A slicing authentication method and corresponding device

By storing the authentication results of network slices before the terminal device moves, and when the new access management node obtains the results from the data management network element, the signaling overhead and service delay problems caused by the old access management node not supporting the network slice authentication function are solved, and an efficient movement process is achieved.

CN114095925BActive Publication Date: 2025-06-10HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010791231.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-07
Publication Date
2025-06-10
Estimated Expiration
2040-08-07

AI Technical Summary

Technical Problem

When a terminal device moves from an access management node that does not support the network slice authentication function to an access management node that supports the function, the old access management node cannot provide the authentication result of the network slice, resulting in the new access management node having to re-execute the network slice authentication process, which increases signaling overhead and service delay of the terminal device.

Method used

Before the terminal device is moved, the access management node that supports the network slice authentication function stores the authentication results of the network slice to the data management network element. Then, when the terminal device moves from an access management node that does not support the network slice authentication function to an access management node that supports the function, the new access management node obtains the required authentication results from the data management network element to avoid re-executing the authentication process.

Benefits of technology

This method effectively saves system signaling overhead, reduces the service delay of terminal equipment, and improves service performance during mobile.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114095925B_ABST
    Figure CN114095925B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a slicing authentication method and a corresponding device. After the terminal device moves from the service range of a second access management network element that does not support network slicing authentication function to the service range of a third access management network element that supports network slicing authentication function, the third access management network element can send a first request message to the first network element to obtain the authentication result of the first slice that needs to be authenticated. Thus, the third access management network element does not need to execute the network slicing authentication process, which can effectively save the system signaling overhead. At the same time, the terminal device no longer needs to wait for the third access management network element to complete the network slicing authentication process before establishing a session to a specific network slice, accelerating the service establishment process and reducing the service latency of the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a slice authentication method and a corresponding device. Background Art

[0002] Currently, after a terminal device moves from the service range of an old access management node to the service range of a new access management node, the new access management node is allowed to obtain the authentication result of a network slice from the old access management node. Furthermore, the new access management node can omit the process of performing network slice authentication on the terminal device, which can effectively reduce signaling overhead. However, the prerequisite for the new access management node to be able to obtain the authentication result of the network slice from the old access management node is that the old access management node supports the network slice authentication function, because only the access management node that supports the network slice authentication function has the authentication result of the network slice.

[0003] However, in actual applications, the old access management node is very likely not to support the network slice authentication function (i.e., there is no authentication result of the network slice). For example, the old access management node is an access management node in a 4th-Generation (4G) mobile communication network, or the old access management node is an access management node in the 5th-Generation (5G) that does not support the network slice authentication function. These situations will cause the new access management node to be unable to obtain the authentication result of the network slice from the old access management node. Then, when the terminal device moves to the service range of the new access management node, the new access management node must perform the network slice authentication process on the terminal device to obtain the authentication result, which results in an increase in system signaling overhead and an increase in the service delay of the terminal device. Summary of the Invention

[0004] Embodiments of this application provide a slice authentication method and a corresponding device for saving system signaling overhead and reducing the service delay of a terminal device.

[0005] In a first aspect, a slice authentication method is provided, including: after a terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, the third access management network element sends a first request message to a first network element, where the first request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; the third access management network element receives a first response message from the first network element, and the first response message includes the authentication result corresponding to the first slice.

[0006] In an embodiment of the present application, after the terminal device moves from the service area of a second access management network element that does not support network slice authentication function to the service area of a third access management network element that supports network slice authentication function, the third access management network element can obtain the authentication result of a first slice to be authenticated from a first network element, so that there is no need to execute the network slice authentication process, which can effectively save the system signaling overhead; at the same time, the terminal device no longer needs to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, accelerating the service establishment process and reducing the service latency of the terminal device.

[0007] In a possible implementation manner, the first network element is a data management network element; before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from a first access management network element that supports network slice authentication function to the second access management network element, and the method further includes: the first access management network element or a first slice authentication network element stores the authentication result corresponding to the first slice into the data management network element.

[0008] Through this implementation manner, the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice into the data management network element, so that after the terminal device moves from the service area of the second access management network element that does not support network slice authentication function to the service area of the third access management network element that supports network slice authentication function, the third access management network element can obtain the authentication result of the first slice to be authenticated from the data management network element, ensuring the reliability of the solution.

[0009] In a possible implementation manner, the first network element is a second slice authentication network element.

[0010] Through this implementation manner, after the terminal device moves from the service area of the second access management network element that does not support network slice authentication function to the service area of the third access management network element that supports network slice authentication function, the third access management network element can obtain the authentication result of the first slice to be authenticated from the second slice authentication network element, and thus does not need to execute the network slice authentication process for the first slice, which can save the system signaling overhead and reduce the service latency of the terminal device.

[0011] In a possible implementation manner, after the third access management network element sends a first request message to the first network element, the method further includes: the second slice authentication network element sends the identification information of the first slice to the data management network element; the second slice authentication network element receives the authentication result corresponding to the first slice from the data management network element; the second slice authentication network element sends the authentication result corresponding to the first slice to the third access management network element.

[0012] Through this embodiment, after the terminal device moves from the service area of the second access management network element that does not support the network slice authentication function to the service area of the third access management network element that supports the network slice authentication function, the third access management network element can obtain the authentication result corresponding to the first slice on the data management network element through the second slice authentication network element, and thus does not need to execute the network slice authentication process for the first slice, which can save the system signaling overhead and reduce the service latency of the terminal device.

[0013] In a possible embodiment, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function to the second access management network element, and the method further includes: the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice into the data management network element.

[0014] Through this embodiment, the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice into the data management network element, so that after the terminal device moves from the service area of the second access management network element that does not support the network slice authentication function to the service area of the third access management network element that supports the network slice authentication function, the third access management network element can obtain the authentication result corresponding to the first slice from the data management network element through the second slice authentication network element, ensuring the reliability of the solution.

[0015] In a possible embodiment, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service area of the second access management network element, the method further includes: the first slice authentication network element or the second slice authentication network element receives an authentication revocation message from the authentication, authorization, and accounting (AAA) server, and according to the authentication revocation message, modifies the authentication result corresponding to the first slice stored in the data management network element to authentication failure; or, the first slice authentication network element or the second slice authentication network element receives a re-authentication message from the AAA server, and according to the re-authentication message, deletes the authentication result corresponding to the first slice stored in the data management network element.

[0016] Through this embodiment, after the data management network element stores the authentication result of the first slice, the AAA server can also trigger a re-authentication or authentication result revocation process for the first slice, improving the flexibility of network slice authentication.

[0017] In a possible implementation manner, after the third access management network element sends a first request message to the first network element, the method further includes: the second slice authentication network element sends the identification information of the first slice to the first slice authentication network element; the second slice authentication network element receives the authentication result corresponding to the first slice from the first slice authentication network element; the second slice authentication network element sends the authentication result corresponding to the first slice to the third access management network element.

[0018] Through this implementation manner, after the terminal device moves from the service range of the second access management network element that does not support network slice authentication function to the service range of the third access management network element that supports network slice authentication function, the third access management network element can obtain the authentication result corresponding to the first slice from the first slice authentication network element, and thus does not need to execute the network slice authentication process for the first slice, which can save the system signaling overhead and reduce the service delay of the terminal device.

[0019] In a possible implementation manner, before the second slice authentication network element sends a third request message to the first slice authentication network element, the method further includes: the second slice authentication network element sends a request message to the data management network element; the second slice authentication network element receives the identification of the first slice authentication network element from the data management network element; the second slice authentication network element sends a third request message to the first slice authentication network element, including: the second slice authentication network element sends the identification information of the first slice to the first slice authentication network element according to the identification of the first slice authentication network element.

[0020] Through this implementation manner, the second slice authentication network element can query the storage location of the authentication result corresponding to the first slice (i.e., the first slice authentication network element) from the data management network element, and then send the identification information of the first slice to the first slice authentication network element to obtain the authentication result corresponding to the first slice from the first slice authentication network element, ensuring the reliability of the solution.

[0021] In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the method further includes: after the authentication of the first slice is completed, the first slice authentication network element saves the authentication result corresponding to the first slice and registers the identification of the first slice authentication network element to the data management network element.

[0022] Through this implementation manner, the first slice authentication network element not only saves the authentication result corresponding to the first slice, but also registers the identification of the first slice authentication network element to the data management network element, so as to facilitate other network elements to query the storage location of the authentication result corresponding to the first slice later, further improving the reliability of the solution.

[0023] In a possible implementation, the first network element is a first slice authentication network element; before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from a first access management network element that supports network slice authentication function to the second access management network element, and the method further includes: the first slice authentication network element stores the authentication result corresponding to the first slice.

[0024] Through this implementation, the first slice management network element stores the authentication result corresponding to the first slice. After the terminal device moves from the service range of the second access management network element that does not support network slice authentication function to the service range of the third access management network element that supports network slice authentication function, the third access management network element directly obtains the authentication result corresponding to the first slice from the first slice management network element, and thus does not need to execute the network slice authentication process for the first slice, which can save system signaling overhead and reduce the service latency of the terminal device.

[0025] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element, the method further includes: the first slice authentication network element or the second slice authentication network element receives an authentication revocation message from the AAA server, and according to the authentication revocation message, modifies the authentication result corresponding to the first slice stored in the first slice authentication network element to authentication failure; or, the first slice authentication network element or the second slice authentication network element receives a re-authentication message from the AAA server, and according to the re-authentication message, deletes the authentication result corresponding to the first slice stored in the first slice authentication network element.

[0026] Through this implementation, after the first slice authentication network element stores the authentication result of the first slice, the AAA server can also trigger a re-authentication or authentication result revocation process for the first slice, improving the flexibility of network slice authentication.

[0027] In a possible implementation, after the terminal device moves from the second access management network element to the third access management network element and before the third access management network element sends a first request message to the first network element, the method further includes: if the second access management network element is a mobility management entity (MME) of a 4G network, the third access management network element determines that the second access management network element does not support the network slice authentication function; or, the third access management network element obtains the user context of the terminal device from the second access management network element, where the user context does not include the authentication result corresponding to the first slice, then the third access management network element determines that the second access management network element does not support the network slice authentication function; or, the third access management network element obtains the list of supported features of the second access management network element from the second access management network element, and determines that the second access management network element does not support the network slice authentication function according to the list of supported features.

[0028] This implementation provides multiple implementation manners for the third access management network element to determine that the second access management network element does not support the network slice authentication function, improving the flexibility of the solution.

[0029] In a second aspect, a slice authentication method is provided, including: after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, the third access management network element sends a first request message to the first network element, where the first request message includes the identification information of a first slice, and the first slice is the slice that needs to be authenticated; the third access management network element receives a first response message from the first network element, and the first response message includes the authentication result corresponding to the first slice.

[0030] In a possible implementation, the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.

[0031] In a possible implementation, after the terminal device moves from the second access management network element to the third access management network element and before the third access management network element sends a first request message to the first network element, the method further includes: if the second access management network element is the MME of the 4G network, the third access management network element determines that the second access management network element does not support the network slice authentication function; or, the third access management network element obtains the user context of the terminal device from the second access management network element, where the authentication result corresponding to the first slice is not included in the user context, and the third access management network element determines that the second access management network element does not support the network slice authentication function; or, the third access management network element obtains the list of supported features of the second access management network element from the second access management network element, and determines that the second access management network element does not support the network slice authentication function according to the list of supported features.

[0032] In a third aspect, a slice authentication method is provided, including: after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, the data management network element receives a request message from the third access management network element, where the request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated; the data management network element returns a response message to the third access management network element, and the response message includes the authentication result corresponding to the first slice.

[0033] In a possible implementation, the data management network element receiving a request message from the third access management network element includes: the data management network element receives a request message sent by a second slice authentication network element, where the request message sent by the second slice authentication network element is sent by the third access management network element to the second slice authentication network element; the data management network element returning a response message to the third access management network element includes: the data management network element sends the response message to the second slice authentication network element, and the second slice authentication network element sends the response message to the third access management network element.

[0034] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from a first access management network element that supports the network slice authentication function to the second access management network element, and the method further includes: the data management network element receives the authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element; the data management network element stores the authentication result corresponding to the first slice.

[0035] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element, the method further includes: the data management network element receives a first message from the first slice authentication network element or the second slice authentication network element, and modifies the stored authentication result corresponding to the first slice to authentication failure according to the first message; or, the data management network element receives a second message from the first slice authentication network element or the second slice authentication network element, and deletes the stored authentication result corresponding to the first slice according to the second message.

[0036] In a fourth aspect, a slice authentication method is provided, including: after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, the first slice authentication network element receives a request message from the second slice authentication network element, where the request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated; the first slice authentication network element returns a response message to the second slice authentication network element, and the response message includes the authentication result corresponding to the first slice.

