virtual identity has been successfully verified by the DA server, meaning that the virtual identity has been implicitly authenticated. The Metaverse application server verifies the virtual identity identifier, user identifier, and Metaverse business API identifier by comparing them with the DA file; that is, it verifies the relationship between the virtual identity, the user, and the Metaverse application, such as verifying whether the virtual identity can be used to represent the user indicated by the identifier, and / or whether the user is allowed to use the virtual identity.

[0420] Step S4206: The Metaverse application server sends a Metaverse business API call response to the API caller.

[0421] Optionally, the Metaverse business API call response may include: a success indication and / or the result of the business API call, or a failure indication.

[0422] In some embodiments, the API caller can be the first device in the previous embodiments, the metaverse application server can be the second device in the previous embodiments, the DA server can be the third device in the previous embodiments, and the CCF can be the fourth device in the previous embodiments. The virtual identity identifier can be the first identifier in the previous embodiments; the user identifier can be the second identifier in the previous embodiments; the caller identifier can be the third identifier in the previous embodiments; the metaverse business API identifier can be the fifth identifier in the previous embodiments; and the DA service API identifier can be the ninth identifier in the previous embodiments. The DA server API call request can be the fourth information in the previous embodiments; and the DA server API call response can be the fifth information in the previous embodiments.

[0423] The information processing method involved in the embodiments of this disclosure may include at least one of steps S4201 to S4206. For example, step S4201 can be implemented as an independent embodiment; step S4202 can be implemented as an independent embodiment; step S4203 can be implemented as an independent embodiment; step S4204 can be implemented as an independent embodiment; step S4205 can be implemented as an independent embodiment; step S4206 can be implemented as an independent embodiment; a combination of steps S4201 and S4202 can be implemented as an independent embodiment; a combination of steps S4202 and S4203 can be implemented as an independent embodiment; a combination of steps S4203 and S4204 can be implemented as an independent embodiment; a combination of steps S4202 to S4204 can be implemented as an independent embodiment; a combination of steps S4201 to S4204 can be implemented as an independent embodiment; a combination of steps S4201 to S4205 can be implemented as an independent embodiment; a combination of steps S4201 to S4206 can be implemented as an independent embodiment.

[0424] In some embodiments, step S4203 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0425] In Example 3, the Metaverse service request is indirectly sent to the Metaverse application server via the DA server.

[0426] Metaverse service requests can be sent indirectly to the Metaverse application server (i.e., the VAL server) via the DA server, instead of directly from the VAL client in the UE. Since, according to Figure 4B, the DA server can be mapped to the AEF in the PLMN trusted domain (API provider domain 1), and the Metaverse application server can be mapped to the AEF in the third-party trusted domain (API provider domain 2), CAPIF access control of cascaded AEFs can be used as a benchmark for verifying virtual identities and authorizing users.

[0427] Figure 4E is a flowchart illustrating an information processing method according to an embodiment of the present disclosure. As shown in Figure 4E, the present disclosure relates to an information processing method, which includes:

[0428] Step S4301: The API caller sends a DA service API call request to the DA server.

[0429] Optionally, the API caller can be a DA service API caller in the UE. Here, the DA service API call request can be replaced with a metaverse service API call request.

[0430] Optionally, if the DA server is configured as the interface for the service API, the DA service API caller in the UE may send a service API call request to the DA server including at least one of the following: caller ID, avatar identifier and the corresponding avatar image (i.e., avatar object), user identifier, and DA service API identifier.

[0431] Step S4302: The DA server verifies the authenticity of the virtual identity's appearance.

[0432] Optionally, when the DA server receives a DA service API call request, if the DA service API call request includes the image of the virtual identity, the DA server verifies the authenticity of the virtual identity image.

[0433] In step S4303, the DA server verifies whether the virtual identity is associated with the user and the metaverse application.

[0434] Optionally, if the virtual identity's appearance is verified as authentic, it means that the virtual identity's appearance is implicitly authenticated. The DA server verifies the virtual identity identifier, user identifier, and DA service API identifier by comparing them with locally stored authorization information; that is, it verifies the relationship between the virtual identity and the user and the metaverse application, such as verifying whether the virtual identity can be used to represent the user indicated by the identifier, and / or whether the user is allowed to use the virtual identity.

[0435] Step S4304: The DA server sends a Metaverse business API call request to the Metaverse application server.

[0436] Optionally, if the access control executed by the DA server is successful, the DA server will forward the received metaverse business API call request to the metaverse application server.

