Permission control method and apparatus
Patent Information
- Application Number
- PCT/CN2026/072264
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-19
- Filing Date
- 2026-01-13
- Publication Date
- 2026-08-27
Smart Images

Figure CN2026072264_27082026_PF_FP_ABST
Abstract
Description
A method and apparatus for access control
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202510189332.7, filed on February 19, 2025, entitled "A Method and Apparatus for Access Control", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of communication technology, and in particular to an access control method and apparatus. Background Technology
[0004] Data plays a vital role in communication networks, and efficient data utilization requires data services. Data service (DS) refers to providing data as a service product after data collection, preprocessing, distribution, publication, and analysis.
[0005] With the development of mobile communication networks and new technologies, the amount of data in mobile communication networks is increasing, leading to a growing demand for data services. Currently, it is possible to process data in mobile communication networks based on a data service architecture; however, improving data security remains a significant challenge. Summary of the Invention
[0006] This application provides an access control method and apparatus for controlling data access permissions and / or publishing permissions for data services, thereby improving security.
[0007] The embodiments of this application can be applied to systems that include network elements, devices, or functional entities such as data orchestration / data controllers and data communication agents.
[0008] In a first aspect, an access control method is provided, which can be applied to a data orchestration / data controller. The method includes: determining access control information for a first data service, wherein the access control information is used to instruct a data agent to obtain and / or publish permissions for the first data service; and sending the access control information to a data communication agent.
[0009] In the above implementation, the data orchestration / data controller can send the access control information of the first data service to the data communication agent, so that the data communication agent can determine the data agent's access permission or publishing permission for the first data service based on the access control information, thereby realizing the control of access / publishing permissions and improving data security.
[0010] In one possible implementation, the access permission includes being allowed to access and / or not being allowed to access; the publishing permission includes being allowed to publish and / or not being allowed to publish.
[0011] In one possible implementation, allowing access includes allowing subscription, and disallowing access includes disallowing subscription; or, allowing access includes allowing retrieval, and disallowing access includes disallowing retrieval; or, allowing access includes allowing both subscription and retrieval, and disallowing subscription includes disallowing both subscription and retrieval.
[0012] In one possible implementation, the permission control information includes topic permission control information, which indicates: the data agent's permission to access topics of the first data service; and / or, the data agent's permission to publish topics of the first data service.
[0013] In one possible implementation, the topic of the first data service includes a first topic, and the topic permission control information includes first topic permission control information, which is used to indicate: the data agent's access permission to the first topic; and / or, the data agent's publishing permission to the first topic.
[0014] In one possible implementation, the first topic permission control information includes: information of one or more data proxies, and at least one of the following: access permission information of the one or more data proxies for the first topic, or publication permission information of the one or more data proxies for the first topic; or, information of one or more regions, and at least one of the following: access permission information of data proxies within the one or more regions for the first topic, or publication permission information of data proxies within the one or more regions for the first topic; wherein the access permission information is used to indicate access permission, and the publication permission information is used to indicate publication permission.
[0015] In one possible implementation, the first topic access control information includes at least one of the following: allowed access to information, prohibited access to information, allowed publication of information, and prohibited publication of information; the allowed access information includes information of one or more data proxies, wherein the one or more data proxies are allowed to access the first topic; or, the allowed access information includes information of one or more regions, wherein data proxies within the one or more regions are allowed to access the first topic; or, the prohibited access information includes information of one or more data proxies, wherein the one or more data proxies are not allowed to access the first topic; or, the prohibited access information includes information of one or more regions, wherein data proxies within the one or more regions are not allowed to access the first topic; the allowed publication information includes information of one or more data proxies, wherein the one or more data proxies are allowed to publish the first topic; or, the allowed publication information includes information of one or more regions, wherein data proxies within the one or more regions are allowed to publish the first topic; or, the prohibited publication information includes information of one or more data proxies, wherein the one or more data proxies are not allowed to publish the first topic; or, the prohibited publication information includes information of one or more regions, wherein data proxies within the one or more regions are not allowed to publish the first topic.
[0016] In one possible implementation, the access control information includes information about one or more data proxies, and the roles of the one or more data proxies for the first data service.
[0017] In one possible implementation, the one or more data agents include a first data agent, the role of which includes a first role and / or a second role, or the role of the first data agent is one of a first role, a second role, and a third role; the first role is a role that allows or disallows access to the first data service; the second role is a role that allows or disallows the publication of the first data service; and the third role is a role that allows or disallows both access to and publication of the first data service.
[0018] In one possible implementation, the permission control information further includes the control permissions represented by the role, wherein the control permissions include at least one of acquisition permissions and release permissions.
[0019] In one possible implementation, determining the access control information of the first data service includes: determining the access control information of the first data service based on the access control policy corresponding to the first data service and / or the demand information of the first data service.
[0020] In one possible implementation, the requirement information for the first data service includes at least one of the following: data service type, data service security level, data service area information, and data service time information.
[0021] In one possible implementation, the access control policy corresponding to the first data service is a topic-based access control policy; determining the access control information of the first data service includes: determining topic access control information, which is used to indicate the data agent's access permission and / or publishing permission for the topic of the first data service; or, the access control policy corresponding to the first data service is a role-based access control policy; determining the access control information of the first data service includes: determining the role of the data agent, which includes at least one of the following: a role that is allowed or not allowed to access the first data service, and / or a role that is allowed or not allowed to publish the first data service.
[0022] One possible implementation also includes: obtaining the access control policy corresponding to the first data service.
[0023] In one possible implementation, obtaining the access control policy corresponding to the first data service includes: sending a request message, the request message being used to obtain the access control policy corresponding to the first data service; and receiving information about the access control policy corresponding to the first data service.
[0024] In one possible implementation, the request message includes the demand information for the first data service.
[0025] In one possible implementation, before determining the access control information of the first data service, the method further includes: receiving a service request message, wherein the service request message is used to request the first data service.
[0026] Optionally, the service request message may include the demand information for the first data service.
[0027] One possible implementation further includes: updating the access control information; and sending the updated access control information to the data communication proxy.
[0028] One possible implementation further includes: when the first data service ends, notifying the data communication agent to delete the access control information.
[0029] Secondly, a permission control method is provided, which can be applied to a data communication proxy. The method includes: receiving permission control information corresponding to a first data service, wherein the permission control information is used to instruct the data proxy on access permissions and / or publishing permissions for the first data service; upon receiving a data access request message from the first data proxy, responding to the data access request message according to the first data proxy's access permissions for the first data service; or, upon receiving a data publishing request message from the first data proxy, responding to the data publishing request message according to the first data proxy's publishing permissions for the first data service; wherein the first data proxy's access permissions and publishing permissions for the first data service are determined based on the permission control information.
[0030] In one possible implementation, the access permission includes being allowed to access and / or not being allowed to access; the step of responding to the data access request message according to the access permission of the first data agent to the first data service includes: determining whether the first data agent is allowed to access the first data service based on the access permission of the first data agent to the first data service.
[0031] In one possible implementation, the data acquisition request message is a data subscription request message; determining whether the first data agent is allowed to acquire the first data service includes: determining whether the first data agent is allowed to subscribe to the first data service; or, the data acquisition request message is a data extraction request message; determining whether the first data agent is allowed to acquire the first data service includes: determining whether the first data agent is allowed to extract the first data service.
[0032] In one possible implementation, the access control information includes topic access control information, which includes first topic access control information. The first topic access control information is used to indicate: the first data agent's access permission to a first topic of the first data service; determining whether the first data agent is allowed to access the first data service includes: determining whether the first data agent is allowed to access the first topic based on the information of the first topic included in the data acquisition request message.
[0033] In one possible implementation, the first topic access control information includes: information about one or more data proxies, and access permission information for the one or more data proxies to access the first topic, wherein the access permission information is used to indicate access permission; determining whether the first data proxies are allowed to access the first topic includes: determining whether the first data proxies are allowed to access the first topic based on whether the first data proxies are one of the one or more data proxies; or, the first topic access control information includes: information about one or more regions, and access permission information for the first topic for data proxies within the one or more regions, wherein the access permission information is used to indicate access permission; determining whether the first data proxies are allowed to access the first topic includes: determining whether the first data proxies are allowed to access the first topic based on whether the region where the first data proxies are located is within the one or more regions.
[0034] In one possible implementation, the first topic access control information includes at least one of the following: allowed access to information, prohibited access to information; the allowed access information includes information about one or more data proxies, which are allowed to access the first topic; determining whether the first data proxy is allowed to access the first topic based on whether the first data proxy is one of the one or more data proxies includes: if the first data proxy is one of the one or more data proxies, then the first data proxy is allowed to access the first topic; or, the allowed access information includes information about one or more regions, where data proxies within the one or more regions are allowed to access the first topic; determining whether the first data proxy is allowed to access the first topic based on whether the region where the first data proxy is located is within the one or more regions includes: if the region where the first data proxy is located is within the one or more regions, The first data agent is allowed to access the first topic; or, the prohibited access information includes information about one or more data agents, which are not allowed to access the first topic; determining whether the first data agent is allowed to access the first topic based on whether the first data agent is one of the one or more data agents includes: if the first data agent is not one of the one or more data agents, then the first data agent is allowed to access the first topic; or, the prohibited access information includes information about one or more regions, where data agents within the one or more regions are not allowed to access the first topic; determining whether the first data agent is allowed to access the first topic based on whether the region where the first data agent is located is within the one or more regions includes: if the region where the first data agent is located is not within the one or more regions, then the first data agent is allowed to access the first topic.
[0035] In one possible implementation, the publishing permission includes being allowed to publish and / or not being allowed to publish; the step of responding to the data publishing request message according to the publishing permission of the first data agent for the first data service includes: determining whether the first data agent is allowed to publish the first data service based on the publishing permission of the first data agent for the first data service.
[0036] In one possible implementation, the permission control information includes topic permission control information, which includes first topic permission control information. The first topic permission control information is used to indicate: the first data agent's publishing permission for a first topic of the first data service; determining whether the first data agent is allowed to publish the first data service includes: determining whether the first data agent is allowed to publish the first topic based on the information of the first topic included in the data publishing request message.
[0037] In one possible implementation, the first topic permission control information includes: information about one or more data proxies, and publishing permission information of the one or more data proxies for the first topic, wherein the publishing permission information is used to indicate publishing permissions; determining whether the first data proxies are allowed to publish the first topic includes: determining whether the first data proxies are allowed to publish the first topic based on whether the first data proxies are one of the one or more data proxies; or, the first topic permission control information includes: information about one or more regions, and publishing permission information of data proxies within the one or more regions for the first topic, wherein the publishing permission information is used to indicate publishing permissions; determining whether the first data proxies are allowed to publish the first topic includes: determining whether the first data proxies are allowed to publish the first topic based on whether the region where the first data proxies are located is within the one or more regions.
[0038] In one possible implementation, the first topic access control information includes at least one of the following: allowing information posting, prohibiting information posting; the allowed posting information includes information about one or more data proxies, which are allowed to post the first topic; determining whether the first data proxy is allowed to post the first topic based on whether it is one of the one or more data proxies includes: if the first data proxy is one of the one or more data proxies, then the first data proxy is allowed to post the first topic; or, the allowed posting information includes information about one or more regions, where data proxies within the one or more regions are allowed to post the first topic; determining whether the first data proxy is allowed to post the first topic based on whether the region where the first data proxy is located is within the one or more regions includes: if the region where the first data proxy is located is within the one or more regions, then... The first data agent is allowed to publish the first topic; or, the prohibited publishing information includes information about one or more data agents, and the one or more data agents are not allowed to publish the first topic; determining whether the first data agent is allowed to publish the first topic based on whether the first data agent is one of the one or more data agents includes: if the first data agent is not one of the one or more data agents, then the first data agent is allowed to publish the first topic; or, the prohibited publishing information includes information about one or more regions, and data agents in the one or more regions are not allowed to publish the first topic; determining whether the first data agent is allowed to publish the first topic based on whether the region where the first data agent is located is located within the one or more regions includes: if the region where the first data agent is located is not within the one or more regions, then the first data agent is allowed to publish the first topic.
[0039] In one possible implementation, the access control information includes information about one or more data proxies, and the roles of the one or more data proxies for the first data service; the step of responding to the data acquisition request message based on the first data proxies' access permissions to the first data service includes: determining whether the first data proxies are allowed to acquire the first data service based on their roles.
[0040] In one possible implementation, the role of the first data agent includes a first role and / or a second role, or the role of the first data agent is one of a first role, a second role, and a third role; wherein, the first role is the role that is allowed or not allowed to access the first data service, the second role is the role that is allowed or not allowed to publish the first data service, and the third role is the role that is allowed or not allowed to access and publish the first data service; the step of determining whether the first data agent is allowed to access the first data service based on the role of the first data agent includes: if the role of the first data agent includes the first role, or the role of the first data agent is the third role, then it is determined that the first data agent is allowed or not allowed to access the first data service.
[0041] In one possible implementation, the access control information includes information about one or more data proxies, and the roles of the one or more data proxies for the first data service; the step of responding to the data acquisition request message based on the publishing permissions of the first data proxies for the first data service includes: determining whether the first data proxies are allowed to publish the first data service based on the roles of the first data proxies.
[0042] In one possible implementation, the role of the first data agent includes a first role and / or a second role, or the role of the first data agent includes one of a first role, a second role, and a third role; wherein, the first role is the role that is allowed or not allowed to obtain the first data service, the second role is the role that is allowed or not allowed to publish the first data service, and the third role is the role that is allowed or not allowed to obtain and publish the first data service; the step of determining whether the first data agent is allowed to publish the first data service based on the role of the first data agent includes: if the role of the first data agent includes the second role, or the role of the first data agent is the third role, then determining whether the first data agent is allowed or not allowed to publish the first data service.