[0037] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device moves from a first access management network element that supports the network slice authentication function to the second access management network element, the method further includes: after the authentication of the first slice is completed, the first slice authentication network element saves the authentication result corresponding to the first slice, and registers the identification of the first slice authentication network element to the data management network element.

[0038] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element, the method further includes: the first slice authentication network element receives an authentication revocation message from the AAA server, and modifies the stored authentication result corresponding to the first slice to authentication failure according to the authentication revocation message; or, the first slice authentication network element receives a re-authentication message from the AAA server, and deletes the stored authentication result corresponding to the first slice according to the re-authentication message; or, the first slice authentication network element receives a third message from the second slice authentication network element, and modifies the stored authentication result corresponding to the first slice to authentication failure according to the third message; or, the first slice authentication network element receives a fourth message from the second slice authentication network element, and deletes the stored authentication result corresponding to the first slice according to the fourth message.

[0039] Fifth aspect, a slice authentication system is provided, including: a terminal device, a second access management network element that does not support network slice authentication function, a third access management network element that supports network slice authentication function, and a first network element; wherein, the third access management network element is configured to: after the terminal device moves from the second access management network element to the third access management network element, send a first request message to the first network element, where the first request message includes identification information of a first slice, and the first slice is the slice that needs to be authenticated; the first network element is configured to: receive the first request message and send a first response message to the third access management network element, and the first response message includes the authentication result corresponding to the first slice; the third access management network element is further configured to: receive the first response message from the first network element.

[0040] In a possible implementation manner, the first network element is a data management network element, and the system further includes a first access management network element and a first slice authentication network element; before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports network slice authentication function to the second access management network element; the first access management network element or the first slice authentication network element is configured to: store the authentication result corresponding to the first slice into the data management network element.

[0041] In a possible implementation manner, the first network element is a second slice authentication network element.

[0042] In a possible implementation manner, the second slice authentication network element is configured to: after the third access management network element sends the first request message to the first network element, send the identification information of the first slice to the data management network element; receive the authentication result corresponding to the first slice from the data management network element; and send the authentication result corresponding to the first slice to the third access management network element.

[0043] In a possible implementation manner, the system further includes a first access management network element and a first slice authentication network element; before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports network slice authentication function to the second access management network element; the first access management network element or the first slice authentication network element is configured to: store the authentication result corresponding to the first slice into the data management network element.

[0044] In a possible implementation, the system further includes the first slice authentication network element; the second slice authentication network element is configured to: after the third access management network element sends a first request message to the first network element, send the identification information of the first slice to the first slice authentication network element; the first slice authentication network element is configured to: receive the identification information of the first slice from the second slice authentication network element, and send the authentication result corresponding to the first slice to the second slice authentication network element; the second slice authentication network element is further configured to: receive the authentication result corresponding to the first slice from the first slice authentication network element; and send the authentication result corresponding to the first slice to the third access management network element.

[0045] In a possible implementation, the second slice authentication network element is further configured to: before the second slice authentication network element sends a third request message to the first slice authentication network element, send a request message to the data management network element; receive the identification of the first slice authentication network element from the data management network element; when the second slice authentication network element sends a third request message to the first slice authentication network element, specifically configured to: send the identification information of the first slice to the first slice authentication network element according to the identification of the first slice authentication network element.

[0046] In a possible implementation, the first slice authentication network element is further configured to: before the terminal device moves from the second access management network element to the third access management network element, after the authentication corresponding to the first slice is completed, save the authentication result corresponding to the first slice, and register the identification of the first slice authentication network element to the data management network element.

[0047] In a possible implementation, the first network element is the first slice authentication network element; before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element; the first slice authentication network element is further configured to: store the authentication result corresponding to the first slice.

[0048] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element, the first slice authentication network element or the second slice authentication network element is further configured to: receive an authentication revocation message from the Authentication, Authorization and Accounting (AAA) server, and according to the authentication revocation message, modify the authentication result corresponding to the first slice stored in the data management network element to authentication failure; or, receive a re-authentication message from the AAA server, and according to the re-authentication message, delete the authentication result corresponding to the first slice stored in the data management network element.

[0049] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element, the first slice authentication network element or the second slice authentication network element is further configured to: receive an authentication revocation message from the AAA server, and according to the authentication revocation message, modify the authentication result corresponding to the first slice stored in the first slice authentication network element to authentication failure; or, receive a re-authentication message from the AAA server, and according to the re-authentication message, delete the authentication result corresponding to the first slice stored in the first slice authentication network element.

[0050] In a possible implementation, after the terminal device moves from the second access management network element to the third access management network element, before the third access management network element sends a first request message to the first network element, the third access management network element is further configured to: if the second access management network element is a mobility management entity (MME) of a 4G network, determine that the second access management network element does not support the network slice authentication function; or, obtain the user context of the terminal device from the second access management network element, where the user context does not include the authentication result corresponding to the first slice, and determine that the second access management network element does not support the network slice authentication function; or, obtain the list of supported features of the second access management network element from the second access management network element, and determine that the second access management network element does not support the network slice authentication function according to the list of supported features.

[0051] In a sixth aspect, a slice authentication apparatus is provided, which may be, for example, a third access management network element or a chip disposed inside the third access management network element. The apparatus includes a module for performing the method according to the second aspect or any possible implementation manner of the second aspect.

[0052] Exemplarily, the apparatus may include: a sending unit, configured to: after the terminal device moves from a second access management network element that does not support the network slice authentication function to the apparatus that supports the network slice authentication function, send a first request message to the first network element, where the first request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated; and a receiving unit, configured to receive a first response message from the first network element, where the first response message includes the authentication result corresponding to the first slice.

[0053] In a seventh aspect, a slice authentication apparatus is provided, which may be, for example, a data management network element or a chip disposed inside the data management network element. The apparatus includes a module for performing the method according to the third aspect or any possible implementation manner of the third aspect.

[0054] Exemplarily, the apparatus may include: a receiving unit, configured to, after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, receive a request message from the third access management network element, where the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; a sending unit, configured to send a response message to the third access management network element, where the response message includes the authentication result corresponding to the first slice.

[0055] In a eighth aspect, there is provided a slice authentication apparatus, which may be, for example, a first slice authentication network element or a chip disposed inside the first slice authentication network element. The apparatus includes a module for executing the method described in the fourth aspect or any possible implementation manner of the fourth aspect.

[0056] Exemplarily, the apparatus may include: a receiving unit, configured to: after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, receive a request message from a second slice authentication network element, where the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated; a sending unit, configured to send a response message to the second slice authentication network element, where the response message includes the authentication result corresponding to the first slice.

[0057] In a ninth aspect, there is provided a communication apparatus, including: at least one processor; and a communication interface communicatively connected to the at least one processor; the at least one processor, by executing instructions stored in a memory, causes the apparatus to execute the method described in the second aspect or any possible implementation manner of the second aspect or the third aspect or any possible implementation manner of the third aspect or the fourth aspect or any possible implementation manner of the fourth aspect through the communication interface.

[0058] Optionally, the memory is located outside the apparatus.

[0059] Optionally, the apparatus includes the memory, the memory is connected to the at least one processor, and the memory stores instructions executable by the at least one processor.

[0060] In a tenth aspect, there is provided a computer-readable storage medium, including a program or instructions, which, when running on a computer, causes the method described in the second aspect or any possible implementation manner of the second aspect or the third aspect or any possible implementation manner of the third aspect or the fourth aspect or any possible implementation manner of the fourth aspect to be executed.

[0061] In an eleventh aspect, there is provided a chip, which is coupled to a memory and is configured to read and execute program instructions stored in the memory, so that the method described in the second aspect or any possible implementation manner of the second aspect or the third aspect or any possible implementation manner of the third aspect or the fourth aspect or any possible implementation manner of the fourth aspect is executed.

[0062] In a twelfth aspect, there is provided a computer program product including instructions, which, when running on a computer, cause the method described in the second aspect or any possible implementation manner of the second aspect or the third aspect or any possible implementation manner of the third aspect or the fourth aspect or any possible implementation manner of the fourth aspect to be executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 Flowchart for network slice authentication;

[0064] Figure 2 Network architecture diagram of a communication system to which embodiments of the present application are applicable;

[0065] Figure 3 Flowchart of a slice authentication method provided by an embodiment of the present application;

[0066] Figure 4 Flowchart of a specific slice authentication method provided by this embodiment;

[0067] Figure 5 Flowchart of an authentication result withdrawal method and a re - authentication method provided by an embodiment of the present application;

[0068] Figure 6 Flowchart of another specific slice authentication method provided by an embodiment of the present application;

[0069] Figure 7 Flowchart of another authentication result withdrawal method and a re - authentication method provided by an embodiment of the present application;

[0070] Figure 8 Flowchart of another specific slice authentication method provided by this embodiment;

[0071] Figure 9 Flowchart of another authentication result withdrawal method and a re - authentication method provided by an embodiment of the present application;

[0072] Figure 10 Flowchart of another specific slice authentication method provided by this embodiment;

[0073] Figure 11 Flowchart of another authentication result withdrawal method and a re - authentication method provided by an embodiment of the present application;

[0074] Figure 12 Schematic structural diagram of a slice authentication device provided by an embodiment of the present application;

[0075] Figure 13 Schematic structural diagram of another slice authentication device provided by an embodiment of the present application;

[0076] Figure 14 Schematic structural diagram of another slice authentication device provided by an embodiment of the present application;

[0077] Figure 15 Schematic structural diagram of a communication device provided by an embodiment of the present application. Detailed implementation manners

[0078] The Network Slice-Specific Authentication and Authorization (NSSAA) function is used to authenticate and authorize the slices subscribed by the terminal device.

[0079] Figure 1 Is a flowchart of network slice authentication. As Figure 1 shown, the access management node triggers the network slice authentication process for the slice that needs to perform network slice authentication according to the slice information subscribed in the subscription data of the terminal device:

[0080] S101. The access management node sends a network slice authentication request message to the terminal device, and the request message contains a slice identifier: Single Network Slice Selection Assistance Information (S-NSSAI).

[0081] S102. After receiving the request message, the terminal device replies a response message to the terminal device. The response message contains the slice identifier S-NSSAI and an Extensible Authentication Protocol (EAP) message, and the EAP message contains the EAP identifier assigned to the terminal device.

[0082] S103. The access management node sends a request message to the slice authentication function. The request message contains a user identifier: Generic Public Subscription Identifier (GPSI), the slice identifier S-NSSAI, and the EAP message received by the access management node in step S102.

[0083] S104. The slice authentication function sends an Authentication, Authorization, Accounting (AAA) protocol message to the AAA server. The AAA protocol message contains the user identifier GPSI, slice identifier S-NSSAI, and EAP message received by the slice authentication function in step S103.

[0084] S105. The AAA server replies with an AAA protocol message to the slice authentication function. The AAA protocol message contains the user identifier GPSI, slice identifier S-NSSAI, and the EAP message sent to the terminal device.

[0085] S106. The slice authentication function replies with a response message to the access management node. The response message contains the user identifier GPSI, slice identifier S-NSSAI, and EAP message received by the slice authentication function in step S105.

[0086] S107. The access management node sends a request message to the terminal device. The request message contains the slice identifier S-NSSAI and the EAP message.

[0087] S108. After receiving the network slice authentication request message, the terminal device replies with a response message to the access management node. The response message contains the slice identifier S-NSSAI and the EAP message sent to the AAA server.

[0088] S109. The access management node sends a request message to the slice authentication function. The request message contains the user identifier GPSI, slice identifier S-NSSAI, and the EAP message received by the access management node in step S108.

[0089] S1010. The slice authentication function sends an AAA protocol message to the AAA server. The AAA protocol message contains the user identifier GPSI, slice identifier S-NSSAI, and EAP message received by the slice authentication function in step S109.

[0090] It should be noted that steps S105 to S1010 are the process of completing an EAP message interaction (EAP authentication process) between the AAA server and the terminal device. Through the EAP authentication process, the terminal device and the AAA server authenticate each other. For example, the AAA server verifies the legal identity of the terminal device, and the terminal device verifies the legal identity of the AAA server, etc. The access management node and the slice authentication function are only used to forward the EAP messages between the terminal device and the AAA server during this process. If multiple EAP message interactions are required between the AAA server and the terminal device to complete the authentication process, steps S105 to S1010 can be executed multiple times, which will not be elaborated here.

[0091] S1011. The AAA server replies to the slice authentication function with an AAA protocol message, which contains the user identifier GPSI, the slice identifier S-NSSAI, the EAP message sent to the terminal device, and the authentication result (EAP success / failure) for this slice.

