Method and apparatus for authentication authorization
By using the session management network element to determine the authentication result of the data network, the secondary authentication process can be skipped or suspended, which solves the problem of repeated authentication under multiple PDU sessions, reduces signaling overhead, and is suitable for various communication scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2020-05-22
- Publication Date
- 2026-04-24
AI Technical Summary
The existing method of determining whether to perform secondary authentication based on whether the DNN of a PDU session is the same may result in multiple secondary authentication processes being performed for multiple PDU sessions accessing the same data network, leading to increased signaling overhead.
The session management network element determines whether the data network has already authenticated the terminal device. If an authentication result exists, the secondary authentication process is skipped; otherwise, secondary authentication is performed, or the session is suspended until an authentication result is obtained.
It reduces the repeated execution of secondary authentication processes under different DNNs, lowers signaling overhead, and is suitable for more scenarios, including high-reliability low-latency communication.
Smart Images

Figure CN113784346B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more specifically, to a method and apparatus for authentication and authorization. Background Technology
[0002] In terms of network security, the primary task of the network includes authenticating and authorizing terminal devices accessing the network. A commonly used authentication method is two-factor authentication. After a terminal device successfully completes the first level of authentication with the operator's network, if the terminal device needs to access a data network (DN), it establishes a Protocol Data Unit (PDU) session with the operator's network. During the establishment of the PDU session, a second level of authentication occurs between the terminal device and the authentication network element corresponding to the DN.
[0003] In practical communication, for the same DN, a terminal device can establish two or more PDU sessions in certain scenarios. For secondary authentication in scenarios with multiple PDU sessions, a common approach includes determining whether to perform secondary authentication by checking if the DN identifiers (data network name, DNN) of the two PDU sessions are the same.
[0004] Specifically, when a terminal device initiates the first PDU session establishment request, it performs secondary authentication and stores authentication information, including a Authentication Name Node (DNN). When the terminal device initiates the second PDU session establishment request, if the DNN in the second PDU session establishment request is the same as the DNN in the stored authentication information of the first PDU session, then it is determined that the secondary authentication process will not be executed; if the DNN in the second PDU session establishment request is different from the DNN in the stored authentication information of the first PDU session, then it is determined that the secondary authentication process will be executed.
[0005] This method of determining whether to perform a secondary authentication process based on whether the DNNs of two PDU sessions are the same has limited application scenarios. It may result in multiple PDU sessions connected to the same DN performing the secondary authentication process multiple times, thus causing additional signaling overhead. Summary of the Invention
[0006] This application provides an authentication and authorization method and apparatus, which can be applied to more scenarios, reduce the signaling overhead caused by repeated secondary authentication, and the solution is simple and easy to implement.
[0007] Firstly, an authentication and authorization method is provided. This method can be executed by a session management network element, or by a chip, chip system, or circuit configured in the session management network element; this application does not limit the execution of this method.
[0008] The method may include: receiving a session establishment request message from a terminal device, the session establishment request message being used to request the establishment of a session with a data network; determining whether there is an authentication result from the data network for the terminal device; and skipping the secondary authentication process for the session when the authentication result exists.
[0009] In one example, the authentication result is successful, meaning the data network has already authenticated the terminal device and the authentication authorization was successful. In this example, the secondary authentication process can be skipped, meaning the secondary authentication process can be skipped and the session can be established using the authentication authorization information (i.e., the authentication authorization information from successful authentication).
[0010] In another example, the authentication result is failure, meaning the data network has already authenticated the terminal device, and the authentication authorization failed. In this example, the secondary authentication process is skipped. In this case, the session can be refused. Alternatively, the reason for the failure can be used to determine whether to refuse to establish the session.
[0011] Based on the above technical solution, during session establishment, the session management network element can determine whether to initiate a secondary authentication process based on whether the data network (or the data network's authentication network element) has already authenticated the terminal device. That is, the authentication and authorization process is used by the data network to authenticate and authorize whether the terminal device can establish a session to access the data network. For example, if an authentication result exists, the secondary authentication process can be skipped. This makes it applicable to more scenarios, such as scenarios where different data network names (DNNs) are used, ensuring that the secondary authentication process is avoided from being repeated. Through the embodiments of this application, it can be ensured that even when using different DNNs to access the data network, the session management network element can avoid repeating the secondary authentication process as much as possible.
[0012] In conjunction with the first aspect, in some implementations of the first aspect, the authentication result includes authentication authorization information, which includes one or more of the following: one or more data network identifiers, identifiers of authentication network elements of the data network, timeliness information, index of the data network authorization text, aggregate maximum bit rate of the data network authorized session, allowed media access control addresses, allowed virtual local area networks, and information for indicating the reporting of session information.
[0013] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: when the authentication result does not exist, initiating a secondary authentication process for the session, or suspending the session.
[0014] For example, suspending a session, or pausing session establishment, means temporarily stopping the establishment of a session, temporarily stopping the secondary authentication process for the session, or waiting for the authentication result of another session.
[0015] For example, if it is determined that the session should be suspended, a request for or subscription to the secondary authentication result can be made to the unified data management network element.
[0016] In one scenario, the terminal device includes an indication in the session establishment request message that the session is redundant. In this scenario, based on this indication, the secondary authentication can be skipped directly, or the session can be suspended and the authentication result of another session can be reused.
[0017] In another scenario, a terminal device initiates two sessions simultaneously. The session establishment request message includes indication information, which either indicates that the current session should be suspended, or indicates that another session on the data network will require secondary authentication. In this scenario, the secondary authentication process can be skipped and the current session suspended based on this indication information.
[0018] Based on the above technical solution, it can be applied to scenarios where multiple sessions are established simultaneously, or scenarios where the data network and terminal device are performing secondary authentication when a session establishment request is initiated. This further avoids repeatedly executing the secondary authentication process.
[0019] In conjunction with the first aspect, in some implementations of the first aspect, after initiating a secondary authentication process for the session, the method further includes: suspending the session according to first indication information sent by the authentication network element of the terminal device or the data network, wherein the first indication information is used to instruct the data network to perform secondary authentication for another session of the terminal device.
[0020] For example, the first indication information can also be used to indicate that the session is suspended. It should be understood that the specific content indicated by the first indication information is not limited, and any method by which the session management network element instructs the authentication network element of the terminal device or data network to suspend the session falls within the protection scope of the embodiments of this application.
[0021] Based on the above technical solution, when it is determined that no authentication result exists, a secondary authentication process can be initiated. During the secondary authentication process, if the terminal device or data network (or the authentication network element of the data network) determines that the data network and / or the terminal device is currently performing secondary authentication (i.e., performing secondary authentication for another session), it can send a suspension instruction (i.e., the first instruction information). This allows the session management network element to suspend the session, i.e., temporarily stop establishing the session, based on the instruction information. Therefore, the terminal device or data network (or the authentication network element of the data network) at the centralized control point can indicate that secondary authentication is being performed, thereby avoiding the signaling overhead caused by repeatedly executing the secondary authentication process.
[0022] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: when the authentication result does not exist, determining whether the data network performs secondary authentication on another session of the terminal device; when the data network performs secondary authentication on another session of the terminal device, suspending the session; or, when the data network does not perform secondary authentication on another session of the terminal device, initiating a secondary authentication process for the session.
[0023] Based on the above technical solution, the session management network element can determine whether the data network is performing secondary authentication after determining that no authentication result exists.
[0024] In conjunction with the first aspect, in some implementations of the first aspect, after suspending the session, the method further includes: obtaining the authentication result of another session of the terminal device by the data network, wherein the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0025] The authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0026] For example, the authentication result of another session of the data network for the terminal device is saved.
[0027] For example, the authentication result of another session of the data network for the terminal device is obtained from any of the following: the authentication network element of the data network, the terminal device, the unified data management network element, or the local network.
[0028] In conjunction with the first aspect, in some implementations of the first aspect, when the authentication result of the other session indicates that the secondary authentication of the other session is successful, the secondary authentication process for the session is skipped and the subsequent session establishment process continues; or, when the authentication result of the other session indicates that the secondary authentication of the other session fails, the session is refused to be established.
[0029] For example, if the authentication result of the other session indicates that the secondary authentication for the other session has failed, the session management network element can also determine whether to refuse to establish the session and / or whether to save the authentication result based on the reason for the failure.
[0030] Based on the above technical solution, the secondary authentication process can be skipped, and the terminal device or data network (or the authentication network element of the data network) can directly send the authentication and authorization result to the session management network element, thereby avoiding the signaling overhead caused by repeatedly executing the secondary authentication process.
[0031] In conjunction with the first aspect, in some implementations of the first aspect, when initiating a secondary authentication process for the session, the method further includes: after successful secondary authentication of the session, determining whether to store the authentication result of the session according to any one of the following: session attributes, local policies, or second indication information of the session, wherein the second indication information is: authentication network element from the data network or information from the terminal device indicating whether to store the authentication result of the session.
[0032] In conjunction with the first aspect, in some implementations of the first aspect, determining whether the authentication result of the data network exists for the terminal device includes: determining whether the authentication result exists locally; or, determining whether the authentication result exists in the unified data management network element; or, determining whether the authentication result exists based on third indication information from the authentication network element of the terminal device or the data network; or, determining whether the authentication result exists in the authenticated dataset.
[0033] For example, an authenticated dataset can be obtained locally or from a unified data management network element.
[0034] For example, the "authenticated dataset" represents the authentication results that have been authenticated, which may include successful authentication results and / or failed authentication results. For instance, one can check the successful authentication results to see if there is information indicating that the data network has authenticated the terminal device; if so, it means that the data network has authenticated the terminal device, and the authentication result was successful. Similarly, one can check the failed authentication results to see if there is information indicating that the data network has authenticated the terminal device; if so, it means that the data network has authenticated the terminal device, and the authentication result was failed.
[0035] In one example, the third indication information comes from the terminal device, and this third indication information can be represented as a session identifier. This example can be used in high-reliability, low-latency communication scenarios.
[0036] For example, when establishing a session (e.g., denoted as session #1), the terminal device simultaneously carries the session identifier (such as session ID) of another session (e.g., session #2). This indicates that session #1 and session #2 are redundant, meaning they are accessing the same data network. For such session #1, the session management network element can further determine that secondary authentication is unnecessary, or that the authentication and authorization result of another session #2 can be reused.
[0037] In another example, the third instruction information comes from the terminal device, and this third instruction information can be represented as a DNN. This example can be used in high-reliability, low-latency communication scenarios.
[0038] For example, when establishing a session (e.g., denoted as session #1), the terminal device simultaneously carries the DNN of another session (e.g., session #2). This indicates that session #1 is a session on the same data network, different from the previous DNN. For such session #1, the session management network element can further determine whether secondary authentication is unnecessary, or whether to reuse the authentication and authorization result of another session #2.
[0039] In conjunction with the first aspect, in some implementations of the first aspect, determining whether the authentication result exists in the authenticated dataset includes: determining that the authentication result exists when the authenticated dataset includes the identifier of the data network; or determining that the authentication result does not exist when the authenticated dataset does not include the identifier of the data network.
[0040] Secondly, an authentication and authorization method is provided. This method can be executed by a session management network element, or by a chip, chip system, or circuit configured in the session management network element; this application does not limit the execution of this method.
[0041] The method may include: receiving a session establishment request message from a terminal device, the session establishment request message being used to request the establishment of a session with a data network; determining whether the data network performs secondary authentication on another session of the terminal device; and suspending the session when the data network performs secondary authentication on another session of the terminal device.
[0042] Based on the above technical solution, during the session establishment process, the session management network element can determine whether to suspend the session based on whether the data network (or the authentication network element of the data network) is currently authenticating the terminal device (i.e., authenticating another session of the terminal device). For example, when the data network is performing secondary authentication on another session of the terminal device, it can suspend the session, wait for the authentication result of the other session, and determine whether to initiate secondary authentication or establish a session based on the authentication result of the other session. This can be applied to more scenarios, such as ensuring that the secondary authentication process is avoided even when another session is undergoing secondary authentication when a session establishment request is initiated. Through the embodiments of this application, the repeated execution of the secondary authentication process can be avoided as much as possible.
[0043] In conjunction with the second aspect, in some implementations of the second aspect, suspending the session when the data network performs secondary authentication on another session of the terminal device includes: suspending the session according to first indication information carried in the session establishment request message, wherein the first indication information is used to instruct the data network to perform secondary authentication on another session of the terminal device.
[0044] In conjunction with the second aspect, in some implementations of the second aspect, after suspending the session, the method further includes: obtaining the authentication result of another session of the terminal device by the data network, wherein the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0045] For example, the authentication result of another session of the data network for the terminal device is obtained from any of the following: the authentication network element of the data network, the terminal device, the unified data management network element, or the local network.
[0046] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: when the authentication result of the other session indicates that the secondary authentication of the other session is successful, skipping the secondary authentication process for the session and continuing the subsequent session establishment process; or, when the authentication result of the other session indicates that the secondary authentication of the other session fails, refusing to establish the session.
[0047] Based on the above technical solution, after determining whether there is ongoing secondary authentication, it is also possible to determine whether there is an authentication result, that is, whether the data network has already authenticated the terminal device, thereby avoiding duplicate authentication.
[0048] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: when the data network does not perform secondary authentication for another session of the terminal device, determining whether there is an authentication result of the data network for the terminal device; when the authentication result exists, skipping the secondary authentication process for the session; or, when the authentication result does not exist, initiating a secondary authentication process for the session.
[0049] In conjunction with the second aspect, in some implementations of the second aspect, when initiating a secondary authentication process for the session, the method further includes: after successful secondary authentication of the session, determining whether to store the authentication result of the session according to any one of the following: the session attributes, local policy, or second indication information of the session, wherein the second indication information is: authentication network element from the data network or information from the terminal device indicating whether to store the authentication result of the session.
[0050] In conjunction with the second aspect, in some implementations of the second aspect, determining whether the authentication result of the data network exists for the terminal device includes: determining whether the authentication result exists locally; or, determining whether the authentication result exists in the unified data management network element; or, determining whether the authentication result exists based on third indication information from the authentication network element of the terminal device or the data network; or, determining whether the authentication result exists in the authenticated dataset.
[0051] In conjunction with the second aspect, in some implementations of the second aspect, the certified dataset includes a dataset that has been successfully certified; determining whether the certification result exists in the certified dataset includes: determining that the certification result exists when the successfully certified dataset includes the identifier of the data network; and determining that the certification result does not exist when the successfully certified dataset does not include the identifier of the data network.
[0052] Thirdly, an authentication and authorization method is provided. This method can be executed by a terminal device, or by a chip, chip system, or circuit configured in the terminal device; this application does not limit the scope of the method.
[0053] The method may include: determining whether there is an authentication result of the data network for the terminal device; sending a session establishment request message and first indication information to a session management network element, wherein the session establishment request message is used to request the establishment of a session with the data network, and the first indication information is used to indicate that there is an authentication result of the data network for the terminal device.
[0054] Fourthly, an authentication and authorization method is provided. This method can be executed by a terminal device, or by a chip, chip system, or circuit configured in the terminal device; this application does not limit the scope of the method.
[0055] The method may include: determining that the data network performs secondary authentication for another session of the terminal device; sending a session establishment request message and first indication information to a session management network element, wherein the session establishment request message is used to request the establishment of a session with the data network, and the first indication information is used to instruct the data network to perform secondary authentication for another session of the terminal device.
[0056] Fifthly, an authentication and authorization method is provided. This method can be executed by a terminal device, or by a chip, chip system, or circuit configured in the terminal device; this application does not limit the scope of the method.
[0057] The method may include: sending a session establishment request message to a session management network element, the session establishment request message being used to request the establishment of a session with a data network; during the process of secondary authentication of the session with the data network, determining whether the data network performs secondary authentication on another session of the terminal device; when the data network performs secondary authentication on another session of the terminal device, sending first indication information to the session management network element, the first indication information being used to instruct the data network to perform secondary authentication on another session of the terminal device.
[0058] Based on the above technical solution, during the session establishment process (such as during a secondary authentication process), the terminal device can determine whether to send a suspension instruction to the session management network element based on whether the data network (or the authentication network element of the data network) is currently authenticating the terminal device (i.e., authenticating another session of the terminal device). For example, when the data network is performing secondary authentication on another session of the terminal device, it can send a suspension instruction, wait for the authentication result of the other session, and determine whether to initiate secondary authentication or establish a session based on the authentication result of the other session. This can be applied to more scenarios, such as ensuring that the secondary authentication process is avoided even when another session is undergoing secondary authentication when a session establishment request is initiated. Through the embodiments of this application, the repeated execution of the secondary authentication process can be avoided as much as possible.
[0059] In conjunction with the third, fourth, or fifth aspects, in some implementations, determining whether the data network performs secondary authentication for another session of the terminal device during the secondary authentication process of the session with the data network includes: after receiving an authentication protocol request message from the session management network element, determining whether the data network performs secondary authentication for another session of the terminal device.
[0060] In some implementations, in conjunction with the third, fourth, or fifth aspects, the method further includes: after the data network completes the secondary authentication of the terminal device for another session, sending the authentication result of the other session to the session management network element, wherein the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0061] In conjunction with the third, fourth, or fifth aspects, in some implementations, based on one or more of the stored information and the session attributes of the session, it is determined that after the secondary authentication of another session of the terminal device by the data network is completed, the authentication result of the other session is sent to the session management network element, wherein the stored information is used to instruct that the authentication result of the other session is sent to the session management network element after the secondary authentication of the other session of the terminal device by the data network is completed.
[0062] In some implementations, in conjunction with the third, fourth, or fifth aspects, the method further includes: sending second indication information to the session management network element, the second indication information being used to indicate whether to store information about the authentication result of the data network for the terminal device.
[0063] Sixthly, an authentication and authorization method is provided. This method can be executed by an authentication network element of a data network, or by a chip, chip system, or circuit configured in the authentication network element of the data network; this application does not limit this.
