IP Library Granted Patent US 12695749
Granted Patent B2
US 12695749 · App. 18/504,954 · Granted Jul 28, 2026

Communication method and apparatus

Inventor: Yizhuang Wu (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L63/0884H04L67/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695749
App. No.
18/504,954
Granted
Jul 28, 2026
Kind
B2
Abstract

A communication method includes sending, by a service consumer network element, a first service request message to a service communication proxy, and receiving, by the service consumer network element, a first response message of the first service request message from the service communication proxy. The first service request message is useable to request a first service from a service producer network element. The first service request message includes a first client credentials assertion. The first client credentials assertion is useable to authenticate the service consumer network element. The first client credentials assertion includes a first network function type of the service producer network element and a second network function type of a network element configured to provide a second service. The second service is useable to provide information about the service producer network element.

Claims (66)

1 . A communication method, wherein the method comprises:

sending, by a service consumer network element, a first service request message to a service communication proxy, wherein the first service request message is used to request a first service from a service producer network element, the first service request message comprises a first client credentials assertion, the first client credentials assertion is used to authenticate the service consumer network element, the first client credentials assertion comprises a first network function type of the service producer network element and a second network function type of a network element configured to provide a second service, wherein the second service is used to provide information about the service producer network element; and

receiving, by the service consumer network element, a first response message of the first service request message from the service communication proxy.

2 . The method according to claim 1 , further comprising:

determining, by the service consumer network element, that the first service request message triggers the service communication proxy to request the second service.

3 . The method according to claim 2 , wherein the determining, by the service consumer network element, that the first service request message triggers the service communication proxy to request the second service comprises:

determining, by the service consumer network element based on one or more of:

that context of a first terminal device fails to be stored and the first terminal device is associated with the first service;

that context of the first service fails to be stored;

that the service producer network element is part of a first slice and context corresponding to the first slice fails to be stored; or

that the service consumer network element is configured to communicate with the service communication proxy for a first time.

4 . The method according to claim 1 , further comprising:

determining, by the service consumer network element, to request that the first service is in an indirect communication mode with delegated discovery (mode D).

5 . The method according to claim 1 , further comprising:

sending, by the service consumer network element, a second service request message to the service communication proxy, wherein the second service request message is used to request the first service, the second service request message comprises a second client credentials assertion, the second client credentials assertion comprises the first network function type, and the second client credentials assertion is used to authenticate the service consumer network element; and

receiving, by the service consumer network element, a second response message for the second service request message from the service communication proxy, wherein the second response message for the second service request message comprises indication information; and

the sending, by the service consumer network element, the first service request message to the service communication proxy comprises:

sending, by the service consumer network element, the first service request message to the service communication proxy based on the indication information.

6 . The method according to claim 5 , wherein

the indication information comprises a third client credentials assertion, the third client credentials assertion comprises the second network function type, and the third client credentials assertion is used to authenticate the network element providing the second service; and

the sending, by the service consumer network element, the first service request message to the service communication proxy based on the indication information comprises:

sending, by the service consumer network element, the first service request message to the service communication proxy, based on the third client credentials assertion, in response to the authentication on the network element providing the second service succeeding.

7 . The method according to claim 1 , wherein the network element configured to provide the second service is a network repository function network element.

8 . The method according to claim 1 , wherein the first client credentials assertion further comprises one or more of:

an identifier of the service consumer network element, or

validity time information, wherein the validity time information represents validity time of the first client credentials assertion.

9 . A communication apparatus, comprising:

a memory configured to store non-transitory instructions, and

a processor configured to execute the non-transitory instructions thereby causing the apparatus to:

send a first service request message to a service communication proxy, wherein the first service request message is used to request a first service from a service producer network element, the first service request message comprises a first client credentials assertion, the first client credentials assertion is used to authenticate the apparatus, the first client credentials assertion comprises a first network function type of the service producer network element and a second network function type of a network element configured to provide a second service, wherein the second service is used to provide information about the service producer network element; and

receive a first response message of the first service request message from the service communication proxy.

10 . The communication apparatus according to claim 9 , wherein the processor is further configured to execute the non-transitory instructions thereby further causing the apparatus to:

determine that the first service request message triggers the service communication proxy to request the second service.

11 . The communication apparatus according to claim 9 , wherein the processor is further configured to execute the non-transitory instructions thereby further causing the apparatus to:

determine to request that the first service is in an indirect communication mode with delegated discovery (mode D).

12 . The communication apparatus according to claim 9 , wherein the network element configured to provide the second service is a network repository function network element.

13 . The communication apparatus according to claim 9 , wherein the first client credentials assertion further comprises one or more of:

an identifier of the communication apparatus, or

validity time information, wherein the validity time information represents validity time of the first client credentials assertion.

14 . A communication system, comprising:

a service consumer network element; and

a service communication proxy, wherein

the service consumer network element is configured to:

send a first service request message to the service communication proxy, wherein the first service request message is used to request a first service from a service producer network element, the first service request message comprises a first client credentials assertion, the first client credentials assertion is used to authenticate the service consumer network element, the first client credentials assertion comprises a first network function type of the service producer network element and a second network function type of a network element configured to provide a second service, and the second service is associated with the first service;

the service communication proxy is configured to:

receive the first service request message, and send a first response message of the first service request message to the service consumer network element; and

the service consumer network element is further configured to:

receive the first response message of the first service request message from the service communication proxy.

15 . The system according to claim 14 , wherein the service consumer network element is further configured to determine that the first service request message triggers the service communication proxy to request the second service.

16 . The system according to claim 14 , wherein the service consumer network element is further configured to determine to request that the first service is in an indirect communication mode with delegated discovery (mode D).

17 . The system according to claim 14 , wherein

the service communication proxy is further configured to:

after receiving the first service request message from the service consumer network element, send a second service request message to the network element configured to provide the second service, wherein the second service request message is used to request the second service, and the second service request message comprises the first client credentials assertion; and

the network element providing the second service is configured to:

receive the second service request message from the service communication proxy, and authenticate the service consumer network element based on the first client credentials assertion, wherein the network element providing the second service configured to authenticate the service consumer network element based on the first client credentials assertion comprises:

the network element providing the second service being configured to determine whether the network function type of the network element configured to provide the second service matches one or more of the first network function type and the second network function type, and in response to the authentication on the service consumer network element succeeding, the network element providing the second service being configured to send a second response message of the second service request message to the service communication proxy, wherein the second response message of the second service request message indicates to provide the second service.

18 . The system according to claim 17 , wherein

the first client credentials assertion further comprises one or more of:

an identifier of the service consumer network element, or

validity time information, wherein the validity time information represents validity time of the first client credentials assertion; and

the network element providing the second service is configured to authenticate the service consumer network element based on the first client credentials assertion further comprises one or more of:

verifying whether a signature of the first client credentials assertion succeeds,

verifying, based on the validity time information comprised in the first client credentials assertion, whether the first client credentials assertion expires, or

verifying whether the identifier of the service consumer network element in the first client credentials assertion is the same as an identifier of a network element in a certificate for signing the first client credentials assertion.

19 . The system according to claim 14 , wherein the network element configured to provide the second service is a network repository function network element.

20 . The system according to claim 14 , wherein the second service is used to provide information about the service producer network element.