[0043] In one possible implementation, responding to the data acquisition request message based on the first data agent's access permission to the first data service includes: if the first data agent is not allowed to acquire the first data service, sending a failure response message to the first data agent, the failure response message indicating that the first data agent is not allowed to acquire the first data service; or, responding to the data publishing request message based on the first data agent's publishing permission to the first data service includes: if the first data agent is not allowed to publish the first data service, sending a failure response message to the first data agent, the failure response message indicating that the first data agent is not allowed to publish the first data service.
[0044] In one possible implementation, responding to the data acquisition request message based on the first data agent's access permission to the first data service includes: if the first data agent is not allowed to acquire the first topic of the first data service, then the data communication agent abandons sending data of the first topic to the first data agent.
[0045] In one possible implementation, responding to the data publishing request message based on the first data agent's publishing permission for the first data service includes: if the first data agent is not allowed to publish the first topic of the first data service, then when the data communication agent receives data from the first data agent on the first topic, it discards the data, that is, it will not send the data to other DAs that have subscribed to the data.
[0046] In one possible implementation, responding to the data acquisition request message based on the first data agent's access permission to the first data service includes: if the first data agent is allowed to acquire a first topic of the first data service, the data communication agent can send data of the first topic to the first data agent.
[0047] In one possible implementation, responding to the data publishing request message based on the first data agent's publishing permission for the first data service includes: if the first data agent is allowed to publish the first data service, then when the data communication agent receives data from the first data agent on the first topic, it sends the data to the data agent that has subscribed to the first topic.
[0048] In one possible implementation, the method further includes receiving updated access control information.
[0049] In one possible implementation, the method further includes: receiving a notification message; and deleting the access control information based on the notification message.
[0050] Thirdly, an access control method is provided, which can be applied to a first network element, such as a core network element, or more specifically, a policy control function. The method includes: receiving a request message from a data communication agent, the request message being used to obtain an access control policy corresponding to a first data service; and sending information about the access control policy corresponding to the first data service to the data communication agent according to the request message.
[0051] In one possible implementation, the request message includes demand information for the first data service; the method further includes: obtaining the access control policy corresponding to the first data service based on the demand information.
[0052] In one possible implementation, the business requirement information includes the data service type of the first data service; obtaining the access control policy corresponding to the first data service based on the requirement information includes: obtaining the access control policy corresponding to the data service type based on the data service type.
[0053] In one possible implementation, the business requirement information includes the data service type and data service security level of the first data service; obtaining the access control information corresponding to the first data service based on the requirement information includes: obtaining the access control policy corresponding to the data service type and the data service security level based on the data service type and the data service security level.
[0054] In one possible implementation, the business requirement information includes the data service type and data service area information of the first data service, wherein the data service area information indicates the area where the first data service is applied; the step of obtaining the access control information corresponding to the first data service based on the requirement information includes: obtaining the access control policy corresponding to the data service type and the one or more regions based on the data service type and one or more regions, wherein the one or more regions are within the area indicated by the data service area information.
[0055] In one possible implementation, the business requirement information includes the data service type and data service time information of the first data service, wherein the data service time information indicates the start and end times of the first data service; the step of obtaining the access control information corresponding to the first data service based on the requirement information includes: obtaining the access control policy corresponding to the data service type and the one or more time periods based on the data service type and one or more time periods, wherein the one or more time periods are within the range of the start and end times.
[0056] In one possible implementation, the access control policy corresponding to the first data service is used to instruct the data communication agent to set the data agent's access permissions and / or publishing permissions for the topic of the first data service, or the access control policy corresponding to the first data service is used to instruct the data communication agent to set the data agent's role for the first data service.
[0057] Fourthly, a communication device is provided, the communication device including a unit or module for performing the method as described in any of the first aspects above, or including a unit or module for performing the method as described in any of the second aspects above, or including a unit or module for performing the method as described in any of the third aspects above.
[0058] Fifthly, a communication device is provided, the communication device comprising: one or more processors configured to perform the method as described in any one of the first aspects above, or to perform the method as described in any one of the second aspects above, or to perform the method as described in any one of the third aspects above.
[0059] In a sixth aspect, a readable storage medium is provided, the readable storage medium storing a program or instructions that, when the program or instructions are executed on a device, cause the device to perform the method as described in any one of the first aspects above, or to perform the method as described in any one of the second aspects above, or to perform the method as described in any one of the third aspects above.
[0060] In a seventh aspect, a chip system or chip is provided, including a processor, for supporting a computer device to implement the method as described in any one of the first aspects above, or to implement the method as described in any one of the second aspects above, or to implement the method as described in any one of the third aspects above.
[0061] Eighthly, a computer program product is provided, the computer program product comprising a program; when the computer program is run on a computer, the computer causes the computer to perform the method as described in any one of the first aspects above, or to perform the method as described in any one of the second aspects above, or to perform the method as described in any one of the third aspects above.
[0062] A ninth aspect provides a communication system including a data orchestration / data controller and a data communication agent, wherein the data orchestration / data controller performs the method described in any one of the first aspects, and the data communication agent performs the method described in any one of the second aspects.
[0063] In a tenth aspect, a communication system is provided, including a first network element and a data orchestration / data controller, wherein the first network element performs the method described in any one of the third aspects above. Attached Figure Description
[0064] Figure 1 is a schematic diagram of data transmission based on DCP in an embodiment of this application;
[0065] Figure 2 is a schematic diagram of a data service architecture applicable to an embodiment of this application;
[0066] Figure 3 is a schematic diagram of a system architecture for introducing DCP in a 3GPP network according to an embodiment of this application;
[0067] Figure 4 is a schematic diagram of a protocol stack according to this application;
[0068] Figure 5 is a schematic diagram of another system architecture for introducing DCP in a 3GPP network according to an embodiment of this application;
[0069] Figures 6a, 6b and 6c are schematic diagrams of a protocol stack according to this application;
[0070] Figure 7 is a flowchart illustrating an access control method provided in an embodiment of this application;
[0071] Figure 8 is a flowchart illustrating another access control method provided in an embodiment of this application;
[0072] Figure 9 is a flowchart illustrating another access control method provided in an embodiment of this application;
[0073] Figure 10 is a flowchart illustrating another access control method provided in an embodiment of this application;
[0074] Figure 11 is a flowchart illustrating another access control method provided in an embodiment of this application;
[0075] Figure 12 is a schematic diagram of the communication device provided in an embodiment of this application;
[0076] Figure 13 is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation
[0077] This application provides an access control method and an apparatus for implementing the method, used to control subscription permissions and / or publishing permissions for data services, thereby improving security. The method and apparatus provided in this application are based on the same technical concept. Since the principles by which the method and apparatus solve the problem are similar, the implementation of the apparatus and method can be referred to each other, and repeated details will not be elaborated further.
[0078] The embodiments of this application will now be described with reference to the accompanying drawings.
[0079] To facilitate understanding by those skilled in the art, some terms used in this application will be explained below.
[0080] (1) Access network equipment
[0081] Access network equipment can be any type of wireless transceiver device used to communicate with terminal devices, providing access for those devices. Access network equipment can also be called network equipment, access node (AN), radio access network (RAN) equipment, etc. Access network equipment can be a base station, an evolved Node B (eNB or e-NodeB) in a Long Term Evolution (LTE) or Long Term Evolution-Advanced (LTE-A) system, a transmission reception point (TRP), a next-generation NodeB (gNB) in a 5th generation (5G) mobile communication system, a next-generation base station in a future mobile communication system, a base station in a future mobile communication system, or an access node in a wireless fidelity (WiFi) system, etc.
[0082] For example, access network equipment can be a macro base station, a micro base station (also known as a small station), an indoor station, a relay node, or a donor node. Access network equipment can also be a radio network controller (RNC), a Node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (e.g., a home evolved Node B, or a home Node B, HNB), a base band unit (BBU), a remote radio unit (RRU), a Wi-Fi access point (AP), or a base band pool (BBU pool) and RRU in a cloud radio access network (CRAN), and can also be satellite or drone equipment.
[0083] In some deployments, access network equipment can also be access network equipment in an Open RAN (ORAN) system. Optionally, access network equipment can also be a module or unit that performs some of the functions of a base station, and may also include an active antenna unit (AAU). For example, access network equipment can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. Here, the CU is responsible for handling non-real-time protocols and services, performing the functions of the radio resource control (RRC) protocol and packet data convergence protocol (PDCP) of the base station, and can also perform the functions of the service data adaptation protocol (SDAP); the DU is responsible for handling physical layer protocols and real-time services, performing the functions of the radio link control (RLC) layer and medium access control (MAC) layer of the base station, and can also perform some or all of the physical (PHY) layer functions. In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in the ORAN system, CU can also be called O-CU, DU can also be called open (O)-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CUP-UP, and RU can also be called O-RU.
[0084] The AAU implements some physical layer processing functions, radio frequency processing, and related functions of the active antenna. RRC layer information is generated by the CU and ultimately encapsulated into PHY layer information by the DU's PHY layer, or it may be derived from PHY layer information. Therefore, in this architecture, higher-layer signaling such as RRC layer signaling can be considered to be sent by the DU, or by the DU+AAU. It is understood that access network equipment can be one or more of the following: CU nodes, DU nodes, and AAU nodes. Furthermore, the CU can be classified as an access network device in the RAN, or it can be classified as an access network device in the core network (CN); this application does not limit this classification.
[0085] In this embodiment, the access network device can also be a functional module, chip, or chip system. Optionally, the functional module, chip, or chip system can be disposed within the access network device.
[0086] The embodiments of this application do not limit the specific technology or specific device form used in the access network equipment.
[0087] (2) Terminal equipment
[0088] Terminal equipment, also known as a terminal, user terminal, user device, user equipment (UE), user unit, user station, mobile station (MS), mobile station, remote station, remote terminal, mobile terminal (MT), user agent, etc., is a device that provides voice and / or data connectivity to a user. For example, terminal equipment can include handheld devices with wireless connectivity, computing devices or other processing devices connected to a wireless modem, in-vehicle equipment, etc., and may be a terminal in a 5G network or a future evolved network.
[0089] Currently, terminal devices can be: cellular phones (e.g., mobile phones), cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), tablets, laptops, handheld computers, mobile internet devices (MIDs), wearable devices, customer premises equipment (CPEs), virtual reality (VR) devices, augmented reality (AR) devices, extended reality (XR) devices, and mixed reality (MR) devices.
[0090] For example, terminal devices can also be wireless terminals in industrial control, self-driving, remote medical surgery, smart grids, transportation safety, smart cities, smart homes, express delivery terminals in smart logistics (e.g., devices that can monitor the location of cargo vehicles, devices that can monitor the temperature and humidity of cargo), wireless terminals in smart agriculture (e.g., wearable devices that can collect relevant data on poultry and livestock), wireless terminals in smart buildings (e.g., smart elevators, fire monitoring equipment, and smart meters), wireless terminals in smart healthcare (e.g., wearable devices that can monitor the physiological state of humans or animals), wireless terminals in smart transportation (e.g., smart buses, smart vehicles, shared bicycles, charging pile monitoring equipment, smart traffic lights, smart monitoring and smart parking equipment), and wireless terminals in smart retail (e.g., vending machines, self-checkout machines, and unmanned convenience stores).
[0091] For example, the terminal device can also be a device-to-device (D2D) communication terminal device, a vehicle-to-everything (V2X) communication terminal device, an intelligent vehicle, a vehicle-to-everything (Telematics Box, TBOX) system, a machine-to-machine / machine-type (M2M / MTC) communication terminal device, or an Internet of Things (IoT) terminal device. For instance, the terminal device can be a vehicle, ship, or aircraft, or a terminal-type roadside unit, or a communication module or chip built into a vehicle or roadside unit. For example, the terminal device can be an in-vehicle module, which can be built into a vehicle as one or more components or units, such as an in-vehicle module, in-vehicle component, in-vehicle chip, or in-vehicle unit.
[0092] For example, the terminal device can also be a smart internet of things (SIoT) terminal device or a non-SIoT terminal device, possessing certain computing and storage capabilities. Non-SIoT terminal devices can collect data through an IoT gateway; for instance, a non-SIoT terminal device can be a terminal with limited computing power, such as a single-function sensor. Optionally, an SIoT terminal device can have a built-in data proxy, or the SIoT terminal device can implement a data proxy function.
[0093] In this embodiment, the terminal device can also be a functional module, chip, or chip system. Optionally, the functional module, chip, or chip system can be disposed within the terminal device.
[0094] The embodiments of this application do not limit the specific technology or specific device form used in the terminal device.
[0095] (3) Data acquisition and data acquisition permissions
[0096] Data acquisition methods include data push and data fetch. Data fetch can also be called data pull.
[0097] The process of a data consumer obtaining data via push notifications can include: the data consumer initiating a data subscription request to a data communication proxy (DCP), after which the DCP proactively pushes the subscribed data to the data consumer. The process of a data consumer obtaining data via retrieval can include: the data consumer initiating a data subscription request to the DCP, after which the data consumer proactively sends a data retrieval request to the DCP to obtain the subscribed data.
[0098] Data subscription is a method of information delivery, or a messaging pattern, used to obtain and subscribe to data or data updates of interest in real time. Data subscription allows users to choose the data type, frequency, and format to subscribe to according to their needs, ensuring that only data of interest is obtained and reducing unnecessary data transmission.