[0064] The method may include: receiving an authentication authorization message from a session management network element, the authentication authorization message being used by the data network to verify whether a terminal device is authorized to establish a session to access the data network; determining whether there is an authentication result of the data network for the terminal device, or determining whether the data network performs secondary authentication for another session of the terminal device; sending first indication information to the session management network element, the first indication information being used to indicate whether there is an authentication result of the data network for the terminal device, or the first indication information being used to instruct the data network to perform secondary authentication for another session of the terminal device.
[0065] Based on the above technical solution, during session establishment, the data network (or the authentication element of the data network) determines whether a secondary authentication process is in progress, allowing the authentication and authorization result to be sent directly to the session management element without skipping the secondary authentication process. Therefore, the data network (or the authentication element of the data network) can determine whether to reuse the secondary authentication result, thereby avoiding the signaling overhead caused by repeatedly executing the secondary authentication process.
[0066] In conjunction with the sixth aspect, in some implementations of the sixth aspect, when it is determined that the data network performs secondary authentication for another session of the terminal device, the method further includes: after the data network completes the secondary authentication for another session of the terminal device, sending the authentication result of the other session to the session management network element, wherein the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0067] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: determining, based on stored information and one or more of the session attributes of the session, to send the authentication result of the other session to the session management network element after the secondary authentication of the other session by the data network for the terminal device is completed, wherein the stored information is used to instruct that the authentication result of the other session be sent to the session management network element after the secondary authentication of the other session by the data network for the terminal device is completed.
[0068] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the method further includes: sending second indication information to the session management network element, the second indication information being used to indicate whether to store information on the authentication result of the data network for the terminal device.
[0069] Seventhly, an authentication and authorization method is provided. This method can be executed by a session management network element and a unified data management network element, or it can be executed by a chip, chip system, or circuit configured in the session management network element and the unified data management network element; this application does not limit this.
[0070] The method may include: a session management network element receiving a session establishment request message from a terminal device, the session establishment request message being used to request the establishment of a session with the data network; the session management network element sending a request message to a unified data management network element, the request message being used to request the authentication result of the terminal device; the unified data management network element sending the authentication result of the terminal device to the session management network element; and when the data network has an authentication result for the terminal device, skipping the secondary authentication process for the session.
[0071] Eighthly, an authentication and authorization apparatus is provided, the apparatus being used to perform the methods provided in the first to seventh aspects. Specifically, the apparatus may include modules for performing the methods provided in the first to seventh aspects.
[0072] A ninth aspect provides an authentication and authorization apparatus, including a processor. The processor is coupled to a memory and is configured to execute instructions in the memory to implement the methods of the first to seventh aspects or any possible implementation thereof. Optionally, the apparatus further includes a memory. Optionally, the apparatus further includes a communication interface, to which the processor is coupled, the communication interface being used for inputting and / or outputting information. The information includes at least one of instructions and data.
[0073] In one implementation, the device is an apparatus, such as a session management network element, an authentication network element of a data network, or a terminal device. When the device is an apparatus, the communication interface can be a transceiver, or an input / output interface.
[0074] In another implementation, the device is a chip or a chip system. When the device is a chip or a chip system, the communication interface can be an input / output interface, which may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip or chip system. The processor can also be a processing circuit or a logic circuit.
[0075] In another implementation, the device is a chip or chip system configured in a device, such as a session management network element or an authentication network element or terminal device in a data network.
[0076] Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.
[0077] In a tenth aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a device, causes the device to implement the methods of the first to seventh aspects and any possible implementations of the first to seventh aspects.
[0078] Eleventhly, a computer program product comprising instructions is provided, which, when executed by a computer, cause the apparatus to perform the methods provided in the first to seventh aspects.
[0079] In a twelfth aspect, a communication system is provided, including the aforementioned session management network element, terminal equipment, and authentication network element of the data network, or including the aforementioned session management network element, terminal equipment, authentication network element of the data network, and unified data management network element. Attached Figure Description
[0080] Figure 1 This is a schematic diagram of a network structure applicable to embodiments of this application.
[0081] Figure 2 A schematic diagram of the secondary authentication process is shown.
[0082] Figure 3 and Figure 4 A schematic diagram of a multi-PDU session scenario applicable to embodiments of this application is shown.
[0083] Figure 5 This diagram illustrates multiple PDU sessions served by different SMF services.
[0084] Figure 6 This is a schematic diagram of the authentication and authorization method proposed according to the embodiments of this application.
[0085] Figure 7 (1) and (2) in the figure show a schematic diagram of an authentication and authorization method applicable to an embodiment of the present application.
[0086] Figure 8 A schematic diagram of an authentication and authorization method applicable to yet another embodiment of this application is shown.
[0087] Figure 9 A schematic diagram of an authentication and authorization method applicable to another embodiment of this application is shown.
[0088] Figure 10 A schematic diagram of an authentication and authorization method applicable to another embodiment of this application is shown.
[0089] Figure 11 This is a schematic block diagram of the authentication and authorization device provided in the embodiments of this application.
[0090] Figure 12 This is a schematic diagram of the structure of the authentication and authorization device provided in the embodiments of this application. Detailed Implementation
[0091] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0092] The technical solutions provided in this application can be applied to various communication systems, such as 5th Generation (5G) mobile communication systems or new radio access technology (NR). The 5G mobile communication system can include non-standalone (NSA) and / or standalone (SA) networking.
[0093] The technical solution provided in this application can be applied to any scenario in which a terminal device establishes multiple protocol data unit (PDU) sessions.
[0094] The technical solutions provided in this application can also be applied to machine-type communication (MTC), Long Term Evolution-machine (LTE-M) technology, device-to-device (D2D) networks, machine-to-machine (M2M) networks, Internet of Things (IoT) networks, or other networks. Among these, IoT networks may include, for example, vehicle-to-everything (V2X) networks. The communication methods in V2X systems are collectively referred to as vehicle-to-X (V2X), where X can represent anything. For example, V2X may include vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, or vehicle-to-network (V2N) communication, etc.
[0095] To facilitate understanding of the embodiments of this application, firstly, in conjunction with Figure 1 The network architecture applicable to the embodiments of this application is described in detail.
[0096] Figure 1 This is a schematic diagram of the network architecture applicable to the methods provided in the embodiments of this application. For example... Figure 1As shown, this network architecture is, for example, the 5G system (5GS) defined by the 3rd Generation Partnership Project (3GPP). This network architecture can be divided into two parts: the access network (AN) and the core network (CN). The access network is used to implement radio access-related functions and can include 3GPP access networks (or 3GPP access technologies) and non-3GPP access networks (or non-3GPP access technologies). The core network mainly includes the following key logical network elements: access and mobility management function (AMF) elements, session management function (SMF) elements, user plane function (UPF) elements, policy control function (PCF) elements, and unified data management (UDM) elements, etc.
[0097] The following is about Figure 1 A brief introduction to each network element shown in the image:
[0098] 1. User equipment (UE): can also be called terminal equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user device.
[0099] Terminal devices can be devices that provide voice / data connectivity to users, such as handheld devices with wireless connectivity, in-vehicle devices, etc. Currently, some examples of terminals include: mobile phones, tablets, computers with wireless transceiver capabilities (such as laptops, PDAs, etc.), mobile internet devices (MIDs), virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, and personal digital assistants (PDAs). PDA (Power Assistant), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in 5G networks or terminal devices in future public land mobile networks (PLMNs), etc.
[0100] Furthermore, terminal devices can also be terminal devices in Internet of Things (IoT) systems. IoT is an important component of future information technology development. Its main technical characteristic is connecting objects to networks through communication technologies, thereby realizing an intelligent network that enables human-machine interconnection and machine-to-machine interconnection. IoT technology can achieve massive connectivity, deep coverage, and low terminal power consumption through technologies such as narrowband (NB) technology.
[0101] In addition, terminal devices may also include sensors such as smart printers, train detectors, and gas stations. Their main functions include collecting data (for some terminal devices), receiving control information and downlink data from network devices, and sending electromagnetic waves to transmit uplink data to network devices.
[0102] It should be understood that a terminal device can be any device capable of accessing a network. Terminal devices and access network devices can communicate with each other using some form of air interface technology.
[0103] 2. Access Network (AN): The access network provides network access functionality for authorized users in a specific area, and includes radio access network (RAN) equipment and AN equipment. RAN equipment is mainly 3GPP network radio network equipment, while AN equipment can be access network equipment defined outside of 3GPP.
[0104] Access networks can employ different access technologies. Currently, there are two types of wireless access technologies: 3GPP access technologies (such as those used in 3G, 4G, or 5G systems) and non-3GPP access technologies. 3GPP access technologies refer to those that conform to 3GPP standards and specifications. For example, in 5G systems, access network equipment is called a next-generation node base station (gNB) or RAN. Non-3GPP access technologies refer to those that do not conform to 3GPP standards and specifications. Examples include air interface technologies such as access points (APs) in Wireless Fidelity (WiFi), Worldwide Interoperability for Microwave Access (WiMAX), and Code Division Multiple Access (CDMA) networks. Access network equipment (AN equipment) allows terminal devices and the 3GPP core network to interconnect using non-3GPP technologies.
[0105] An access network that implements access network functions based on wireless communication technology can be called a Radio Access Network (RAN). The RAN is responsible for functions such as radio resource management, quality of service (QoS) management, data compression, and encryption on the air interface side. The RAN provides access services to terminal devices, thereby completing the forwarding of control signals and user data between the terminal and the core network.
[0106] Wireless access networks can include, but are not limited to: macro base stations, micro base stations (also known as small stations), radio network controllers (RNCs), Node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home-evolved Node Bs, or home Node Bs, HNBs), baseband units (BBUs), access points (APs), wireless relay nodes, wireless backhaul nodes, transmission points (TPs), or transmission and reception points (TRPs) in WiFi systems. They can also be gNBs or transmission points (TRPs or TPs) in 5G (e.g., NR) systems, one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or network nodes constituting gNBs or transmission points, such as baseband units (BBUs), distributed units (DUs), or base stations in next-generation 6G communication systems. This application does not limit the specific technologies or equipment forms used in the wireless access network devices.
[0107] The access network can provide services to the cell. Terminal devices can communicate with the cell through the transmission resources (e.g., frequency domain resources, or spectrum resources) allocated by the access network devices.
[0108] 3. AMF (Active Mobile Element): Primarily used for mobility management and access management, such as user location updates, user registration with the network, and user handover. AMF can also be used to implement other functions of the Mobility Management Entity (MME) besides session management. For example, it can perform functions such as lawful interception or access authorization (or authentication).
[0109] 4. SMF Network Element: Primarily used for session management, UE Internet Protocol (IP) address allocation and management, selection of manageable user plane functions, policy control, or terminal points for charging function interfaces, and downlink data notification. In this embodiment, the SMF is mainly responsible for session management in the mobile network, such as session establishment, modification, and release. Specific functions may include, for example, allocating IP addresses to terminal devices and selecting UPFs that provide packet forwarding capabilities.
[0110] 5. UPF Network Element: Responsible for forwarding and receiving user data in terminal devices. The UPF network element can receive user data from the data network (DN) and transmit it to the terminal device through the access network equipment. The UPF network element can also receive user data from the terminal device through the access network equipment and forward it to the data network. The transmission resources and scheduling functions providing services to the terminal device within the UPF network element are managed and controlled by the SMF network element.
[0111] 6. Data Network (DN): A service network used to provide data services to users. Examples include the Internet, third-party business networks, and IP Multimedia Service (IMS) networks.
[0112] 7. Authentication server function (AUSF): mainly used for user authentication, etc.
[0113] 8. Network Exposure Function (NEF) element: mainly used to support the exposure of capabilities and events, such as to securely expose services and capabilities provided by 3GPP network functions to the outside world.
[0114] 9. Network Function (NF) Repository Function (NRF): Used to store network function entities and their descriptions of the services they provide, as well as to support service discovery, network element entity discovery, etc.
[0115] 10. PCF Network Element: A unified policy framework used to guide network behavior, providing policy rule information to control plane functional network elements (such as AMF, SMF, etc.), and responsible for obtaining user subscription information related to policy decisions.
[0116] 11. UDM network element: used for generating authentication credentials, user identification processing (such as storing and managing permanent user identities), access authorization control, and subscription data management.
[0117] 12. Application function (AF) network element: mainly supports interaction with the 3GPP core network to provide services, such as influencing data routing decisions, interacting with policy control functions (PCF), or providing third-party services to the network side.
[0118] exist Figure 1In the network architecture shown, network elements can communicate with each other through the interfaces shown in the diagram. Some interfaces can be implemented using service-oriented interfaces. As shown, the UE and AMF can interact through the N1 interface, and the interaction messages can be called N1 messages. The RAN and AMF can interact through the N2 interface, which can be used for sending non-access stratum (NAS) messages. The RAN and UPF can interact through the N3 interface, which can be used to transmit user plane data. The SMF and UPF can interact through the N4 interface, which can be used to transmit information such as tunnel identification information for N3 connections, data buffer indication information, and downlink data notification messages. The UPF and DN can interact through the N6 interface, which can be used to transmit user plane data. The relationships between other interfaces and network elements are as follows: Figure 1 As shown, for the sake of brevity, not all details are provided here.
[0119] It should be understood that the network architecture described above in the embodiments of this application is merely an example of a network architecture described from the perspective of a traditional point-to-point architecture and a service-oriented architecture. The network architecture applicable to the embodiments of this application is not limited to this, and any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of this application.
[0120] It should also be understood that Figure 1 The AMF, SMF, UPF, network slice selection function (NSSF), NEF, AUSF, NRF, PCF, and UDM shown can be understood as network elements in the core network used to implement different functions, such as network slices that can be combined as needed. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements.
[0121] It should also be understood that the above naming is defined solely for the purpose of distinguishing different functions and should not constitute any limitation on this application. This application does not preclude the possibility of using other naming conventions in 5G networks and other future networks. For example, in 6G networks, some or all of the above-mentioned network elements may use the terminology from 5G, or may use other names, etc. Figure 1 The interface names between the various network elements are merely examples; in actual implementations, the interface names may differ, and this application does not impose any specific limitations on them. Furthermore, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0122] To facilitate understanding of the embodiments of this application, the terms involved in this application will be briefly explained first.
[0123] 1. Protocol Data Unit (PDU) Session
[0124] The 5G core network (5GC) supports PDU connection services. PDU connection services refer to the exchange of PDU data packets between a terminal device and the DN (Digital Data Center). PDU connection services are implemented by the terminal device initiating the establishment of a PDU session. Once a PDU session is established, a data transmission channel between the terminal device and the DN is established. In other words, the PDU session is at the UE (User Equipment) level. Each terminal device can establish one or more PDU sessions. The terminal device can access the DN through the PDU session established between the terminal device and the DN.
[0125] As mentioned earlier, the SMF (Session Management Function) is primarily responsible for session management in the mobile network. PDU sessions can be established, modified, or released between the terminal device and the SMF via NAS (Session Management, SM) signaling.
[0126] In the embodiments of this application, the terminal device can establish multiple PDU sessions or multiple PDU connection services. For example, the terminal device can establish two or more PDU sessions, and there is no limitation on the number of PDU sessions. For example, the DN identifiers (data network name, DNN) of these PDU sessions can be different or the same. Furthermore, different PDU sessions can be served by the same SMF or by different SMFs. Also, the establishment of these PDU sessions can be initiated simultaneously or sequentially.
[0127] 2. Secondary authentication
[0128] In terms of network security, the primary tasks of the network include authenticating and authorizing terminals accessing the network. Only after a terminal device has been authenticated can it access the 3GPP network and further request the establishment of a PDU session to access various services on the DN.
[0129] In current 4G networks, terminal device authentication and authorization are handled directly by the operator's network. In 5G standardization, this authentication method is called Primary Authentication, or Level 1 Authentication. With the development of vertical industries and the Internet of Things (IoT), it is foreseeable that data networks (DNs) outside the operator's network will also have authentication and authorization requirements for terminal devices accessing the DN (although through the operator's network). To address this need, 3GPP has defined a new authentication method in its 5G security standardization, called Secondary Authentication, or Level 2 Authentication. This method allows data networks outside the operator's network to authenticate or authorize terminal devices through the operator's network.
[0130] After a terminal device successfully completes the first-level authentication with the operator's network, if it needs to access a specific DN (Network Node), it establishes a PDU (Programmable Component Unit) session with the operator's network. During this PDU session establishment, a second-level authentication occurs between the terminal device and the authentication server (i.e., the authentication network element) corresponding to the DN. This authentication server includes network elements used to perform the secondary authentication. The establishment of the PDU session can be triggered by the terminal device or the operator's core network (CN). During or after the PDU session establishment, the operator's network initiates the secondary authentication process. For example, the terminal device can send an authentication request to the operator's network, which can forward the request to the authentication server corresponding to the DN, allowing the DN's authentication server to perform authentication and / or authorization between the DN and the terminal device. The authentication server corresponding to the DN (e.g., simply referred to as the DN's authentication server) can be, for example, an authentication, authorization, and accounting (AAA) server. The authentication server corresponding to the DN sends the authentication and / or authorization results of the terminal device to the operator network. The operator network uses this result to determine whether to establish a corresponding PDU session connection for the terminal device.
[0131] For ease of understanding, combined with Figure 2 Here's a brief overview of the two-factor authentication process.
[0132] 201. The terminal device sends a registration request to the AMF.
[0133] 202. Terminal devices undergo Level 1 authentication with the operator's network.
[0134] After receiving a registration request from the terminal device, AMF can trigger AUSF to perform the first level of authentication between the terminal device and the operator's network.