[0092] S1012. The slice authentication function replies with a response message to the access management node. The response message contains the user identifier GPSI, the slice identifier S-NSSAI, the EAP message, and the authentication result (EAP success / failure) received by the slice authentication function in step S1011.

[0093] S1013. The access management node sends a network slice authentication result notification message to the terminal device. The notification message contains the slice identifier S-NSSAI and the EAP message, and the EAP message contains information on whether the EAP authentication is successful or failed.

[0094] Through the above network slice authentication process, the access management node can learn that the authentication result of the network slice is EAP success / failure, and perform corresponding operations according to the authentication result. For example, for a network slice with EAP success, the access management node allows the terminal device to establish a session to this network slice; for a network slice with EAP failure, the access management node does not allow the terminal device to establish a session to this network slice.

[0095] It can be seen from the above network slice authentication process that the network slice authentication process involves multiple signaling interactions between the terminal device and the AAA server. When the terminal device moves, it may move out of the service range of the old access management node and needs to select a new access management node to access. In this case, to save signaling overhead, the new access management node can obtain the authentication result of the network slice from the old access management node, and thus does not need to execute the above network slice authentication process again for the new access management node.

[0096] However, the network slice authentication function is a function that only started to exist in the fifth-generation (5G) mobile communication network. When the terminal device moves from a 5G network (the first access management node) to a 4G network (the second access management node), and then moves to a 5G network (the third access management node, the third access management node may be the same as or different from the first access management node), since the second access management node does not support the network slice authentication function, it will not obtain the authentication result of the network slice from the first access management node, resulting in the third access management node being unable to obtain the authentication result of the network slice from the second access management node. Therefore, when the terminal device moves to the third access management node, it needs to re-execute the above network slice authentication process to obtain the authentication result.

[0097] Moreover, in the actual deployment of 5G mobile communication networks, only some access management nodes support the network slice authentication function, while some other access management nodes do not support the network slice authentication function. When a terminal device moves in a 5G network from a first access management node that supports the network slice authentication function to a second access management node that does not support the network slice authentication function, and then to a third access management node that supports the network slice authentication function, since the second access management node does not support the network slice authentication function, the third access management node cannot obtain the authentication result of the network slice from the second access management node. Therefore, when the terminal device moves to the third access management node, it still needs to re-execute the above network slice authentication process to obtain the authentication result.

[0098] In the above two scenarios of terminal device movement, the third access management node needs to re-execute the network slice authentication process to obtain the authentication result corresponding to the network slice, which increases the signaling overhead. Moreover, since the third access management node needs to obtain the authentication result to know whether the terminal device can establish a session to the network slice, and the network slice authentication process involves multiple signaling interactions between the terminal device and the AAA server and takes a certain amount of time, it also brings a certain delay to the services of the terminal device.

[0099] In view of this, the embodiments of the present application provide a slice authentication method and a corresponding device. When a terminal device is within the service range of any access management node, if the system executes the network slice authentication process for any network slice and obtains the authentication result of the network slice, the authentication result of the network slice can be saved to a specified network element (this specified network element can be a data management function or a slice authentication function, etc., which is not limited in the embodiments of the present application). In this way, when the terminal device moves to the service range of a new access management node, if the old access management node supports the network slice authentication function, the new access management node can not only obtain the authentication result of the network slice from the old access management node, but also obtain the authentication result of the network slice from the specified network element; if the old access management node does not support the network slice authentication function, the new access management node can obtain the authentication result of the network slice from the specified network element. It can be seen that through the embodiments of the present application, after the terminal device enters the service range of the new access management node from the service range of the old access management node, regardless of whether the old access management node supports the network slice authentication function, it does not need to re-execute the network slice authentication process to obtain the authentication result of the network slice, thus saving the system signaling overhead and improving the service performance of the terminal device. The specific solution will be further introduced in detail later.

[0100] The technical solution of the embodiment of the present application can be applied to various communication systems, such as: the fifth-generation (5G) communication system, the sixth-generation (6G) communication system, or other future evolved systems, or other various wireless communication systems adopting wireless access technologies, etc. As long as there is a network slice authentication requirement in the communication system, the technical solution of the embodiment of the present application can be adopted.

[0101] Figure 2 FIG. shows a network architecture diagram of a communication system applicable to the embodiment of the present application. The communication system includes a terminal device, an access node, an access management network element, a data management network element, a slice authentication network element, and an AAA server, etc. The terminal device accesses the wireless network through the access node at the current location. It should be noted that Figure 2 only one of each network element is exemplarily shown. In actual applications, any network element in the communication system may be multiple.

[0102] The access management network element is used for device registration, security authentication, mobility management, and location management of the terminal device, etc.

[0103] The data management network element is used for managing the subscribed data of the terminal device.

[0104] The slice authentication network element is used for forwarding relevant messages between the terminal device and the AAA server for slice authentication / slice re-authentication / authentication result revocation, etc.

[0105] The AAA server is used for performing EAP authentication of the network slice.

[0106] A terminal device, also known as a terminal, includes devices that provide voice and / or data connectivity to users. For example, it can include handheld devices with wireless connection capabilities, or processing devices connected to a wireless modem. The terminal device can communicate with the core network via a radio access network (RAN) and exchange voice and / or data with the RAN. The terminal device can include user equipment (UE), wireless terminal device, mobile terminal device, device-to-device (D2D) communication terminal device, vehicle-to-everything (V2X) terminal device, machine-to-machine / machine-type communications (M2M / MTC) terminal device, Internet of Things (IoT) terminal device, subscriber unit, subscriber station, mobile station, remote station, access point (AP), remote terminal, access terminal, user terminal, user agent, or user device, etc. For example, it can include mobile phones (or "cellular" phones), computers with mobile terminal devices, portable, pocket-sized, handheld, or computer-integrated mobile devices, etc. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), etc. It also includes restricted devices, such as devices with lower power consumption, or limited storage capacity, or limited computing capacity, etc. For example, it includes information sensing devices such as barcodes, radio frequency identification (RFID), sensors, global positioning system (GPS), laser scanners, etc.

[0107] By way of example and not limitation, in the embodiments of the present application, the terminal device may also be a wearable device. A wearable device may also be referred to as a wearable intelligent device or a smart wearable device, etc. It is a general term for devices developed by applying wearable technology to the intelligent design of daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is directly worn on the body or integrated into the user's clothes or accessories. A wearable device is not just a hardware device, but also realizes powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable intelligent devices include those with complete functions and large sizes that can achieve complete or partial functions without relying on a smartphone, such as smart watches or smart glasses, etc., and those that only focus on a certain type of application function and need to cooperate with other devices such as smartphones, such as various smart bracelets for physical sign monitoring, smart helmets, and smart jewelry.

[0108] And for various terminal devices introduced above, if they are located on a vehicle (for example, placed inside or installed inside a vehicle), they can all be considered in-vehicle terminal devices. In-vehicle terminal devices are also referred to as on-board units (OBUs) for example.

[0109] An access node, for example, includes an access network (AN) device, a radio access network (RAN) device. The access network device such as a base station (e.g., an access point) can refer to a device in the access network that communicates with a wireless terminal device through one or more cells over the air interface. The base station can be used to mutually convert the received air frames and Internet Protocol (IP) packets and act as a router between the terminal device and the rest of the access network, where the rest of the access network may include an IP network. The network device can also coordinate the attribute management of the air interface. For example, the network device can include an evolved Node B (NodeB or eNB or e-NodeB) in a Long Term Evolution (LTE) system or a Long Term Evolution - Advanced (LTE-A) system, or can also include a next generation Node B (gNB) or a next generation evolved Node B (ng-eNB), en-gNB (enhanced next generation Node B, gNB) in a 5th generation (5G) new radio (NR) system: an enhanced next generation base station; it can also include a centralized unit (CU) and a distributed unit (DU) in a cloud radio access network (Cloud RAN) system, or can also include a relay device, which is not limited in the embodiments of this application.

[0110] It should be understood that Figure 2 The shown network architecture can be applied to an actual mobile communication network. For example, when applied to a 5G mobile communication network, the access management node can be the Access & Mobility Function (AMF) in the 5G network, the data management function can be the Unified Data Management (UDM) in the 5G network, the slice authentication function can be the Network Slice - Specific Authentication and Authorization Function (NSSAAF) in the 5G network, and the AAA server can be the AAA Server (AAA - S) in the 5G network.

[0111] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be further described in detail below with reference to the accompanying drawings.

[0112] In the embodiments of this application, the terms "network slice" and "slice" refer to the same content, and one of them can be used to describe in different places, and the two can be interchanged.

[0113] In the embodiments of this application, each network element can be a physical concept. For example, physically, it can be a single device or node, or at least two network elements can be integrated on the same physical device or node. Or, the network elements shown in this article can also be logical concepts, such as software modules or network functions corresponding to the services provided by each network element. The network function can be understood as a virtualized function under virtualized implementation, and can also be understood as a network function that provides services in a service-based network. For example, a network function specifically used to allocate PDU session resources for the user plane, or a network function specifically used to perform EAP authentication for network slices, etc. The embodiments of this application do not make specific limitations.

[0114] The term "network element" in the embodiments of this application can also be replaced by other terms, such as it can be replaced by "function" or "node", etc. For example, "access management network element" can also be replaced by "access management node", "data management network element" can also be replaced by "data management function", "slice authentication network element" can also be replaced by "slice authentication function", etc.

[0115] In the embodiments of this application, the terms "system" and "network" can be used interchangeably. "At least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following (items)" or its similar expressions refer to any combination of these items, including any combination of single items (items) or multiple items (items). For example, at least one of a, b, or c can represent: a, or b, or c, or a and b, or b and c, or a and c, or a, b, and c.

[0116] Unless otherwise stated, the ordinal numbers such as "first" and "second" mentioned in the embodiments of this application are used to distinguish multiple objects, and are not used to limit the order, time sequence, priority, or importance of multiple objects. For example, the first priority criterion and the second priority criterion are only used to distinguish different criteria, rather than indicating differences in the content, priority, or importance of these two criteria, etc.

[0117] The terms "including" and "having" in the embodiments, claims, and accompanying drawings of this application are not exclusive. For example, a process, method, system, product, or device that includes a series of steps or modules is not limited to the listed steps or modules, but may also include steps or modules that are not listed.

[0118] As Figure 3 shown, it is a flowchart of a slice authentication method provided by an embodiment of this application. This method can be applied to Figure 2 the communication system shown. The method includes:

[0119] S301. After the terminal device moves from the second access management network element that does not support the network slice authentication function to the third access management network element that supports the network slice authentication function, the third access management network element sends a first request message to the first network element. The first request message includes the identification information of the first slice; the first network element receives the first request message from the third access management network element.

[0120] The first request message is used to request to obtain the authentication result corresponding to the first slice, and the first slice is the slice that needs to be authenticated.

[0121] The third access management network element determines that the second access management network element does not support the network slice authentication function includes the following three situations:

[0122] Situation 1. After the terminal device moves from the second access management network element to the third access management network element and learns that the second access management network element is the Mobility Management Entity (MME) of the 4G network, the third access management network element determines that the second access management network element does not support the network slice authentication function.

[0123] Situation 2. After the terminal device moves from the second access management network element to the third access management network element, the third access management network element obtains the user context of the terminal device from the second access management network element. If the authentication result corresponding to the first slice is not included in the user context, the third access management network element determines that the second access management network element does not support the network slice authentication function.

[0124] Situation 3. After the terminal device moves from the second access management network element to the third access management network element, the third access management network element obtains the list of supported features of the second access management network element from the second access management network element, and determines that the second access management network element does not support the network slice authentication function according to the list of supported features. For example, the list of features includes various features supported by the second access management network element, and the network slice authentication function is not included in the list of features, then the third access management network element determines that the second access management network element does not support the network slice authentication function.

[0125] S302. The first network element returns a first response message to the third access management network element. The first response message includes the authentication result corresponding to the first slice. The third access management network element receives the first response message returned by the first network element.

[0126] In the embodiment of the present application, the authentication result corresponding to the first slice is stored on a specified network element in the communication system, and the authentication result is either authentication success or authentication failure. The authentication result corresponding to the first slice stored on the specified network element is saved on the specified network element after the authentication corresponding to the first slice is completed before the terminal device moves from the second access management network element to the third access management network element.

[0127] For example, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports network slice authentication function to the second access management network element, where the first access management network element and the third access management network element may be the same or different. When the terminal device is within the service range of the first access management network element, if the communication system executes the network slice authentication process for the first slice, after the authentication corresponding to the first slice is completed, the authentication result corresponding to the first slice is saved to the specified network element. The method for the communication system to execute the network slice authentication process for the first slice can refer to Figure 1 , which will not be introduced in detail here.