[0099] Data access permissions (or simply access permissions) can include at least one of the following permissions: allowed access, not allowed access. Depending on the data access method, "allowed access" can be understood as allowed subscription, and "not allowed access" as not allowed subscription; or, "allowed access" can be understood as allowed extraction, and "not allowed access" as not allowed extraction; or, "allowed access" can be understood as allowed both subscription and extraction, and "not allowed access" as not allowed both subscription and extraction. For example, for the same type of data (such as data on the same topic), the same data consumer may be allowed to subscribe to the data, or allowed to extract the data, or allowed to subscribe to and extract the data, or not allowed to subscribe to the data, or not allowed to extract the data, or not allowed to subscribe to and extract the data.
[0100] (4) Data publishing and data publishing permissions
[0101] Data publishing is a method of information delivery, or a messaging pattern, used to send data to its subscribers in real time. Through data publishing, data providers can send data updates to their subscribers in real time.
[0102] Data publishing permissions (or simply publishing permissions) can include at least one of the following permissions: allowed to publish, or not allowed to publish. For example, for a certain type of data, the data publisher's publishing permission for that data can be either allowed to publish that type of data or not allowed to publish that type of data.
[0103] In some embodiments of this application, the permission to publish data and the permission to obtain data are independent of each other.
[0104] (5) In the description of this application, the words “first”, “second” and the like are used only for the purpose of distinguishing the description and should not be construed as indicating or implying relative importance or order.
[0105] (6) In the description of this application, "at least one" means one or more, and "more" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0106] (7) In the description of this application, "and / or" describes the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. " / " means "or", for example, a / b means a or b.
[0107] With the decrease in computing and storage costs, and the emergence of numerous low-latency services and local area applications, computing and storage, as well as the intelligent algorithms that rely on them, tend to be deployed closer to the network edge, closer to the data source. This forms a data-centric network architecture, which can be called a data service architecture. The basic function of mobile communication networks is beginning to shift from being a conduit for information transmission to a data service architecture that manages and controls data. This data service architecture acts as both a producer and provider of data, offering trusted data services to intelligent applications, and a consumer of data, leveraging data-driven intelligent applications to improve network performance and operational efficiency.
[0108] In a data service architecture, a single data source can reach multiple data nodes for fusion analysis and processing. To support multi-point to multi-point data exchange, a data communication proxy (DCP) is introduced into the network. DCP supports multi-point to multi-point data exchange, enabling the data origin and destination points to be any terminal device, access network device (e.g., base station), or NF / AF (AF stands for application function; NF stands for network function). A single data source can reach multiple data nodes for fusion analysis and processing, thereby decoupling data producers and consumers, simplifying network topology, achieving efficient asynchronous data exchange, and improving data transmission efficiency.
[0109] DCP can be deployed as an independent network element in 3GPP networks. For example, DCP can be deployed in the access network, the core network, or both. DCP can also be co-located with other network elements or equipment in the 3GPP network; this application does not limit this.
[0110] It should be understood that DCP is only an example name, and DCP can be replaced by other names. Any device with the same function as DCP can be regarded as DCP, and this application does not limit it.
[0111] Figure 1 illustrates an exemplary schematic diagram of data transmission based on DCP. As shown in the figure, the system architecture includes a data producer, a data consumer, and DCP.
[0112] In this context, data producers and data consumers can be network elements within a 3GPP network. Data producers and data consumers can be of the same type or different types of network elements. For example, the data producer may be a first access network device, and the data consumer a second access network device. Alternatively, the data producer may be a first core network device, and the data consumer a second core network device. Another example is that the data producer is an access network device, and the data consumer is a core network device. Yet another example is that the data producer is a core network device, and the data consumer is an access network device. Optionally, the same network element in a 3GPP network can act as a data consumer in one scenario and as a data producer in another; this application does not impose any limitations on this.
[0113] Data producers can send data to the DCP, such as through topic publishing as shown in Figure 1. The DCP can then send this data to data consumers who have subscribed to it. Data consumers can subscribe to topics or fetch data from the DCP, and the DCP can send the requested data to the data consumer. Each data consumer in a group can subscribe to and / or fetch data from the DCP.
[0114] DCP can support multiple transport protocols, such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Quick UDP Internet Connection (QUIC), or other transport protocols. DCP can include an adapter layer and a distributed message queue (DMQ) to support efficient data distribution. The adapter layer adapts the transport protocol (e.g., TCP, UDP, QUIC) for clients (such as data producers or consumers), interacts directly with the client, and distributes client requests to processing threads. DMQ handles message exchange, distributing messages published by data producers to corresponding data consumers. For example, DMQ can be RabbitMQ based on the Advanced Message Queuing Protocol (AMQP); or it can be implemented using a custom-developed message queue system, such as Kafka based on a custom protocol. This application does not limit the implementation method of DCP.
[0115] In some embodiments, DCP can communicate with data producers or data consumers through some interfaces.
[0116] For example, DCP can subscribe to data through an interface with a data consumer by transmitting messages to that data consumer. During data subscription, the message received by DCP may include the data consumer ID and a list of information types. It should be understood that the information type list is only one form; one or more information types may be carried in the message in other forms, and this application does not limit this. For example, the information type list may include a list of topics. Optionally, the message received by DCP through this interface may also include the subscription duration.
[0117] For example, DCP can communicate with data producers through an interface to publish data. During data publication, the messages received by DCP may include the data producer ID, a list of information types, and the data itself.
[0118] For example, DCP can communicate with data consumers through an interface to facilitate data consumption, i.e., the data extraction process. During data consumption, the messages received by DCP may include the data consumer producer ID and the information type. The messages sent by DCP during data consumption may include the data required by the consumer.
[0119] DCP supports transport layer security (TLS) for data encryption and integrity protection in scenarios where data is transmitted over TCP or QUIC. DCP also supports datagram transport layer security (DTLS) for data encryption and integrity protection in scenarios where data is transmitted over UDP.
[0120] In this embodiment of the application, a network element with control functions in the data service system architecture can provide access control information to the Data Provider (DCP). This allows the DCP to control access permissions for data consumers' data acquisition and / or data publishers' data publication. For example, upon receiving a data subscription request from a data consumer, the DCP can determine, based on the access control information, whether the data consumer is permitted to subscribe to the requested data; or upon receiving a data retrieval request from a data consumer, it can determine, based on the access control information, whether the data consumer is permitted to retrieve the requested data; or upon receiving a data publication request from a data publisher, it can determine, based on the access control information, whether the data publisher is permitted to publish the requested data. This enables control over data acquisition and / or publication permissions, thereby improving security.
[0121] In this embodiment, the network element with control function can be a data controller (DC). The DC can also be replaced by a data orchestration (DO), meaning that the functions of the DC in this application embodiment can be implemented by the DO. Therefore, in this application embodiment, the network element with control function is referred to as DO / DC.
[0122] It should be understood that DO / DC can also be replaced by other names, and any device with the same function as DO / DC can be regarded as DO / DC. This application does not limit this.
[0123] Referring to Figure 2, a schematic diagram of a data service architecture applicable to an embodiment of this application is shown. As shown in Figure 2, the communication system may include the following network elements: DO / DC, DCP, data processing function (DPF), and data agent (DA). Optionally, it may also include a distributed data storage function (DSF) network element (not shown in the figure). The number of the above network elements may be one or more, and this application does not limit it.
[0124] The aforementioned network elements can be logical entities or physical entities, and this application does not impose any restrictions.
[0125] It should be understood that the names of the network elements described above are not limited in the embodiments of this application. The functions and deployment methods of the above network elements are explained below using DO / DC, DA, DPF, and DCP as examples.
[0126] The DO / DC can translate service requests into data service requirements, determine the DAs used to fulfill those requirements, orchestrate the functions of each DA, manage the lifecycle of data service tasks, enable the DAs to perform corresponding operations, and establish a dynamic logical network topology to achieve the desired service. In some embodiments of this application, the DO / DC can set corresponding access control information for a specific data service and distribute this access control information to the DCP. This access control information can instruct one or more DAs on their access rights to acquire and / or publish the corresponding data.
[0127] DO / DC can be deployed in any core network element, transfer network (TN) element, access network equipment, or other network elements (such as operation administration and maintenance (OAM) elements), or it can be deployed independently. For example, DO / DC can be deployed hierarchically on the core network or access network equipment side. DO / DC can be deployed in network service (NS) elements. As another example, DO / DC can be deployed independently in the network as an NF or network element. In actual deployment, one or more NFs can form a network element.
[0128] Data Acquisition Providers (DAs) can perform one or more of the following functions: data acquisition, data preprocessing, data storage, data analysis, data protection, and data forwarding. Different DAs can have the same or different data service capabilities and can perform the same or different functions. DAs can interact with Data Publishers (DOs) / Data Controllers (DCs) to obtain the relevant operations required to fulfill service requirements and execute those operations. DAs can establish a logical network topology, forming a dynamic data pipeline (also called data flow, business logic, functional chain, operation chain, etc.). This data pipeline consists of one or more functions corresponding to DAs according to service requirements, with the output of the previous function being the input of the next function, thereby realizing the corresponding data service. DAs can also possess artificial intelligence (AI) and / or machine learning (ML) computing capabilities. In some embodiments of this application, a DA can send a data subscription request message to a Data Publisher (DCP) as a data consumer, or send a data publication request message to a DCP as a data publisher, or send a data extraction request message to a DCP as a data consumer.
[0129] A Data Provider (DA) can be deployed in any core network element, transmission network element, terminal device, access network device, or other network element (such as an OAM element). For example, a DA can evolve from any core network element, transmission network element, terminal device, access network device, or other network element. A DA can implement the functions that any core network element, transmission network element, terminal device, access network device, or other network element can perform. A DA can also be deployed independently; for example, a DA can be deployed independently in the network as an NF or network element.
[0130] A Data Provider (DP) is a special type of Data Analyzer (DA) capable of performing data analysis and processing functions. A DP can interact with Data Analyzers (DOs) / Data Controllers (DCs) to obtain and execute the necessary operations to fulfill service requirements. A DP can also possess AI and / or ML computing capabilities. In some embodiments of this application, the DP can act as a data consumer to send a data subscription request message to a Data Publisher (DCP), or as a data publisher to send a data publication request message to the DCP, or as a data consumer to send a data retrieval request message to the DCP.
[0131] DPF can be deployed in core network elements, transmission network elements, access network devices or other network elements, or DPF can be deployed independently. For example, DPF can be deployed independently in the network as an NF or network element.
[0132] The data service architecture shown in Figure 1 or Figure 2 can be applied to mobile communication networks, enabling the processing of data within these networks to provide data services. Figure 3 provides some examples of applying this data service architecture to mobile communication systems.
[0133] Figure 3 illustrates a possible architecture diagram for introducing DCP in a 3GPP network.
[0134] In this system architecture, the DO / DC can implement the control plane functions for data services. For example, for a certain type of data service, the DO / DC can orchestrate and select DAs based on their capabilities (e.g., determining the data processing operations that DAs need to perform, selecting DAs that can act as data consumers and DAs that can act as data publishers), and determine access control information, which is then sent to the DCP. The DO / DC can be mounted on the SBI bus through a service-based interface (SBI) to communicate with other core network elements.
[0135] DPF can be used to implement data plane functions for data services. For example, DPF can process business data for data services. DPF can be mounted to the SBI bus via SBI to communicate with other core network elements, or it can communicate with other DPFs through a separate interface, or communicate with DO / DC through a separate interface.
[0136] DSF can store business data for data services.
[0137] The core network elements in the system architecture shown in Figure 3, such as the access and mobility management function (AMF), network exposure function (NEF), policy control function (PCF), and charging function (CHF), can act as data consumers to subscribe to and / or retrieve data from the DCP, or as data producers to send data to the DCP.
[0138] The access network equipment and / or terminal equipment in Figure 3 can also act as data consumers to request data subscription and / or data retrieval from the DCP, or as data producers to send data to the DCP.
[0139] It should be understood that the devices included in the system architecture shown in Figure 3 are merely examples. In actual applications, other devices may be included, or some of the devices shown in Figure 3 may not be included. This application does not limit this.
[0140] Based on the system architecture shown in Figure 3, the protocol stack of the network elements in this architecture can be shown in Figure 4. The Data Forwarding Protocol (DFP-S) is a data processing protocol. The main functions of the DFP-S layer include data acquisition, data processing, data storage, data analysis, packet header parsing and reassembly, statistical information reporting, data compression, and privacy protection. The Data Spine Adaptor (DSA) layer is a newly introduced protocol layer based on the introduction of the DCP. The main function of the DSA layer is message queue adaptation (such as creating data consumers, creating data producers, data publishing, data subscription, data unsubscribing, and data consumption). Optionally, DSA can also be replaced by Message Queue Adaptor (MQA), or it can have other names; this application does not limit this.
[0141] Figure 5 shows a schematic diagram of another possible system architecture for introducing DCP in a 3GPP network.
[0142] In this system architecture, service data for data services can be transmitted to the DCP via the user plane function (UPF). For example, access network device 1, acting as a data publisher, first transmits data to the UPF, which then transmits the data to the DCP. Access network device 2, also acting as a data publisher, obtains data from the terminal device, first transmits the data to the UPF, which then transmits the data to the DCP.
[0143] The functions of DO / DC, DPF and DSF can be found in the relevant descriptions in the system architecture shown in Figure 3, and will not be described in detail here.
[0144] Similarly, core network elements in this system architecture, such as AMF, session management function (SMF), NEF, PCF, CHF, and application function (AF), can act as data consumers to request data subscription and data retrieval from DCP, or as data producers to send data to DCP.
[0145] It should be understood that the devices included in the system architecture shown in Figure 5 are merely examples. In actual applications, other devices may be included, or some of the devices shown in Figure 3 may not be included. This application does not limit this.