[0135] Optionally, during the first-level authentication process between the terminal device and the operator network, AUSF can obtain the authentication information required for the first-level authentication from the UDM, and then realize the first-level authentication between the terminal device and the operator network based on the authentication information generated by the UDM or the stored authentication information.
[0136] 203. Establish NAS security between the terminal device and AMF.
[0137] After the first-level authentication between the terminal device and the operator's network is successful, the AMF can establish NAS security with the terminal device. NAS exists in the Universal Mobile Telecommunications System (UMTS) wireless communication protocol stack as a functional layer between the CN and the terminal device. NAS supports signaling and / or data transmission between the CN and the terminal device.
[0138] 204, The terminal device initiates a session establishment request.
[0139] After the terminal device establishes NAS security with the AMF, it can initiate a session establishment request to the AMF. This session establishment request can be used, for example, to request the establishment of a PDU session. The terminal device sends a NAS message to the AMF, and the session establishment request can be carried in the NAS message.
[0140] 205, AMF sends a session establishment request to SMF.
[0141] After receiving the NAS message from the terminal device, the AMF can decode the session establishment request in the NAS message and then send the session establishment request to the SMF. The SMF can be the SMF that the PDU session requested to establish in the session establishment request is connecting to.
[0142] 206, SMF verifies contract data.
[0143] After receiving the session establishment request, the SMF obtains the subscription data from the UDM. If the subscription data indicates that secondary authentication is required, step 207 can be executed.
[0144] 207. SMF launched the Extensible Authentication Protocol (EAP) authentication process.
[0145] Optionally, if the session establishment request does not carry authentication information, steps 208 and 209 are executed; if the session establishment request carries authentication information, steps 208 and 209 can be skipped.
[0146] 208, SMF sends an EAP request to the terminal device.
[0147] SMF sends an EAP request to the terminal device, requesting the terminal device's identity information.
[0148] 209. The terminal device sends an EAP response to the SMF.
[0149] The terminal device sends an EAP response to the SMF to notify the terminal device of its identity information.
[0150] 210, SMF initiates the establishment of an N4 interface session connection with UPF.
[0151] If there is no UPF for transmitting messages between the SMF and the DN's authentication server (such as the AAA server), the SMF initiates an N4 interface session connection with the UPF.
[0152] It is understandable that if there is a UPF between the SMF and DN authentication servers for transmitting messages, then step 210 may not need to be performed.
[0153] 211. SMF sends an EAP response and the identity information of the terminal device to the DN's authentication server.
[0154] like Figure 2 As shown, SMF sends the EAP response and the terminal device's identity information to the DN authentication server via UPF.
[0155] The SMF sends the EAP response and authentication information (i.e., the terminal device's identity information) from the terminal device to the UPF through the N4 interface session connection established in step 210. The UPF then sends the EAP response and the terminal device's identity information to the DN authentication server.
[0156] 212, DN's authentication server authenticates and / or authorizes terminal devices.
[0157] The terminal device and the DN authentication server can exchange EAP messages once or multiple times to complete the authentication of the terminal device by the DN authentication server.
[0158] The message type or interaction method of the EAP messages exchanged between the terminal device and the DN's authentication server depends on the specific EAP authentication method used, and this application does not impose any restrictions on them.
[0159] 213. The DN's authentication server sends an authentication success message to the SMF via the UPF.
[0160] If the DN authentication server successfully authenticates the terminal device, the DN authentication server can send an authentication success message to the UPF, and then send the authentication success message to the SMF through the UPF and N4 interface session connection.
[0161] 214. Other procedures initiated by SMF to establish a PDU session.
[0162] After the DN authentication server completes the EAP authentication of the terminal device, the SMF can continue to initiate other processes for establishing a PDU session, such as including but not limited to: the SMF sending an N4 interface session establishment / modification request to the UPF, and the UPF sending an N4 interface session establishment / modification response back to the SMF.
[0163] 215. The SMF sends a PDU session establishment success message to the terminal device through the AMF.
[0164] The SMF sends a PDU session establishment success message to the AMF, and the AMF forwards the PDU session establishment success message to the terminal device.
[0165] It should be understood that steps 201 to 215 above are merely illustrative and do not limit the scope of protection of the embodiments of this application.
[0166] 3. Multi-PDU session scenarios
[0167] In practical communication, for the same DN, in certain scenarios, a terminal device can establish two or more PDU sessions. Several possible scenarios are described below.
[0168] Scenario 1: Ultra reliable low latency communication (URLLC)
[0169] To ensure reliable service transmission, when an initiated service requires high reliability, the terminal device can establish multiple PDU sessions (e.g., two PDU sessions) through the operator's network to transmit the same service; that is, these multiple PDU sessions are used to access the same DN. Taking two PDU sessions as an example, the specific details are as follows... Figure 3 As shown,
[0170] like Figure 3As shown, two PDU sessions established between the terminal device and the DN, namely PDU session 1 and PDU session 2, can be served by different SMFs, such as SMF1 and SMF2, and both PDU session 1 and PDU session 2 access the same DN. It should be understood that multiple PDU sessions established between the terminal device and the DN can also be served by the same SMF. When multiple PDU sessions are established between the terminal device and the DN for accessing the same DN, the DNN and / or network identifier (such as single network slice selection assistance information, S-NSSAI) provided by the terminal device are different. For example, the DNNs provided by the terminal devices are different; or the S-NSSAIs provided by the terminal devices are different; or both the DNNs and S-NSSAIs provided by the terminal devices are different.
[0171] Scenario 2: Edge computing (EC) communication
[0172] In EC communication, to support services accessing the EC environment, three access methods can be included, such as... Figure 4 As shown.
[0173] like Figure 4 As shown, Access Method 1: Distributed Anchor Point, where the terminal device establishes a PDU session for accessing services in the local EC environment. Access Method 2: Session Breakout, where the terminal device establishes a PDU session that can access services in the local EC environment and also services deployed remotely. In other words, service offloading can be achieved through Access Method 2. Specifically, service offloading can be achieved, for example, through an Uplink Classifier (UL CL) or a Branching Point (BP), without limitation. It should be understood that Access Method 1 and Access Method 2 are merely illustrative and do not limit the scope of protection of the embodiments in this application.
[0174] Access Method 3: The terminal device establishes multiple PDU sessions simultaneously (e.g., two PDU sessions). One PDU session is used to access services in the local EC environment, and the other PDU session is used to access services deployed remotely in a centralized manner. It should be understood that these multiple PDU sessions can be established on demand at different times, or simultaneously. The SMF serving the PDU sessions can be the same or different. Furthermore, the DNN used to establish the PDU sessions can also be different. Therefore, it is possible for a terminal device to establish multiple PDU sessions in EC communication.
[0175] Scenario 3: Sessions with the same DN but different needs
[0176] For the same DN, different services may have different requirements, such as varying service continuity requirements. Alternatively, to ensure service continuity, a make-before-break mechanism can be used. Make-before-break is a mechanism that establishes a new path before the original path is torn down. In this case, two PDU sessions will be established between the terminal device and the operator's network. In this scenario, the DNNs for these multiple PDU sessions can be the same or different.
[0177] As can be seen from the above three scenarios, for the same DN, a terminal device can establish two or more PDU sessions. These two or more PDU sessions can be established simultaneously or at different times as needed. The DNNs used to establish these two or more PDU sessions can be different.
[0178] The foregoing has briefly described a scenario involving multiple PDU sessions applicable to the embodiments of this application. It should be understood that the embodiments of this application are not limited thereto. Any scenario involving multiple PDU sessions is applicable to the embodiments of this application.
[0179] Regarding secondary authentication in scenarios with multiple PDU sessions, we will briefly introduce existing solutions using two PDU sessions as an example.
[0180] The existing approach involves the terminal device initiating the first PDU session. The SMF determines whether to perform secondary authentication and stores the successful authentication information locally or in the UDM. This authentication information includes the Designated Name Authentication Network (DNN). During the establishment of the second PDU session, the SMF obtains the authentication information from the first PDU session (either locally stored or obtained from the UDM). If the DNN in the second PDU session request matches the DNN in the authentication information of the first PDU session, the SMF determines that the secondary authentication process should not be performed and authorizes the establishment of a newly initiated PDU session (i.e., the second PDU session), thus continuing the subsequent PDU session establishment process.
[0181] In existing solutions, the SMF determines whether to initiate a secondary authentication process based on whether the DNN in the authentication information is the same. This approach has limited application scenarios and may result in multiple PDU sessions accessing the same DN performing multiple secondary authentication processes, leading to additional signaling overhead. For example, when multiple PDU sessions accessing the same DN use different DNNs, the above solution cannot identify new PDU sessions used to access the same DN, causing multiple PDU sessions accessing the same DN to perform multiple secondary authentication processes, resulting in additional signaling overhead.
[0182] Furthermore, existing solutions primarily address scenarios where, when a terminal device initiates the establishment of a second PDU session, the secondary authentication process initiated by the SMF with the DN has already been completed, and the result is stored in the SMF or UDM. If the terminal device initiates the second PDU session while the secondary authentication process is in progress, the existing logic prevents the SMF from determining whether to skip the secondary authentication process. This is especially problematic when the two PDU sessions are served by different SMFs, such as... Figure 5 As shown, the first PDU session is served by SMF1, and the second PDU session is served by SMF2, which may also lead to additional signaling overhead.
[0183] In view of this, this application provides a method that can be applied to more scenarios, reduces the signaling overhead caused by repeated secondary authentication, and is simple and easy to implement.
[0184] The various embodiments provided in this application will now be described in detail with reference to the accompanying drawings.
[0185] Figure 6 This is a schematic interactive diagram illustrating an authentication and authorization method 600 provided in an embodiment of this application. Method 600 may include the following steps.
[0186] 610, SMF receives a session establishment request message from the terminal device, which requests the establishment of session #1 with data network #1.
[0187] For the sake of distinction and without loss of generality, in step 610, the session requested by the terminal device to be established is denoted as session #1, and the data network requested by the terminal device to be accessed is denoted as data network #1.
[0188] The terminal device initiates a session establishment request, which can be used, for example, to request the establishment of a PDU session with the data network. For instance, the terminal device initiates a PDU session establishment request to the AMF, and the AMF sends a PDU session establishment request to the SMF.
[0189] During the session establishment process, SMF can determine whether to initiate a secondary authentication process based on whether there is an authentication result of the terminal device by data network #1.
[0190] 620, SMF determines whether there is an authentication result from data network #1 for the terminal device.
[0191] The authentication result, or authentication and authorization result, is used to determine whether the data network #1 has authenticated and authorized the terminal device. For example, the authentication result can indicate the authentication result of another session of the terminal device (such as the success or failure of secondary authentication for another session).
[0192] Optionally, the authentication result may include time information, that is, the validity information of the authentication result or a valid authentication result. For example, the authentication result may include an authentication time range. Within the authentication time range, the authentication result is valid; outside the authentication time range, the authentication result is invalid. It should be understood that this is merely an illustrative example and does not limit the scope of protection of the embodiments of this application. For example, after the authentication time range has expired, the authentication result may no longer be saved.
[0193] One possible outcome is that the authentication result is successful. In other words, the SMF can determine whether data network #1 has successfully authenticated and authorized the terminal device.
[0194] Another possible scenario is that the authentication result is authentication failure. In other words, SMF can determine whether data network #1 has failed to authenticate and authorize the terminal device.
[0195] The SMF's method for determining whether an authentication result exists is described in detail below.
[0196] Method 600 may include steps 631 or 632.
[0197] 631. If an authentication result exists, skip the secondary authentication process for session #1.
[0198] In one possible scenario, the SMF determines that data network #1 has successfully authenticated and authorized the terminal device. In this case, the SMF skips the secondary authentication process for session #1 and establishes session #1 using the successfully authenticated authorization information. For possible steps after the SMF determines that the secondary authentication process for session #1 has been skipped, please refer to step 706B in method 700 below.
[0199] Another possible scenario is that the SMF determines that data network #1 failed to authenticate the terminal device. It's understandable that after the data network fails to authenticate the terminal device, it can record the failure (or determine whether to record the failure based on the reason for the failure), such as recording it for a period of time. In this way, when the terminal device requests access to the data network again, the SMF can determine, based on the authentication failure result, not to initiate secondary authentication for that terminal device. Furthermore, in this case, the SMF can refuse to establish session #1.
[0200] In this application, the term "skipping the secondary authentication process" is mentioned multiple times, and those skilled in the art should understand its meaning. Skipping the secondary authentication process includes skipping all steps of the secondary authentication process or skipping only some steps. For example, skipping steps 207 to 213 as described above, or steps 210 to 213, or steps 212 to 213, etc., can be implemented. For instance, when the authentication result is successful, it indicates that the data network has authenticated and authorized the terminal device, and the terminal device can access the data network or communicate with the data network based on the previous authentication result.
[0201] 632. If no authentication result exists, initiate a secondary authentication process for session #1, or suspend session #1.
[0202] One possible scenario is that, if no authentication result exists, a secondary authentication process is initiated for session #1.
[0203] Data network #1 has not authenticated the terminal device. In this case, a secondary authentication process can be initiated for session #1. For details, please refer to step 706A in method 700 below.
[0204] Another possible scenario is that if no authentication result exists, session #1 is suspended.
[0205] Data network #1 may be authenticating or about to authenticate the terminal device. In this case, when the SMF determines that data network #1 is authenticating or about to authenticate the terminal device, it can suspend session #1. Suspending session #1, or pausing the establishment of session #1, means temporarily stopping the establishment of session #1 or temporarily stopping the secondary authentication process for session #1. For example, it could be waiting for the authentication result of another session, and determining how to handle session #1 based on the authentication result of the other session. The authentication result of the other session can be used to indicate whether the secondary authentication of the other session was successful or failed.
[0206] In one possible scenario, when establishing session #1, the terminal device simultaneously carries session information (such as session ID) of another session (e.g., session #2). This indicates that session #1 and session #2 are redundant, meaning they are connected to the same DN. For such session #1, the SMF can further determine that secondary authentication is unnecessary, or reuse the authentication and authorization result of another session #2 (e.g., suspend session #1 and wait for the authentication and authorization result of session #2). Taking the URLLC scenario as an example, the indication information #1 sent by the terminal device indicates that session #1 is a redundant session. In this scenario, the SMF does not need to perform secondary authentication. The SMF can obtain the result based on the indication information #1. In other words, when secondary authentication is required, it is always initiated for another session (e.g., session 2), and secondary authentication for session #1 can be skipped directly.
[0207] Another possible scenario is that the terminal device initiates two sessions simultaneously, one designated as session #1 and the other as session #3. The session #1 establishment request message includes indication information, either to suspend session #1 or to indicate that another session (session #3) will require secondary authentication for data network #1. In this scenario, the SMF can also suspend session #1 by skipping the secondary authentication process based on this indication information. Optionally, in this scenario, the SMF can request or subscribe to the secondary authentication result from the UDM to process the suspended session #1 according to the result of the secondary authentication.
[0208] This application repeatedly mentions that secondary authentication is in progress, which can include whether secondary authentication is ongoing or about to be performed. For example, secondary authentication will be performed or is in progress for another session. For the sake of brevity, the term "secondary authentication in progress" will be used consistently below.
[0209] This situation will be described in detail below in conjunction with aspect two.
[0210] Through the embodiments of this application, during the session establishment process, the SMF can determine whether to initiate a secondary authentication process based on whether the data network has already authenticated the terminal device, or whether the SMF can determine whether to suspend the session based on whether the data network and the terminal device are currently authenticating or about to authenticate. In other words, the authentication and authorization process is used by the data network to authenticate and authorize whether the terminal device can establish a session to access the data network. This ensures that even in scenarios where different DNNs identify the data network, and in scenarios where sessions are established simultaneously or another session is being authenticated while a session is being established, the repeated execution of the secondary authentication process can be avoided. Through the embodiments of this application, it can be ensured that even when using different DNNs to access the data network, the SMF can minimize the repeated execution of the secondary authentication process.
[0211] The embodiments of this application are described in detail below with reference to several aspects. These aspects can be used individually or in combination, and there is no limitation thereto.
[0212] Aspect 1: How SMF determines whether an authentication result exists.
[0213] Implementation method 1: SMF can determine whether an authentication result exists based on the authentication authorization information.
[0214] For example, the SMF can determine whether the authentication result exists in the authenticated dataset. The authenticated dataset represents data or information that has already been authenticated. For instance, the SMF can determine whether data network #1 is included in the data networks that have already authenticated the terminal device, or whether the terminal device is included in the data network #1 that has already authenticated. The authenticated dataset can include two datasets, such as a dataset of successfully authenticated data and a dataset of failed authentication data. The SMF can determine whether the authentication result exists from both the successfully authenticated dataset and the failed authentication dataset.
[0215] For example, the terminal device sends a Data Network Name (DNN) to the SMF to identify data network #1, denoted as DNN#1. The authentication and authorization information includes successfully authorized DNNs. By checking if DNN#1 exists among successfully authorized DNNs, it is determined whether an authentication result exists, such as whether the terminal device has been successfully authenticated and authorized.
[0216] Optionally, the authentication and authorization information may also include, but is not limited to, one or more of the following: Data Network Specific Id (DN-Specific Id), Identifier (Id) of the data network's authentication server (e.g., DN-AAA Id), validity period information, index of the data network authorization text, aggregated maximum bit rate (AMBR) of the data network authorized session, allowed MAC addresses(s), allowed virtual local area network (VLAN) identifiers (VIDs), session information reporting indication, and session management and control related information. Among these, the session information reporting indication is used to indicate the reporting of relevant session information, such as session address information.
[0217] When the DNN and DNN#1 contained in the authentication authorization information are the same, it indicates that they are from the same data network, meaning that secondary authentication is not required. When the DNN and DNN#1 contained in the authentication authorization information are different, it can be determined whether the DNN contained in the authentication authorization information and DNN#1 are equivalent DNNs, i.e., whether they indicate the same data network. An equivalent DNN is one that identifies the same data network.