[0128] Another example is that before the terminal device moves from the second access management network element to the third access management network element, the terminal device first moves from the first access management network element that supports network slice authentication function to the fourth access management network element that does not support network slice authentication function, and then moves from the fourth access management network element to the second access management network element that does not support network slice authentication function, where the first access management network element and the third access management network element may be the same or different. When the terminal device is within the service range of the first access management network element, the communication system executes the network slice authentication process for the first slice, and after the authentication corresponding to the first slice is completed, the authentication result corresponding to the first slice is saved to the specified network element.

[0129] Of course, before the terminal device moves from the second access management network element to the third access management network element, it may also experience more handovers of access management network elements, which are not restricted here. As long as the communication system performs the network slice authentication process for the first slice when the terminal device is within the service range of any access management network element before moving from the second access management network element to the third access management network element, the communication system can save the authentication result corresponding to the first slice to the specified network element. For ease of description, in the following embodiments, the process in which the terminal device first moves from the first access management network element supporting the network slice authentication function to the second access management network element not supporting the network slice authentication function, and then moves from the second access management network element not supporting the network slice authentication function to the third access management network element supporting the network slice authentication function is mainly used as an example.

[0130] In the embodiment of the present application, the slice authentication network elements connected by the first access management network element and the third access management network element may be the same or different, specifically depending on the actual deployment of the network architecture. For example, the first access management network element is connected to the first slice authentication network element, the second access management network element is connected to the second slice authentication network element, and the first slice authentication network element and the second slice authentication network element are different. Another example is that the first access management network element is connected to the first slice authentication network element, the second access management network element is connected to the second slice authentication network element, and the first slice authentication network element and the second slice authentication network element are the same (both the first access management network element and the second access management network element are connected to the first slice authentication network element).

[0131] In a possible design, the specified network element is the first network element. In other words, if the first network element stores the authentication result corresponding to the first slice, after receiving the first request message, the first network element reads the authentication result corresponding to the first slice from its own storage unit, and then generates and returns a first response message to the third access management network element.

[0132] For example, the first network element is specifically a data management network element. Before the terminal device moves from the second access management network element to the third access management network element, when the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element and is within the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first access management network element or the first slice authentication network element connected to the first access management network element stores the authentication result corresponding to the first slice in the data management network element.

[0133] Alternatively, for example, the first network element is specifically the first slice authentication network element. Before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function to the second access management network element. When the terminal device is within the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first slice authentication network element connected to the first access management network element stores the authentication result corresponding to the first slice.

[0134] In another possible design, the designated network element is the second network element, which is different from the first network element. In other words, the first network element does not store the authentication result corresponding to the first slice, but the first network element can obtain the authentication result corresponding to the first slice from the second network element that stores the authentication result corresponding to the first slice. After receiving the first request message, the first network element obtains the authentication result corresponding to the first slice from the second network element, and then generates and returns the first response message to the third access management network element.

[0135] For example, the first network element is specifically the second slice authentication network element, and the second network element is specifically the data management network element. Before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function to the second access management network element. When the terminal device is within the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice in the data management network element. After the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends the first request message to the second slice authentication network element; after receiving the first request message, the second slice authentication network element first obtains the authentication result corresponding to the first slice from the data management network element (for example, the second slice authentication network element sends the identification information of the first slice to the data management network element, and the data management network element returns the authentication result corresponding to the first slice to the second slice authentication network element according to the identification information of the first slice); then, the second slice authentication network element sends the authentication result corresponding to the first slice (the first response message) to the third access management network element.

[0136] Alternatively, for example, the first network element is specifically the second slice authentication network element, and the second network element is specifically the first slice authentication network element. Before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports the network slice authentication function to the second access management network element. When the terminal device is within the service range of the first access management network element, after the authentication corresponding to the first slice is completed, the first slice authentication network element connected to the first access management network element saves the authentication result corresponding to the first slice and registers the identifier of the first slice authentication network element to the data management network element, so as to facilitate other network elements to query the storage location of the authentication result corresponding to the first slice subsequently. After the terminal device moves from the second access management network element to the third access management network element, the third access management network element sends a first request message to the second slice authentication network element; after receiving the first request message, the second slice authentication network element first sends a request message (including the identifier information of the first slice, used to query the storage location of the authentication result corresponding to the first slice) to the data management network element. After receiving the request message, the data management network element returns the identifier of the first slice authentication network element (i.e., the storage location of the authentication result corresponding to the first slice) to the second slice authentication network element; the second slice authentication network element determines that the authentication result corresponding to the first slice is stored in the first slice authentication network element according to the received identifier of the first slice authentication network element, and sends the identifier information of the first slice to the first slice authentication network element; the first slice authentication network element returns the authentication result corresponding to the first slice to the second slice authentication network element. After receiving the authentication result corresponding to the first slice returned by the first slice authentication network element, the second slice authentication network element returns the authentication result corresponding to the first slice to the third access management network element (the first response message).

[0137] Of course, the above is only an example rather than a limitation on the specific implementation manner of the authentication result storage location and the first network element. In actual applications, it is not excluded that there are other implementation manners for the authentication result storage location and the first network element.

[0138] Optionally, after the first access management network element or the first slice authentication network element stores the authentication result corresponding to the first slice into the specified network element, the AAA server may trigger a withdrawal process or a re-authentication process for the authentication result corresponding to the first slice.

[0139] The AAA server triggering a withdrawal process or a re-authentication process for the authentication result corresponding to the first slice includes but is not limited to the following four situations:

[0140] Case 1. When the authentication result corresponding to the first slice is stored in the data management network element, when the terminal device is within the service range of the second access management network element, the AAA server can trigger a revocation process or a re-authentication process for the authentication result corresponding to the first slice. Since the second access management network element does not support the slice authentication function and the authentication result of the slice is stored in the specified network element, the slice authentication network element can notify the specified network element to execute the authentication result revocation or re-authentication.

[0141] 1) The AAA server triggers a revocation process for the authentication result corresponding to the first slice:

[0142] Specifically, when the authentication result is successful authentication, the AAA server can send an authentication revocation message to the first slice authentication network element or the second slice authentication network element; the first slice authentication network element or the second slice authentication network element modifies the authentication result corresponding to the first slice stored in the data management network element to authentication failure according to the authentication revocation message. The specific way for the first slice authentication network element or the second slice authentication network element to modify the authentication result corresponding to the first slice stored in the data management network element to authentication failure can be: the first slice authentication network element or the second slice authentication network element sends a first message (including the identifier of the first slice, used to notify the data management network element to modify the authentication result corresponding to the first slice to authentication failure) to the data management network element, and the data management network element modifies the authentication result corresponding to the first slice stored by itself to authentication failure according to the first message.

[0143] Optionally, the data management network element can specifically modify the authentication result corresponding to the first slice to EAP failure.

[0144] Of course, if there are other slice authentication network elements in the system, other slice authentication network elements can also be used to replace the first slice authentication network element or the second slice authentication network element to execute the above authentication result revocation process.

[0145] 2) The AAA server triggers a re-authentication process for the first slice:

[0146] Specifically, when the authentication result is successful authentication or authentication failure, the AAA server sends a re-authentication message to the first slice authentication network element or the second slice authentication network element; the first slice authentication network element or the second slice authentication network element deletes the authentication result corresponding to the first slice stored in the data management network element according to the re-authentication message. Further, the specific way for the first slice authentication network element or the second slice authentication network element to delete the authentication result corresponding to the first slice stored in the data management network element can be: the first slice authentication network element or the second slice authentication network element sends a second message (including the identifier of the first slice, used to notify the data management network element to delete the authentication result corresponding to the first slice) to the data management network element, and the data management network element deletes the authentication result corresponding to the first slice stored by itself according to the second message.

[0147] Of course, if there are other slice authentication network elements in the system, the above re-authentication process can also be performed by replacing the first slice authentication network element or the second slice authentication network element with other slice authentication network elements.

[0148] When the authentication result corresponding to the first slice stored in the data management network element is deleted, and the third access management network element discovers that the data management network element does not have the authentication result corresponding to the first slice, it will trigger the third access management network element to execute the re-authentication process for the first slice.

[0149] Optionally, if the authentication result corresponding to the first slice is specifically stored in the subscription data of the terminal device (the subscription data of the terminal device is stored on the data management network element), the above first message and second message can specifically be subscription data update request messages.

[0150] Case 2: When the authentication result corresponding to the first slice is stored in the first slice authentication network element, and the terminal device is within the service range of the second access management network element, the AAA server can trigger the withdrawal process or the re-authentication process for the authentication result corresponding to the first slice. Since the second access management network element does not support the slice authentication function and the authentication result of the slice is stored in the first slice authentication network element, the slice authentication network element can be notified to the first slice authentication network element to execute the authentication result withdrawal or re-authentication.

[0151] 1) The AAA server triggers the withdrawal process for the authentication result corresponding to the first slice:

[0152] Specifically, when the authentication result is a successful authentication, the AAA server sends an authentication withdrawal message to the first slice authentication network element, and the first slice authentication network element modifies the authentication result corresponding to the first slice stored in itself to an authentication failure according to the authentication withdrawal message; or, the AAA server sends an authentication withdrawal message to the second slice authentication network element, and the second slice authentication network element sends a third message (including the identifier of the first slice, used to notify the first slice authentication network element to modify the authentication result corresponding to the first slice to an authentication failure) to the first slice authentication network element according to the authentication withdrawal message, and the first slice authentication network element modifies the authentication result corresponding to the first slice stored in itself to an authentication failure according to the third message. Optionally, the first slice authentication network element can specifically modify the authentication result corresponding to the first slice to an EAP failure.

[0153] 2) The AAA server triggers the re-authentication process for the authentication result corresponding to the first slice:

[0154] Specifically, when the authentication result is successful authentication or failed authentication, the AAA server sends a re - authentication message to the first slice authentication network element, and the first slice authentication network element deletes the authentication result corresponding to the first slice stored in itself according to the re - authentication message; or, the AAA server sends a re - authentication message to the second slice authentication network element, and the second slice authentication network element sends a fourth message (including the identifier of the first slice, used to notify the first slice authentication network element to delete the authentication result corresponding to the first slice) to the first slice authentication network element according to the re - authentication message, and the first slice authentication network element deletes the authentication result corresponding to the first slice stored in itself according to the fourth message.

[0155] Case 3: When the authentication result corresponding to the first slice is stored in the data management network element, when the terminal device is within the service scope of the first access management network element, the AAA server can trigger a process for withdrawing or re - authenticating the authentication result corresponding to the first slice. Since the first access management network element supports the slice authentication function and the authentication result of the slice is stored in the first access management network element and the designated network element, the slice authentication network element can be used to notify the first access management network element to execute the withdrawal or re - authentication of the authentication result.

[0156] 1) The AAA server triggers a process for withdrawing the authentication result corresponding to the first slice:

[0157] Specifically, when the authentication result is successful authentication, the AAA server sends an authentication withdrawal message (including the identifier of the first slice) to the first slice authentication network element or the second slice authentication network element. After receiving the message, the first slice authentication network element or the second slice authentication network element sends an authentication withdrawal message (including the identifier of the first slice) to the first access management network element; after obtaining the authentication withdrawal message, the first access management network element sends a fifth message (including the identifier of the first slice, used to notify the data management network element to modify the authentication result corresponding to the first slice to failed authentication) to the data management network element; after receiving the fifth message, the data management network element modifies the authentication result corresponding to the first slice stored in itself to failed authentication.

[0158] 2) The AAA server triggers a process for re - authenticating the authentication result corresponding to the first slice:

[0159] Specifically, when the authentication result is successful authentication or failed authentication, the AAA server sends a re - authentication message (including the identifier of the first slice) to the first slice authentication network element or the second slice authentication network element; after receiving the re - authentication message, the first slice authentication network element or the second slice authentication network element sends a re - authentication message (including the identifier of the first slice) to the first access management network element; after obtaining the re - authentication message, the first access management network element sends a sixth message (including the identifier of the first slice, used to notify the data management network element to delete the authentication result corresponding to the first slice) to the data management network element; after receiving the sixth message, the data management network element deletes the authentication result corresponding to the first slice stored in itself.

[0160] Of course, in this case, the authentication result revocation or re - authentication can also be performed by the slicing authentication network element. The specific method can refer to the above - mentioned Case 1 and will not be elaborated here.

[0161] Optionally, if the authentication result corresponding to the first slice is specifically stored in the subscription data of the terminal device (the subscription data storage data management network element of the terminal device), then the above - mentioned fifth message and sixth message can specifically be subscription data update request messages.