[0146] Based on the system architecture shown in Figure 5, in one possible approach, the access network device can transparently transmit data from the terminal device to the UPF, without processing the data. In this case, the protocol stack can be as shown in Figure 6a.
[0147] In another possible approach, the access network device needs to process the data after receiving it from the terminal device. In this case, the protocol stack can be as shown in Figure 6b.
[0148] It should be understood that access network devices can also act as data publishers, that is, access network devices can collect data. In this case, the protocol stack can be as shown in Figure 6c.
[0149] The embodiments of this application can be applied to 5G systems, future evolved communication systems, satellite communications, or short-range wireless communication systems. The wireless communication systems mentioned in these embodiments include, but are not limited to, the three major application scenarios of 5G systems or future evolved systems: enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and massive machine-type communications (mMTC), as well as long-range (LoRa) systems or vehicle-to-everything (V2X) systems. These embodiments can also be applied to ORAN systems, etc.
[0150] Based on the above description, the permission control method provided in the embodiments of this application will be described in detail below. In the following embodiments, the operation performed by a certain device (or network element) can also be performed by the processor, chip, chip system, or functional module of the certain device (or network element). This application only uses the execution of a certain device (or network element) as an example, but it is not intended to limit this application.
[0151] Based on the system architecture shown in Figures 1, 2, 3, or 5 above, Figure 7 illustrates a flowchart of an access control method provided in an embodiment of this application. Through this flowchart, the DO / DC can send access control information to the DCP. Upon receiving a data acquisition request or data publication request from the DA, the DCP can perform access control on the DA's data acquisition or data publication based on the access control information.
[0152] Referring to Figure 7, which is a flowchart illustrating an access control method provided in an embodiment of this application, the process may include the following steps:
[0153] Step 701: AF sends a service request message to DO / DC.
[0154] The service request message is used to request the first data service. The first data service is a type of service, also referred to as the first data business or the first service; therefore, the service request message is used to request the first data service (or the first service).
[0155] Requesting the first data service can be understood as requesting the execution of an operation related to the first data service, or as triggering an operation related to the first data service. For example, in this embodiment, a service request message can trigger a DO / DC to determine the access control information of the first data service.
[0156] In one implementation, the AF can directly send service request messages to the DO / DC. In another implementation, the AF can send service request messages to the DO / DC through the NEF or other network elements.
[0157] Besides the AF (Agent) initiating service requests to the DO / DC (Network Node / DC), other network elements or devices, such as third-party entities (or third-party applications), network NFs (Network Functions), or terminal devices, can also initiate service requests to the DO / DC. This application does not restrict the initiator of the service request.
[0158] In one possible implementation, the service request message may include demand information for the first data service, which indicates the business requirements of the first data service.
[0159] Optionally, the requirements information may include one or more of the following:
[0160] (1) Data Service Type: The data service type can be indicated by indication information. This indication information can indicate the business type of the first data service, such as environmental reconstruction business;
[0161] (2) Data service area information: This information indicates the area of the first data service application, which can also be called the business area;
[0162] (3) Data service security level. This information indicates the security level of the first data service. The same data service may have multiple security levels, or different types of data services may have different security levels.
[0163] (4) Data service time information: This information indicates the time range of the first data service application. For example, data service time information may include start and end times.
[0164] (5) Other information.
[0165] DO / DC can translate the service request message into a service requirement for data, determine the DA used to fulfill the service requirement, orchestrate the function of each DA, manage the lifecycle of data service tasks, enable the DA to perform corresponding operations, and establish a dynamic logical network topology to fulfill the corresponding service requirement.
[0166] Step 702: DO / DC sends a request message to the first network element.
[0167] The request message is used to obtain the access control policy corresponding to the first data service.
[0168] In one possible implementation, the request message includes the demand information for the first data service.
[0169] Step 703: The first network element sends the access control policy information corresponding to the first data service to the DO / DC.
[0170] In this embodiment, the access control policy can be a topic-based access control policy or a role-based access control policy. The DO / DC can determine the access control information of the first data service based on the access control policy corresponding to the first data service. For details regarding the access control information, please refer to the relevant content in subsequent step 704.
[0171] In one possible implementation, the access control policy information can be access control policy indication information. That is, the first network element can send access control policy indication information to the DO / DC to indicate whether the access control policy is a topic-based access control policy or a role-based access control policy. This application does not limit the specific implementation method of the access control policy information.
[0172] In one possible implementation, the access control policies may be the same or different for different types of data services. For example, for some types of data services, the corresponding access control policy indicates that access control information is set based on the topic, while for other types of data services, the corresponding access control policy indicates that access control information is set based on the role.
[0173] The two access control strategies will be explained below.
[0174] (a) Topic-based access control strategy
[0175] Topic-based access control policies are used to instruct DO / DC to set control permissions for topics based on data services. That is, to set control permissions for one or more topics respectively, so as to achieve topic-level (or topic-granular) control permissions.
[0176] Optionally, control permissions may include at least one of the following: acquire permissions and publish permissions. That is, a topic-based permission control policy may instruct the DO / DC to set one or more of acquire permissions and publish permissions based on the topic.
[0177] In one possible implementation, the first network element stores access control policies corresponding to various data services. Upon receiving a request message, the first network element can retrieve the access control policy corresponding to the first data service from among these policies. For example, the access control policy corresponding to the first data service can be retrieved based on the service's requirement information.
[0178] In some embodiments, the first network element stores access control policies corresponding to one or more data service types. The first network element can obtain the access control policy corresponding to the first data service according to the data service type of the first data service, and instruct the access control policy to the DO / DC.
[0179] For example, the first network element stores access control policies corresponding to various data service types, and the access control policy corresponding to the first type is a topic-based access control policy. The data service type of the first data service is the first type. After receiving a request message, the first network element obtains the access control policy corresponding to the data service type (i.e., the first type) of the first data service carried in the request message, and sends the indication information of the access control policy to the DO / DC.
[0180] In other embodiments, the first network element stores access control policies corresponding to one or more service types, as well as access control policies corresponding to data service security levels. The requirements for access control may differ for different security levels, meaning the access control policies may vary. For example, the access control policy corresponding to the first security level may control both acquisition and publication permissions; the access control policy corresponding to the second security level may control only publication permissions, without controlling acquisition permissions. Optionally, the first security level is higher than the second security level. Using the access control policy corresponding to the second security level for access control can reduce device power consumption compared to using the access control policy corresponding to the first security level. The first network element can obtain the corresponding access control policy based on the data service type and data service security level of the first data service, and then instruct the DO / DC on the access control policy.
[0181] For example, the first network element stores access control policies corresponding to various data service types. The access control policy corresponding to the first type is a topic-based access control policy. The first network element also stores access control policies corresponding to a first security level and a second security level. The data service type of the first data service is the first type, and the data service security level is the second security level. After receiving a request message, the first network element, based on the data service type (i.e., the first type) and the second security level carried in the request message, obtains the access control policy corresponding to that type and security level, and sends the instruction information of the access control policy to the DO / DC. Since the type of the first data service is the first type and the data service security level is the second security level, the instruction information of the access control policy sent by the first network element to the DO / DC instructs the DO / DC to set access control information based on topics, and all DAs selected through orchestration are allowed to access the corresponding topics.
[0182] In other embodiments, the first network element stores access control policies corresponding to one or more service types, as well as access control policies corresponding to different regions. The access control requirements may differ for different regions, meaning the access control policies may vary. For example, the access control policy for the first region might be: control only publishing permissions, not acquiring permissions; the access control policy for the second region might be: control only acquiring permissions, not publishing permissions; and the access control policy for the third region might be: control both acquiring and publishing permissions. The first network element can obtain the corresponding access control policy based on the data service type of the first data service and the positional relationship between the data service area of the first data service and the aforementioned first, second, and third regions, and then instruct the DO / DC on this access control policy.
[0183] For example, the first network element stores access control policies corresponding to various data service types. The access control policy corresponding to the first type is a topic-based access control policy. The first network element also stores access control policies corresponding to the first region, the second region, and the third region. The data service type of the first data service is the first type, and the data service region includes the first region and the second region. After receiving a request message, the first network element obtains the access control policy corresponding to the first type and the data service region based on the data service type (i.e., the first type) and the data service region carried in the request message, and sends the instruction information of the access control policy to the DO / DC. Since the first data service type is the first type and the data service region includes the first region and the second region, the instruction information of the access control policy sent by the first network element to the DO / DC instructs the DO / DC to set access control information based on the topic. DAs located in the first region, selected through orchestration, are allowed to obtain the corresponding topics, and DAs located in the second region, selected through orchestration, are allowed to publish the corresponding topics.
[0184] In other embodiments, the first network element stores access control policies corresponding to one or more service types, as well as access control policies corresponding to different time periods. The requirements for access control may differ for different time periods, meaning the access control policies may vary. For example, the access control policy for the first time period might be: control only publishing permissions, not acquiring permissions; the access control policy for other time periods might be: no control is required for publishing or acquiring permissions. The first network element can obtain the corresponding access control policy based on the data service type of the first data service and the relationship between the data service time of the first data service and the aforementioned first time period, and then instruct the DO / DC on the access control policy.
[0185] For example, the first network element stores access control policies corresponding to various data service types. The access control policy corresponding to the first type is a topic-based access control policy. The first network element also stores access control policies corresponding to a first time period and other time periods. The data service type of the first data service is the first type, and the data service time is within the first time period. After receiving a request message, the first network element obtains the access control policy corresponding to the first type and the data service area based on the data service type (i.e., the first type) and data service time carried in the request message, and sends the instruction information of the access control policy to the DO / DC. Since the type of the first data service is the first type and the data service time is within the first time period, the instruction information of the access control policy sent by the first network element to the DO / DC instructs the DO / DC to set access control information based on the topic, and all DAs selected through orchestration can be allowed to obtain the corresponding topic.
[0186] For example, if the data service time of the first data service falls within the other time periods mentioned above, then the permission control policy instruction information sent by the first network element to the DO / DC instructs the DO / DC to set permission control information based on the topic, and all DAs selected through orchestration can be allowed to obtain and publish the corresponding topics.
[0187] For example, if the data service time of the first data service is partly located within the first time period and partly located within the other time periods, then the permission control policy instruction information sent by the first network element to the DO / DC instructs the DO / DC to set permission control information based on the topic, and the DA selected through orchestration can be allowed to obtain the corresponding topic in the first time period, and can be allowed to obtain and publish the corresponding topic in the other time periods.
[0188] It should be understood that the above are merely exemplary examples of how the first network element obtains access control policies, and this application does not impose any restrictions on this.
[0189] It should be understood that the above-mentioned implementation methods of various access control strategies can be combined with each other. For example, the first network element can obtain the access control strategy corresponding to the first data service based on the type of the first data service and a combination of at least two of the following: the security level of the data service, the data service area, and the data service time.
[0190] (ii) Role-based access control strategy
[0191] Role-based access control policies instruct DO / DC to set roles for DAs. There is a correspondence between DA roles and control permissions; that is, a role can represent a corresponding control permission, implementing business-level control. In other words, for a DA, roles can be set according to the data service type. For example, if a DA is allowed to publish type 1 data services and subscribe to type 2 data services, then DO / DC can set roles A and B for that DA. Role A represents being allowed to publish type 1 data services, and role B represents being allowed to subscribe to type 2 data services.
[0192] Optionally, control permissions may include at least one of the following: acquire permissions and publish permissions. That is, a topic-based access control policy may instruct the DO / DC to set one or more of acquire permissions and publish permissions based on the topic. A role-based access control policy may instruct the DO / DC to set corresponding roles for the DA corresponding to the first data service, using roles to represent at least one of the DA's acquire permissions and extract permissions to the first data service.
[0193] Here, "DA corresponding to the first data service" can be understood as: the DA selected by DO / DC for the first data service after orchestration, which may include DAs as data consumers and DAs as data publishers. This application embodiment does not limit the orchestration and selection methods of DO / DC.
[0194] In this context, a role refers to an identity or abstract concept that is assigned a specific set of permissions within a system or application. Roles are typically used to simplify permission management by binding relevant permissions to roles, rather than directly granting permissions to users or entities, thus facilitating permission control and management. A role can be viewed as a single permission or a set of permissions. In this embodiment, the DO / DC can set (or assign) one or more roles to the DA. In this way, the DA can obtain the corresponding control permissions without having to configure control permissions separately for each DA.
[0195] In one possible implementation, the first network element is configured with access control policies corresponding to various data services. The first network element can obtain the corresponding access control policy from the access control policies corresponding to the various data services based on the demand information carried in the request message, and send the access control policy information to the DO / DC.
[0196] For example, the first network element stores access control policies corresponding to various data service types, and the access control policy corresponding to the second type is a role-based access control policy. The data service type of the first data service is the second type. After receiving a request message, the first network element obtains the access control policy corresponding to the data service type (i.e., the second type) of the first data service carried in the request message, and sends the instruction information of the access control policy to the DO / DC.
[0197] For example, the first network element stores access control policies corresponding to one or more service types, as well as one or more of the following: access control policies corresponding to the security level of the data service, access control policies corresponding to one or more regions, and access control policies corresponding to one or more time periods. Accordingly, the first network element can obtain the access control policy corresponding to the first data service based on the type of the first data service, and based on at least one of the security level, data service region, and data service time. For specific implementation details, please refer to the relevant content in "Topic-Based Access Control Policies".
[0198] In one possible implementation, the access control policy information may further include a validity period, which indicates the validity period of the access control policy. Optionally, the validity period may be determined by the first network element based on the time indicated by the data service time information of the first data service carried in the received request message. For example, the time period indicated by the validity period may be the same as the time period indicated by the data service time information of the first data service, or longer than the data service time of the first data service.