[0218] For example, multiple DNNs (or a list of DNNs) (i.e., equivalent DNNs) can be pre-configured to indicate the same data network. For instance, the SMF obtains these multiple DNNs based on the acquired authentication and authorization information.
[0219] For example, DNN#1 is DNN1, and the authentication and authorization information includes multiple DNNs (i.e., equivalent DNNs) such as {DNN1, DNN2, DNN3}. This indicates that the authenticated and authorized data network and the data network #1 requested by the terminal device are the same data network; or, in other words, the terminal device has already been authenticated with the requested data network and does not need to undergo a secondary authentication process. In this case, method 600 may include step 631.
[0220] For example, if DNN#1 is DNN5, and the authentication and authorization information includes multiple DNNs (i.e., equivalent DNNs) such as {DNN1, DNN2, DNN3}, then this indicates that the authenticated and authorized data network is different from the data network #1 that the terminal device is requesting access from; or, in other words, the terminal device has not been authenticated with the data network it is requesting access from, and a secondary authentication process is required. In this case, method 600 may include step 632.
[0221] Alternatively, authentication and authorization information can be obtained based on any of the following.
[0222] For example, the SMF can obtain authentication and authorization information through the context of the terminal device. In other words, the SMF can obtain the context of the terminal device and determine whether to initiate a secondary authentication process for session #1 based on the context of the terminal device.
[0223] In another example, SMF retrieves authentication and authorization information stored locally.
[0224] In another example, SMF obtains authentication and authorization information from the authentication server of the data network.
[0225] In another example, the SMF obtains authentication and authorization information from the UDM.
[0226] The following section outlines a possible complete process for SMF to obtain authentication and authorization information. Figures 7 to 10 Specific embodiments are described below.
[0227] Implementation method 2: SMF can determine whether there is an authentication result based on the instruction information #1.
[0228] It should be understood that, for the sake of distinction and without loss of generality, in the embodiments of this application, indication information #1 represents information used to determine whether an authentication result exists.
[0229] For example, the indication message #1 comes from the terminal device.
[0230] The terminal device sends an indication message #1 to the SMF so that the SMF can determine whether an authentication result exists based on the indication message #1. This indication message #1 can be sent to the SMF via separate signaling or included in the session establishment request message; there is no limitation on this.
[0231] In one possible scenario, instruction message #1 can be sent before determining whether an authentication result exists. For example, if the SMP determines that no authentication result exists and initiates a secondary authentication process for session #1, it sends an EAP to the terminal device. Upon receiving the EAP, the terminal device sends instruction message #1. Alternatively, if the SMP determines that no authentication result exists but before initiating a secondary authentication process for session #1, the terminal device sends instruction message #1 to the SMF.
[0232] In another possible scenario, indication message #1 can be sent before determining whether an authentication result exists. For example, when the terminal device initiates a session establishment request, it can first determine whether there is an authentication result or whether there is ongoing secondary authentication. If so, it sends indication message #1. In this case, SMF does not need to determine whether an authentication result exists; it can directly determine whether there is an authentication result or whether to suspend session #1 based on indication message #1.
[0233] There are no restrictions on the format of instruction message #1.
[0234] One possible form is that the instruction information #1 can be represented as a session identifier.
[0235] For example, when establishing session #1, the terminal device simultaneously carries the session identifier (such as session ID) of another session (e.g., session #2). This indicates that session #1 and session #2 are redundant, meaning they access the same DN. For such session #1, the SMF can further determine that secondary authentication is unnecessary, or reuse the authentication and authorization result of another session #2. In one possible scenario, taking a URLLC scenario, the indication information #1 sent by the terminal device indicates that session #1 is a redundant session. In this scenario, the SMF does not need to perform secondary authentication; the SMF can obtain the result based on the indication information #1. In other words, when secondary authentication is required, it is always initiated for another session (e.g., session 2), and secondary authentication for session #1 can be skipped.
[0236] Another possible form is that the instruction information #1 can be represented as a DNN.
[0237] For example, when establishing session #1, the terminal device simultaneously carries the DNN of another session (e.g., denoted as session #2). This indicates that session #1 is a session with the same DN but a different DNN from the previous one. For such session #1, the SMF can further determine whether secondary authentication is unnecessary, or whether the authentication and authorization result of another session #2 can be reused.
[0238] Another possible form is that the instruction information #1 can be represented by adding a new field or reusing an existing field.
[0239] For example, when establishing session #1, the terminal device determines whether session #1 is a session on the same data network, that is, whether data network #1 is the same as the data network of previously established sessions. For instance, if the value of the newly added or existing field is "0", indicating that they are different, the SMF can initiate secondary authentication for this type of session #1; if the value of the newly added or existing field is "1", indicating that they are the same, the SMF can further determine that secondary authentication is not required for this type of session #1, or reuse the authentication and authorization result of another session #2.
[0240] Therefore, by sending indication information to the SMF through the terminal device, the SMF becomes aware that sessions using different DNNs have been established. Thus, the SMF can identify sessions using different DNNs on the same data network, thereby avoiding the signaling overhead of repeatedly performing secondary authentication procedures.
[0241] Another example indicates that message #1 comes from the authentication server of data network #1.
[0242] The authentication server of data network #1 sends indication information #1 to the SMF so that the SMF can determine whether an authentication result exists based on the indication information #1.
[0243] During session establishment, the authentication server of data network #1 determines whether the terminal device has been authenticated and can directly send the authentication authorization result to the SMF. Therefore, the authentication server of the centralized control point data network can reuse the secondary authentication result, thereby avoiding the signaling overhead caused by repeatedly performing the secondary authentication process.
[0244] The first part above mainly introduced how SMF determines whether an authentication result exists. The following part, combined with the second part, introduces the solution for ongoing secondary authentication.
[0245] Aspect 2: SMF has confirmed that it is currently undergoing a second certification process.
[0246] For the same data network, a terminal device can establish two or more sessions. These sessions can be established simultaneously or at different times as needed. Therefore, it's possible that when the terminal device initiates a session #1 establishment request, two-factor authentication might be in progress.
[0247] For example, after the terminal device initiates a session establishment request for session #1 and the SMF determines that no authentication result exists, it can initiate a secondary authentication process for session #1. Alternatively, it can determine whether secondary authentication is currently in progress. Or, before determining whether an authentication result exists, the SMF may have already determined whether secondary authentication is currently in progress. If the SMF determines that secondary authentication is in progress, such as for session #2, then session #1 is suspended.
[0248] Based on the authentication and authorization result of session #2, SMF determines whether to continue establishing session #1 or refuse to establish session #1.
[0249] In one possible scenario, the authentication and authorization result indicates that the secondary authentication for session #2 was successful. This result may also include authentication and authorization information. In this case, the SMF determines, based on the authentication and authorization result, to continue establishing session #1 without requiring further secondary authentication (i.e., skipping the secondary authentication process), and continues establishing session #1 based on the authentication and authorization information.
[0250] Another possible scenario is that the authentication and authorization result indicates that the secondary authentication for session #2 failed. In this case, the SMF can determine to refuse the establishment of session #1 based on the authentication and authorization result, that is, terminate the establishment of session #1; or, the SMF can also determine whether to terminate the establishment of session #1 based on the reason for the authentication and authorization failure.
[0251] Optionally, the SMF can determine whether the secondary authentication of session #2 was successful or failed based on feedback from the authentication server of the data network.
[0252] For example, the SMF can determine subsequent processing based on whether it receives feedback from the data network's authentication server, such as the authentication result of session #2, after a preset time period. This preset time period can be a predefined duration, such as one predefined by the protocol; or it can be a duration determined based on historical communication data.
[0253] For example, this can be achieved using a timer. For instance, after SMF suspends session #1, a timer is activated for a preset duration. If no authentication result for session #2 is received before the timer expires, the secondary authentication for session #2 is deemed a failure, and the establishment of session #1 is terminated.
[0254] One possible implementation: SMF can determine that a second authentication is in progress based on indication information #2.
[0255] It should be understood that, for the sake of distinction and without loss of generality, in the embodiments of this application, indication information #2 represents information used to indicate that secondary authentication is in progress.
[0256] For example, the instruction message #2 is from the terminal device.
[0257] The terminal device sends indication information #2 to the SMF so that the SMF can suspend session #1 based on indication information #2. This indication information #2 can be sent to the SMF via separate signaling or included in the session establishment request message; there is no limitation on which method is used.
[0258] For example, before sending a session establishment request message, the terminal device can first determine that a session (let's call it session #2) is currently undergoing a secondary authentication process on the same data network (i.e., data network #1). Therefore, the terminal device sends instruction information #2 to the SMF, causing the SMF to suspend session #1. In this case, the SMF does not need to determine whether an authentication result exists; instead, based on the terminal device's instruction, it determines that a secondary authentication process is unnecessary.
[0259] For example, a terminal device may initiate two sessions simultaneously (session #1 and session #3). The session establishment request for session #1 includes indication information #2. When the SMF receives indication information #2, it can skip the secondary authentication process directly based on this information and suspend session #1. In this case, neither the SMF nor the other SMF has yet received the establishment request for the other session (i.e., session #3), or they have both received the request simultaneously. However, the SMF can use the indication information to skip the secondary authentication process, thus avoiding duplicate secondary authentication.
[0260] For example, after the SMF determines that there is no authentication result and decides to initiate a secondary authentication process for session #1, during the secondary authentication process, the terminal device sends instruction information #2 to the SMF so that the SMF can suspend session #1 according to instruction information #2.
[0261] Another example indicates that message #2 comes from the authentication server of data network #1.
[0262] The authentication server of data network #1 sends indication information #2 to the SMF so that the SMF can determine that secondary authentication is in progress and suspend session #1.
[0263] During the session establishment process, the authentication server of data network #1 determines whether the terminal device is being authenticated.
[0264] It should be understood that the above-mentioned SMF's determination that secondary authentication is in progress based on instruction information #2 is merely an illustrative example and is not intended to limit the scope of the determination. For example, the SMF may also determine on its own whether secondary authentication is in progress.
[0265] Optionally, in aspect two, the SMF can also determine whether to continue the session #1 establishment process based on the result of the ongoing secondary authentication, according to indication information #4. It should be understood that, for distinction and without loss of generality, in the embodiments of this application, indication information #4 represents information used to determine whether to continue the session #1 establishment process based on the result of the ongoing secondary authentication. Specifically, please refer to the following... Figure 8 The description in the text.
[0266] The solutions described in Aspect 1 and Aspect 2 can be used individually or in combination. For example, the SMF determines whether an authentication result exists based on the solution described in Aspect 1. If no authentication result exists, it then determines whether secondary authentication is in progress based on the solution described in Aspect 2. Alternatively, the SMF can first determine whether secondary authentication is in progress based on the solution described in Aspect 2, and if it is determined that secondary authentication is in progress, it can directly suspend the session.
[0267] The following section, in conjunction with aspect three, introduces a scheme for storing authentication and authorization results and / or authentication and authorization information.
[0268] Part 3: SMF determines whether to store the authentication result. Authentication results may include, for example, authentication authorization results (such as authentication success or failure) and / or authentication authorization information.
[0269] Implementation method 1: SMF can determine whether to store the authentication result based on instruction information #3.
[0270] It should be understood that, for the sake of distinction and without loss of generality, in the embodiments of this application, indication information #3 represents information used to determine whether to store the authentication result.
[0271] For example, if indication #3 indicates that the authentication result can be reused, or if indication #3 indicates that the SMF should store the authentication result, the SMF determines to store the authentication authorization information based on indication #3. If indication #3 indicates that the authentication result cannot be reused, or if indication #3 indicates that the SMF should not store the authentication result, the SMF determines not to store the authentication authorization information based on indication #3.
[0272] For example, the instruction message #3 indicates that it comes from the terminal device.
[0273] The terminal device sends an indication message #3 to the SMF so that the SMF can determine whether to store the authentication result based on the indication message #3. This indication message #3 can be sent to the SMF via separate signaling or included in the session establishment request message; there is no limitation on this.
[0274] Another example indicates that message #3 comes from the authentication server of data network #1.
[0275] The authentication server of data network #1 sends indication information #3 to the SMF so that the SMF can determine whether to store the authentication result based on the indication information #3.
[0276] Implementation Method 2: SMF can determine whether to store authentication results based on session attributes and / or local policies.
[0277] Local policies can represent predefined requirements, such as pre-specifying the storage of authentication results or pre-specifying the non-storage of authentication results.
[0278] Session attributes may include, but are not limited to: session type (e.g., IP, Ethernet, or unstructured), session and service continuity mode, user plane security management information, multi-access PDU connectivity service, and high reliability type. For example, for multi-access PDU connectivity service, SMF stores authentication results.
[0279] Selectively storing authentication results can improve resource and space utilization. It should be understood that the above is merely illustrative and not intended to be limiting. For example, it can be pre-defined, such as in a protocol definition, that the authentication results of secondary authentication be stored for a certain duration.
[0280] Optionally, when determining the storage duration of authentication results, the SMF can store them for a certain period, such as a storage duration or validity period. After the storage period expires, the authentication results can be deleted, thus ensuring higher security. The storage duration can be predefined or provided by the authentication network element of the data network; there is no limitation on this.
[0281] The solutions described in each of the above aspects can be used individually or in combination. For example, SMF determines whether an authentication result exists based on the solution described in aspect one. If no authentication result exists, it then determines that secondary authentication is in progress based on the solution described in aspect two. Furthermore, it can determine whether to store the authentication result based on the solution described in aspect three.
[0282] The preceding text briefly introduced the embodiments of this application from three aspects. The following text takes an example of a data network authentication server using DN-AAA and a PDU session, combined with... Figures 7 to 10The possible complete process is shown, and several specific embodiments applicable to this application are described.
[0283] Figure 7 (1) and (2) show schematic interactive diagrams of a method 700 applicable to an embodiment of this application. Method 700 mainly introduces the above-described scheme for SMF to determine whether an authentication result exists based on authorization information.
[0284] Method 700 may include the following steps.
[0285] 701, The terminal device initiates a PDU session establishment request to the AMF.
[0286] Terminal devices can send NAS messages to the AMF via the access network (AN or RAN). These NAS messages contain PDU session establishment requests. For example, a NAS message may contain Single Network Slice Selection Assistance Information (S-NSSAI) and session management (SM) (N1SM) information, with the N1SM information containing the session establishment request. By initiating a PDU session through the terminal device, PDU connection services can be implemented, enabling the exchange of PDU data packets between the terminal device and the DN. Once a PDU session is established, a data transmission channel between the terminal device and the DN is established.
[0287] For example, the NAS message may also carry a DNN, which is used to indicate the DN that the terminal device wants to connect to.
[0288] 702, AMF sends a PDU session establishment request to SMF.
[0289] For example, the AMF can send N to the SMF. smf Interface PDU Session Establishment Session Management Context Request (N smf The message contains a PDU session establishment request (_PDUSession_CreateSMContext Request). Optionally, the message may also contain a DNN to indicate the DN that the terminal device wants to access.
[0290] It should be understood that N smf The _PDUSession_CreateSMContext Request message is merely illustrative and not intended to be limiting. As long as the AMF can send a PDU session establishment request to the SMF, this request can be carried in any message.
[0291] After receiving a PDU session establishment request, the SMF can first obtain the session management subscription of the terminal device. For example, it can obtain it locally or from the UDM. For ease of explanation, Figure 7 Only the case obtained from UDM is shown. It should be understood that any scheme that enables SMF to obtain the session management subscription of the terminal device is applicable to the embodiments of this application.
[0292] 703, SMF requests session management subscription information for the terminal device from UDM.
[0293] For example, SMF can send N to UDM udm Interface session management contract acquisition (N) udm The _SDM_Get message requests session management subscription information from the terminal device.
[0294] It should be understood that N udm The _SDM_Get message is merely illustrative and is not intended to be limiting. As long as the SMF can request session management subscription information from the UDM, this request can be carried in any message.
[0295] 704, UDM sends session management subscription information of the terminal device to SMF.
[0296] For example, UDM can send N to SMF udm Interface session management, signing up, and receiving responses (N) udm The _SDM_Getresponse message contains session management subscription information for the terminal device.
[0297] It should be understood that N udm The _SDM_Get response message is merely illustrative and not intended to be limiting. As long as the UDM can send the terminal device's session management subscription information to the SMF, this session management subscription information can be carried in any message.
[0298] After obtaining the session management subscription information of the terminal device, the SMF can determine whether the PDU session requires secondary authentication and authorization. Let's assume the SMF determines that the PDU session requires secondary authentication and authorization.
[0299] 705, SMF has determined that the authentication method is two-factor authentication.
[0300] In other words, the SMF determines that the PDU session requires secondary authentication. This means the SMF determines that the terminal device and the DN require secondary authentication. Before initiating the secondary authentication process, the SMF can determine whether the terminal device has already performed secondary authentication with the DN (i.e., whether an authentication result exists), thus determining whether to initiate secondary authentication.
[0301] 706, SMF determines whether to initiate a secondary authentication process.
[0302] Optionally, steps 705 and 706 can also be combined, meaning that determining whether to initiate a two-factor authentication process and determining whether to initiate a two-factor authentication process are the same step. Alternatively, it can be understood that if the authentication method is two-factor authentication, a default step is to determine whether to initiate a two-factor authentication process.
[0303] For example, based on implementation method 1 described in aspect 600, it can be determined whether to initiate a secondary authentication process. Two schemes are briefly introduced below.
[0304] Option 1: The SMF determines whether to initiate a secondary authentication process based on the UE context information.
[0305] If the SMF has the UE's context, the SMF can determine whether to initiate a secondary authentication process based on the UE's context. If the SMF determines that secondary authentication is required based on the UE's context, then it will proceed. Figure 7 Step 706A in (1). If the SMF determines, based on the UE context, to skip the secondary authentication process (or not initiate the secondary authentication process), then execute... Figure 7 (2) Step 706B.