[0437] In step S4305, the Metaverse application server sends a DA service API call response to the DA server.

[0438] Optionally, the DA service API call response may include: a success indication and / or the result of the service API call, or a failure indication. Here, the DA service API call response can be replaced with the Metaverse service API call response.

[0439] Step S4306: The DA server sends a DA service API call response to the API caller.

[0440] Optionally, the DA server resolves the destination API caller address, modifies the source address information of the metaverse application server in the DA service API response, and then forwards the DA service API call response to the DA service API caller.

[0441] In some embodiments, the API caller can be the first device in the previous embodiments, the metaverse application server can be the second device in the previous embodiments, the DA server can be the third device in the previous embodiments, and the CCF can be the fourth device in the previous embodiments. The virtual identity can be the first identity in the previous embodiments; the user identity can be the second identity in the previous embodiments; the caller identity can be the third identity in the previous embodiments; and the DA service API identity can be the ninth identity in the previous embodiments.

[0442] The information processing method involved in the embodiments of this disclosure may include at least one of steps S4301 to S4306. For example, step S4301 may be implemented as a standalone embodiment; step S4302 may be implemented as a standalone embodiment; step S4303 may be implemented as a standalone embodiment; step S4304 may be implemented as a standalone embodiment; a combination of steps S4301 and S4302 may be implemented as a standalone embodiment; a combination of steps S4302 and S4303 may be implemented as a standalone embodiment; a combination of steps S4301 to S4303 may be implemented as a standalone embodiment; a combination of steps S4301 to S4306 may be implemented as a standalone embodiment.

[0443] In some embodiments, steps S4304, S4305 and S4306 may be optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0444] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0445] This disclosure also proposes an apparatus (also referred to as a communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is proposed that includes units or modules for implementing the steps performed by network devices (e.g., access network devices, core network functional nodes, core network devices (e.g., first device, second device, third device, fourth device, terminal, etc.) in any of the above methods.

[0446] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an Application-Specific Integrated Circuit (ASIC), and the functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a Programmable Logic Device (PLD), such as a Field Programmable Gate Array (FPGA), which can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0447] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0448] Figure 5A is a schematic diagram of the structure of a first device 5100 provided in an embodiment of this disclosure. As shown in Figure 5A, the first device 5100 includes a first transceiver module 5101. In some embodiments, the first transceiver module 5101 is used to send first information to a second device. Optionally, the first transceiver module 5101 is used to perform at least one of the sending and / or receiving steps (e.g., step S2101, but not limited thereto) performed by the first device 5100 in any of the above methods, which will not be described in detail here. In some embodiments, the first device 5100 may include a first processing module.

[0449] Figure 5B is a schematic diagram of the structure of the second device 5200 provided in an embodiment of this disclosure. As shown in Figure 5B, the second device 5200 includes at least one of a second transceiver module 5201 and a second processing module 5202. In some embodiments, the second transceiver module 5201 is used to acquire first information. Optionally, the second transceiver module 5201 is used to perform at least one of the sending and / or receiving steps performed by the second device 5200 in any of the above methods (e.g., steps S2101, S2102, S2105, S2106 and / or S2109, etc., but not limited thereto), which will not be elaborated here. In some embodiments, the second processing module 5202 is used to determine at least one of the following based on authorization information: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier. Optionally, the second processing module 5202 is used to execute at least one of the processing steps (such as step S2110, but not limited to) executed by the second device 5200 in any of the above methods, which will not be described in detail here.

[0450] Figure 5C is a schematic diagram of the structure of a third device 5300 provided in an embodiment of this disclosure. As shown in Figure 5C, the third device 5300 includes at least one of a third transceiver module 5301 and a third processing module 5302. In some embodiments, the third transceiver module 5301 is used to acquire first information. Optionally, the third transceiver module 5301 is used to perform at least one of the sending and / or receiving steps (e.g., steps S2101, S2103, S2104, S2106, S2107, S2108 and / or S2109, etc., but not limited thereto) performed by the third device 5300 in any of the above methods, which will not be described in detail here. In some embodiments, the third processing module 5302 is used to determine at least one of the following based on authorization information: verifying whether the user and the virtual identity are associated, and verifying whether the virtual identity is allowed to be used in the application indicated by the fourth identifier. Optionally, the third processing module 5302 is used to execute at least one of the processing steps (such as step S2109, but not limited to) executed by the third device 5300 in any of the above methods, which will not be described in detail here.