[0199] In one possible implementation, the first network element can send the correspondence information between roles and control permissions of the first data service to the DO / DC, or the first network element can indicate the control permissions represented by each role to the DO / DC.
[0200] In some embodiments, a DA can be assigned one or more roles. In this case, the correspondence between roles and control permissions (or the control permissions represented by each role) can be referred to Table 1.
[0201] Table 1: Roles and Control Permissions
[0202] In some other embodiments, a DA is assigned to at most one role. In this case, the correspondence between roles and control permissions (or the control permissions represented by each role) can be referred to Table 2.
[0203] Table 2: Roles and Control Permissions
[0204] It should be understood that Tables 1 and 2 above are merely illustrative examples of the correspondence between roles and control permissions, and this application does not impose any limitations. For example, an "obtain" permission in Table 1 or Table 2 indicates that obtaining is not permitted, or a "publish" permission in Table 1 or Table 2 indicates that publishing is not permitted.
[0205] In one possible implementation, the first network element is a PCF, but it can also be other network elements that can provide access control policies; this application does not limit this.
[0206] Steps 701-703 above are optional. For example, if different types of data services all use the same access control policy, or if they all use the default access control policy, the DO / DC does not need to obtain the access control policy for the first data service from the first network element. As another example, if the DO / DC has already obtained the access control policy corresponding to the first data service, or if the DO / DC already has the access control policy corresponding to the first data service and that policy is still valid, the DO / DC does not need to obtain the access control policy for the first data service from the first network element again.
[0207] Step 704: DO / DC determines the access control information for the first data service.
[0208] The access control information is used to instruct the DA to obtain and / or publish permissions for the first data service.
[0209] The "DA's permission to access the first data service" can be understood as the DA's permission to access the business data (or updates to business data) of the first data service. For example, whether the DA is allowed to extract the business data or subscribe to updates to the business data. Similarly, the "DA's permission to publish to the first data service" can be understood as the DA's permission to publish the business data of the first data service, i.e., whether the DA is allowed to publish the business data. Here, the DA refers to one or more DAs corresponding to the first data service, or one or more DAs selected by the DO / DC through orchestration to implement the first data service.
[0210] In one possible implementation, the access control information can be either topic access control information or role access control information. The topic access control information can indicate the DA's control permissions over a topic, such as indicating at least one of the DA's access rights and publishing rights to the topic. The role access control information can indicate the DA's role.
[0211] The following sections explain the topic permission control information and the role permission control information respectively.
[0212] (I) Subject Access Control Information
[0213] The business data of a data service can be divided according to topics, which can be understood as information types or other categories. The business data of a data service can be divided into one or more topics. In this embodiment, for a first data service, the data of the first data service can be divided into one or more topics. These one or more topics can be topics specific to the first data service, or all or part of these topics can be topics shared with other data services. For example, the first topic of the first data service can also be the first topic of the second data service. DO / DC can determine one or more topics of the first data service. This embodiment does not limit the method of topic division or the specific implementation method of assigning topics to the business data of the first data service.
[0214] Taking a first data service whose subject includes a first topic as an example, the subject permission control information of the first data service includes first topic permission control information, which indicates one or more DAs' access permissions and publishing permissions for the first topic. If the first data service's subject also includes a second topic, then the first data service's subject permission control information may also include second topic permission control information, which indicates one or more DAs' access permissions and publishing permissions for the second topic. If the first data service's subject also includes more topics, the same principle applies, and will not be repeated.
[0215] The following section uses the first topic as an example to explain the data format and setting method of the first topic's access control information.
[0216] One possible form of the first topic access control information is as follows: the first topic access control information includes information about one or more Data Authorities (DAs), and at least one of the following: access permission information of the one or more DAs for the first topic, or access permission information of the one or more DAs for the first topic. Another possible form of the first topic access control information is as follows: the first topic access control information includes information about one or more regions, and at least one of the following: access permission information of DAs within the one or more regions for the first topic, or access permission information of DAs within the one or more regions for the first topic. Wherein, the access permission information indicates access permission, and the access permission information indicates access permission.
[0217] Optionally, the information of one or more DAs may be the identifiers or other indications of these DAs (e.g., address information), which is not limited in this application.
[0218] Optionally, the information for one or more areas may be the identifier of the community, geographical area information, or other information used to indicate the area; this application is not limited to this.
[0219] Based on the data format of the first topic access control information described above, one possible implementation includes at least one of the following: allowing access to information, prohibiting access to information, allowing the publication of information, and prohibiting the publication of information. These access control information will be described in detail below.
[0220] (1) Allow access to information
[0221] In one possible implementation, the information allowed to be accessed may include information from one or more Data Controllers (DAs), which are allowed to access the first topic. Here, "allowed to access the first topic" can be understood as: being allowed to subscribe to data on the first topic, or being allowed to extract data from the first topic, or being allowed to both subscribe to and extract data from the first topic.
[0222] Optionally, the permitted information can be a permitted access list, and this application does not impose any restrictions on the data structure of the permitted information. Table 3 exemplarily illustrates a permitted access list corresponding to multiple topics of a first data service.
[0223] Table 3: List of Permitted Access Points for First Data Services
[0224] In another possible implementation, the permitted information includes information about one or more regions, where DAs within these regions are permitted to access the first topic. These one or more regions are located within the data service area of the first data service. Optionally, the permitted information can be a permitted access list; this application does not limit the data structure of the permitted information. Table 4 exemplarily illustrates a permitted access list corresponding to multiple topics of a first data service.
[0225] Table 4: List of Permitted Access Points for First Data Services
[0226] The above-mentioned list of allowed accesses can also be called an access permission whitelist.
[0227] (2) Prohibition of access to information
[0228] In one possible implementation, the information to be prohibited includes information about one or more Data Analysts (DAs), which are not allowed to access the first topic.
[0229] In another possible implementation, information access is prohibited in one or more regions, where the DA within those regions is not allowed to access the first topic.
[0230] Optionally, the prohibited information can be a prohibited list; this application does not restrict the data structure of the prohibited information. The prohibited list can also be called a blacklist for access permission subscriptions.
[0231] (3) Allow information posting
[0232] In one possible implementation, the information allowed to be published includes information from one or more Data Agents (DAs), which are permitted to publish to the first topic. Here, "permitted to publish to the first topic" can be understood as: data permitted to publish to the first topic, or data updates permitted to publish to the first topic.
[0233] In another possible implementation, the published information may include information from one or more regions, where DAs within those regions are permitted to publish a first topic. These one or more regions are located within the data service area of the first data service.
[0234] Optionally, the allowed information to be published can be a list of allowed publications; this application does not impose restrictions on the data structure of the allowed information. The list of allowed publications can also be called a whitelist of publication permissions.
[0235] (4) Information posting is prohibited
[0236] In one possible implementation, the prohibited information includes information from one or more Data Authorities (DAs), which are not allowed to publish the first topic.
[0237] In another possible implementation, the prohibited information includes information from one or more regions, where DAs within these regions are not allowed to publish the first topic. These one or more regions are located within the data service area of the first data service.
[0238] Optionally, the prohibited information can be a prohibited list; this application does not restrict the data structure of the prohibited information. A prohibited list can also be called a blacklist of posting permissions.
[0239] (II) Role-based access control information
[0240] The role and access control information for the first data service can indicate the roles of one or more Data Authorities (DAs) corresponding to the first data service. Specifically, the role and access control information may include information about one or more DAs, and the roles of those one or more DAs for the first data service.
[0241] Optionally, the information of one or more DAs may be the identifiers or other indications of these DAs (e.g., address information), which is not limited in this application.
[0242] In one possible implementation, one or more roles can be set (or configured or assigned) for a Data Authority (DA). Taking the first DA as an example, the roles of the first DA can include one or more of a first role and a second role. The first role is the role that is allowed or not allowed to access the first data service; the second role is the role that is allowed or not allowed to publish the first data service.
[0243] In another possible implementation, a maximum of one role can be assigned to a Data Provider (DA). Taking the first DA as an example, the role of the first DA can be one of the following: a first role, a second role, and a third role. The first and second roles are described above; the third role is the role that is allowed or not allowed to access and publish the first data service.
[0244] It should be understood that the role of a Data Provider (DA) is relative to the data service. In other words, the same DA may have different roles for different data services. For example, if an DA is for a first data service, its role is the first role, indicating that it is allowed to access the first data service but not to publish to it. If the DA is for a second data service, its role includes both the first and third roles, indicating that it is allowed to subscribe to and publish to the second data service.
[0245] For example, if RAN1 and DPF1 are selected to perform the first data service, the roles of RAN1 and DPF1 can be as shown in Table 5.
[0246] Table 5: Roles of DA
[0247] In this table, ServiceType1_consumer represents the first role, and ServiceType1_publisher represents the second role. Based on Table 5, RAN1 has the second role and is allowed to publish the first data service (of type ServiceType1). DPF1 has both the first and second roles and is allowed to acquire and publish the first data service.
[0248] For example, Table 6 shows the correspondence between roles and control permissions.
[0249] Table 6: Roles and Control Permissions
[0250] Optionally, the correspondence between roles and control permissions can be preset, set by the DO / DC, or the first network element can send the correspondence information to the DO / DC; this application does not impose any restrictions.
[0251] In one possible implementation, the access control information has an expiration date. The access control information is valid within its expiration date and becomes invalid after that date. The expiration date can be included in the access control information sent to the DCP, or it can be sent to the DCP independently of the access control information.
[0252] Optionally, the validity period of the access control information can be a default setting, or it can depend on the requirements of the first data service or on the access control policy; this application does not impose any restrictions on this.
[0253] For example, the system can set a default validity period for access control information, and DO / DC can determine the validity period of the access control information for the first data service based on the system's default validity period setting.
[0254] For example, the DO / DC can determine the validity period of the access control information for the first data service based on the demand information of the first data service. For instance, if the demand information for the first data service includes data service time information, then the validity period of the access control information for the first data service can be set according to the time period indicated by that data service time information.
[0255] For example, if the information of the access control policy corresponding to the first data service includes an expiration date, the DO / DC can set the expiration date of the access control information of the first data service according to the expiration date of the access control policy.
[0256] In one possible implementation, the DO / DC can determine the access control information of the first data service based on at least one of the access control policy and required information corresponding to the first data service.
[0257] For example, if the access control policy corresponding to the first data service is a topic-based access control policy, then the DO / DC can determine topic access control information. This topic access control information is used to instruct the DAs on one or more of the access and publishing permissions for the topics of the first data service. For instance, the process of the DO / DC determining the topic access control information may include: orchestrating DAs; selecting DAs based on the demand information of the first data service; determining the data transmission processing path; determining the topics of the first data service (there may be multiple topics); and, based on the access control policy corresponding to the first data service (which is a topic-based access control policy), determining the access and / or publishing permissions for each selected DA for each topic, and generating access control information.
[0258] For example, if the access control policy corresponding to the first data service is a role-based access control policy, then the DO / DC determines the role of the DA, which includes at least one of the following: a role that is allowed or not allowed to access the first data service, and a role that is allowed or not allowed to publish the first data service. Exemplarily, the process by which the DO / DC determines role access control information may include: orchestrating DAs; selecting DAs based on the demand information of the first data service; determining the data transmission processing path; determining the topic of the first data service (there may be multiple topics); and assigning roles to each selected DA based on the access control policy corresponding to the first data service (which is a role-based access control policy).
[0259] Step 705: DO / DC sends the access control information for the first data service to DCP.
[0260] Step 706: The first DA sends a first request message to the DCP.
[0261] The first request message is used to request the acquisition or publication of the first data service.
[0262] The first request message may include information about a first topic, which indicates the type of information in the target data.
[0263] Optionally, the first request message is a data retrieval request message, used to request retrieval of a first topic (or, in other words, to request retrieval of data from the first topic). For example, the data retrieval request message may be a data subscription request message, used to request subscription to the first topic (or, in other words, to request subscription to data from the first topic). As another example, the data retrieval request message may be a data extraction request message, used to request extraction of the first topic (or, in other words, to request extraction of data from the first topic).
[0264] Optionally, the first request message is a data publication request message, which is used to request the publication of the first topic (or to request the extraction of data from the first topic).
[0265] Step 707: DCP responds to the first request message based on the access control information of the first data service.
[0266] In this step, DCP responds to the first request message based on the access control information, which may include the following situations:
[0267] Scenario 1:
[0268] If the first request message is a data subscription request message, which is used to request subscription to the first topic, then the DCP can determine the first DA's subscription permission to the first data service based on the permission control information, that is, determine whether the first DA is allowed to subscribe to the first topic, and take corresponding actions based on the determination result.
[0269] In one possible implementation, the access control information is topic access control information, which includes first topic access control information. This first topic access control information is used to indicate the first DA's access permission to the first topic of the first data service. Accordingly, the DCP can determine whether the first DA is allowed to subscribe to the first topic based on the information about the first topic included in the data subscription request message.
[0270] In one implementation of the first topic access control information, the first topic access control information includes: information about one or more Data Authorities (DAs), and access permission information for the one or more DAs to the first topic. Accordingly, the Data Content Provider (DCP) can determine whether the first DA is allowed to subscribe to the first topic based on whether the first DA is one of the one or more DAs.
[0271] For example, the first topic access control information includes permitted access information (e.g., a permitted access list), which includes information about one or more Data Providers (DAs) that are permitted to subscribe to the first topic. Based on this permitted access information, if the DCP determines that the first DA is one of the one or more DAs, then it determines that the first DA is permitted to subscribe to the first topic.