[0306] Specifically, the SMF can determine whether to perform secondary authentication based on whether the UE's context contains: authentication and authorization information corresponding to the DNN, or authentication and authorization information of the DN indicated by the DNN.
[0307] The authentication and authorization information may include a Data Name Node (DNN) used to identify the Domain Node (DN). The DNN is compared with the DNN received from the AMF to determine if they belong to the same DN. The authentication and authorization information may also include PDU session management and control information. Optionally, the authentication and authorization information may also include, but is not limited to, one or more of the following: DN-Specific ID, DN-AAA ID, validity information, index of the DN authorization text, Aggregated Maximum Bit Rate (AMBR) of the DN-authorized session, allowed MAC addresses(s), allowed Virtual Local Area Network (VIDs) identifiers (VIDs), and an indication to report PDU session information. The indication to report PDU session information is used to indicate relevant information for reporting PDU sessions, such as the address information of the PDU session.
[0308] When the DNN contained in the authentication authorization information is the same as the DNN received from the AMF, it indicates that they are the same DN, meaning no secondary authentication is required. When the DNN contained in the authentication authorization information is different from the DNN received from the AMF, it can be determined whether the DNN contained in the authentication authorization information and the DNN received from the AMF are equivalent DNNs, i.e., whether they indicate the same DN. An equivalent DNN is one that identifies the same DN.
[0309] For example, multiple DNNs (or a list of DNNs) (i.e., equivalent DNNs) can be pre-configured to indicate the same DN. For instance, the UDM may include these multiple DNNs in the session management subscription information of the terminal device sent to the SMF. Alternatively, the SMF may obtain the DNN from locally stored authentication and authorization information or from the UDM.
[0310] For example, if the DNN received from the AMF is DNN1, and the authentication and authorization information contains multiple DNNs (i.e., equivalent DNNs) including {DNN1, DNN2, DNN3}, then it means that the authenticated and authorized DN is the same DN as the DN requested for access by the terminal device; or in other words, the terminal device has already been authenticated with the requested DN, and a secondary authentication process is not required. In this case, the SMF can execute... Figure 7 (2) Step 706B.
[0311] For example, if the DNN received from the AMF is DNN5, and the authentication and authorization information contains multiple DNNs (i.e., equivalent DNNs) including {DNN1, DNN2, DNN3}, then this indicates that the authenticated and authorized DN is different from the DN requested by the terminal device; or in other words, the terminal device has not been authenticated with the requested DN and a secondary authentication process is required. In this case, the SMF can execute... Figure 7 Step 706A in (1).
[0312] Based on Scheme 1 above, SMF can determine whether to initiate a secondary authentication process based on the UE context stored locally, which is a simple and easy-to-implement solution.
[0313] Option 2: SMF determines whether to initiate a secondary authentication process based on the obtained authentication and authorization information.
[0314] Optionally, if the SMF does not have the UE's context, the SMF can request the terminal device's authentication and authorization information from the UDM, i.e., the SMF can execute steps 707 and 708. The SMF can request the terminal device's authentication and authorization information from the UDM, or historical secondary authentication and authorization information, i.e., information related to the terminal device's previous secondary authentication and authorization. Thus, the SMF can determine whether to initiate a secondary authentication process based on the obtained authentication and authorization information.
[0315] 707, SMF requests authentication and authorization information for the terminal device from UDM.
[0316] For example, SMF can send N to UDM udm The _UE_Get message requests authentication and authorization information from the terminal device. Optionally, this N... udm The _UE_Get message can also contain DNN information.
[0317] It should be understood that N udm The _UE_Get message is merely an example and is not intended to be limiting.
[0318] Optionally, steps 707 and 703 can also be combined, that is, when the SMF requests the UE's session management subscription information, it can simultaneously request the UE's authentication and authorization information.
[0319] 708. UDM sends the terminal device's authentication and authorization information to SMF.
[0320] Optionally, steps 708 and 704 can also be combined, that is, when the UDM sends the UE's session management subscription information, it can simultaneously send the UE's authentication and authorization information.
[0321] In one scenario, the UDM stores the authentication and authorization information of the terminal device. For example, the UDM can send N to the SMF. udm The _UE_Getresponse message contains the authentication and authorization information of the terminal device. Optionally, the UDM contains DNN information equivalent to the DNN in the authentication and authorization information.
[0322] If the SMF's request message to the UDM for authentication and authorization information of the terminal device includes DNN information, then the authentication and authorization information of the UE obtained by the SMF is the authentication and authorization information of the data network corresponding to that DNN. The UDM can configure the DNN list information for the DN, meaning that multiple DNNs (i.e., equivalent DNNs) can indicate the same DN. Optionally, the authentication and authorization information sent by the UDM to the SMF carries one or more DNNs equivalent to the DNN.
[0323] Based on the authentication and authorization information in the response message, the SMF determines whether to initiate a secondary authentication process. If the SMF determines that secondary authentication is required based on the authentication and authorization information in the response message, then it executes the secondary authentication. Figure 7 (1) Step 706A. If the SMF determines to skip the secondary authentication process based on the authentication and authorization information in the response message, then execute... Figure 7 (2) Step 706B. For the content of the authentication and authorization information and the method of SMF judgment, please refer to the description in Scheme 1, which will not be repeated here.
[0324] In another scenario, the UDM does not store the authentication and authorization information of the terminal device. For example, the UDM can send N to the SMF. udm The _UE_Get response message does not contain authentication and authorization information for the terminal device. Alternatively, the UDM may not send a message to the SMF. If the SMF does not receive a response from the UDM (e.g., after a preset time period), it will by default not have authentication and authorization information for the terminal device. In this case, the SMF can determine to initiate a secondary authentication process, i.e., execute step 706A.
[0325] It should be understood that steps 707 and 708 are merely illustrative examples. Optionally, the SMF may also store the authentication and authorization information locally. In this case, the SMF may not need to request the authentication and authorization information from the UDM, i.e., steps 707 and 708 may not need to be executed.
[0326] The steps are described below. Figure 7 (1) 706A and Figure 7 (2) Step 706B.
[0327] Step 706A: Perform the two-factor authentication process. For example... Figure 7 As shown in (1), after the SMF determines to initiate the secondary authentication process, method 700 may include steps 706A1 to 706A7.
[0328] 706A1, SMF has determined to initiate a secondary authentication process.
[0329] It's understandable that SMF triggers the secondary authentication process.
[0330] 706A2, secondary authentication and authorization between the terminal device and DN-AAA.
[0331] DN-AAA authenticates and / or authorizes terminal devices. The terminal device and DN-AAA can exchange EAP messages once or multiple times to complete DN-AAA authentication of the terminal device. The process of secondary authentication between the terminal device and DN-AAA can refer to existing secondary authentication procedures, such as the descriptions on sections 206 to 212 above, and is not limited thereto.
[0332] If DN-AAA successfully authenticates the terminal device, DN-AAA can send an authentication success message to SMF.
[0333] 706A3, DN-AAA sends an authentication success message to SMF.
[0334] The successful authentication message, or authentication result, indicates that secondary authentication for another PDU session has been successful. The successful authentication message may include authentication authorization information. Optionally, the successful authentication message may include indication information #3, which indicates whether the authentication result can be reused, or whether the SMF needs to store the authentication result.
[0335] 706A4, SMF storage certification and authorization information.
[0336] As an example, SMF determines whether to store authentication and authorization information based on instruction information #3.
[0337] If instruction #3 indicates that the authentication result can be reused, or if instruction #3 indicates that the SMF should store the authentication result, the SMF determines to store the authentication authorization information based on instruction #3. If instruction #3 indicates that the authentication result cannot be reused, or if instruction #3 indicates that the SMF should not store the authentication result, the SMF determines not to store the authentication authorization information based on instruction #3.
[0338] In another example, SMF determines whether to store authentication and authorization information based on local policies or PDU session attributes.
[0339] Local policies can represent predefined requirements, such as pre-specifying the storage of authentication and authorization information or pre-specifying the non-storage of authentication and authorization information.
[0340] PDU session attributes may include, but are not limited to: PDU session type (e.g., IP, Ethernet, or unstructured), session and service continuity mode, user plane security management information, multi-access PDU connectivity service, and high reliability type. For example, for multi-access PDU connectivity service, SMF stores authentication and authorization information.
[0341] In another example, the SMF determines whether to store authentication and authorization information based on whether it receives instruction message #3.
[0342] If the SMF receives instruction message #3 from DN-AAA indicating that the authentication result can be reused or that the authentication result should be stored, the SMF determines to store the authentication authorization information; if the SMF does not receive instruction message #3 from DN-AAA, the SMF determines not to store the authentication authorization information.
[0343] It should be understood that the above examples are merely illustrative and this application is not limited thereto. For example, SMF can directly store authentication and authorization information by default.
[0344] 706A5, SMF sends authentication and authorization information to UDM.
[0345] For example, SMF can send N to UDM udm Interface Session Management Subscription Update (N) udm The message (_SDM_Update) includes authentication and authorization information for secondary authentication. This information may include, but is not limited to: DN-SpecificId, DNN, DN-AAA Id, expiration information, index of the DN authorization text, AMBR of the DN-authorized session, allowed MAC addresses(s), allowed VID(s), and indication of reported PDU session information.
[0346] It should be understood that N udm The _SDM_Update message is merely illustrative and is not intended to be limiting. As long as the SMF can send authentication and authorization information to the UDM, this information can be carried in any message.
[0347] 706A6, UDM sends a response message to SMF.
[0348] The UDM sends a response message to the SMF regarding authentication and authorization information. For example, the SMF receives N from the UDM. udm _SDM_Update response(N udm The message is _SDM_Updateresponse.
[0349] 706A7, SMF continues the PDU session establishment process.
[0350] After DN-AAA authentication of the terminal device is completed, the SMF can continue to initiate other processes for establishing a PDU session, such as including but not limited to: the SMF sending an N4 interface session establishment / modification request to the UPF, and the UPF sending an N4 interface session establishment / modification response back to the SMF. The SMF can also send a PDU session establishment success message to the terminal device through the AMF.
[0351] It should be understood that the above is only a simple illustrative example. For specific secondary authentication and authorization processes, existing solutions can be referred to, and the embodiments in this application are not limited.
[0352] Step 706B: Do not perform the two-factor authentication process. For example... Figure 7 As shown in (2), if the SMF determines to skip the secondary authentication process, method 700 may include steps 706B1 to 706B6.
[0353] 706B1, SMF has determined to skip the second authentication.
[0354] For example, in this case, it is not necessary to execute Figure 7 Step 706A2 in (1).
[0355] 706B2, SMF confirms the address of the PDU session of the terminal device.
[0356] The SMF executes the PDU session establishment procedure based on the obtained authentication and authorization information. This authentication and authorization information may be obtained by the SMF from the UE's context, obtained by the SMF from the UDM, or stored locally by the SMF. Please refer to the description above for details.
[0357] If the SMF receives authorization information for PDU session control, this information may include, but is not limited to: an index of the DN authorization text, the AMBR of the DN-authorized session, allowed MAC addresses(s), allowed VIDs(s), and an indication to report PDU session information. The SMF uses this authorization information to execute the PDU session establishment process. For example, the SMF can send the index of the DN authorization text and the AMBR of the DN-authorized session to the PCF, and determine the address of the PDU session based on the allowed MAC addresses(s) and allowed VIDs(s).
[0358] 706B3, SMF determines the target DN-AAA based on the obtained DNN or certification authorization information.
[0359] Taking the SMF's determination of the target DN-AAA based on authentication and authorization information as an example, one possible implementation is to store the DN-AAA address in the authentication result, so that the DN-AAA can be determined based on the authentication result; another possible implementation is to include the DN-Specific ID in the authentication result, and determine the DN-AAA address based on the DN-Specific ID.
[0360] It should be understood that any method that enables the SMF to determine the target DN-AAA is applicable to the embodiments of this application.
[0361] 706B4, SMF reports the address information of the PDU session to the target DN-AAA.
[0362] The address information of a PDU session may include, but is not limited to, IP address, MAC address, or VIDs.
[0363] As an example, the SMF can report the address information of a PDU session based on the instructions from DN-AAA. For instance, the SMF can determine which address information of the PDU session to notify DN-AAA based on the instruction to report PDU session information in the authentication and authorization information.
[0364] In another example, the SMF can determine the address information to be notified to the DN-AAA PDU session based on local configuration (such as the requirement to notify the address information of the PDU session).
[0365] Optionally, the SMF may also carry the terminal device's Generic Public Subscription Identifier (GPSI).
[0366] 706B5, DN-AAA stores information about the new SMF.
[0367] DN-AAA can determine the storage of new SMF information, that is, maintain the session with SMF for subsequent interactions between DN-AAA and SMF.
[0368] 706B6, SMF continues the PDU session establishment process.
[0369] The SMF continues to execute the PDU session establishment process, which may include, but is not limited to: the SMF sending an N4 interface session establishment / modification request to the UPF, and the UPF sending an N4 interface session establishment / modification response back to the SMF.
[0370] It should be understood that the sequence number of each step does not imply the order of execution; the execution order of each process should be determined by its function and internal logic. For example, step 706B4 can also occur after the PDU session is established, i.e., after step 706B6. Furthermore, steps 706 and 705 can be combined, i.e., determining the authentication method as two-factor authentication and deciding whether to initiate a two-factor authentication process are the same step.
[0371] The above text combined Figure 7 The method 700 described herein presents a specific embodiment. Through this embodiment, during the PDU session establishment process, the SMF can determine whether to initiate a secondary authentication process based on the UE context, authentication authorization information obtained from the UDM, or locally stored authentication authorization information. The authentication authorization information also includes PDU session management and control related information, so that when skipping the secondary authentication process, the PDU session can be established directly based on this authentication authorization information. Furthermore, the authentication authorization information may also include multiple DNN information (i.e., equivalent DNNs) used to identify the same DN, thereby ensuring that even when using different DNNs to identify the DN, the secondary authentication process can be avoided from being repeatedly executed. Through this embodiment, it can be ensured that even when using different DNNs to access the DN, the SMF can avoid repeatedly executing the secondary authentication process as much as possible. In addition, the stored authorization information is enhanced, thereby ensuring that the control information of the PDU session can also be used.
[0372] Figure 8A schematic interactive diagram of method 800 applicable to another embodiment of this application is shown. Method 800 mainly introduces the above-described scheme for secondary authentication in progress. In method 800, after the SMF determines to initiate the secondary authentication process based on whether an authentication result exists, the DN authentication server can instruct the SMF to suspend the session.
[0373] Method 800 may include the following steps.
[0374] 801, The terminal device initiates a PDU session establishment request to the AMF.
[0375] For example, the terminal device sends a NAS message to the AMF, which may also carry a DNN, indicating the DN that the terminal device wants to connect to.
[0376] It should be understood that step 801 is similar in process to step 701 in method 700 above. Since step 701 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0377] Unlike step 701, in step 801, the terminal device can also send the authentication and authorization information corresponding to the DN, such as including the authentication and authorization information corresponding to the DN in the PDU session establishment request, or sending the authentication and authorization information corresponding to the DN to the AMF separately.
[0378] 802, AMF sends a PDU session establishment request to SMF.
[0379] It should be understood that step 802 is similar in process to step 702 in method 700 above. Since step 702 has already been described in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0380] 803, SMF requests session management subscription information for the terminal device from UDM.
[0381] It should be understood that step 803 is similar in process to step 703 in method 700 above. Since step 703 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0382] 804, UDM sends session management subscription information of the terminal device to SMF.
[0383] It should be understood that step 804 is similar in process to step 704 in method 700 above. Since step 704 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0384] 805, SMF has determined that the authentication method is two-factor authentication.
[0385] It should be understood that step 805 is similar in process to step 705 in method 700 above. Since step 705 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0386] 806, SMF can determine whether to initiate a two-factor authentication process.
[0387] For example, it may include steps 807 and 808.
[0388] 807. SMF requests authentication and authorization information for the terminal device from UDM.
[0389] It should be understood that step 807 is similar in process to step 707 in method 700 above. Since step 707 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0390] 808, UDM sends the terminal device's authentication and authorization information to SMF.
[0391] It should be understood that step 808 is similar in process to step 708 in method 700 above. Since step 708 has already been described in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0392] It should be understood that step 806 is similar in process to step 706 in method 700 above. Since step 706 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0393] Assuming that the SMF determines to initiate a secondary authentication process based on the assessment,...
[0394] 809. SMF confirms initiation of secondary authentication process.
[0395] In method 800, after the SMF determines whether a secondary authentication process has been initiated based on whether there is an authentication result, the SMF can also determine whether there is an ongoing secondary authentication process.
[0396] For example, in step 806, the SMF can further determine whether the local storage contains a DN corresponding to the DNN (i.e., the DNN in step 801) with an ongoing secondary authentication process. If so, the SMF skips the secondary authentication process and stores indication information #4 locally, which indicates that it is necessary to determine whether to continue the PDU session process based on the result of the ongoing secondary authentication. If not, it determines to initiate a secondary authentication process. Specifically, the following description is based on the embodiment shown in method 1000.
[0397] 810, SMF sends an authentication and authorization request message to DN-AAA.
[0398] SMF sends an authentication and authorization request message to DN-AAA, which contains information for authentication and authorization (such as EAP information).
[0399] 811, DN-AAA confirms that the authentication is performed on the same terminal device.
[0400] Based on the request message sent by SMF, DN-AAA determines that two-factor authentication is being performed for the same DN (DN-specific ID) on the same terminal device. DN-AAA can store the SMF identifier and indication information #5 locally. Indication information #5 is used to indicate that the SMF needs to be notified of the two-factor authentication authorization result.
[0401] 812, DN-AAA sends an authentication and authorization response message to SMF.