[0162] Case 4, when the authentication result corresponding to the first slice is stored in the first slice authentication network element, when the terminal device is within the service range of the first access management network element, the AAA server can trigger the process of withdrawing the authentication result corresponding to the first slice or the re - authentication process. Since the first access management network element supports the slicing authentication function and the authentication result of the slice is stored in the first access management network element, the slicing authentication network element can be used to notify the first access management network element to perform the authentication result revocation or re - authentication.

[0163] 1) The AAA server triggers the process of withdrawing the authentication result corresponding to the first slice:

[0164] Specifically, when the authentication result is authentication success, first, the AAA server sends an authentication revocation message to the first slice authentication network element or the second slice authentication network element; then, the first slice authentication network element or the second slice authentication network element sends an authentication revocation message to the first access management network element; after obtaining the authentication revocation message, the first access management network element sends a seventh message (including the identifier of the first slice, used to notify the first slice authentication network element to modify the authentication result corresponding to the first slice to authentication failure) to the first slice authentication network element; after receiving the seventh message, the first slice authentication network element modifies the authentication result corresponding to the first slice stored in itself to authentication failure.

[0165] 2) The AAA server triggers the process of re - authenticating the authentication result corresponding to the first slice:

[0166] Specifically, when the authentication result is authentication success or authentication failure, first, the AAA server sends a re - authentication message to the first slice authentication network element or the second slice authentication network element; then, the first slice authentication network element or the second slice authentication network element sends a re - authentication message to the first access management network element; after obtaining the re - authentication message, the first access management network element sends an eighth message (including the identifier of the first slice, used to notify the first slice authentication network element to delete the authentication result corresponding to the first slice) to the first slice authentication network element; after receiving the eighth message, the first slice authentication network element re - authenticates the authentication result corresponding to the first slice stored in itself.

[0167] Of course, in this case, the authentication result revocation or re - authentication can also be performed by the slicing authentication network element. For the specific method, reference can be made to Case 2 above, which will not be elaborated here.

[0168] As can be seen from the above, in the embodiments of the present application, when the terminal device moves from the service range of the second access management network element that does not support the network slicing authentication function to the service range of the third access management network element that supports the network slicing authentication function, the third access management network element can obtain the authentication result of the network slice (such as the first slice) to be authenticated from the specified network element (such as the first slicing authentication network element, data management network element, etc.), without having to re - execute the network slicing authentication process, which can effectively save the system signaling overhead. At the same time, the terminal device no longer needs to wait for the third access management network element to complete the network slicing authentication process before establishing a session to a specific network slice, accelerating the service establishment process and reducing the service delay of the terminal device.

[0169] It should be understood that the above - mentioned embodiments can be combined with each other to achieve different technical effects.

[0170] To facilitate a clearer understanding of the technical solutions provided by the embodiments of the present application, several more specific implementation solutions are introduced below.

[0171] Embodiment 1

[0172] This embodiment mainly introduces: the authentication result of the network slice is stored on the data management network element, and the first access management network element stores the authentication result on the data management network element during the network slice authentication process; the third access management network element obtains the authentication result from the data management network element. Optionally, in the re - authentication or authentication result revocation process triggered by the AAA server, when the terminal device is within the service range of the second access management network element, after the second slicing authentication network element learns from the access management network element registration information obtained from the data management network element that the second access management network element does not support the network slicing authentication function, it directly modifies the authentication result on the data management network element; or, when the terminal device is within the service range of the first access management network element, after the second slicing authentication network element learns from the access management network element registration information obtained from the data management network element that the first access management network element supports the network slicing authentication function, the second slicing authentication network element notifies the first access management network element, and the first access management network element modifies the authentication result on the data management network element.

[0173] As Figure 4 shown, a specific slicing authentication method provided by this embodiment can be applied to the Figure 2 network architecture shown. The method includes:

[0174] S401. The first access management network element triggers the network slice authentication process.

[0175] Specifically, the terminal device accesses the first access management network element. The first access management network element obtains the subscription data of the terminal device from the data management network element. If the first access management network element learns from the slice identifier S-NSSAI included in the subscription data and its network slice authentication indication information that the network slice identified by the S-NSSAI (equivalent to the first slice in the above text) needs to perform network slice authentication, the first access management network element triggers the network slice authentication process. The specific process is the same as that of Figure 1 The process is the same. Among them, the first access management network element corresponds to Figure 1 the access management node in Figure 1 and the first slice authentication network element corresponds to

[0176] the slice authentication function in Figure 1 After the first access management network element learns the authentication result of the network slice (that is, after executing S1012 shown in

[0177] ), it continues to execute the following steps:

[0178] S402: The first access management network element sends a request message to the data management network element. The request message includes the slice identifier S-NSSAI and its authentication result (that is, the authentication result corresponding to the network slice identified by the S-NSSAI). After receiving the message, the data management network element updates the subscription data and stores the authentication result in the data corresponding to the slice identifier S-NSSAI in the subscription data. It should be noted that if the slice identifier S-NSSAI does not exist in the subscription data of the terminal device, the data management network element may not update the subscription data.

[0178] S403: The data management network element replies with a response message to the first access management network element to indicate whether the subscription data update is successful or failed.

[0179] It should be noted that the terminal device can subscribe to multiple slice identifiers S-NSSAI (that is, multiple different first slices) that need to perform network slice authentication. The first access management network element can execute multiple requests, and each request is used to store one or more slice identifiers S-NSSAI and the authentication results corresponding to the slices identified by each S-NSSAI.

[0180] The above S401 to S403 introduce the process of the first access management network element storing the authentication result in the data management network element. Next, the process of the new access management network element (that is, the third access management network element) obtaining the authentication result from the data management network element after the terminal device moves is introduced.

[0181] Scenario 1: The terminal device moves from a 5G network to a 4G network and selects the service of the second access management network element of the 4G network. Subsequently, the terminal device moves to a 5G network and selects the service of the third access management network element of the 5G network, where the third access management network element and the first access management network element may be the same or different. For the 4G network, the access management network element may specifically be a Mobility Management Entity (MME).

[0182] Scenario 2: The terminal device moves within a 5G network, from the first access management network element that supports the network slice authentication function to the second access management network element that does not support the network slice authentication function, and then moves to the third access management network element that supports the network slice authentication function, where the third access management network element and the first access management network element may be the same or different. For the 5G network, the access management network element may specifically be an Access & Mobility Function (AMF).

[0183] When the movement of the terminal device occurs in any of the above scenarios, after the terminal device moves from the first access management network element to the second access management network element, the second access management network element obtains the user context of the terminal device on the first access management network element. Since the second access management network element is a node of the 4G network, or the second access management network element does not support the network slice authentication function, the user context sent by the first access management network element does not contain the slice identifier S-NSSAI and its authentication result. Or, the user context sent by the first access management network element contains the slice identifier S-NSSAI and its authentication result, but the second access management network element directly discards it because it does not recognize the slice identifier S-NSSAI and its authentication result. After the first access management network element sends the user context to the second access management network element, it deletes the locally stored user context.

[0184] Subsequently, when the terminal device moves from the second access management network element to the third access management network element, the process is similar. The third access management network element obtains the user context of the terminal device on the second access management network element. The user context does not contain the slice identifier S-NSSAI and its authentication result.

[0185] Please continue to refer to Figure 4 , in the process of the terminal device moving from the second access management network element to the third access management network element, the terminal device triggers a registration update process:

[0186] S404: In the registration process, the terminal device sends a registration update request message to the third access management network element.

[0187] S405: In the registration process, the third access management network element sends a subscription data request message (the first request message) to obtain the subscription data of the terminal device from the data management node.

[0188] S406: The data management node sends a subscription data response message (the first response message) to the third access management network element, and the subscription data contains the authentication result.

[0189] Optionally, the subscription data further contains a slice identifier S-NSSAI.

[0190] Optionally, the subscription data can further contain multiple slice identifiers S-NSSAI (i.e., multiple first slices) and their authentication results.

[0191] After obtaining the above slice identifier S-NSSAI and its authentication result, the third access management network element performs an operation of allowing or not allowing the terminal device to establish a session to the network slice, and does not repeat the network slice authentication process.

[0192] Alternatively, in the above S401 - S403 processes, the slice authentication network element can also store the authentication result of the network slice into the subscription data of the terminal device. The specific difference is that the above S401 - S403 are sequentially replaced with the following steps 1) - 3):

[0193] 1) The terminal device accesses the first access management network element. The first access management network element obtains the subscription data of the terminal device from the data management network element. According to the slice identifier S-NSSAI and its network slice authentication indication information contained in the subscription data, the first access management network element learns that the network slice identified by S-NSSAI (equivalent to the first slice in the above text) needs to perform the network slice authentication process, and then the first access management network element triggers the network slice authentication process. The specific process is the same as Figure 1 the process. Among them, the first access management network element corresponds to Figure 1 the access management node in Figure 1 and the first slice authentication network element corresponds to

[0194] the slice authentication function in Figure 1 When the first slice authentication network element learns the authentication result of the network slice (i.e., after executing

[0195] 2) The first slice authentication network element sends a request message to the data management network element. The message contains the slice identifier S-NSSAI and its authentication result. After receiving the message, the data management network element updates the subscription data and stores the authentication result into the data corresponding to the slice identifier S-NSSAI in the subscription data. If the slice identifier S-NSSAI does not exist in the subscription data of the terminal device, the data management network element does not update the subscription data;

[0196] 3) The data management network element replies with a response message to the first slice authentication network element, which is used to indicate whether the subscription data update is successful or failed.

[0197] Similarly, the terminal device may subscribe to multiple slice identifiers S-NSSAI that require network slice authentication. The first slice authentication network element may perform multiple requests, and each request is used to store one or more slice identifiers S-NSSAI and their corresponding authentication results.

[0198] After the first access management network element or the first slice authentication network element stores the authentication result in the subscription data, the AAA service may also trigger a process for withdrawing the authentication result or re-authentication.

[0199] The following describes the method for the AAA service to trigger the process of withdrawing the authentication result or re-authentication.

[0200] As Figure 5 shown, it is a flowchart of a method for withdrawing an authentication result provided by an embodiment of the present application. This method can be applied to Figure 2 the network architecture shown, and specifically can be executed when the terminal device accesses the first access management network element or the second access management network element. The method includes:

[0201] S501: The AAA server sends an AAA protocol message to the second slice authentication network element, which is used to trigger the process of withdrawing the authentication result or re-authentication.

[0202] Specifically, due to configuration information modification, etc. on the AAA server, the process of withdrawing the authentication result (i.e., Figure 5 S501a shown) or the re-authentication process (i.e., Figure 5 S501b shown) is triggered. Among them, the process of withdrawing the authentication result is applied to the network slice with the authentication result of EAP success, and the authentication result is changed to EAP failure; the re-authentication process is used to notify the access management network element to trigger the network slice authentication process and re-perform EAP authentication on the network slice. The AAA server sends the corresponding AAA protocol message to the second slice authentication network element, and the second slice authentication network element may be the same as or different from the first slice authentication network element.

[0203] S502: After receiving the message, the second slice authentication network element sends a request message to the data management network element, and this request message is used to query the registration information of the mobility management network element of the serving terminal device;

[0204] S503: The data management network element sends a response message to the second slice authentication network element. The response message contains the mobility management network element registration information, and the mobility management network element registration information contains the access management network element identifier. For example, the access management network element identifier is the network function instance identity (NF Instance ID).

[0205] The content of the mobility management network element registration information includes but is not limited to the following three cases:

[0206] Case1, the mobility management network element registration information includes the access management network element identifier. When the terminal device is currently accessing through the first access management network element, the access management network element identifier is the identifier of the first access management network element.

[0207] Case2, the mobility management network element registration information includes the access management network element identifier. When the terminal device moves from the first access management network element to the second access management network element, that is, in the scenario of the above scenario 1, if the second access management network element is within the 4G network, the access management network element identifier is the identifier of the first access management network element; and the mobility management network element registration information also contains a clear indication, and the clear indication is used to indicate that the first access management network element has been separated.

[0208] Case3, the mobility management network element registration information includes the access management network element identifier. When the terminal device moves from the first access management network element to the second access management network element, in the scenario of the above scenario 2, if the second access management network element is within the 5G network, the access management network element identifier is the identifier of the second access management network element, and the mobility management network element registration information also contains the features supported by the second access management network element, indicating that the second access management network element does not support the network slice authentication function.

[0209] The second slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:

[0210] A. If the mobility management network element registration information contains the identifier of the access management network element, and the clear indication indicates that the access management network element is separated, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is, the above case2 or 3, the second slice authentication network element executes S504a and S505a.

[0211] S504a: The second slice authentication network element sends a subscription data update request message to the data management network element. The message contains the slice identifier S-NSSAI. Optionally, the message also contains the authentication result.