[0272] For example, the first topic's access control information includes prohibited access information (e.g., a prohibited access list). This prohibited access information includes information about one or more Data Controllers (DAs) that are not allowed to subscribe to the first topic. Based on this prohibited access information, if the DCP determines that the first DA is not one of these one or more DAs, then it determines that the first DA is allowed to subscribe to the first topic.
[0273] In another implementation of the first topic access control information, the first topic access control information includes: information about one or more regions, and access permission information for DAs within those one or more regions to access the first topic. Accordingly, the DCP can determine whether the first DA is allowed to subscribe to the first topic based on whether the region where the first DA is located is within those one or more regions.
[0274] For example, the first topic access control information includes permitted access information (e.g., a permitted access list), which includes information about one or more regions where DAs within those regions are permitted to subscribe to the first topic. Based on this permitted access information, if the DCP determines that the region where the first DA is located is within those one or more regions, then it determines that the first DA is permitted to subscribe to the first topic.
[0275] For example, the first topic access control information includes prohibited access information (e.g., a prohibited access list). This prohibited access information includes information about one or more regions where DAs within those regions are not allowed to subscribe to the first topic. Based on this prohibited access information, if the DCP determines that the region where the first DA is located is not within those one or more regions, then it determines that the first DA is allowed to subscribe to the first topic.
[0276] In another possible implementation, the access control information is role-based access control information, which includes information about one or more Data Authorities (DAs) and the roles of those DAs for the first data service. The roles of the first DA can include one or more, for example, the roles of the first DA can include at least one of a first role and a second role; the roles of the first DA can also be a first role, a second role, or a third role. See step 704 for details. The Data Access Control Center (DCP) can determine whether the first DA is allowed to access the first data service based on its role.
[0277] For example, if the roles of the first DA may include one or more, and if the roles of the first DA include the first role, then the DCP can determine whether the first DA is allowed to subscribe to the first data service or is not allowed to subscribe to the first data service, depending on the subscription rights represented by the first role.
[0278] For example, if the role of the first DA includes at most one person, and if the role of the first DA is either the first role or the third role, then the DCP can determine whether the first DA is allowed to subscribe to the first data service or is not allowed to subscribe to the first data service, depending on the subscription rights represented by these roles.
[0279] In one possible implementation, if the DCP determines that the first DA is allowed to subscribe to the first topic, then the DCP can add the first DA to the subscriber list of the first topic. When the DCP receives data from the first topic, it can send the data to the first DA according to the subscriber list of the first topic.
[0280] Optionally, the DCP can send a success response message to the first DA to notify the first DA that the subscription was successful.
[0281] In one possible implementation, if the DCP determines that the first DA is not allowed to subscribe to the first topic, then when the DCP receives data from the first topic, it will not add the first DA to the subscriber list of the first topic, and thus will not forward the data of the first topic to the first DA.
[0282] Optionally, the DCP can send a failure response message to the first DA, notifying the first DA of the subscription failure. Optionally, the failure response message includes failure reason information, indicating the reason for the subscription failure, for example, the reason for the subscription failure is that the first DA is not allowed to subscribe to the first topic.
[0283] Scenario 2:
[0284] If the first request message sent by the first DA is a data extraction request message, which is used to request the extraction of the first topic (or, in other words, to request the extraction of data from the first topic), then the DCP can determine the first DA's extraction permission for the first data service based on the access control information, that is, determine whether the first DA is allowed to extract the first topic, and take appropriate action based on the determination result. The specific implementation of this process can be found in Case 1 above, where the DCP determines whether the first DA is allowed to subscribe to the first topic.
[0285] In another possible implementation, if the DCP determines that the first DA exists in the subscriber list of the first topic, then it can be determined that the first DA is allowed to retrieve the first topic; if the DCP determines that the first DA does not exist in the subscriber list of the first topic, then it can be determined that the first DA is not allowed to retrieve the first topic.
[0286] In one possible implementation, if the DCP determines that the first DA is allowed to retrieve the first topic, then the DCP can send the data of the first topic to the first DA. Optionally, the DCP sends a success response message to the first DA, notifying the first DA that the retrieval was successful.
[0287] In one possible implementation, if the DCP determines that the first DA is not allowed to retrieve the first topic, then the DCP will not send the data for the first topic to the first DA. Optionally, the DCP sends a failure response message to the first DA, notifying the first DA of the retrieval failure. Optionally, the failure response message includes failure reason information, which indicates the reason for the retrieval failure, for example, the reason for the retrieval failure is that the first DA is not allowed to retrieve the first topic.
[0288] Scenario 3:
[0289] If the first request message sent by the first DA is a data publication request message, which is used to request the publication of the first topic, then the DCP can determine the first DA's publication permission for the first data service based on the permission control information, that is, determine whether the first DA is allowed to publish the first topic, and take corresponding actions based on the determination result.
[0290] In one possible implementation, the access control information is topic access control information, which includes first topic access control information. This first topic access control information is used to indicate the first Data Controller's (DA) access permission to the first topic of the first data service. Accordingly, the Data Controller (DCP) can determine whether the first DA is permitted to publish the first topic based on the first topic information included in the data publishing request message.
[0291] In one implementation of the first topic access control information, the first topic access control information includes: information about one or more Data Authorities (DAs), and the publishing permission information of the one or more DAs for the first topic. Accordingly, the Data Content Provider (DCP) can determine whether the first DA is allowed to publish to the first topic based on whether the first DA is one of the one or more DAs.
[0292] For example, the first topic access control information includes permitted posting information (e.g., a permitted posting list), which includes information about one or more Data Authorities (DAs) that are permitted to post to the first topic. Based on this permitted posting information, if the DCP determines that the first DA is one of the one or more DAs, then it determines that the first DA is permitted to post to the first topic.
[0293] For example, the first topic access control information includes prohibited posting information (e.g., a prohibited posting list), which includes information about one or more Data Authorities (DAs) that are not allowed to post to the first topic. Based on this prohibited posting information, if the DCP determines that the first DA is not one of the one or more DAs, then it determines that the first DA is allowed to post to the first topic.
[0294] In another implementation of the first topic access control information, the first topic access control information includes: information about one or more regions, and the publishing permission information of DAs within those one or more regions for the first topic. Accordingly, the DCP can determine whether the first DA is allowed to publish the first topic based on whether the region where the first DA is located is within those one or more regions.
[0295] For example, the first topic access control information includes permitted posting information (e.g., a permitted posting list), which includes information about one or more regions where a Data Access Provider (DA) is permitted to post the first topic. Based on this permitted posting information, if the Data Access Control Platform (DCP) determines that the region containing the first DA is located within one or more of those regions, then it determines that the first DA is permitted to post the first topic.
[0296] For example, the first topic access control information includes prohibited posting information (e.g., a prohibited posting list). This prohibited posting information includes information about one or more regions, where DAs within these regions are not allowed to post the first topic. Based on this prohibited posting information, if the DCP determines that the region where the first DA is located is not within these one or more regions, then it determines that the first DA is allowed to post the first topic.
[0297] In another possible implementation, the access control information is role-based access control information, which includes information about one or more Data Authorities (DAs) and the roles of these DAs for the first data service. The roles of the first DA can include one or more, for example, at least one of a first role, a second role, and a third role; the roles of the first DA can also be one of a first role, a second role, a third role, a fourth role, a fifth role, a sixth role, and a seventh role. See step 704 for details. The Data Controller (DCP) can determine whether the first DA is permitted to publish the first data service based on its role.
[0298] For example, if the roles of the first DA can include one or more, and if the roles of the first DA include a third role, then the DCP can determine whether the first DA is allowed to publish the first data service or is not allowed to publish the first data service, depending on the publishing permissions represented by the third role.
[0299] For example, if the role of the first DA is at most one, and the role of the first DA is the third, fifth, sixth, or seventh role, then the DCP can determine whether the first DA is allowed to publish the first data service or not, depending on the publishing permissions represented by these roles.
[0300] In one possible implementation, if the DCP determines that the first DA is allowed to publish the first topic, it can send a success response message to the first DA, notifying the first DA that the publication was successful. After receiving the data for the first topic from the first DA, the DCP can then send that data to all DAs that have subscribed to the first topic.
[0301] In one possible implementation, if the DCP determines that the first DA is not allowed to publish the first topic, the DCP can send a failure response message to the first DA to notify the first DA of the publication failure. Optionally, the failure response message includes failure reason information, which indicates the reason for the publication failure, for example, the reason for the publication failure is that the first DA is not allowed to publish the first topic.
[0302] The process shown in Figure 7 illustrates an example where the DO / DC determines the access control information for the first data service after receiving a service request message. In other words, the service request message triggers the DO / DC to execute step 704 and subsequent steps. In other embodiments, the DO / DC can also determine the access control information for the first data service and send it to the DCP based on other triggering methods. For example, when the DO / DC's access control function is enabled, it can generate access control information for the currently running data service and send it to the DCP. Alternatively, during the first data service, based on access control requests from AF or other network elements, it can generate access control information for the first data service and send it to the DCP. This application does not impose limitations. That is, in the embodiments of this application, the transmission step of the service request message is optional.
[0303] Based on the process shown in Figure 7 above, the DO / DC can send the access control information of the first data service to the DCP, so that the DCP can determine the access or publishing permission of the DA that initiates the data access or publishing request for the first data service according to the access control information, thereby realizing the control of access / publishing permissions and improving data security.
[0304] During the first data service process, various factors may cause changes in the network elements performing data collection and processing. These factors include, for example, changes in service requirements, switching of terminal devices acting as Data Acquisition (DA), load balancing by the Data Processing Filter (DPF), and the addition of new tasks of the same type. To address this situation, embodiments of this application provide a method for updating access control information.
[0305] Referring to Figure 8, this is a flowchart of an access control method provided in an embodiment of this application, through which access control information can be updated in a timely manner.
[0306] As shown in Figure 8, the process may include the following steps:
[0307] Step 801: DO / DC updates the access control information corresponding to the first data service.
[0308] In one possible implementation, the DO / DC can be configured to monitor a first event related to the first data service. When the first event is detected, the DO / DC updates the access control information of the first data service. Optionally, the first event may include one or more of the following:
[0309] (1) Changes in the demand information of the first data service, such as a change in the data service area of the first data service. When the data service area of the first data service changes, the DO / DC can determine the access / publishing permissions of the DAs in the changed area for the relevant topics, thereby obtaining the updated access control information.
[0310] (2) The DA corresponding to the first service is switched. Taking the switch from DA1 to DA2 as an example, DO / DC can determine DA2's access / publishing permissions for the relevant topics, thereby updating the access control information.
[0311] (3) The DPF corresponding to the first service performs load balancing. For example, if DPF1 is allowed to obtain and publish the first topic, when the load of DPF1 is higher than the threshold, the publishing permission of DPF1 to the first topic can be cancelled, so that DPF1 is no longer allowed to publish the first topic, thereby reducing the load of DPF1.
[0312] It should be understood that the above are merely exemplary examples of several possible instances of the first event, and the embodiments of this application do not limit the first event.
[0313] In one possible implementation, if the access control information of the first data service was topic-based access control information before the update, then the updated access control information of the DO / DC will still be topic-based access control information. In another possible implementation, if the access control information of the first data service was role-based access control information before the update, then the updated access control information of the DO / DC will still be role-based access control information.
[0314] In one possible implementation, the DO / DC can also update the mapping between roles and permissions, and can send the updated mapping information to the DCP.
[0315] Step 802: DO / DC sends the updated access control information for the first data service to DCP.
[0316] Step 803: DCP saves the updated access control information for the first data service.
[0317] After the aforementioned access control information is updated, during the first data service process, when the DCP receives a data subscription request message, data retrieval request message, or data publication request message from the DA, it can determine whether the DA is allowed to subscribe to / retrieve / publish data on the requested topic based on the updated access control information.
[0318] Based on the process shown in Figure 8 above, the access control information can be updated in a timely manner according to the changes in the first data service, so that the updated access control information can adapt to the changed situation, thereby realizing dynamic management of access control information.
[0319] In one possible implementation, after the first data service ends, the DO / DC can notify the DCP to delete the access control information of the first data service in order to save storage resources.
[0320] Referring to Figure 9, it is a flowchart of an access control method provided in an embodiment of this application. This process allows access control information to be deleted promptly when the first data service ends.
[0321] As shown in Figure 9, the process may include the following steps:
[0322] Step 901: DO / DC determines that the first data service has ended.
[0323] In one possible implementation, the DO / DC determines the end of the first data service based on the data service time information of the first data service. This data service time information can indicate the start and end times of the first data service. When the DO / DC determines that the end time of the first data service has been reached, it determines that the first data service has ended.
[0324] Step 902: DO / DC sends a notification message to DCP, which instructs DCP to delete the access control information of the first data service.
[0325] In one possible implementation, the notification message may include indication information of the first data service, such as the data service type of the first data service.
[0326] Step 903: Based on the notification message, DCP deletes the access control information for the first data service.
[0327] Based on the process shown in Figure 9 above, access control information can be deleted in a timely manner when the data service ends, so as to save storage resources and enable dynamic management of access control information.
[0328] In another possible implementation, the access control information of the first data service has an expiration date. When the DCP determines that the access control information has expired based on its expiration date, it can delete the access control information.
[0329] Based on the process shown in Figure 7, Figure 10 illustrates a specific implementation process in an application scenario. In this scenario, the PCF provides a topic-based access control policy to the DO / DC, and the DO / DC sends topic access control information to the DCP. DPF1 sends a data subscription request message to the DCP to request subscription to data on the first topic. The DCP determines whether DPF1 is allowed to subscribe to data on the first topic based on the topic access control information. RAN1 sends a data publication request message to the DCP to request publication of data on the first topic. The DCP determines whether RAN1 is allowed to publish data on the first topic based on the topic access control information.