[0402] The response message sent by DN-AAA to SMF may include a suspension instruction, which instructs SMF to suspend the PDU session. Suspension, or pause, indicates a temporary halt to establishing a PDU session or a temporary halt to the secondary authentication process.
[0403] 813, SMF suspends PDU session.
[0404] SMF suspends the PDU session, meaning SMF does not continue the PDU session establishment process.
[0405] The SMF can determine subsequent processing based on feedback from DN-AAA, such as the authentication result of another PDU session. For example, after successful secondary authentication of another PDU session, the SMF can continue the PDU session establishment process without repeating the secondary authentication process; for instance, it can execute step 706B in method 700. Alternatively, if secondary authentication of another PDU session fails, the SMF can terminate the PDU session establishment. Or, if authentication and authorization fail, the SMF can determine whether to terminate the PDU session establishment based on the reason for the authentication failure.
[0406] For example, the SMF can determine subsequent processing based on whether it receives feedback from DN-AAA after a preset time period, such as the secondary authentication result of another PDU session (i.e., the secondary authentication result of the PDU session that just underwent secondary authentication). This preset time period can be a pre-defined duration, such as one predefined by the protocol; or it can be a duration determined based on historical communication data.
[0407] For example, this can be achieved using a timer. For instance, after the SMF suspends a PDU session, a timer can be activated for a preset duration. Similarly, after receiving a DN-AAA authentication authorization response message, the SMF can activate a timer for a preset duration. If no secondary authentication result message (i.e., the secondary authentication result of the PDU session that just underwent secondary authentication) is received from another PDU session before the timer expires, the secondary authentication of the other PDU session is deemed to have failed, and the establishment of the PDU session is terminated.
[0408] 814, DN-AAA certification completed, confirm and notify SMF.
[0409] DN-AAA can determine whether to notify SMF based on the locally stored instruction information #5, or DN-AAA can notify SMF by default.
[0410] If the secondary authentication authorization is successful, DN-AAA sends an authentication result indicating the success of the secondary authentication for another PDU session (i.e., whether the secondary authentication for the other PDU session that just underwent secondary authentication was successful or failed) and authentication authorization information to the SMF after the secondary authentication authorization fails. If the secondary authentication authorization fails, DN-AAA sends an indication to the SMF that the secondary authentication for the other PDU session failed (i.e., the secondary authentication for the other PDU session that just underwent secondary authentication failed). Alternatively, if the secondary authentication authorization fails, DN-AAA does not send the secondary authentication result for the other PDU session, and the SMF defaults to authentication authorization failure if it does not receive an authentication result after a preset time.
[0411] 815, DN-AAA sends the authentication and authorization result to SMF.
[0412] The authentication and authorization result includes: the authentication result of a successful secondary authentication of another PDU session (i.e., the secondary authentication of the PDU session that just underwent secondary authentication was successful) and authentication and authorization information; or, the authentication and authorization result includes: the authentication result of a failed secondary authentication of another PDU session.
[0413] 816. SMF processes suspended PDU sessions based on authentication and authorization results.
[0414] For example, the SMF determines whether to continue or reject the PDU session establishment based on the authentication and authorization results.
[0415] In one possible scenario, the authentication and authorization result includes: the authentication result of a successful secondary authentication of another PDU session (i.e., the secondary authentication of the PDU session that just underwent secondary authentication was successful) and authentication and authorization information. In this case, the SMF determines to continue establishing the PDU session based on the authentication result, without needing to perform the secondary authentication process again, and continues to establish the PDU session based on the authentication and authorization information.
[0416] Another possible scenario is that the authentication and authorization result includes an authentication failure for a second authentication attempt on another PDU session. In this case, the SMF can determine whether to refuse the establishment of the PDU session based on the authentication and authorization result, i.e., terminate the establishment of the PDU session. Alternatively, in this case, the SMF can also determine whether to refuse the establishment of the PDU session based on the reason for the authentication and authorization failure.
[0417] Optionally, if authentication and authorization are successful, the SMF can report the address information of the PDU session to the DN-AAA.
[0418] 817. SMF reports the address information of the PDU session to DN-AAA.
[0419] The address information of a PDU session may include, but is not limited to, IP address, MAC address, or VIDs.
[0420] As an example, the SMF can report the address information of a PDU session based on the instructions from DN-AAA. For instance, the SMF can determine which address information of the PDU session to notify DN-AAA based on the instruction to report PDU session information in the authentication and authorization information.
[0421] In another example, the SMF can determine the address information to be notified to the DN-AAA PDU session based on local configuration (such as the requirement to notify the address information of the PDU session).
[0422] In another example, the SMF can determine the address information to be notified to the DN-AAA PDU session based on the subscription information obtained from the UDM.
[0423] Optionally, the SMF can also carry the GPSI of the terminal device.
[0424] The above text combined Figure 8 The method 800 described herein introduces another specific embodiment. Through this embodiment, during the PDU session establishment process, the DN authentication server determines whether a secondary authentication process is in progress and stores indication information, enabling the secondary authentication process to be skipped and the authentication authorization result to be sent directly to the SMF. Therefore, the DN authentication server at the centralized control point can determine the reuse of the secondary authentication result, thereby avoiding the signaling overhead caused by repeatedly executing the secondary authentication process.
[0425] Figure 9 A schematic interactive diagram of method 900 applicable to another embodiment of this application is shown. Method 900 mainly introduces the above-described scheme for secondary authentication in progress. In method 900, after the SMF determines to initiate the secondary authentication process based on whether an authentication result exists, the terminal device can instruct the SMF to suspend the session.
[0426] Method 900 may include the following steps.
[0427] 901, The terminal device initiates a PDU session establishment request to the AMF.
[0428] It should be understood that step 901 is similar in process to step 701 in method 700 above. Since step 701 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0429] 902, AMF sends a PDU session establishment request to SMF.
[0430] It should be understood that step 902 is similar in process to step 702 in method 700 above. Since step 702 has already been described in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0431] 903, SMF requests session management subscription information for the terminal device from UDM.
[0432] It should be understood that step 903 is similar in process to step 703 in method 700 above. Since step 703 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0433] 904, UDM sends the terminal device's session management subscription information to SMF.
[0434] It should be understood that step 804 is similar in process to step 704 in method 700 above. Since step 704 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0435] 905, SMF determines that a PDU session requires secondary authentication and authorization.
[0436] It should be understood that step 905 is similar in process to step 705 in method 700 above. Since step 705 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0437] 906. SMF can determine whether to initiate a two-factor authentication process.
[0438] For example, it may include steps 907 and 908.
[0439] 907. SMF requests authentication and authorization information for the terminal device from UDM.
[0440] It should be understood that step 907 is similar in process to step 707 in method 700 above. Since step 707 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0441] 908, UDM sends the terminal device's authentication and authorization information to SMF.
[0442] It should be understood that step 908 is similar in process to step 708 in method 700 above. Since step 708 has already been described in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0443] It should be understood that step 906 is similar in process to step 906 in method 700 above. Since step 906 has already been described in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0444] Assuming that the SMF determines to initiate a secondary authentication process based on the assessment,...
[0445] 909, SMF confirms initiation of secondary authentication process.
[0446] 910. SMF sends an authentication message to AMF.
[0447] The SMF sends an authentication message to the terminal device so that the terminal device can perform authentication. Optionally, the SMF can send the authentication message to the terminal device through the AMF.
[0448] For example, the SMF can send N to the AMF. amf Interface N1N2 message transfer (N smf The message (_N1N2MessageTransfer) contains an authentication message.
[0449] 911, AMF sends an authentication message to the terminal device.
[0450] For example, the AMF can send a NAS session management (SM) transport message to the end device, which includes an authentication message.
[0451] After receiving the authentication message, the terminal device can determine whether it is performing secondary authentication. Let's assume the terminal device determines that it is performing secondary authentication.
[0452] 912, The terminal device is confirmed to be performing secondary authentication.
[0453] If the terminal device determines that it is performing secondary authentication for the same DN (or the same DN-specific ID), then the terminal device can send a suspension indication (i.e., indication information #2) to the SMF. The terminal device can send the suspension indication to the SMF through the AMF.
[0454] Optionally, the terminal device can also locally store indication information #5, indicating that it needs to notify the SMF of the secondary authentication authorization result (e.g., the terminal device sends indication information #1). Alternatively, it can be pre-defined that the terminal device needs to notify the SMF of the secondary authentication authorization result.
[0455] 913, the terminal device sends a hangup instruction to the AMF.
[0456] For example, an end device can send a NAS SM transport message to the AMF, which includes a suspension indication. The suspension indication is used to indicate that the SMF is performing a secondary authentication process.
[0457] 914, AMF sends a hangup instruction to SMF.
[0458] For example, the AMF can send N to the SMF. smf Interface PDU Session Update Session Management Context (N) smf The message `_PDUSession_UpdateSMContext` contains a suspension instruction. The suspension instruction is used to indicate that the SMF is performing a secondary authentication process.
[0459] 915, SMF suspends PDU session.
[0460] Upon receiving a suspension instruction, the SMF suspends the PDU session, meaning it does not continue the PDU session establishment process. Optionally, after receiving the suspension instruction, the SMF can also subscribe to authorization result notifications from the UDM. Based on this subscription, the UDM will notify the SMF when it receives a new authentication result. Alternatively, the SMF can also subscribe to authorization result notifications from the DN-AAA. Based on this subscription, the DN-AAA will notify the SMF when it receives a new authentication result.
[0461] The SMF can determine subsequent processing based on feedback from the terminal device, such as the authentication result of a successful secondary authentication for another PDU session or the authentication result of a failed secondary authentication for another PDU session. For example, after a successful secondary authentication for another PDU session, the SMF can continue the PDU session establishment process without repeating the secondary authentication process; for instance, it can execute step 706B in method 700. Conversely, if a secondary authentication for another PDU session fails, the SMF can terminate the establishment of the PDU session; or, based on the reason for the authentication failure, it can determine whether to terminate the establishment of the PDU session.
[0462] For example, the SMF can determine subsequent processing based on whether feedback is received from the terminal device after a preset time period, such as the authentication result of a secondary authentication for another PDU session. This preset time period can be a predefined duration, such as one predefined by the protocol; or it can be a duration determined based on historical communication data.
[0463] For example, this can be achieved using a timer. For instance, after the SMF suspends the PDU session, a timer can be activated for a preset duration. Alternatively, after receiving a suspension instruction from the AMF, the SMF can activate a timer for a preset duration. If no authentication result for the secondary authentication of another PDU session is received before the timer expires, the authentication authorization is deemed to have failed, and the establishment of the PDU session is terminated.
[0464] 916, the terminal device confirms the completion of the second authentication.
[0465] After the terminal device confirms that the secondary authentication is complete, it can send an authentication result notification to the SMF based on the locally stored instruction information #5 or according to pre-defined rules. For example, the terminal device can notify the SMF of the secondary authentication result, or it can notify the SMF to retrieve the secondary authentication result.
[0466] Terminal devices can send authentication result notification information to SMF through AMF.
[0467] 917, the terminal device sends an authentication result notification to the AMF.
[0468] For example, the terminal device can send a NAS SM transport message to the AMF, which contains authentication result notification information.
[0469] On September 18th, the AMF sent an authentication result notification to the SMF.
[0470] For example, the AMF can send N to the SMF. smfThe _PDUSession_UpdateSMContext message contains authentication result notification information, which indicates whether the secondary authentication of the session was successful or failed.
[0471] In one scenario, if the authentication result notification information is sent to the SMF regarding the secondary authentication result, the SMF can determine whether the authentication authorization was successful or failed based on this notification information.
[0472] In another scenario, if the authentication result notification informs the SMF to obtain a secondary authentication result, then the SMF can request the UDM to provide a secondary authentication authorization result based on the authentication result notification. In this case, method 900 may further include steps 919 to 921.
[0473] 919. Based on the authentication result notification information, SMF obtains authentication authorization information from UDM.
[0474] 920, SMF requests authentication and authorization information for the terminal device from UDM.
[0475] It should be understood that step 920 is similar in process to step 707 in method 700 above. Since step 707 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0476] It should also be understood that step 920 may not be performed. That is, UDM will notify SMF when it receives a new authentication result, based on the previous subscription authorization result notification from SMF.
[0477] 921, UDM sends the terminal device's authentication and authorization information to SMF.
[0478] It should be understood that step 921 is similar in process to step 708 in method 700 above. Since step 708 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0479] Based on the terminal device's notification or the terminal device's authentication and authorization information obtained from the UDM, the SMF can confirm the authentication and authorization result and determine whether to continue or reject the PDU session establishment based on the authentication and authorization result.
[0480] In one possible scenario, the authentication and authorization result includes: the authentication result of a successful secondary authentication of another PDU session (i.e., the secondary authentication of the PDU session that just underwent secondary authentication was successful) and authentication and authorization information. In this case, the SMF determines to continue establishing the PDU session based on the authentication and authorization result, without needing to perform the secondary authentication process again, and continues to establish the PDU session based on the authentication and authorization information.
[0481] Another possible scenario is that the authentication and authorization result includes an authentication failure for another PDU session. In this case, the SMF determines to reject the establishment of the PDU session based on the authentication and authorization result, i.e., terminates the establishment of the PDU session. Alternatively, in this case, the SMF may also determine whether to reject the establishment of the PDU session based on the reason for the authentication and authorization failure.
[0482] Optionally, upon successful authentication and authorization, the SMF can report the address information of the PDU session to the DN-AAA. The address information of the PDU session may include, but is not limited to, IP address, MAC address, or VIDs.
[0483] If authentication and authorization are successful, and the SMF determines that the address information of the PDU session needs to be reported to DN-AAA, then the SMF can determine the target DN authentication server based on the DN-specific ID.
[0484] 922, SMF identifies target DN-AAA.
[0485] SMF can determine the target DN-AAA based on the obtained DN-specific ID (DNN).
[0486] 923, SMF reports the address information of the PDU session to the target DN-AAA.
[0487] Optionally, the SMF can determine the address of the target DN-AAA based on the DN-specific ID, or the SMF can report the PDU session address to the DN-AAA based on the DN-AAA address in the authentication and authorization information.
[0488] 924, DN-AAA determines that new SMF information is stored.
[0489] If the SMF is a new SMF, then DN-AAA determines to store the SMF information.
[0490] One possible implementation is to determine whether to store SMF information based on whether the local machine has already established an association with SMF.
[0491] For example, if DN-AAA has already been associated with SMF, it indicates that the SMF is not new, so there is no need to store SMF information.
[0492] For example, if DN-AAA is not associated with SMF, it indicates that the SMF is new, so SMF information is stored.
[0493] The above text combined Figure 9The method 900 described herein introduces another specific embodiment. Through this embodiment, during the PDU session establishment process, the terminal device determines whether a secondary authentication process is in progress and stores indication information, enabling the authentication and authorization result to be sent directly to the SMF by skipping the secondary authentication process. Therefore, by having the terminal device indicate that secondary authentication is in progress, the signaling overhead caused by repeatedly executing the secondary authentication process can be avoided.
[0494] Figure 10 A schematic interactive diagram is shown for a method 1000 applicable to another embodiment of this application. Method 1000 mainly describes how a terminal device, when requesting to establish a session, instructs the SMF to suspend the session or whether a secondary authentication process needs to be initiated.
[0495] Method 1000 may include the following steps.
[0496] 1001, the terminal devices are identified as PDU sessions within the same DN.
[0497] It is understandable that before sending a PDU session establishment request, the terminal device can first determine that the PDU session to be established is the same as the DN, that is, the same as the DN of the previously established session or the DN of the session currently performing secondary authentication.
[0498] For example, the terminal device determines that the established PDU session is one of the redundant PDU sessions of the DN.
[0499] For example, the terminal device determines that it is using a PDU session with the same DN that is different from the previous DNN.
[0500] For example, the terminal device determines that there is a PDU session performing a secondary authentication process corresponding to the same DN.
[0501] 1002, The terminal device initiates a PDU session establishment request to the AMF.
[0502] It should be understood that step 1002 is similar in process to step 701 in method 700 above. Since step 701 has already been described in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0503] Unlike step 701, in step 1002, the terminal device may also send information (i.e., indication information #1) to determine whether to perform the secondary authentication process. This information may be included in the PDU session establishment request, or it may be sent separately to the AMF.
[0504] Optionally, the terminal device may send one or more of the following: DNN information, the PDU session ID of the associated PDU session, an indication that secondary authentication is being performed or that secondary authentication is not required (i.e., indication information #2).
[0505] As an example, if the terminal device determines that the established PDU session is one of the redundant PDU sessions of the DN, the terminal device can send: associated PDU session information, such as the PDU session ID of the associated PDU session.
[0506] In another example, if the terminal device determines that it is using a PDU session with the same DN that is different from the previous DNN, the terminal device can send: DNN information, that is, the DNN of the PDU session previously established with the DN.
[0507] In another example, if the terminal device determines that a PDU session corresponding to the same DN is performing a secondary authentication process, the terminal device can send either an indication that secondary authentication is being performed or an indication that secondary authentication is not required (i.e., indication information #2).
[0508] 1003, AMF sends a PDU session establishment request to SMF.
[0509] It should be understood that step 1003 is similar in process to step 702 in method 700 above. Since step 702 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0510] Unlike step 702, in step 1003, the AMF may also send information to the SMF to determine whether to perform a secondary authentication process. This information can be included in the PDU session establishment request, or it can be sent separately to the SMF.
[0511] 1004, SMF requests session management subscription information for the terminal device from UDM.
[0512] For example, SMF can send N to UDM udm The _SDM_Get message requests session management subscription information from the terminal device.