[0451] Figure 5D is a schematic diagram of the structure of the fourth device 5400 provided in an embodiment of this disclosure. As shown in Figure 5D, the fourth device 5400 includes a fourth transceiver module 5401. In some embodiments, the fourth transceiver module 5401 is used to acquire second information. Optionally, the aforementioned fourth transceiver module 5401 is used to perform at least one of the sending and / or receiving steps (e.g., steps S2102, S2103, S2104, S2105, S2107 and / or S2108, etc., but not limited thereto) performed by the fourth device 5400 in any of the above methods, which will not be elaborated here. In some embodiments, the fourth device 5400 may be a fourth processing module.

[0452] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, which may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver. For example, the first transceiver module described above includes a first transmitting module and / or a first receiving module. For example, the second transceiver module described above includes a second transmitting module and / or a second receiving module.

[0453] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module.

[0454] In some embodiments, the processing module can be replaced by the processor, and the transceiver module can be replaced by the transceiver.

[0455] Figure 6A is a schematic diagram of the structure of the communication device 6100 proposed in an embodiment of this disclosure. The communication device 6100 can be a network device (e.g., an access network device (e.g., a base station), a core network device (e.g., a first device, a second device, a third device, a fourth device, etc.), a terminal (e.g., a user equipment), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 6100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0456] As shown in Figure 6A, the communication device 6100 is used to execute any of the above methods. In some embodiments, the communication device 6100 includes one or more processors 6101. The processor 6101 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 6100 is used to execute any of the above methods. Optionally, one or more processors 6101 are used to invoke instructions to cause the communication device 6100 to execute any of the above methods.

[0457] In some embodiments, the communication device 6100 further includes one or more transceivers 6102. When the communication device 6100 includes one or more transceivers 6102, the transceiver 6102 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2102, S2103, S2104, S2105, S2107, S2108 and / or S2109, but not limited thereto), and the processor 6101 performs at least one of other steps (e.g., step S2110, but not limited thereto). In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., can be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.

[0458] In some embodiments, the communication device 6100 further includes one or more memories 6103 for storing data and / or instructions. Optionally, one or more processors 6101 are used to invoke instructions stored in the memory 6103 to cause the communication device 6100 to perform any of the above methods. Optionally, all or part of the memory 6103 may also be located outside the communication device 6100. In an optional embodiment, the communication device 6100 may include one or more interface circuits 6104. Optionally, the interface circuit 6104 is connected to the memory 6103 and can be used to receive data and / or instructions from the memory 6103 or other devices, and can be used to send data and / or instructions to the memory 6103 or other devices. For example, the interface circuit 6104 can read data and / or instructions stored in the memory 6103 and send the data and / or instructions to the processor 6101.

[0459] The communication device 6100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 6100 described in this disclosure is not limited thereto, and the structure of the communication device 6100 may not be limited by FIG. 6A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection having one or more ICs, optionally, the IC collection may also include storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0460] Figure 6B is a schematic diagram of the structure of chip 6200 according to an embodiment of this disclosure. For cases where the communication device 6100 can be a chip or a chip system, please refer to the schematic diagram of chip 6200 shown in Figure 6B, but it is not limited thereto.

[0461] Chip 6200 includes one or more processors 6201. Chip 6200 is used to perform any of the methods described above.

[0462] In some embodiments, chip 6200 further includes one or more interface circuits 6202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6200 further includes one or more memories 6203 for storing data and / or instructions. Optionally, all or part of the memories 6203 may be located outside of chip 6200. Optionally, interface circuit 6202 is connected to memory 6203, and interface circuit 6202 can be used to receive data and / or instructions from memory 6203 or other devices, and interface circuit 6202 can be used to send data and / or instructions to memory 6203 or other devices. For example, interface circuit 6202 can read data and / or instructions stored in memory 6203 and send the data and / or instructions to processor 6201.

[0463] In some embodiments, the interface circuit 6202 performs at least one of the communication steps such as sending and / or receiving in the above-described method (e.g., steps S2101, S2102, S2103, S2104, S2105, S2107, S2108, and / or S2109, but not limited thereto). The interface circuit 6202 performing the communication steps such as sending and / or receiving in the above-described method refers, for example, to the interface circuit 6202 performing data and / or instruction interaction between the processor 6201, the chip 6200, the memory 6203, or the transceiver device. In some embodiments, the processor 6201 performs at least one of other steps (e.g., step S2110, but not limited thereto).

[0464] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0465] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0466] This disclosure also proposes a program product, including a program and / or instructions, which, when executed by a communication device, cause the communication device to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.