[0212] Specifically, according to the AAA protocol message received in step S501, if the AAA server triggers an authentication result withdrawal process, the subscription data update request message is used to notify the data management network element to modify the authentication result. The subscription data update request message carries the authentication result and the authentication result is EAP failure. If the AAA server triggers a re-authentication process, the subscription data update request message is used to notify the data management network element to delete the authentication result. The subscription data update request message may not contain the authentication result, or contain an empty authentication result, or contain the authentication result and also contain a deletion indication message. Correspondingly, if the AAA server triggers an authentication result withdrawal process, the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the subscription data on the data management network element to EAP failure; if the AAA server triggers a re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the subscription data on the data management network element.

[0213] S505a: The data management network element replies with a subscription data update response message to the second slice authentication network element, which is used to indicate whether the subscription data update is successful or failed.

[0214] B. If the mobility management network element registration information contains the identifier of the access management network element and the purge indication indicates that the access management network element has not detached, or the mobility management network element registration information does not contain the purge indication message and the supported feature information indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the second slice authentication network element executes step S504b and subsequent steps or step S504c and subsequent steps.

[0215] The following separately introduces the authentication result withdrawal and re-authentication processes.

[0216] If the AAA server triggers a re-authentication process, then execute:

[0217] S504b: The second slice authentication network element sends a re-authentication notification message to the first access management network element, and the message contains the user identifier and the slice identifier S-NSSAI.

[0218] S505b: The first access management network element replies with a re-authentication notification response message.

[0219] S506b: The first access management network element triggers a network slice authentication process for the re-authenticated network slice, and the specific process is the same as Figure 1 the process.

[0220] S507b: The first access management network element sends a subscription data update request message to the data management network element, and the subscription data update request message carries the slice identifier and the authentication result obtained after re-authentication.

[0221] S508: The data management network element replies with a subscribed data update response message to the first access management network element, which is used to indicate whether the subscribed data update is successful or failed.

[0222] If the AAA server triggers an authentication result revocation process, then execute:

[0223] S504c: The second slice authentication network element sends an authentication result revocation notification message to the first access management network element, and the message contains the user identifier and the slice identifier S-NSSAI.

[0224] S505c: The first access management network element replies with an authentication result revocation notification response message.

[0225] S506a: The first access management network element sends a subscribed data update request message to the data management network element, and the message contains the slice identifier S-NSSAI and its authentication result. The message is used to modify the authentication result corresponding to the slice identifier S-NSSAI to EAP failure. After receiving the message, the data management network element updates the subscribed data and stores the authentication result in the data corresponding to the slice identifier S-NSSAI in the subscribed data.

[0226] S507a: The data management network element replies with a subscribed data update response message to the first access management network element, which is used to indicate whether the subscribed data update is successful or failed.

[0227] It should be noted that in the above process, S507b and S506a can also be executed by the second slice authentication network element, storing the authentication result obtained after re-authentication in the subscribed data of the terminal device, or modifying the authentication result corresponding to the slice identifier S-NSSAI to EAP failure.

[0228] In the above Embodiment 1, the first access management network element stores the authentication result on the data management network element during the network slice authentication process, so that in the mobile scenarios listed in the above Scenario 1 and Scenario 2, the third access management network element can obtain the authentication result from the data management network element, and thus does not need to execute the network slice authentication process for the network slice, saving network signaling overhead. At the same time, the terminal device also does not need to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, accelerating the service establishment process and improving the service experience of the terminal device. In addition, when the data management network element stores the authentication result, the AAA server can also trigger a re-authentication or authentication result revocation process, improving the flexibility of network slice authentication.

[0229] Embodiment 2

[0230] This embodiment mainly introduces: the authentication result is stored on the data management network element, and the first slice authentication network element stores it on the data management network element during the network slice authentication process; the third access management network element requests the authentication result from the second slice authentication network element, and the second slice authentication network element requests the authentication result from the data management network element. Optionally, in the re-authentication or authentication result withdrawal process triggered by the AAA server, the second slice authentication network element modifies the authentication result on the data management network element.

[0231] The differences from Example 1 include: In Example 2, the authentication result is stored by the slice authentication network element to the data management network element, and is also obtained by the slice authentication network element from the data management network element; while in Example 1, the authentication result is stored by the access management network element to the data management network element, and is also obtained by the access management network element from the data management network element.

[0232] like Figure 6 As shown, it is a flowchart of another specific slice authentication method provided in an embodiment of the present application, which can be applied to Figure 2 In the network architecture shown, the method includes:

[0233] S601. The first access management network element triggers the network slice authentication process.

[0234] Specifically, the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element learns that the network slice identified by S-NSSAI (equivalent to the first slice mentioned above) needs to perform network slice authentication based on the slice identifier S-NSSAI contained in the subscription data and its network slice authentication indication information, then the first access management network element triggers the network slice authentication process, and the specific process is Figure 1 The process is the same. The first access management network element corresponds to Figure 1 The access management network element in the first slice authentication network element corresponds to Figure 1 Slice authentication function in .

[0235] When the first slice authentication network element obtains the authentication result of the network slice (i.e., completes the Figure 1 After S1011), continue to perform the following steps:

[0236] S602: The first slice authentication network element sends a request message to the data management network element, the message including the slice identifier S-NSSAI and its authentication result. After receiving the message, the data management network element stores the slice identifier S-NSSAI and its authentication result.

[0237] Optionally, the data management network element may determine whether the subscribed slice identifier S-NSSAI is subscribed in the subscription data of the terminal device. If the slice identifier S-NSSAI does not exist in the subscription data of the terminal device, the data management network element does not store the slice identifier S-NSSAI and its authentication result.

[0238] S603: The data management network element sends a response message to the first slice authentication network element to indicate whether the authentication result update is successful or failed.

[0239] It should be noted that the terminal device may subscribe to multiple slice identifiers S-NSSAI that require network slice authentication. The first slice authentication network element may perform multiple requests, and each request is used to store one or more slice identifiers S-NSSAI and their corresponding authentication results.

[0240] The above S601 - S603 introduce the process of the first slice authentication network element storing the authentication result in the data management network element. Next, the process of the new access management network element (the third access management network element) obtaining the authentication result from the data management network element after the terminal device moves is introduced.

[0241] The scenarios where the terminal device moves can refer to Scenario 1 and Scenario 2 in Embodiment 1, which will not be elaborated here.

[0242] Please continue to refer to Figure 6 , in the process of the terminal device moving from the second access management network element to the third access management network element, the terminal device triggers a registration update process:

[0243] S604: The terminal device sends a registration update request message to the third access management network element.

[0244] S605: In the registration update process, the third access management network element sends an authentication result request message (the first request message) to the second slice authentication network element to obtain the authentication result of the terminal device. This message contains the identifier of the terminal device and also contains one or more slice identifiers S-NSSAI.

[0245] S606: The second slice authentication network element sends an authentication result request message to the data management network element. The message contains the identifier of the terminal device and also contains one or more slice identifiers S-NSSAI.

[0246] S607: The data management network element sends an authentication result response message to the second slice authentication network element. The message contains its authentication result.

[0247] Optionally, the message may also contain the slice identifier S-NSSAI.

[0248] Optionally, the authentication result response message may specifically include multiple slice identifiers S-NSSAI, and the authentication result corresponding to each slice.

[0249] S608: The second slice authentication network element replies with an authentication result response message (the first response message) to the third access management network element, and the authentication result response message includes the authentication result. Optionally, the authentication result response message further includes the slice identifier S-NSSAI.

[0250] Specifically, the authentication result response message may include one or more slice identifiers S-NSSAI and their authentication results.

[0251] After the first slice authentication network element stores the authentication result in the authentication result data, the AAA service may further trigger the process of withdrawing the authentication result or re-authentication. The following describes the method for the AAA service to trigger the process of withdrawing the authentication result or re-authentication.

[0252] As Figure 7 shown, it is a flowchart of another method for withdrawing the authentication result provided by the embodiment of the present application. This method can be applied to Figure 2 the network architecture shown, and can be specifically executed when the terminal device accesses the first access management network element or the second access management network element. The method includes:

[0253] S701: The AAA server sends an AAA protocol message to the second slice authentication network element to trigger the process of withdrawing the authentication result or re-authentication.

[0254] For the specific implementation process of S701, reference can be made to the specific implementation process of S501 in the above text, which will not be elaborated here.

[0255] S702: After receiving the message, the second slice authentication network element sends a request message to the data management network element, and the request message is used to query the mobile management network element registration information of the service terminal device.

[0256] S703: The data management network element replies with a response message to the second slice authentication network element. The message includes the mobile management network element registration information, and the mobile management network element registration information includes the access management network element identifier. For example, the access management network element identifier is the NF Instance ID.

[0257] The content of the mobile management network element registration information can refer to the three cases (Case1, Case2, Case3) in Embodiment 1, which will not be elaborated here.

[0258] Furthermore, the second slice authentication network element performs different processing according to the specific content of the received mobile management network element registration information:

[0259] A. If the mobility management network element registration information contains the identifier of the access management network element, and the clear indication indicates the separation of the access management network element, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is, the above case 2 or 3, the second slice authentication network element executes S704a and S705a.

[0260] S704a: The second slice authentication network element sends an authentication result update request message to the data management network element. The authentication result update request message contains the slice identifier S-NSSAI. Optionally, the authentication result update request message also contains the authentication result.

[0261] After receiving the authentication result update request message, if the AAA server triggers an authentication result withdrawal process, the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the authentication result data to EAP failure; if the AAA server triggers a re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the subscribed data.

[0262] Specifically, according to the AAA protocol message received in step S701, if the AAA server triggers an authentication result withdrawal process, the authentication result update request message is used to notify the data management network element to modify the authentication result, and the subscribed data update request message carries the authentication result and the authentication result is EAP failure. If the AAA server triggers a re-authentication process, the authentication result update request message is used to notify the data management network element to delete the authentication result, and the subscribed data update request message may not contain the authentication result, or contain an empty authentication result, or contain the authentication result and also contain a deletion indication message.

[0263] It should be noted that in this embodiment, the slice identifier S-NSSAI and the authentication result are stored in the authentication result data of the data management network element. The difference from Embodiment 1 is that in Embodiment 1, the authentication result is stored in the data corresponding to the slice identifier S-NSSAI in the subscribed data of the data management network element. Therefore, in S704a of this embodiment, the second slice authentication network element sends an authentication result update request message to the data management network element, while in S504a of Embodiment 1, the second slice authentication network element sends a subscribed data update request message to the data management network element.

[0264] S705a: The data management network element replies with an authentication result update response message to the second slice authentication network element, which is used to indicate whether the update of the authentication result data is successful or failed.

[0265] B. If the mobility management network element registration information contains the identifier of the access management network element, and the purge indication indicates that the access management network element is not detached, or the mobility management network element registration information does not contain the purge indication information, and the supported feature information indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the second slice authentication network element executes step S704b and subsequent steps or S704c and subsequent steps.

[0266] The authentication result withdrawal and re - authentication processes are introduced separately below.

[0267] If the AAA server triggers the re - authentication process, then execute:

[0268] S704b: The second slice authentication network element sends a re - authentication notification message to the first access management network element, and the message contains the user identifier and the slice identifier S - NSSAI.

[0269] S705b: The first access management network element replies with a re - authentication notification response message.

[0270] S706b: The first access management network element triggers a network slice authentication process for the re - authenticated network slice, and the specific process is the same as Figure 1 the process.

[0271] S707b: The second slice authentication network element sends an authentication result update request message to the data management network element, and the message carries the slice identifier and the authentication result obtained after re - authentication.

[0272] S708: The data management network element replies with an authentication result update response message to the second slice authentication network element, which is used to indicate whether the subscribed data update is successful or failed.

[0273] If the AAA server triggers the authentication result withdrawal process, then execute:

[0274] S704c: The second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, and the message contains the user identifier and the slice identifier S - NSSAI;

[0275] S705c: The first access management network element replies with an authentication result withdrawal notification response message;

[0276] S706a: The second slice authentication network element sends an authentication result update request message to the data management network element. The message contains the slice identifier S - NSSAI and its authentication result. The message is used to modify the authentication result corresponding to the slice identifier S - NSSAI to EAP failure. After receiving the message, the data management network element stores the slice identifier S - NSSAI and its authentication result.

[0277] S707a: The data management network element replies to the second slice authentication network element with an authentication result update response message to indicate whether the authentication result update is successful or failed.

[0278] In the second embodiment above, the first slice authentication network element stores the authentication result on the data management network element during the network slice authentication process. In the mobile scenarios listed in Scenario 1 and Scenario 2 above for the terminal device, the third access management network element can obtain the authentication result from the data management network element. Thus, there is no need to execute the network slice authentication process for the network slice, saving network signaling overhead. At the same time, the terminal device does not need to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, accelerating the service establishment process and improving the service experience of the terminal device. Additionally, when the data management network element stores the authentication result, the AAA server can also trigger a re-authentication or authentication result withdrawal process, enhancing the flexibility of network slice authentication.