[0513] In one scenario, if the information used to determine whether to perform a secondary authentication process (i.e., indication information #1) includes indication information that secondary authentication is being performed (i.e., indication information #2), then the SMF sends N to the UDM. udm The _SDM_Get message may include instructions instructing the UDM to notify the SMF after receiving authentication and authorization information from the terminal device. In this case, method 1000 may include performing steps 1006 and 1007.
[0514] In another scenario, if the information used to determine whether to perform a secondary authentication process (i.e., indication information #1) includes DNN information, then the N sent by the SMF to the UDM... udm The _SDM_Get message may include instructions for the UDM to send the authentication and authorization information for the corresponding DNN. In this case, steps 1006 and 1007 are unnecessary.
[0515] In another scenario, if the information used to determine whether to perform a secondary authentication process (i.e., indication information #1) includes the PDU session ID of the associated PDU session, then the SMF sends N to the UDM. udm The _SDM_Get message may include instructions for the UDM to send the authentication and authorization information corresponding to the PDU session ID. In this case, steps 1009 and 1010 are unnecessary.
[0516] 1005, UDM sends the terminal device's session management subscription information to SMF.
[0517] For example, UDM can send N to SMF udm The _SDM_Get response message contains the session management subscription information of the terminal device.
[0518] After obtaining the session management subscription information of the terminal device, the SMF can determine whether the PDU session requires secondary authentication and authorization. Let's assume the SMF determines that the PDU session requires secondary authentication and authorization.
[0519] 1006, SMF determines that the authentication method is two-factor authentication. That is, SMF determines that the PDU session requires two-factor authentication authorization.
[0520] It should be understood that step 1006 is similar in process to step 705 in method 700 above. Since step 705 has already been explained in detail in method 700 above, it will not be repeated here for the sake of brevity.
[0521] 1007. SMF can determine whether to initiate a two-factor authentication process.
[0522] Scenario 1: The terminal device determines that a PDU session corresponding to the same DN is performing a secondary authentication process. The terminal device sends an indication message (i.e., indication message #2) to the SMF indicating that secondary authentication is being performed. Based on this indication, the SMF can determine to skip the secondary authentication.
[0523] Scenario 2: The terminal device determines that the established PDU session is one of the redundant PDU sessions of the DN. The terminal device sends the associated PDU session information (such as the PDU session ID of the associated PDU session) to the SMF. Based on this indication, the SMF can determine to skip the secondary authentication.
[0524] In scenario 1 or 2, the SMF can send a subscribe message (such as the Nudm_SDM_subscribe message) to the UDM, instructing the UDM to notify the SMF upon receiving authentication and authorization information from the terminal device. Alternatively, the SMF can subscribe to authorization result notifications from the UDM, which will then notify the SMF upon receiving a new authentication result. Alternatively, the SMF can also subscribe to authorization result notifications from the DN-AAA. Optionally, in this case, the SMF can directly send a request message to the DN-AAA or the UDM to request notification of authentication and authorization results (i.e., the authentication result of secondary authentication for another PDU session). If authentication and authorization are successful, the SMF determines whether to continue establishing the PDU session based on the authentication and authorization result; if authentication and authorization fail, the SMF determines whether to reject the PDU session establishment based on the authentication and authorization result, i.e., terminate the PDU session establishment, or determines whether to reject the PDU session establishment based on the reason for the authentication and authorization failure.
[0525] It should be understood that the above is merely an illustrative example. For instance, in scenario 1 or 2, the SMF can also check if there is any ongoing secondary authentication or authentication result locally. If not, the SMF subscribes to the result from the UDM or DN-AAA.
[0526] Scenario 3: If the terminal device determines that it is using a PDU session with the same DN but a different DNN than the previous one, the terminal device sends DNN information to the SMF, which is the DNN of the PDU session previously established with the DN. Based on this DNN information, the SMF can determine to skip the secondary authentication.
[0527] In scenario 3, the SMF can determine whether there is an authentication and authorization result corresponding to the DNN based on local information. If there is an authentication and authorization result corresponding to the DNN locally, it is reused; if there is no authentication and authorization result corresponding to the DNN locally, the SMF queries the UDM to see if there is an authentication and authorization result corresponding to the DNN. Optionally, when the SMF queries the UDM to see if there is an authentication and authorization result corresponding to the DNN, it can include the DNN information in the query request. In another scenario, if the information used to determine whether to perform the secondary authentication process (i.e., indication information #1) includes the PDU session ID of the associated PDU session, then the SMF can determine whether there is an authentication and authorization result corresponding to the PDU session ID based on local information. If there is an authentication and authorization result corresponding to the PDU session ID locally, it is reused; if there is no authentication and authorization result corresponding to the PDU session ID locally, the SMF queries the UDM to see if there is an authentication and authorization result corresponding to the PDU session ID. Optionally, when the SMF queries the UDM to see if there is an authentication and authorization result corresponding to the PDU session ID, it can include the PDU session ID in the query request.
[0528] The above three scenarios are merely illustrative. Through step 1007, the SMF can determine whether to initiate a secondary authentication process based on the terminal device's instructions. Alternatively, the SMF can also query locally or based on the UDM to determine whether to initiate a secondary authentication process.
[0529] 1008, SMF has decided to skip the secondary authentication process.
[0530] Taking case 1 or case 2 as an example, the SMF can send a subscription message to the UDM, that is, method 1000 can include step 1009.
[0531] At 10:09, SMF sends a subscription message to UDM.
[0532] In other words, the SMF subscribes to events from the UDM to notify the UDM to notify the SMF after receiving the authentication and authorization information from the terminal device.
[0533] It should be understood that, for ease of description, Figure 10 This example only illustrates the scenario where the SMF sends a subscription message to the UDM, and is not intended to limit the scope of the example. For instance, the SMF could also send a subscription message to DN-AAA.
[0534] 1010, UDM sends authentication and authorization information to SMF.
[0535] When the UDM receives the authentication and authorization information, it notifies the SMF. The SMF can then continue establishing the PDU session based on this authentication and authorization information.
[0536] 1011, SMF reports the address information of the PDU session to DN-AAA.
[0537] Optionally, the SMF can report the PDU session address to the DN-AAA.
[0538] Optionally, the SMF can also carry the GPSI of the terminal device.
[0539] 1012, DN-AAA determines that new SMF information is stored.
[0540] DN-AAA can store SMF and corresponding PDU session information.
[0541] It should be understood that step 1012 is similar in process to step 924 in method 900 above. Since step 924 has already been explained in detail in method 900 above, it will not be repeated here for the sake of brevity.
[0542] The above text combined Figure 10 The illustrated method 1000 introduces yet another specific embodiment. Through this embodiment, the terminal device sends indication information to the SMF, enabling the SMF to detect whether a secondary authentication is in progress or whether a PDU session using a different DNN has been established. Therefore, the SMF can identify PDU sessions using different DNNs for the same DN, and whether a secondary authentication process is in progress, thereby avoiding the signaling overhead caused by repeatedly executing the secondary authentication process.
[0543] The above text combined Figures 7 to 10 Several possible complete processes are described in detail. It should be understood that in the embodiments described above, each network element can execute some or all of the steps in each embodiment. These steps or operations are merely examples; other operations or variations of various operations can also be performed in the embodiments of this application. Furthermore, the steps can be executed in different orders as presented in the embodiments, and it is not necessary to execute all the operations in the embodiments of this application. Moreover, the sequence number of each step does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0544] It should be understood that in some of the above embodiments, the PDU session is used as an example for illustrative purposes, and is not intended to be limiting. Any session used for accessing the DN is applicable to the embodiments of this application.
[0545] It should also be understood that in some of the above embodiments, specific messages, such as N, are used. smf _PDUSession_UpdateSMContext Request message, N udm _SDM_Get message, N udm _SDM_Get response message, N udm _UE_Get message, Nudm _UE_Get response message, N udm _SDM_Update message, N udm The naming and type of messages such as _SDM_Updateresponse are not limited. Any message that can achieve the same function is applicable to the embodiments of this application.
[0546] Based on the above technical solution, the authentication and authorization process can be used to authenticate and authorize whether a terminal device can establish a session to access the data network. Specifically, during the session establishment process, the SMF can determine whether to initiate a secondary authentication process based on whether the data network has successfully authenticated and authorized the terminal device. This ensures that even when using different DNNs to identify the data network, the secondary authentication process can be avoided from being executed repeatedly. Through the embodiments of this application, it can be ensured that even when using different DNNs to access the data network, the SMF can avoid executing the secondary authentication process as much as possible.
[0547] Furthermore, based on the above technical solution, during session establishment, the DN authentication server or terminal device determines whether a secondary authentication process is in progress and stores indication information, enabling the secondary authentication process to be skipped and the authentication and authorization result to be sent directly to the SMF. Therefore, the reuse of the secondary authentication result can be determined by the centralized control point DN authentication server or terminal device, thereby avoiding the signaling overhead caused by repeatedly executing the secondary authentication process.
[0548] The various embodiments described herein can be independent solutions or combinations thereof based on their inherent logic, and all such solutions fall within the protection scope of this application.
[0549] It is understood that the methods and operations implemented by devices (such as SMF, terminal devices, DN authentication servers, etc.) in the above-described method embodiments can also be implemented by components (such as chips or circuits) that can be used in the devices.
[0550] The above, combined with Figures 6 to 10 The methods provided in the embodiments of this application are described in detail below. Figure 11 and Figure 12 The apparatus provided in the embodiments of this application is described in detail. It should be understood that the description of the apparatus embodiments corresponds to the description of the method embodiments. Therefore, for content not described in detail, please refer to the method embodiments above. For the sake of brevity, it will not be repeated here.
[0551] The above mainly describes the solution provided by the embodiments of this application from the perspective of interaction between various network elements. It is understood that each network element, such as a terminal device, SMF, or DN-AAA, includes corresponding hardware structures and / or software modules to perform the above functions. Those skilled in the art should recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0552] This application embodiment can divide each network element into functional modules according to the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the division of each functional module according to its own function as an example.
[0553] Figure 11 This is a schematic block diagram of an authentication and authorization device provided in an embodiment of this application. The device 1100 includes a transceiver unit 1110 and a processing unit 1120. The transceiver unit 1110 can implement corresponding communication functions, and the processing unit 1120 is used for data processing. The transceiver unit 1110 can also be referred to as a communication interface or a communication unit.
[0554] Optionally, the device 1100 may further include a storage unit, which can be used to store instructions and / or data, and the processing unit 1120 can read the instructions and / or data in the storage unit so that the communication device can implement the aforementioned method embodiments.
[0555] The device 1100 can be used to perform the actions performed by the terminal device in the above method embodiment. In this case, the device 1100 can be the terminal device or a component that can be configured on the terminal device. The transceiver unit 1110 is used to perform the transceiver-related operations on the terminal device side in the above method embodiment, and the processing unit 1120 is used to perform the processing-related operations on the terminal device side in the above method embodiment.
[0556] Alternatively, the device 1100 can be used to perform the actions performed by the SMF in the above method embodiments. In this case, the device 1100 can be the SMF or a component configurable in the SMF. The transceiver unit 1110 is used to perform transceiver-related operations on the SMF side in the above method embodiments, and the processing unit 1120 is used to perform processing-related operations on the SMF side in the above method embodiments.
[0557] Alternatively, the device 1100 can be used to perform the actions performed by the DN authentication server (or DN authentication network element) in the above method embodiment. In this case, the device 1100 can be the DN authentication server or a component configurable on the DN authentication server. The transceiver unit 1110 is used to perform the transceiver-related operations on the DN authentication server side in the above method embodiment, and the processing unit 1120 is used to perform the processing-related operations on the DN authentication server side in the above method embodiment.
[0558] As a design, the device 1100 is used to perform the above. Figure 6 The actions performed by SMF in the illustrated embodiment.
[0559] In one implementation, the transceiver unit 1110 is configured to: receive a session establishment request message from the terminal device, the session establishment request message being used to request the establishment of a session with the data network; the processing unit 1120 is configured to: determine whether there is an authentication result from the data network for the terminal device; and if there is an authentication result, skip the secondary authentication process for the session.
[0560] As an example, the authentication result includes authentication authorization information, which includes one or more of the following: one or more data network identifiers, identifiers of the authentication network elements of the data network, timeliness information, index of the data network authorization text, aggregate maximum bit rate of the data network authorized session, allowed media access control addresses, allowed virtual LANs, and information for indicating the reporting of session information.
[0561] As another example, the processing unit 1120 is used to: initiate a secondary authentication process for the session when it is determined that no authentication result exists, or suspend the session.
[0562] As another example, the processing unit 1120 is specifically used to: suspend a session according to the first indication information sent by the authentication network element of the terminal device or the data network, wherein the first indication information is used to instruct the data network to perform secondary authentication on another session of the terminal device.
[0563] As another example, the processing unit 1120 is also configured to: determine whether the data network performs secondary authentication on another session of the terminal device when no authentication result exists; suspend the session when the data network performs secondary authentication on another session of the terminal device; or initiate a secondary authentication process for the session when the data network does not perform secondary authentication on another session of the terminal device.
[0564] As another example, the transceiver unit 1110 is also used to: obtain the authentication result of another session of the data network for the terminal device, the authentication result of the other session being used to indicate whether the secondary authentication of the other session was successful or failed.
[0565] As another example, the processing unit 1120 is also configured to: skip the secondary authentication process for the session and continue the subsequent session establishment process when the authentication result of another session indicates that the secondary authentication for the other session is successful; or, refuse to establish the session when the authentication result of another session indicates that the secondary authentication for the other session fails.
[0566] As another example, the processing unit 1120 is further configured to: after successful secondary authentication of the session, determine whether to store the authentication result of the session according to any one of the following: session attributes, local policy, or second indication information, wherein the second indication information is: authentication network element from the data network or information from the terminal device indicating whether to store the authentication result of the session.
[0567] As another example, the processing unit 1120 is specifically used to: determine whether an authentication result exists locally; or, determine whether an authentication result exists in the unified data management network element; or, determine whether an authentication result exists based on the third indication information from the authentication network element of the terminal device or data network; or, determine whether an authentication result exists in the authenticated data set.
[0568] As another example, the processing unit 1120 is specifically used to: determine that an authentication result exists when the authenticated dataset includes the identifier of the data network; or determine that no authentication result exists when the authenticated dataset does not include the identifier of the data network.
[0569] In another implementation, the transceiver unit 1110 is configured to: receive a session establishment request message from the terminal device, the session establishment request message being used to request the establishment of a session with the data network; the processing unit 1120 is configured to: determine whether the data network performs secondary authentication on another session of the terminal device; when the data network performs secondary authentication on another session of the terminal device, suspend the session.
[0570] As an example, the processing unit 1120 is specifically used to: suspend a session according to the first indication information carried in the session establishment request message, wherein the first indication information is used to instruct the data network to perform secondary authentication on another session of the terminal device.
[0571] As another example, the transceiver unit 1110 is also used to: obtain the authentication result of another session of the data network for the terminal device, the authentication result of the other session being used to indicate whether the secondary authentication of the other session was successful or failed.
[0572] As another example, the processing unit 1120 is also configured to: skip the secondary authentication process for the session and continue the subsequent session establishment process when the authentication result of another session indicates that the secondary authentication for the other session is successful; or, refuse to establish the session when the authentication result of another session indicates that the secondary authentication for the other session fails.
[0573] As another example, the processing unit 1120 is also configured to: determine whether there is an authentication result of the data network for the terminal device when the data network does not perform secondary authentication for another session of the terminal device; skip the secondary authentication process for the session when there is an authentication result; or initiate a secondary authentication process for the session when there is no authentication result.
[0574] As another example, the processing unit 1120 is further configured to: determine whether to store the authentication result of the session based on any one of the following: session attributes of the session, local policy, or second indication information, wherein the second indication information is: authentication network element from the data network or information from the terminal device indicating whether to store the authentication result of the session.
[0575] As another example, the processing unit 1120 is specifically used to: determine whether an authentication result exists locally; or, determine whether an authentication result exists in the unified data management network element; or, determine whether an authentication result exists based on the third indication information from the authentication network element of the terminal device or data network; or, determine whether an authentication result exists in the authenticated data set.
[0576] As another example, the processing unit 1120 is specifically used to: determine that an authentication result exists when the authenticated dataset includes the identifier of the data network; or determine that no authentication result exists when the authenticated dataset does not include the identifier of the data network.
[0577] The device 1100 can implement steps or processes corresponding to the SMF execution in methods 600 to 1000 according to embodiments of this application. The device 1100 may include methods for execution. Figure 6 Method 600 to Figure 10The unit in method 1000 that executes the SMF method. Furthermore, each unit in the device 1100 and the other operations and / or functions described above are respectively for implementing... Figure 6 Method 600 to Figure 10 The corresponding process of Chinese method 1000.
[0578] Wherein, when the device 1100 is used to perform Figure 6 When method 600 is used, the transceiver unit 1110 can be used to execute step 610 in method 600, and the processing unit is used to instruct steps 620, 631 or 632 in method 600.
[0579] When the device 1100 is used to perform Figure 7 When method 700 is executed, the transceiver unit 1110 can be used to execute steps 702, 703, 704, 707, 708, 706A3, 706A5, 706A6, and 706B4 in method 700, and the processing unit 1120 can be used to execute steps 705, 706, 706A1, 706A2, 706A4, 706A7, 706B1, 706B2, 706B3, and 706B6 in method 700.
[0580] When the device 1100 is used to perform Figure 8 When method 800 is executed, the transceiver unit 1110 can be used to execute steps 803, 804, 807, 808, 810, 812, 815, and 817 in method 800, and the processing unit 1120 can be used to execute steps 805, 806, 809, 813, and 816 in method 800.
[0581] When the device 1100 is used to perform Figure 9 When method 900 is executed, the transceiver unit 1110 can be used to execute steps 903, 904, 907, 908, 910, 914, 918, 920, 921, and 923 in method 900, and the processing unit 1120 can be used to execute steps 905, 906, 909, 915, 919, and 922 in method 900.