[0467] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Claims

1. An information processing method, characterized in that, Performed by the first device, including: Send first information to a second or third device, wherein the first information is used to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

2. The method according to claim 1, characterized in that, The verification of whether a user and a virtual identity are associated includes at least one of the following: Verify whether the virtual identity is used to represent the user; Verify whether the user is authorized to use the virtual identity.

3. The method according to claim 1 or 2, characterized in that, The first information also includes the image of the virtual identity; the first information is also used to trigger verification of the authenticity of the image of the virtual identity.

4. The method according to any one of claims 1 to 3, characterized in that, The first information also includes at least one of the following: A third identifier, wherein the third identifier is used to indicate the first device; A fourth identifier, wherein the fourth identifier is used to indicate the application requesting access; Location information, wherein the location information is used to indicate the location of the first device.

5. An information processing method, characterized in that, Performed by a second device, including: The device receives first information sent by a first device, wherein the first information is used by the second device to trigger verification of whether a user is associated with a virtual identity; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

6. The method according to claim 5, characterized in that, The verification of whether a user and a virtual identity are associated includes at least one of the following: Verify whether the virtual identity is used to represent the user; Verify whether the user is authorized to use the virtual identity.

7. The method according to claim 5 or 6, characterized in that, The first information also includes at least one of the following: The image of the virtual identity; A third identifier, wherein the third identifier is used to indicate the first device; A fourth identifier, wherein the fourth identifier is used to indicate the application requesting access; Location information, wherein the location information is used to indicate the location of the first device.

8. The method according to any one of claims 5 to 7, characterized in that, The method further includes: Send second information to a fourth device, wherein the second information includes: the first identifier and the image of the virtual identity, and the second information is used to obtain authorization information; The third information sent by the fourth device is received, wherein the third information includes one of the following: authorization information, wherein the authorization information is sent after determining that the image of the virtual identity is real; and first indication information, wherein the first indication information is used to indicate the reason for the failure to obtain the authorization information.

9. The method according to any one of claims 5 to 7, characterized in that, The method further includes: The authenticity of the virtual identity is determined based on the certificate from a third device.

10. The method according to claim 9, characterized in that, The method also includes one of the following: If it is determined that the image of the virtual identity is real, a fourth message is sent to the third device. The fourth message includes the first identifier, the second identifier, and the fourth identifier. The fourth message is used to obtain authorization information. If it is determined that the image of the virtual identity is not real, a second indication message is sent to the first device, the second indication message being used to indicate verification failure; If it is impossible to determine whether the image of the virtual identity is real, the fourth information is sent to the third device. The fourth information also includes the image of the virtual identity and is used to request verification of whether the image of the virtual identity is real.

11. The method according to claim 10, characterized in that, The method further includes: The system receives a fifth message sent by the third device, wherein the fifth message is determined based on the fourth message; the fifth message includes one of the following: Authorization information, wherein the authorization information is sent after confirming that the image of the virtual identity is real; First indication information, wherein the first indication information is used to indicate the reason for failure to obtain the authorization information.

12. The method according to any one of claims 8 to 11, characterized in that, The method further includes at least one of the following: Based on the authorization information, verify whether the user and the virtual identity are associated: Based on the authorization information, verify whether the virtual identity is permitted to be used in the application indicated by the fourth identifier.

13. An information processing method, characterized in that, Performed by a third device, including: The device receives a first identifier and a virtual identity image sent by one of the first device, the second device, and the fourth device, wherein the first identifier is used to indicate the virtual identity; Based on the first identifier and the image of the virtual identity, determine whether the image of the virtual identity is real.

14. The method according to claim 13, characterized in that, The image of the first identifier and virtual identity received from one of the first device, the second device, and the fourth device includes one of the following: Receive first information sent by the first device, wherein the first information includes the first identifier and the image of the virtual identity; Receive fourth information sent by the second device, wherein the fourth information includes the first identifier and the image of the virtual identity; The sixth information sent by the fourth device is received, wherein the sixth information includes the first identifier and the image of the virtual identity.

15. The method according to claim 14, characterized in that, The first information further includes at least one of the following: a second identifier and a fourth identifier; the second identifier is used to indicate a user; the fourth identifier is used to indicate the application requesting access; the first information is also used to request at least one of the following: verifying whether the user is associated with the virtual identity, and whether the virtual identity is allowed to use the application indicated by the fourth identifier; or, The fourth information further includes the second identifier and the fourth identifier; the fourth information is also used to obtain authorization information, which includes first authorization information and second authorization information, wherein the first authorization information is stored in the third device and the second authorization information is stored in the fourth device; or... The sixth piece of information is also used to obtain the first authorization information.