[0330] Referring to Figure 10, it is a flowchart illustrating an access control method provided in an embodiment of this application.
[0331] As shown in Figure 10, the process may include the following steps:
[0332] Step 1001: AF sends a service request message to DO / DC.
[0333] Optionally, the service request message may include the demand information for the first data service.
[0334] Step 1002: DO / DC sends a request message to PCF, which is used to obtain the access control policy corresponding to the first data service.
[0335] Optionally, the request message may include the demand information for the first data service.
[0336] Step 1003: PCF sends the access control policy information corresponding to the first data service to DO / DC. The access control policy is a topic-based access control policy.
[0337] Step 1004: The DO / DC determines the subject permission control information of the first data service according to the permission control policy corresponding to the first data service.
[0338] Step 1005: DO / DC sends the first data service's topic access control information to DCP.
[0339] In this step, after receiving the topic permission control information, DCP saves the topic permission control information and enables topic-based permission control.
[0340] In one possible implementation, the DCP can also send the validity period of the topic access control information to the DCP. Optionally, if the DCP determines that the topic access control information has expired based on its validity period, it can mark the topic access control information as expired or delete it to save storage resources.
[0341] Step 1006: DO / DC sends a data service control message to RAN1.
[0342] RAN1 is one of the DAs selected after the DO / DC is orchestrated.
[0343] For example, the DO / DC can comprehensively consider factors such as the RAN's capabilities and its location, select one or more RANs from the data service area of the first data service, and send data service control messages to the selected RANs.
[0344] Optionally, the data service control message may include one or more of the following information: an instruction to initiate the data service, the data to be collected by the RAN (e.g., the type of data to be collected), and the topic for which the data is published. Through this data service control message, the DO / DC can notify RAN1 what type of data can be collected, the topic for which the data is published, and what processing operations can be performed on the data.
[0345] Step 1007: DO / DC sends a data service control message to DPF1.
[0346] DPF1 is one of the DAs selected after the DO / DC is orchestrated.
[0347] For example, the DO / DC can comprehensively consider factors such as the capabilities of the DPF and its location, select one or more DPFs from the data service area of the first data service, and send data service control messages to the selected DPFs.
[0348] Optionally, the data service control message may include one or more of the following information: instructions to start the data service, and the topics for which the data is subscribed. Through this data service control message, the DO / DC can notify DPF1 which topics(s) of data it can subscribe to, and can also notify DPF1 what processing operations to perform on the data.
[0349] Step 1008: DPF1 sends a data subscription request message to DCP, which is used to request subscription to data for the first topic.
[0350] Taking a DPF1 request to subscribe to data on the first topic as an example, the data subscription request message includes information about the first topic. In other scenarios, if a DPF request subscribes to multiple topics, the data subscription request message may include a list of topics, which contains the topics for which the DPF request is being submitted.
[0351] Optionally, the data subscription request message may also include the data consumer ID.
[0352] Optionally, the data subscription request message may also include the subscription duration.
[0353] Step 1009: After receiving the data subscription request message, DCP determines whether DPF1 is allowed to subscribe to the data of the first topic based on the topic permission control information of the first data service.
[0354] Step 1010: DCP sends a response message to DPF1.
[0355] If, in step 1009, the DCP determines that DPF1 is allowed to subscribe to the data of the first topic, then in step 1010, it sends a success response message to DPF1. This step is optional. Subsequently, after receiving the data of the first topic, the DCP can send that data to DPF1.
[0356] If in step 1009, DCP determines that DPF1 is not allowed to subscribe to data on the first topic, then in step 1010, a failure response message is sent to DPF1. Optionally, the failure response message may include failure reason information, such as a failure reason value, indicating that DPF1 is not allowed to subscribe to data on the first topic.
[0357] Step 1011: RAN1 sends a data publication request message to DCP, which requests the publication of data for the first topic.
[0358] Taking RAN1 requesting to publish data on the first topic as an example, the data publication request message includes information about the first topic. In other scenarios, if DPF requests to publish data on multiple topics, the data publication request message may include a list of topics, which contains the topics requested by the DPF.
[0359] Optionally, the data publishing request message may include the data producer ID.
[0360] Optionally, the data publishing request message may also include the data to be published.
[0361] Step 1012: DCP determines whether RAN1 is allowed to publish data for the first topic based on the topic permission control information of the first data service.
[0362] Step 1013: DCP sends a response message to RAN1.
[0363] If, in step 1012, the DCP determines that RAN1 is permitted to publish data on the first topic, then in step 1013, it sends a success response message to RAN1. This step is optional. Subsequently, the DCP can send the data from the first topic from RAN1 to the DA that has successfully subscribed to the data (e.g., DPF1 mentioned above).
[0364] If, in step 1012, DCP determines that RAN1 is not permitted to publish data on the first topic, then in step 1013, a failure response message is sent to RAN1. Optionally, the failure response message may include failure reason information, such as a failure reason value, indicating that RAN1 is not permitted to publish data on the first topic.
[0365] It should be understood that the sequence of steps in the process shown in Figure 10 above is only one possible example and is not limited in this application.
[0366] The specific implementation methods of the relevant steps in the process shown in Figure 10 can be referred to the process shown in Figure 7, and will not be repeated here.
[0367] Based on the process shown in Figure 7, Figure 11 illustrates the specific implementation process in another application scenario. In this scenario, the PCF provides role-based access control policies to the DO / DC, and the DO / DC sends role access control information to the DCP. DPF1 sends a data subscription request message to the DCP to request subscription to data on the first topic. The DCP determines whether DPF1 is allowed to subscribe to data on the first topic based on the role access control information. RAN1 sends a data publishing request to the DCP, and the DCP determines whether RAN1 is allowed to publish data on the first topic based on the role access control information.
[0368] Referring to Figure 11, it is a flowchart illustrating another access control method provided in an embodiment of this application.
[0369] As shown in Figure 11, the process may include the following steps:
[0370] Step 1101: AF sends a service request to DO / DC.
[0371] Optionally, the service request message may include the demand information for the first data service.
[0372] Step 1102: DO / DC sends a request message to PCF, which is used to obtain the access control policy corresponding to the first data service.
[0373] Optionally, the request message may include the demand information for the first data service.
[0374] Step 1103: PCF sends the access control policy information corresponding to the first data service to DO / DC. This access control policy is a role-based access control policy.
[0375] Step 1104: The DO / DC determines the role and access control information of the first data service according to the access control policy corresponding to the first data service.
[0376] Step 1105: DO / DC sends the role and access control information for the first data service to DCP.
[0377] In this step, after receiving the role access control information, DCP saves the role access control information and enables role-based access control.
[0378] In one possible implementation, the DCP can also send the validity period of the role access control information to the DCP. Optionally, when the DCP determines that the role access control information has expired based on its validity period, it can mark the role access control information as expired or delete it to save storage resources.
[0379] Step 1106: DO / DC sends a data service control message to RAN1.
[0380] RAN1 is one of the DAs selected after the DO / DC is orchestrated.
[0381] For example, the DO / DC can comprehensively consider factors such as the RAN's capabilities and its location, select one or more RANs from the data service area of the first data service, and send data service control messages to the selected RANs.
[0382] Optionally, the data service control message may include one or more of the following information: an instruction to initiate the data service, the data to be collected by the RAN (e.g., the type of data to be collected), and the topic for which the data is published. Through this data service control message, the DO / DC can notify RAN1 what type of data can be collected, the topic for which the data is published, and what processing operations can be performed on the data.
[0383] Step 1107: DO / DC sends a data service control message to DPF1.
[0384] DPF1 is one of the DAs selected after the DO / DC is orchestrated.
[0385] For example, the DO / DC can comprehensively consider factors such as the capabilities of the DPF and its location, select one or more DPFs from the data service area of the first data service, and send data service control messages to the selected DPFs.
[0386] Optionally, the data service control message may include one or more of the following information: instructions to start the data service, and the topics for which the data is subscribed. Through this data service control message, the DO / DC can notify DPF1 which topics(s) of data it can subscribe to, and can also notify DPF1 what processing operations to perform on the data.
[0387] Step 1108: DPF1 sends a data subscription request message to DCP, which is used to request subscription to data for the first topic.
[0388] Taking a DPF request to subscribe to data on the first topic as an example, the data subscription request message includes information about the first topic. In other scenarios, if a DPF request subscribes to multiple topics, the data subscription request message may include a list of topics, which contains the topics for which the DPF request is being submitted.
[0389] Optionally, the data subscription request message may also include the data consumer ID.
[0390] Optionally, the data subscription request message may also include the subscription duration.
[0391] Step 1109: After receiving the subscription request message, DCP determines whether DPF1 is allowed to subscribe to the data of the first topic based on the role permission control information of the first data service.
[0392] Step 1110: DCP sends a response message to DPF1.
[0393] If, in step 1109, the DCP determines that DPF1 is allowed to subscribe to data for the first topic, then in step 1110, it sends a success response message to DPF1. This step is optional. Subsequently, after receiving data from the first topic, the DCP can send that data to DPF1.
[0394] If, in step 1109, DCP determines that DPF1 is not allowed to subscribe to data on the first topic, then in step 1110, a failure response message is sent to DPF1. Optionally, the failure response message may include failure reason information, such as a failure reason value, indicating that DPF1 is not allowed to subscribe to data on the first topic.
[0395] Step 1111: RAN1 sends a data publication request message to DCP, which requests the publication of data for the first topic.
[0396] Taking a RAN request to publish data on a first topic as an example, the data subscription request message includes information about the first topic. In other scenarios, if a DPF requests to publish data on multiple topics, the data publication request message may include a list of topics, which includes the topics requested by the DPF.
[0397] Optionally, the data publishing request message may include the data producer ID.
[0398] Optionally, the data publishing request message may also include the data to be published.
[0399] Step 1112: DCP determines whether RAN1 is allowed to publish data for the first topic based on the role and permission control information of the first data service.
[0400] Step 1113: DCP sends a response message to RAN1.
[0401] If, in step 1112, the DCP determines that RAN1 is permitted to publish data on the first topic, then in step 1113, it sends a success response message to RAN1. This step is optional. Subsequently, the DCP can send the data from the first topic from RAN1 to the DA that successfully subscribed to the data (e.g., DPF1 mentioned above).
[0402] If, in step 1112, DCP determines that RAN1 is not permitted to publish data on the first topic, then in step 1113, a failure response message is sent to RAN1. Optionally, the failure response message may include failure reason information, such as a failure reason value, indicating that RAN1 is not permitted to publish data on the first topic.
[0403] It should be understood that the sequence of steps in the process shown in Figure 11 above is only one possible example and is not limited in this application.
[0404] The specific implementation methods of the relevant steps in the process shown in Figure 11 can be referred to the process shown in Figure 7, and will not be repeated here.
[0405] It is understood that, in order to achieve the functions in the above embodiments, the device (e.g., the aforementioned DO / DC, or DCP) includes hardware structures and / or software modules corresponding to perform each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0406] Figures 12 and 13 are schematic diagrams of possible communication devices provided in embodiments of this application. These communication devices can be used to implement the functions of the related devices in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the communication device can be a DO / DC as shown in Figures 7, 10, or 11, or a DCP as shown in the above figures, or a module (such as a chip) applied to a DO / DC or DCP.
[0407] As shown in Figure 12, the communication device 1200 includes a processing unit 1210 and a transceiver unit 1220. The communication device 1200 is used to implement the functions of DO / DC or DCP in the method embodiments shown in Figures 7, 10, or 11.
[0408] When the communication device 1200 is used to implement the DO / DC function in the method embodiment shown in FIG7, FIG10 or FIG11: the processing unit 1210 is used to determine the permission control information of the first data service, the permission control information being used to instruct the data agent to obtain permission and / or publish permission for the first data service; the processing unit 1210 is also used to send the permission control information to the data communication agent through the transceiver unit 1220.
[0409] When the communication device 1200 is used to implement the DCP function in the method embodiments shown in FIG7, FIG10, or FIG11: the transceiver unit 1220 is used to receive permission control information corresponding to the first data service, wherein the permission control information is used to indicate the data agent's access permission and / or publishing permission for the first data service; the processing unit 1210 is used to: when receiving a data access request message from the first data agent through the transceiver unit 1220, respond to the request message according to the first data agent's access permission for the first data service; or, when receiving a data publishing request message from the first data agent through the transceiver unit 1220, respond to the request message according to the first data agent's publishing permission for the first data service. Wherein, the first data agent's access permission and publishing permission for the first data service are determined according to the permission control information.
[0410] A more detailed description of the processing unit 1210 and the transceiver unit 1220 can be obtained directly from the relevant descriptions in the method embodiments shown in Figures 7, 10 or 11, and will not be repeated here.
[0411] As shown in Figure 13, the communication device 1300 includes a processor 1310 and an interface circuit 1320. The processor 1310 and the interface circuit 1320 are coupled to each other. It is understood that the interface circuit 1320 can be a transceiver or an input / output interface. Optionally, the communication device 1300 may also include a memory 1330 for storing instructions executed by the processor 1310, or storing input data required by the processor 1310 to execute instructions, or storing data generated after the processor 1310 executes instructions.
[0412] When the communication device 1300 is used to implement the method shown in FIG7, FIG10 or FIG11, the processor 1310 is used to implement the function of the processing unit 1210, and the interface circuit 1320 is used to implement the function of the transceiver unit 1220.
[0413] When the aforementioned communication device is a chip applied to a device, the chip implements the functions of the corresponding device in the above method embodiments.