[0582] When the device 1100 is used to perform Figure 10 When method 1000 is executed, the transceiver unit 1110 can be used to execute steps 1004, 1005, 1007, 1009, and 1010 in method 1000, and the processing unit 1120 can be used to execute steps 1006, 1007, and 1008 in method 1000.
[0583] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0584] As an alternative design, device 1100 is used to perform the above. Figure 6 The actions performed by the terminal device in the illustrated embodiment.
[0585] In one implementation, the transceiver unit 1110 is configured to: receive a session establishment request message from the terminal device, the session establishment request message being used to request the establishment of a session with the data network; the processing unit 1120 is configured to: determine whether the data network performs secondary authentication on another session of the terminal device during the process of secondary authentication of the session with the data network; the transceiver unit 1110 is further configured to: send a first indication information to the session management network element when the data network performs secondary authentication on another session of the terminal device, the first indication information being used to instruct the data network to perform secondary authentication on another session of the terminal device.
[0586] As an example, the processing unit 1120 is specifically used to: after the transceiver unit 1110 receives the authentication protocol request message from the session management network element, determine whether the data network performs secondary authentication for another session of the terminal device.
[0587] As another example, the transceiver unit 1110 is also used to: send the authentication result of another session to the session management network element, wherein the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0588] As another example, the transceiver unit 1110 is also configured to: determine, based on one or more of the stored information and the session attributes of the session, to send the authentication result of another session to the session management network element after the secondary authentication of another session of the terminal device by the data network is completed, wherein the stored information is used to instruct that the authentication result of another session be sent to the session management network element after the secondary authentication of another session of the terminal device by the data network is completed.
[0589] As another example, the transceiver unit 1110 is also used to: send a second indication message to the session management network element, the second indication message being used to indicate whether to store information on the authentication result of the data network for the terminal device.
[0590] The device 1100 can implement steps or processes corresponding to the SMF execution in methods 600 to 1000 according to embodiments of this application. The device 1100 may include methods for execution. Figure 6 Method 600 to Figure 10 The unit in method 1000 that executes the SMF method. Furthermore, each unit in the device 1100 and the other operations and / or functions described above are respectively for implementing... Figure 6 Method 600 to Figure 10 The corresponding process of Chinese method 1000.
[0591] Wherein, when the device 1100 is used to perform Figure 6 When using method 600, the transceiver unit 1110 can be used to execute step 610 in method 600.
[0592] When the device 1100 is used to perform Figure 7 When using method 700, the transceiver unit 1110 can be used to execute step 701 in method 700.
[0593] When the device 1100 is used to perform Figure 8 When method 800 is used, the transceiver unit 1110 can be used to execute step 801 in method 800.
[0594] When the device 1100 is used to perform Figure 9 When performing method 900, the transceiver unit 1110 can be used to execute steps 901, 911, 913, and 917 in method 900, and the processing unit 1120 can be used to execute steps 912 and 916 in method 900.
[0595] When the device 1100 is used to perform Figure 10 When method 1000 is used, processing unit 1120 can be used to execute step 1001 in method 1000, and transceiver unit 1110 can be used to execute step 1002 in method 1000.
[0596] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0597] As yet another design, device 1100 is used to perform the above... Figure 6 In the illustrated embodiment, the actions performed by the DN authentication server are as follows: the transceiver unit 1110 is used to: receive an authentication authorization message from the session management network element, the authentication authorization message being used by the data network to verify whether the terminal device is authorized to establish a session to access the data network; the processing unit 1120 is used to: determine whether there is an authentication result from the data network for the terminal device, or determine whether the data network performs secondary authentication for another session of the terminal device; the transceiver unit 1110 is also used to: send first indication information to the session management network element, the first indication information being used to indicate whether there is an authentication result from the data network for the terminal device, or the first indication information being used to instruct the data network to perform secondary authentication for another session of the terminal device.
[0598] As an example, when determining that the data network performs secondary authentication for another session of the terminal device, the transceiver unit 1110 is further configured to: after the data network completes the secondary authentication of another session of the terminal device, send the authentication result of the other session to the session management network element, wherein the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
[0599] As another example, the transceiver unit 1110 is specifically used to: determine, based on one or more of the stored information and the session attributes of the session, to send the authentication result of another session to the session management network element after the secondary authentication of another session of the terminal device by the data network is completed, wherein the stored information is used to instruct that the authentication result of another session be sent to the session management network element after the secondary authentication of another session of the terminal device by the data network is completed.
[0600] As another example, the transceiver unit 1110 is also used to: send a second indication message to the session management network element, the second indication message being used to indicate whether to store information on the authentication result of the data network for the terminal device.
[0601] The apparatus 1100 can implement the steps or processes performed by the authentication server corresponding to the DN in methods 600 to 1000 according to embodiments of this application. The apparatus 1100 may include methods for performing... Figure 6 Method 600 to Figure 10 The authentication server of the DN in method 1000 is a unit that executes the method. Furthermore, each unit in the apparatus 1100 and the other operations and / or functions described above are respectively for implementing... Figure 6 Method 600 to Figure 10 The corresponding process of Chinese method 1000.
[0602] Wherein, when the device 1100 is used to perform Figure 6 When performing method 600, the transceiver unit 1110 can be used to execute step 610 in method 600, and the processing unit 1120 can be used to execute steps 620, 631 or 632 in method 600.
[0603] When the device 1100 is used to perform Figure 7 When performing method 700, the transceiver unit 1110 can be used to execute steps 706A3 and 706B4 in method 700, and the processing unit 1120 can be used to execute steps 706A2 and 706B5 in method 700.
[0604] When the device 1100 is used to perform Figure 8 When method 800 is executed, the transceiver unit 1110 can be used to execute steps 810, 812, 815, and 817 in method 800, and the processing unit 1120 can be used to execute steps 811 and 814 in method 800.
[0605] When the device 1100 is used to perform Figure 9 When using method 900, the transceiver unit 1110 can be used to execute step 923 in method 900, and the processing unit 1120 can be used to execute step 924 in method 900.
[0606] When the device 1100 is used to perform Figure 10 When performing method 1000, the transceiver unit 1110 can be used to execute step 1011 in method 1000, and the processing unit 1120 can be used to execute step 1012 in method 1000.
[0607] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0608] The processing unit 1120 in the above embodiments can be implemented by at least one processor or processor-related circuitry. The transceiver unit 1110 can be implemented by a transceiver or transceiver-related circuitry. The storage unit can be implemented by at least one memory.
[0609] like Figure 12 As shown, this application embodiment also provides an authentication and authorization device 1200. The device 1200 includes a processor 1210, which is coupled to a memory 1220. The memory 1220 is used to store computer programs or instructions and / or data. The processor 1210 is used to execute the computer programs or instructions and / or data stored in the memory 1220, so that the methods in the above method embodiments are executed.
[0610] Optionally, the device 1200 may include one or more processors 1210.
[0611] Optionally, such as Figure 12 As shown, the device 1200 may also include a memory 1220.
[0612] Optionally, the device 1200 may include one or more memories 1220.
[0613] Alternatively, the memory 1220 may be integrated with the processor 1210 or set separately.
[0614] Optionally, such as Figure 12 As shown, the device 1200 may also include a transceiver 1230 for receiving and / or transmitting signals. For example, a processor 1210 is used to control the transceiver 1230 to receive and / or transmit signals.
[0615] As one option, the device 1200 is used to implement the operations performed by the terminal device in the above method embodiments.
[0616] For example, processor 1210 is used to implement the processing-related operations performed by the terminal device in the above method embodiments, and transceiver 1230 is used to implement the sending and receiving-related operations performed by the terminal device in the above method embodiments.
[0617] As an alternative, the device 1200 is used to implement the operations performed by the SMF in the above method embodiments.
[0618] For example, processor 1210 is used to implement the processing-related operations performed by SMF in the above method embodiments, and transceiver 1230 is used to implement the transmission-reception-related operations performed by SMF in the above method embodiments.
[0619] As another option, the device 1200 is used to implement the operations performed by the authentication server of the DN in the above method embodiments.
[0620] For example, processor 1210 is used to implement the processing-related operations performed by the DN authentication server in the above method embodiment, and transceiver 1230 is used to implement the sending and receiving-related operations performed by the DN authentication server in the above method embodiment.
[0621] It should be understood that the specific process of each module performing the above-mentioned steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0622] This application also provides a processing apparatus, including a processor and an interface; the processor is used to execute the method in any of the above method embodiments.
[0623] It should be understood that the aforementioned processing device can be one or more chips. For example, the processing device can be a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system-on-chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0624] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by a terminal device in the above-described method embodiments.
[0625] For example, when the computer program is executed by the computer, it enables the computer to implement the method executed by the terminal device in the above method embodiments.
[0626] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by the SMF in the above method embodiments.
[0627] For example, when the computer program is executed by a computer, it enables the computer to implement the method executed by the SMF in the above method embodiments.
[0628] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by the authentication server of the DN in the above method embodiments.
[0629] For example, when the computer program is executed by a computer, it enables the computer to implement the method executed by the DN authentication server in the above method embodiments.
[0630] This application also provides a computer program product containing instructions that, when executed by a computer, cause the computer to implement the method executed by the terminal device, the method executed by the SMF, or the method executed by the DN authentication server in the above method embodiments.
[0631] This application also provides a communication system, which includes the terminal device, SMF, and DN authentication server described in the above embodiments.
[0632] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the explanations and beneficial effects of the relevant content in any of the communication devices provided above can be referred to the corresponding method embodiments provided above, and will not be repeated here.
[0633] This application does not impose any particular limitation on the specific structure of the execution subject of the method provided in this application embodiment. As long as it is possible to communicate according to the method provided in this application embodiment by running a program that records the code of the method provided in this application embodiment. For example, the execution subject of the method provided in this application embodiment can be a terminal device or a network device, or a functional module in a terminal device or network device that can call and execute a program.
[0634] Various aspects or features of this application may be implemented as methods, apparatus, or articles of manufacture using standard programming and / or engineering techniques. As used herein, the term "article of manufacture" may encompass any computer program accessible from any computer-readable device, carrier, or medium.
[0635] The computer-readable storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. Available media (or computer-readable media) can include, but are not limited to: magnetic media or magnetic storage devices (e.g., floppy disks, hard disks (such as portable hard drives), magnetic tapes), optical media (e.g., optical discs, compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards and flash memory devices (e.g., erasable programmable read-only memory (EPROM), cards, sticks, or key drives, etc.), or semiconductor media (e.g., solid-state disks (SSDs), USB flash drives, read-only memory (ROM), random access memory (RAM), and various other media capable of storing program code).
[0636] The various storage media described herein may represent one or more devices and / or other machine-readable media used for storing information. The term "machine-readable media" may include, but is not limited to, wireless channels and various other media capable of storing, containing and / or carrying instructions and / or data.
[0637] It should be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM can include a variety of forms, such as: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0638] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0639] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0640] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of the apparatus or units may be electrical, mechanical, or other forms.
[0641] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to implement the solution provided in this application, depending on actual needs.
[0642] In addition, the functional units in the various embodiments of this application can be integrated into one unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0643] In the above embodiments, it can be implemented entirely or partially by software, hardware, firmware, or any combination thereof.
[0644] When implemented using software, it can be implemented entirely or partially as a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. For information on computer-readable storage media, please refer to the description above.
[0645] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims and the specification.
Claims
1. A method for authentication and authorization, characterized in that, include: Receive a session establishment request message from a terminal device, the session establishment request message being used to request the establishment of a session with the data network; Determine whether the data network has an authentication result for the terminal device; When the data network identifier of the data network and the data network identifier in the authentication and authorization information are equivalent data network identifiers, it is determined that the authentication result exists. The equivalent data network identifier includes at least two data network identifiers, and the at least two data network identifiers are used to identify the same data network. If the authentication result exists, the secondary authentication process is skipped for the session.
2. The method according to claim 1, characterized in that, The authentication and authorization information includes one or more of the following: One or more data network identifiers, identifiers of the authentication network elements of the data network, timeliness information, index of the data network authorization text, aggregate maximum bit rate of the data network authorized sessions, allowed media access control addresses, allowed virtual local area networks, and information for indicating the reporting of session information.
3. The method according to claim 1, characterized in that, The method further includes: If the authentication result is not available, initiate a secondary authentication process for the session, or suspend the session.
4. The method according to claim 3, characterized in that, After initiating a two-factor authentication process for the session, the method further includes: Based on the first indication information sent by the terminal device or the authentication element of the data network, the session is suspended. The first indication information is used to indicate that the data network is conducting or will conduct a secondary authentication for another session of the terminal device.
5. The method according to claim 3, characterized in that, When the authentication result is not available, initiating a secondary authentication process for the session, or suspending the session, includes: When the authentication result is not available, determine whether the data network is performing or will perform a second authentication for another session of the terminal device. When the data network is performing or about to perform secondary authentication for another session of the terminal device, the session is suspended; or... When the data network does not have another session of the terminal device in progress or about to be performed for secondary authentication, it initiates a secondary authentication process for the session.
6. The method according to claim 5, characterized in that, After suspending the session, the method further includes: The authentication result of another session of the data network for the terminal device is obtained, and the authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
7. The method according to claim 6, characterized in that, When the authentication result of the other session indicates that the secondary authentication for the other session was successful, the secondary authentication process for that session is skipped, and the process of establishing the subsequent sessions continues; or, If the authentication result of the other session indicates that the secondary authentication for the other session has failed, the session shall be refused to be established.
8. The method according to claim 3, characterized in that, When initiating a two-factor authentication process for the session, the method further includes: After successful secondary authentication of the session, determine whether to store the authentication result of the session based on any of the following: the session attributes, local policy, or second indication information of the session. The second indication information is: information from the authentication network element of the data network or from the terminal device indicating whether to store the authentication result of the session.
9. The method according to any one of claims 1 to 8, characterized in that, The determination of whether the data network has an authentication result for the terminal device includes: Determine if the authentication result exists locally; or, Determine whether the authentication result exists in the unified data management network element; or, Based on the third indication information from the authentication network element of the terminal device or the data network, determine whether the authentication result exists; or, Determine whether the authentication result exists in the authenticated dataset.
10. The method according to claim 9, characterized in that, The determination of whether the authentication result exists in the authenticated dataset includes: When the authenticated dataset includes the identifier of the data network, it is determined that the authentication result exists; or, If the authenticated dataset does not include the identifier of the data network, it is determined that the authentication result does not exist.
11. A method for authentication and authorization, characterized in that, include: Send a session establishment request message to the session management network element, the session establishment request message being used to request the establishment of a session with the data network; During the secondary authentication of the session with the data network, it is determined whether the data network is performing or about to perform secondary authentication on another session of the terminal device. When the data network is performing or about to perform secondary authentication for another session of the terminal device, it sends a first indication message to the session management network element. The first indication message is used to indicate that the data network is performing or about to perform secondary authentication for another session of the terminal device.
12. The method according to claim 11, characterized in that, During the secondary authentication process of the session with the data network, determining whether the data network is performing or will perform secondary authentication on another session of the terminal device includes: After receiving the authentication protocol request message from the session management network element, it is determined whether the data network is performing or about to perform secondary authentication for another session of the terminal device.
13. The method according to claim 11 or 12, characterized in that, The method further includes: After the data network completes the secondary authentication of another session for the terminal device, it sends the authentication result of the other session to the session management network element. The authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
14. The method according to claim 13, characterized in that, The method further includes: Based on the stored information and one or more of the session attributes of the session, determine that after the secondary authentication of another session of the terminal device by the data network is completed, the authentication result of the other session is sent to the session management network element; The stored information is used to instruct the session management network element to send the authentication result of the other session after the secondary authentication of the terminal device by the data network for another session has been completed.
15. The method according to claim 11 or 12, characterized in that, The method further includes: Send a second indication message to the session management network element, the second indication message being used to indicate whether to store the authentication result information of the data network for the terminal device.
16. A method for authentication and authorization, characterized in that, The method is applied to the authentication network element of a data network, and the method includes: The system receives an authentication and authorization message from a session management network element. The authentication and authorization message is used by the data network to verify whether the terminal device is authorized to establish a session to access the data network. Determine whether there is an authentication result from the data network for the terminal device, wherein the authentication result is either successful or failed. Send a first indication message to the session management network element, the first indication message being used to indicate whether there is an authentication result of the data network for the terminal device.
17. A method for authentication and authorization, characterized in that, include: Receive authentication and authorization messages from session management network elements, wherein the authentication and authorization messages are used by the data network to verify whether the terminal device is authorized to establish a session to access the data network; Determine whether the data network is performing or will perform secondary authentication for another session with the terminal device. Send a first indication message to the session management network element, the first indication message being used to indicate that the data network is performing or will perform secondary authentication for another session of the terminal device.
18. The method according to claim 17, characterized in that, If it is determined that the data network is performing or will perform secondary authentication for another session of the terminal device, the method further includes: After the data network completes the secondary authentication of another session for the terminal device, it sends the authentication result of the other session to the session management network element. The authentication result of the other session is used to indicate whether the secondary authentication of the other session was successful or failed.
19. The method according to any one of claims 16 to 18, characterized in that, The method further includes: Send a second indication message to the session management network element, the second indication message being used to indicate whether to store the authentication result information of the data network for the terminal device.
20. An authentication and authorization device, characterized in that, Includes units for implementing the method as described in any one of claims 1 to 19.
21. An authentication and authorization device, characterized in that, include: A processor for executing computer instructions stored in memory to cause the apparatus to perform the method as claimed in any one of claims 1 to 19.
22. A computer-readable storage medium, characterized in that, It stores a computer program thereon, which, when executed by a computer, enables the implementation of the method as described in any one of claims 1 to 19.
Citation Information
Patent Citations
Network security management method and apparatus
CN110999356A