[0279] Embodiment 3

[0280] This embodiment mainly introduces that the authentication result is stored on the first slice authentication network element. The first slice authentication network element stores the authentication result during the network slice authentication process and also registers the first slice authentication network element registration information with the data management network element. The third access management network element requests the authentication result from the second slice authentication network element, and the second slice authentication network element obtains the first slice authentication network element registration information from the data management network element and requests the authentication result from the first slice authentication network element according to the first slice authentication network element registration information. Optionally, in the re-authentication or authentication result withdrawal process triggered by the AAA server, the second slice authentication network element notifies the first slice authentication network element to update the authentication result.

[0281] As Figure 8 shown, another specific slice authentication method provided by this embodiment can be applied to the Figure 2 network architecture shown. The method includes:

[0282] S801. The first access management network element triggers the network slice authentication process.

[0283] Specifically, when the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element. The first access management network element learns from the slice identifier S-NSSAI and its network slice authentication indication information included in the subscription data that the network slice (equivalent to the first slice in the above text) identified by the S-NSSAI needs to execute the network slice authentication process. Then the first access management network element triggers the network slice authentication process, and the specific process is the same as the Figure 1 process. Among them, the first access management network element corresponds to Figure 1The access management node therein, the first slice authentication network element corresponds to Figure 1 the slice authentication function therein.

[0284] When the first slice authentication network element learns the authentication result of the network slice (that is, after executing Figure 1 S1011 shown), the following steps are continued:

[0285] S802: The first slice authentication network element saves the user identifier, the network slice S-NSSAI, and the authentication result.

[0286] S803: The first slice authentication network element sends a registration request message to the data management network element to register the first slice authentication network element information in the data management network element. The message contains the user identifier, the network slice S-NSSAI, and the first slice authentication network element identifier. For example, the first slice authentication network element identifier may be a network function instance identifier.

[0287] S804: The data management network element replies with a registration response message to the first slice authentication network element to indicate whether the registration of the first slice authentication network element information is successful or failed.

[0288] S805: The data management network element saves the registration information of the first slice authentication network element.

[0289] The above S801-S805 introduce the process of the first slice authentication network element storing the authentication result and registering the first slice authentication network element registration information in the data management network element. Next, the process of the new access management network element (the third access management network element) obtaining the authentication result from the first slice authentication network element after the terminal device moves is introduced.

[0290] The scenarios where the terminal device moves can refer to Scenario 1 and Scenario 2 in Embodiment 1, which will not be elaborated here.

[0291] Please continue to refer to Figure 8 , in the process of the terminal device moving from the second access management network element to the third access management network element, the terminal device triggers a registration update process:

[0292] S806: In the registration process, the terminal device sends a registration update request message to the third access management network element;

[0293] S807: In the registration process, the third access management network element selects a second slice authentication network element and sends an authentication result acquisition request message (the first request message) to the second slice authentication network element. The message contains the user identifier and the network slice S-NSSAI.

[0294] S808: When the second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, it sends a message for obtaining slice authentication registration information to the data management network element, and the message contains the user identifier and the network slice S-NSSAI.

[0295] S809: The data management network element replies with a response message for obtaining slice authentication registration information to the second slice authentication network element, and the message contains slice authentication network element registration information, and the slice authentication network element registration information includes the identifier of the first slice authentication network element.

[0296] Optionally, the slice authentication network element registration information further includes the network slice S-NSSAI.

[0297] The data management network element queries the slice authentication network element registration information corresponding to the parameters in the message of step S807, and sends the slice authentication network element registration information to the second slice authentication network element.

[0298] S8010: The second slice authentication network element sends a message for requesting an authentication result to the first slice authentication network element according to the identifier of the first slice authentication, and the message contains the user identifier and the network slice S-NSSAI.

[0299] S8011: The first slice authentication network element replies with a response message for obtaining the authentication result to the second slice authentication network element, and the authentication result response message contains the authentication result.

[0300] Optionally, the authentication result response message further includes the user identifier and the network slice S-NSSAI.

[0301] S8012: The second slice authentication network element replies with a response message for obtaining the authentication result to the third access management network element (the first response message), and the authentication result response message contains the authentication result.

[0302] Optionally, the authentication result response message may further include the user identifier and the network slice S-NSSAI.

[0303] It should be noted that the terminal device may subscribe to multiple slice identifiers S-NSSAI that need to perform network slice authentication. The second slice authentication network element may execute multiple requests for obtaining the authentication result, and each request is used to request one or more slice identifiers S-NSSAI and their corresponding authentication results.

[0304] It should be understood that in the above process of obtaining slice authentication registration information, the access management network element may also obtain the slice authentication registration information from the data management network element, and further obtain the authentication result of the network slice. Specifically, S807-S8012 are replaced with the following steps 1) - 4):

[0305] 1) The third access management network element sends a message for obtaining slice authentication registration information to the data management network element, and the message contains a user identifier and a network slice S-NSSAI.

[0306] 2) The data management network element replies with a response message for obtaining slice authentication registration information to the third access management network element, and the message contains slice authentication network element registration information, and the slice authentication network element registration information contains a network slice S-NSSAI and an identifier of the first slice authentication network element.

[0307] 3) The third access management network element sends a request message for obtaining an authentication result to the first slice authentication network element according to the identifier of the first slice authentication network element, and the message contains a user identifier and a network slice S-NSSAI.

[0308] 4) The first slice authentication network element replies with a response message for obtaining an authentication result, and the message contains a user identifier, a network slice S-NSSAI, and an authentication result.

[0309] After the first slice authentication network element saves the authentication result, the AAA service can also trigger a process for withdrawing the authentication result or re-authentication.

[0310] The following introduces a method for the AAA service to trigger a process for withdrawing the authentication result or re-authentication.

[0311] As Figure 9 shown, it is a flowchart of another method for withdrawing an authentication result provided by an embodiment of the present application, and this method can be applied to Figure 2 the network architecture shown, and can be specifically executed when a terminal device accesses through the first access management network element or the second access management network element. The method includes:

[0312] S901: The AAA server sends an AAA protocol message to the second slice authentication network element to trigger a process for withdrawing the authentication result or re-authentication.

[0313] For the specific implementation process of S901, reference can be made to the specific implementation process of S501 in the foregoing text, and details are not described herein again.

[0314] S902: After receiving the message, the second slice authentication network element sends a request message to the data management network element, and the request message is used to query the mobile management network element registration information of the service terminal device.

[0315] S903: The data management network element replies with a response message to the second slice authentication network element, and the message contains mobile management network element registration information, and the mobile management network element registration information contains an access management network element identifier. For example, the access management network element identifier is an NF Instance ID.

[0316] The content of the registration information of the mobility management network element can refer to the three cases (Case1, Case2, Case3) in Embodiment 1, which will not be elaborated here.

[0317] Furthermore, the second slice authentication network element performs different processing according to the specific content of the received registration information of the mobility management network element:

[0318] A. If the registration information of the mobility management network element contains the identifier of the access management network element, and the clearing indication indicates the separation of the access management network element, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is, the above case2 or 3, the second slice authentication network element executes steps S904, S905, S906a, and S907a. Optionally, steps S908a and S909a can also be executed.

[0319] S904: The second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, and sends a message to obtain slice authentication registration information to the data management network element, and the message contains the user identifier and the network slice S-NSSAI.

[0320] S905: The data management network element replies with a message to obtain slice authentication registration information response to the second slice authentication network element, and the message contains slice authentication network element registration information, and the slice authentication network element registration information contains the network slice S-NSSAI and the identifier of the first slice authentication network element. Specifically, the data management network element queries the slice authentication network element registration information corresponding to the parameters according to the parameters in the S904 message, and sends the slice authentication network element registration information to the second slice authentication network element. S906a: The second slice authentication network element sends an update authentication result request message to the first slice authentication network element, and the message contains the user identifier, the slice identifier S-NSSAI, and its authentication result. After receiving the message, the first slice authentication network element updates the authentication result. If the AAA server triggers an authentication result withdrawal process, the second slice authentication network element modifies the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element to EAP failure. If the AAA server triggers a re-authentication process, the second slice authentication network element deletes the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element.

[0321] S907a: The first slice authentication network element replies with an update authentication result response message to the second slice authentication network element, which is used to indicate whether the authentication result update is successful or failed.

[0322] If in S906a, for the re-authentication process triggered by the AAA server, the authentication result corresponding to the slice identifier S-NSSAI in the first slice authentication network element needs to be deleted, the first slice authentication network element executes S908a and S909a.

[0323] S908a: The first slice authentication network element sends a deregistration request message to the data management network element. The message contains the slice identifier S-NSSAI and may also contain the identifier of the first slice authentication network element.

[0324] S909a: The data management network element replies with a deregistration response message to the first slice authentication network element to indicate whether the deregistration of the first slice authentication network element is successful or failed.

[0325] If the mobility management network element registration information contains the identifier of the access management network element, and the clearing indication indicates that the access management network element has not detached, or the mobility management network element registration information does not contain the clearing indication information, and the supported feature information indicates that the access management network element supports the network slice authentication function, that is, the above case 1, the second slice authentication network element executes steps S904, S905, S906b or S906c and subsequent steps.

[0326] S904: If the second slice authentication network element does not have the authentication result corresponding to the user identifier and the network slice S-NSSAI locally, it sends a message to obtain slice authentication registration information to the data management network element. The message contains the user identifier and the network slice S-NSSAI.

[0327] S905: The data management network element replies with a response message to obtain slice authentication registration information to the second slice authentication network element. The message contains the slice authentication network element registration information, and the slice authentication network element registration information contains the network slice S-NSSAI and the identifier of the first slice authentication network element. Specifically, the data management network element queries the slice authentication network element registration information corresponding to the parameters according to the parameters in the S904 message and sends the slice authentication network element registration information to the second slice authentication network element.

[0328] Here, the process of the right result withdrawal triggered by the AAA server and the re-authentication process are introduced separately.

[0329] 1) The AAA server triggers re-authentication:

[0330] S906b: The second slice authentication network element sends a re-authentication notification message to the first access management network element. The message contains the user identifier and the slice identifier S-NSSAI.

[0331] S907b: The first access management network element replies with a re-authentication notification response message.

[0332] S908b: The first access management network element triggers a network slice authentication process for the re-authenticated network slice. The specific process is the same as Figure 1 the process.

[0333] S909b: After the second slice authentication network element obtains the authentication result sent by the AAA server in the network slice authentication process, it notifies the first slice authentication network element to update the authentication result of the network slice.

[0334] For the specific implementation process, reference can be made to S906a and S907a, which will not be elaborated here.

[0335] 2) The AAA server triggers the authentication result withdrawal process:

[0336] S906c: The second slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, and the message contains the user identifier and the slice identifier S-NSSAI.

[0337] S907c: The first access management network element replies with an authentication result withdrawal notification response message.

[0338] S908c: After the second slice authentication network element receives the withdrawal of the authentication result from the AAA server, it notifies the first slice authentication network element to update the authentication result of the network slice, and changes the authentication result to EAP failure.

[0339] For the specific implementation process, reference can be made to S906a and S907a, which will not be elaborated here.

[0340] In the above Embodiment 3, the first slice authentication network element stores the authentication result during the network slice authentication process, and registers the registration information of the first slice authentication network element with the data management network element, so that in the mobile scenarios listed in the above Scenario 1 and Scenario 2, the third access management network element can obtain the authentication result through the second slice authentication network element (that is, trigger the second slice authentication network element to obtain the registration information of the first slice authentication network element from the data management network element, obtain the authentication result from the first slice authentication network element according to the registration information of the first slice authentication network element, and then return the authentication result to the third access management network element). Furthermore, it is not necessary to execute the network slice authentication process for the network slice, saving network signaling overhead. At the same time, the terminal device does not need to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, accelerating the service establishment process and improving the service experience of the terminal device. In addition, when the data management network element stores the authentication result, the AAA server can also trigger the re-authentication or authentication result withdrawal process, improving the flexibility of network slice authentication.

[0341] Embodiment 4

[0342] This embodiment mainly introduces: the authentication result is stored in the first slice authentication network element, and the first slice authentication network element stores the authentication result during the network slice authentication process; the third access management network element requests the authentication result from the first slice authentication network element. Optionally, in the re-authentication or authentication result withdrawal process triggered by the AAA server, the AAA server directly notifies the first slice authentication network element to update the authentication result.