16. The method according to claim 15, characterized in that, The fourth piece of information is sent by the second device after determining that the image of the virtual identity is real; or, The fourth piece of information is sent when the second device cannot determine whether the virtual identity's appearance is real; or, The sixth piece of information is sent by the fourth device when it cannot determine whether the virtual identity is real; or, The sixth piece of information is sent by the fourth device when it determines that the second authorization information is unavailable.

17. The method according to claim 15 or 16, characterized in that, The method further includes: The first authorization information is sent to the fourth device.

18. The method according to claim 15 or 16, characterized in that, The method further includes: Send a seventh message to the fourth device, wherein the seventh message includes the first identifier, the second identifier, and the fourth identifier, and the seventh message is used to obtain the second authorization information; Receive the second authorization information sent by the fourth device.

19. The method according to claim 18, characterized in that, The method further includes: Send a fifth message to the second device, wherein the fifth message includes one of the following: The authorization information is sent after confirming that the image of the virtual identity is real; First indication information, wherein the first indication information is used to indicate the reason for failure to obtain the authorization information.

20. The method according to claim 15, characterized in that, The method further includes at least one of the following: Based on the authorization information, verify whether the user and the virtual identity are associated: Based on the authorization information, verify whether the virtual identity is allowed to use the application indicated by the fourth identifier.

21. The method according to claim 20, characterized in that, The method further includes: The user is associated with the virtual identity and sends the first information to the second device.

22. An information processing method, characterized in that, Performed by a fourth device, including: Receive the second information sent by the second device or the seventh information sent by the third device; The second information includes: a first identifier and the image of the virtual identity, and a fourth identifier, wherein the first identifier is used to indicate the virtual identity; the second information is used to obtain authorization information; the authorization information includes at least one of the following: first authorization information and second authorization information; The seventh information includes the first identifier, the second identifier, and the fourth identifier, wherein the second identifier is used to indicate the user; the seventh information is used to obtain the second authorization information.

23. The method according to claim 22, characterized in that, The method also includes one of the following: Based on the certificate of the third device, determine whether the image of the virtual identity is real; If it is impossible to determine whether the image of the virtual identity is real, a sixth message is sent to the third device. The sixth message includes the first identifier and the image of the virtual identity. The sixth message is used to request at least one of the following: first authorization information, and verification of whether the image of the virtual identity is real. If the second authorization information is unavailable, the sixth information is sent to the third device. The sixth information includes the first identifier and the image of the virtual identity. The sixth information is used to obtain the first authorization information.

24. The method according to claim 23, characterized in that, The method further includes: Receive the first authorization information sent by the third device.

25. The method according to any one of claims 23 to 24, characterized in that, The method further includes: Send a third message to the second device, wherein the third message includes one of the following: Authorization information, wherein the authorization information is sent after confirming that the image of the virtual identity is real; First indication information, wherein the first indication information is used to indicate the reason for failure to obtain the authorization information.

26. The method according to claim 22, characterized in that, The method further includes: Send the second authorization information to the third device.

27. An information processing method, characterized in that, The information processing method is executed by a communication system, which includes a first device, a second device, and a third device; the information processing method includes: The first device sends first information to the second or third device, wherein the first information is used to trigger verification of whether the user and the virtual identity are associated; the first information includes a first identifier and a second identifier; the first identifier is used to indicate the virtual identity, and the second identifier is used to indicate the user.

28. A communication device, characterized in that, The communication device is used to perform the information processing method according to any one of claims 1 to 4, or claims 5 to 12, or claims 13 to 21, or claims 22 to 26.

29. A communication system, characterized in that, include: A first device, a second device, a third device, and a fourth device; wherein the first device is configured to implement the information processing method of any one of claims 1 to 4, the second device is configured to implement the information processing method of any one of claims 5 to 12, the third device is configured to implement the information processing method of any one of claims 13 to 21, and the fourth device is configured to implement the information processing method of any one of claims 22 to 26.

30. A storage medium storing instructions, characterized in that, When the instructions are executed on the communication device, the communication device performs the information processing method as described in any one of claims 1 to 4, or claims 5 to 12, or claims 13 to 21, or claims 22 to 26.

31. A computer program product, comprising at least one of a program and instructions, characterized in that, When at least one of the programs or instructions is executed by a communication device, it implements the information processing method according to any one of claims 1 to 4, or claims 5 to 12, or claims 13 to 22, or claims 23 to 26.