[0414] It is understood that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.
[0415] This application provides another example of a communication device, which includes at least one processor and at least one memory coupled together. The at least one processor is used to store instructions, which, when executed by the at least one processor, cause the communication device to perform the methods described in the above embodiments. Taking a communication device including a processor and a memory as an example, as shown in FIG13, communication device 1300 includes a processor 1310 and a memory 1330. The processor 1310 and the memory 1330 are coupled together. The memory 1330 stores instructions, and when the instructions stored in the memory 1330 are executed by the processor 1310, the communication device 1300 performs the methods performed by the device in the above embodiments.
[0416] The method steps in the embodiments of this application can be implemented in hardware or in software instructions executable by a processor. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. The storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a network device or a terminal device. The processor and storage medium can also exist as discrete components in a network device or a terminal device.
[0417] This application also provides a communication system, which includes a DO / DC and a DCP, and may also include other network elements, such as a PCF, etc., which are not limited in this application. The DO / DC can implement the method implemented by the DO / DC in the above method embodiments of this application, and the DCP can implement the method implemented by the DCP in the above method embodiments of this application. For details, please refer to the relevant content in the method embodiments shown in Figures 7, 10, or 11.
[0418] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both types of storage media.
[0419] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0420] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. In the textual description of this application, the character " / " generally indicates an "or" relationship between the preceding and following related objects; in the formulas of this application, the character " / " indicates a "division" relationship between the preceding and following related objects. "Including at least one of A, B, and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B, and C.
[0421] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.
Claims
1. An access control method, characterized in that, include: Determine the access control information for the first data service, wherein the access control information is used to instruct the data agent to obtain and / or publish the first data service; Send the access control information to the data communication agent.
2. The method as described in claim 1, characterized in that, The access permission includes being allowed to access and / or not being allowed to access; the publishing permission includes being allowed to publish and / or not being allowed to publish.
3. The method as described in claim 2, characterized in that, The allowed access includes allowed subscription, and the disallowed access includes disallowed subscription; or... The allowed access includes allowed extraction, and the disallowed access includes disallowed extraction; or, The allowed access includes allowing subscription and retrieval, and the disallowed subscription includes disallowing subscription and retrieval.
4. The method according to any one of claims 1-3, characterized in that, The access control information includes topic access control information, which is used to indicate: The data agent's access rights to the subject of the first data service; and / or, The data agent has publishing permissions for the topics of the first data service.
5. The method as described in claim 4, characterized in that, The first data service includes a first topic, and the topic permission control information includes first topic permission control information, which is used to indicate: The data agent's access permissions to the first topic; and / or, The data agent's publishing permissions for the first topic.
6. The method as described in claim 5, characterized in that, The first topic access control information includes: Information about one or more data proxies, and at least one of the following: access permission information of the one or more data proxies for the first topic, or publication permission information of the one or more data proxies for the first topic; or, Information about one or more regions, and at least one of the following: access permission information of data agents in the one or more regions for the first topic, or publication permission information of data agents in the one or more regions for the first topic; The permission acquisition information is used to indicate permission acquisition, and the permission release information is used to indicate permission release.
7. The method as described in claim 6, characterized in that, The first topic access control information includes at least one of the following: allowing access to information, prohibiting access to information, allowing posting of information, and prohibiting posting of information; The permitted access information includes information about one or more data proxies, which are permitted to access the first topic; or... The permitted information includes information from one or more regions, where data agents within those regions are permitted to access the first topic; or... The prohibited information includes information from one or more data proxies, which are not allowed to access the first topic; or... The prohibited information includes information from one or more regions, and data proxies within those one or more regions are not allowed to access the first topic. The permitted information publishing includes information about one or more data agents who are permitted to publish the first topic; or... The permitted information publishing includes information from one or more regions, where data agents within those regions are permitted to publish the first topic; or... The prohibited information includes information from one or more data proxies, who are not allowed to publish the first topic; or... The prohibited information includes information from one or more regions, and data agents in those one or more regions are not allowed to publish the first topic.
8. The method according to any one of claims 1-3, characterized in that, The access control information includes information about one or more data proxies, and the roles of the one or more data proxies for the first data service.
9. The method as described in claim 8, characterized in that, The one or more data agents include a first data agent, the role of which includes a first role and / or a second role, or the role of the first data agent is one of a first role, a second role, and a third role; The first role is the role that is allowed or not allowed to access the first data service; The second role is the role that allows or disallows the publication of the first data service; The third role is the role that allows or disallows access to and publication of the first data service.
10. The method according to any one of claims 1-9, characterized in that, The determination of the access control information for the first data service includes: Based on the access control policy corresponding to the first data service and / or the requirement information of the first data service, determine the access control information of the first data service.
11. A method for access control, characterized in that, include: Receive access control information corresponding to the first data service, wherein the access control information is used to instruct the data agent to obtain and / or publish the first data service; Upon receiving a data acquisition request message from the first data agent, respond to the data acquisition request message according to the first data agent's access permission to the first data service; or, upon receiving a data publishing request message from the first data agent, respond to the data publishing request message according to the first data agent's publishing permission to the first data service. The first data agent's access rights and publishing rights to the first data service are determined based on the access control information.
12. The method as described in claim 11, characterized in that, The access permissions include being allowed to access and / or not being allowed to access; The step of responding to the data acquisition request message based on the first data agent's access permission to the first data service includes: Based on the first data agent's access permission to the first data service, determine whether the first data agent is allowed to access the first data service.
13. The method as described in claim 12, characterized in that, The data acquisition request message is a data subscription request message; determining whether the first data agent is allowed to acquire the first data service includes: determining whether the first data agent is allowed to subscribe to the first data service; or... The data acquisition request message is a data extraction request message; determining whether the first data agent is allowed to acquire the first data service includes: determining whether the first data agent is allowed to extract the first data service.
14. The method according to any one of claims 12-13, characterized in that, The access control information includes topic access control information, which includes first topic access control information. The first topic access control information is used to indicate the first data agent's access permission to the first topic of the first data service. Determining whether the first data proxy is allowed to access the first data service includes: Based on the information of the first topic included in the data acquisition request message, determine whether the first data agent is allowed to acquire the first topic.
15. The method as described in claim 14, characterized in that, The first topic access control information includes: information about one or more data proxies, and access permission information for the one or more data proxies to access the first topic, wherein the access permission information is used to indicate access permission; determining whether the first data proxies are allowed to access the first topic includes: Whether the first data agent is allowed to access the first topic is determined based on whether the first data agent is one of the one or more data agents; Alternatively, the first topic access control information includes: information about one or more regions, and access permission information for data agents within the one or more regions to access the first topic, wherein the access permission information is used to indicate access permission; determining whether the first data agent is allowed to access the first topic includes: Whether the first data agent is allowed to access the first topic is determined based on whether the region where the first data agent is located is within one or more of the regions.
16. The method as described in claim 15, characterized in that, The first topic access control information includes at least one of the following: allowing access to information, and prohibiting access to information; The allowed access information includes information about one or more data proxies, which are allowed to access the first topic; determining whether the first data proxy is allowed to access the first topic based on whether the first data proxy is one of the one or more data proxies includes: if the first data proxy is one of the one or more data proxies, then the first data proxy is allowed to access the first topic; Alternatively, the allowed information access includes information about one or more regions, where data proxies within the one or more regions are allowed to access the first topic; determining whether the first data proxy is allowed to access the first topic based on whether the region where the first data proxy is located is within the one or more regions includes: if the region where the first data proxy is located is within the one or more regions, then the first data proxy is allowed to access the first topic. Alternatively, the prohibited information may include information about one or more data proxies, which are not allowed to access the first topic; determining whether the first data proxy is allowed to access the first topic based on whether the first data proxy is one of the one or more data proxies includes: if the first data proxy is not one of the one or more data proxies, then the first data proxy is allowed to access the first topic. Alternatively, the prohibited information includes information from one or more regions, where data proxies within those regions are not allowed to access the first topic; determining whether the first data proxy is allowed to access the first topic based on whether the region where the first data proxy is located is within the one or more regions includes: if the region where the first data proxy is located is not within the one or more regions, then the first data proxy is allowed to access the first topic.
17. The method as described in claim 11, characterized in that, The publishing permissions include being allowed to publish and / or not being allowed to publish; The step of responding to the data publishing request message according to the publishing authority of the first data agent for the first data service includes: Based on the publishing permissions of the first data agent for the first data service, determine whether the first data agent is allowed to publish the first data service.
18. The method as described in claim 17, characterized in that, The access control information includes topic access control information, which includes first topic access control information. The first topic access control information is used to indicate the first data agent's publishing permission for the first topic of the first data service. Determining whether the first data agent is allowed to publish the first data service includes: Based on the information of the first topic included in the data publishing request message, determine whether the first data agent is allowed to publish the first topic.
19. The method as described in claim 18, characterized in that, The first topic access control information includes: information about one or more data proxies, and publishing permission information of the one or more data proxies for the first topic, wherein the publishing permission information is used to indicate publishing permissions; determining whether the first data proxies are allowed to publish the first topic includes: Whether the first data agent is allowed to publish the first topic is determined based on whether the first data agent is one of the one or more data agents; Alternatively, the first topic access control information includes: information about one or more regions, and publishing permission information for the first topic by data agents within the one or more regions, wherein the publishing permission information is used to indicate publishing permissions; determining whether the first data agent is allowed to publish the first topic includes: Whether the first data agent is allowed to publish the first topic is determined based on whether the region where the first data agent is located is within one or more of the regions.
20. The method as described in claim 19, characterized in that, The first topic access control information includes at least one of the following: allowing information posting, and prohibiting information posting; The permission to publish information includes information about one or more data proxies, which are allowed to publish the first topic; determining whether the first data proxy is allowed to publish the first topic based on whether the first data proxy is one of the one or more data proxies includes: if the first data proxy is one of the one or more data proxies, then the first data proxy is allowed to publish the first topic; Alternatively, the permission to publish information may include information about one or more regions, where data agents within those regions are permitted to publish the first topic; determining whether the first data agent is permitted to publish the first topic based on whether the region where the first data agent is located is within the one or more regions includes: if the region where the first data agent is located is within the one or more regions, then the first data agent is permitted to publish the first topic. Alternatively, the prohibited information may include information from one or more data proxies, which are not permitted to publish the first topic; determining whether the first data proxy is permitted to publish the first topic based on whether the first data proxy is one of the one or more data proxies includes: if the first data proxy is not one of the one or more data proxies, then the first data proxy is permitted to publish the first topic; Alternatively, the prohibited information includes information from one or more regions, where data agents within those regions are not permitted to publish the first topic; determining whether the first data agent is permitted to publish the first topic based on whether the region where the first data agent is located is within the one or more regions includes: if the region where the first data agent is located is not within the one or more regions, then the first data agent is permitted to publish the first topic.
21. The method according to any one of claims 11-13, characterized in that, The access control information includes information about one or more data proxies, and the roles of the one or more data proxies for the first data service; The step of responding to the data acquisition request message based on the first data agent's access permission to the first data service includes: Based on the role of the first data agent, determine whether the first data agent is allowed to access the first data service.
22. The method as described in claim 21, characterized in that, The role of the first data agent includes a first role and / or a second role, or the role of the first data agent is one of a first role, a second role, and a third role; wherein, the first role is a role that is allowed or not allowed to access the first data service, the second role is a role that is allowed or not allowed to publish the first data service, and the third role is a role that is allowed or not allowed to access and publish the first data service. The step of determining whether the first data agent is allowed to access the first data service based on the role of the first data agent includes: If the role of the first data agent includes the first role, or the role of the first data agent is the third role, then it is determined whether the first data agent is allowed or not allowed to obtain the first data service.
23. The method according to any one of claims 11-13, characterized in that, The access control information includes information about one or more data proxies, and the roles of the one or more data proxies for the first data service; The step of responding to the data publishing request message according to the publishing authority of the first data agent for the first data service includes: Based on the role of the first data agent, determine whether the first data agent is allowed to publish the first data service.
24. The method as described in claim 23, characterized in that, The role of the first data agent includes a first role and / or a second role, or the role of the first data agent includes one of a first role, a second role, and a third role; wherein, the first role is a role that is allowed or not allowed to access the first data service, the second role is a role that is allowed or not allowed to publish the first data service, and the third role is a role that is allowed or not allowed to access and publish the first data service. The step of determining whether the first data agent is allowed to publish the first data service based on the role of the first data agent includes: If the role of the first data agent includes the second role, or the role of the first data agent is the third role, then it is determined whether the first data agent is allowed or not allowed to publish the first data service.
25. A communication device, characterized in that, It includes units or modules for performing the method as described in any one of claims 1-10, or units or modules for performing the method as described in any one of claims 11-24.
26. A communication device, characterized in that, include: One or more processors are configured to perform the method as claimed in any one of claims 1-10, or to perform the method as claimed in any one of claims 11-24.
27. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed on the device, cause the device to perform the method as claimed in any one of claims 1-10, or the method as claimed in any one of claims 11-24.
28. A chip system or chip, characterized in that, Includes a processor for supporting a computer device in implementing the method as described in any one of claims 1-10, or in implementing the method as described in any one of claims 11-24.
29. A computer program product, characterized in that, The computer program product includes a program; when the computer program is run on a computer, it causes the computer to perform the method as described in any one of claims 1-10, or to perform the method as described in any one of claims 11-24.
30. A communication system, characterized in that, It includes a data orchestration / data controller and a data communication agent, wherein the data orchestration / data controller performs the method as described in any one of claims 1-10, and the data communication agent performs the method as described in any one of claims 11-24.