[0343] The difference between the fourth embodiment and the third embodiment includes: in the fourth embodiment, the first slice authentication network element does not need to register the first slice authentication network element registration information to the data management network element, and the third access management network element can directly obtain the authentication result from the first slice authentication network element. For example, this embodiment can be applicable to the scenario where only one slice authentication network element (i.e., the first slice authentication network element) is deployed in the current network.

[0344] like Figure 10 As shown, another specific slice authentication method provided by this embodiment can be applied to Figure 2 In the network architecture shown, the method includes:

[0345] S1001. The first access management network element triggers the network slice authentication process.

[0346] Specifically, the terminal device accesses the first access management network element, the first access management network element obtains the subscription data of the terminal device from the data management network element, and the first access management network element learns that the network slice identified by S-NSSAI (equivalent to the first slice mentioned above) needs to perform network slice authentication based on the slice identifier S-NSSAI contained in the subscription data and its network slice authentication indication information, then the first access management network element triggers the network slice authentication process, and the specific process is Figure 1 The process is the same. The first access management network element corresponds to Figure 1 The access management node in the first slice authentication network element corresponds to Figure 1 Slice authentication function in .

[0347] When the first slice authentication network element obtains the authentication result of the network slice (i.e., completes the Figure 1 After S1011), continue to perform the following steps:

[0348] S1002: The first slice authentication network element saves the user identifier, network slice S-NSSAI and authentication result.

[0349] S1001 to S1002 above introduce the process of the first slice authentication network element storing the authentication result. Next, after the terminal device moves, the new access management network element (the third access management network element) obtains the authentication result from the first slice authentication network element.

[0350] For the scenarios where the terminal device moves, reference can be made to Scenario 1 and Scenario 2 in Embodiment 1, which will not be elaborated here.

[0351] Please continue to refer to Figure 10 , in the process of the terminal device moving from the second access management network element to the third access management network element, the terminal device triggers a registration update process:

[0352] S1003. In the registration process, the terminal device sends a registration update request message to the third access management network element;

[0353] S1004: The third access management network element sends a request message for obtaining an authentication result (the first request message) to the first slice authentication network element, and the message contains a user identifier and a network slice S-NSSAI.

[0354] Specifically, the message may contain one or more network slice identifiers S-NSSAI.

[0355] S1005: The first slice authentication network element replies with an authentication result response message (the first response message), and the message contains the authentication result.

[0356] Optionally, the authentication result response message further contains a user identifier and a network slice S-NSSAI.

[0357] When the first slice authentication network element saves the authentication result, the AAA service can also trigger a process of withdrawing the authentication result or re-authentication.

[0358] The following introduces the method for the AAA service to trigger the process of withdrawing the authentication result or re-authentication.

[0359] As Figure 11 shown, it is a flowchart of another method for withdrawing the authentication result provided by the embodiment of the present application. This method can be applied to Figure 2 the network architecture shown, and can be specifically executed when the terminal device accesses the first access management network element or the second access management network element. The method includes:

[0360] S1101: The AAA server sends an AAA protocol message to the first slice authentication network element to trigger the process of withdrawing the authentication result or re-authentication.

[0361] Specifically, due to configuration information modification, etc. on the AAA server, the process of withdrawing the authentication result (i.e., Figure 11 S1101a shown) or the re-authentication process (i.e., Figure 11As shown in S1101b). Among them, the authentication result revocation is applied to the network slice with the authentication result of EAP success, and the authentication result is changed to EAP failure; the re-authentication process is used to notify the access management network element to trigger the network slice authentication process and re-perform EAP authentication on the network slice. The AAA server sends the corresponding AAA protocol message to the first slice authentication network element.

[0362] S1102: After receiving the AAA protocol message, the first slice authentication network element sends a request message to the data management network element, and this request message is used to query the mobility management network element registration information of the service terminal device.

[0363] S1103: The data management network element replies with a response message to the first slice authentication network element, and the message contains the mobility management network element registration information, and the mobility management network element registration information contains the access management network element identifier. For example, the access management network element identifier is the NF Instance ID.

[0364] The content of the mobility management network element registration information can refer to the three cases (Case1, Case2, Case3) in Embodiment 1, and will not be elaborated here.

[0365] Furthermore, the first slice authentication network element performs different processing according to the specific content of the received mobility management network element registration information:

[0366] A. If the mobility management network element registration information contains the identifier of the access management network element, and the clear indication indicates that the access management network element is separated, or the supported feature information indicates that the access management network element does not support the network slice authentication function, that is, the above case2 or 3, then execute S1104c.

[0367] S1104c: The first slice authentication network element updates the authentication result corresponding to the slice identifier S-NSSAI stored locally.

[0368] Specifically, if it is the authentication result revocation, the first slice authentication network element changes the authentication result to EAP failure, and if it is the re-authentication, the first slice authentication network element deletes the authentication result.

[0369] B. If the mobility management network element registration information contains the identifier of the access management network element, and the clear indication indicates that the access management network element is not separated, or the mobility management network element registration information does not contain the clear indication information, and the supported feature information indicates that the access management network element supports the network slice authentication function, that is, the above case1, the first slice authentication network element executes step S1104a or S1104b and subsequent steps.

[0370] Here, the authentication result revocation process and the re-authentication process triggered by the AAA server are introduced separately.

[0371] 1) The AAA server triggers re - authentication:

[0372] S1104a: The first slice authentication network element sends a re - authentication notification message to the first access management network element, and the message contains the user identifier and the slice identifier S - NSSAI.

[0373] S1105a: The first access management network element replies with a re - authentication notification response message.

[0374] S1106a: The first access management network element triggers a network slice authentication process for the re - authenticated network slice, and the specific process is the same as Figure 1 the process.

[0375] S1107a: After the first slice authentication network element obtains the authentication result sent by the AAA server in the network slice authentication process, it updates the authentication result of the network slice stored locally and changes the authentication result to EAP failure.

[0376] 2) The AAA server triggers an authentication result withdrawal process:

[0377] S1104b: The first slice authentication network element sends an authentication result withdrawal notification message to the first access management network element, and the message contains the user identifier and the slice identifier S - NSSAI.

[0378] S1105b: The first access management network element replies with an authentication result withdrawal notification response message.

[0379] S1106b: The first slice authentication network element updates the authentication result and deletes the authentication result of the network slice stored locally.

[0380] In the above - mentioned fourth embodiment, the first slice authentication network element stores the authentication result during the network slice authentication process, so that in the mobile scenarios listed in the above - mentioned scenario one and scenario two, the third access management network element can directly obtain the authentication result from the first slice authentication network element. Thus, it is not necessary to execute the network slice authentication process for the network slice, saving network signaling overhead. At the same time, the terminal device does not need to wait for the third access management network element to complete the network slice authentication process before establishing a session to a specific network slice, accelerating the service establishment process and improving the service experience of the terminal device. In addition, when the data management network element stores the authentication result, the AAA server can also trigger a re - authentication or authentication result withdrawal process, improving the flexibility of network slice authentication.

[0381] It should be noted that in Figures 3 to 11In the described embodiment, a scenario is introduced where after the terminal device moves to a new access management network element (the third access management network element), the old access management network element does not support the network slice authentication function, and the new access management network element obtains the authentication result from a specified network element. In practical applications, if the old access management network element supports the network slice authentication function and stores the authentication result (for example, the second access management network element supports the network slice authentication function), then in addition to obtaining the authentication result from the old access management network element (for example, obtaining the user context from the second access management network element, and the authentication result is carried in the user context), the new access management network element can also obtain the authentication result from the specified network element according to the method provided in the embodiments of the present application.

[0382] The above combines the attached Figures 3 to 11 The method provided in the embodiments of the present application is introduced. The following combines the attached Figures 12 to 15 The device provided in the embodiments of the present application is introduced.

[0383] See Figure 12 , based on the same technical concept, the embodiments of the present application provide a slice authentication device 1200, which can be, for example, the third access management network element or a chip disposed inside the third access management network element. The device includes modules for executing the methods performed by the third access management network element in the method embodiments shown above. Figures 3 to 11 The methods performed by the third access management network element in the method embodiments shown above.

[0384] Exemplarily, the device 1200 may include:

[0385] A sending unit 1201, configured to: after the terminal device moves from the second access management network element that does not support the network slice authentication function to the device that supports the network slice authentication function, send a first request message to the first network element, where the first request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated;

[0386] A receiving unit 1202, configured to receive a first response message from the first network element, where the first response message includes the authentication result corresponding to the first slice.

[0387] In a possible implementation manner, the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.

[0388] In a possible implementation manner, the device further includes a processing unit 1203; after the terminal device moves from the second access management network element to the device and before the device sends the first request message to the first network element, the processing unit 1203 is configured to:

[0389] If the second access management network element is the MME of the 4G network, determine that the second access management network element does not support the network slice authentication function; or,

[0390] Obtain the user context of the terminal device from the second access management network element. If the authentication result corresponding to the first slice is not included in the user context, it is determined that the second access management network element does not support the network slice authentication function; or,

[0391] Obtain the list of supported features of the second access management network element from the second access management network element, and determine that the second access management network element does not support the network slice authentication function according to the list of supported features.

[0392] Among them, Figure 12 The dashed box in is used to indicate that the processing unit 1203 is optional for the device 1200.

[0393] It should be understood that all relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.

[0394] See Figure 13 , based on the same technical concept, an embodiment of the present application provides a slice authentication device 1300, which can be, for example, a data management network element or a chip disposed inside the data management network element. The device includes modules for executing the method executed by the data management network element in the method embodiment shown above. Figures 3 to 11 The method executed by the data management network element in the method embodiment shown above.

[0395] Exemplarily, the device 1300 may include:

[0396] A receiving unit 1301, configured to receive a request message from the third access management network element after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function. The request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;

[0397] A sending unit 1302, configured to send a response message to the third access management network element, where the response message includes the authentication result corresponding to the first slice.

[0398] In a possible implementation manner, the receiving unit 1301 is configured to: receive a request message sent by a second slice authentication network element, where the request message sent by the second slice authentication network element is sent by the third access management network element to the second slice authentication network element;

[0399] The sending unit 1302 is configured to: send a response message to the second slice authentication network element, and send the response message to the third access management network element through the second slice authentication network element.

[0400] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element supporting the network slice authentication function to the second access management network element;

[0401] The receiving unit 1301 is further configured to: receive an authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element;

[0402] The apparatus further includes a storage unit 1303 for storing the authentication result corresponding to the first slice.

[0403] In a possible implementation, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element;

[0404] The receiving unit 1301 is further configured to: receive a first message from the first slice authentication network element or the second slice authentication network element; the apparatus further includes a processing unit 1304 for modifying the authentication result corresponding to the first slice stored in the apparatus to authentication failure according to the first message; or,

[0405] The receiving unit 1301 is further configured to: receive a second message from the first slice authentication network element or the second slice authentication network element; the apparatus further includes a processing unit 1304 for deleting the authentication result corresponding to the first slice stored in the apparatus according to the second message.

[0406] Wherein, Figure 13 The dashed box in is used to indicate that the storage unit 1303 and the processing unit 1304 are optional for the apparatus 1300.

[0407] It should be understood that all relevant contents of the steps involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.

[0408] See Figure 14 , based on the same inventive concept, an embodiment of the present application provides a slice authentication apparatus 1400, which can be, for example, the first slice authentication network element or a chip disposed inside the first slice authentication network element. The apparatus includes modules for executing the method performed by the first slice authentication network element in the method embodiment shown above Figures 3 to 11 shown.

[0409] Exemplarily, the apparatus 1400 may include:

[0410] A receiving unit 1401, configured to: after the terminal device moves from a second access management network element that does not support the network slice authentication function to a third access management network element that supports the network slice authentication function, receive a request message from a second slice authentication network element, where the request message includes identification information of a first slice, and the first slice is a slice that needs to be authenticated;

[0411] A sending unit 1402, configured to send a response message to the second slice authentication network element, where the response message includes an authentication result corresponding to the first slice.

[0412] In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from a first access management network element that supports the network slice authentication function to the second access management network element, and the apparatus further includes:

[0413] A storage unit 1403, configured to save an authentication result corresponding to the first slice after the authentication of the first slice is completed;

[0414] A processing unit 1404, configured to register the identification of the apparatus to a data management network element.

[0415] In a possible implementation manner, before the terminal device moves from the second access management network element to the third access management network element, when the terminal device is within the service range of the second access management network element;

[0416] The receiving unit 1401 is further configured to: receive an authentication revocation message from an AAA server; the apparatus further includes a processing unit 1404, configured to modify the stored authentication result corresponding to the first slice to an authentication failure according to the authentication revocation message; or,

[0417] The receiving unit 1401 is further configured to: receive a re-authentication message from an AAA server; the apparatus further includes a processing unit 1404, configured to delete the stored authentication result corresponding to the first slice according to the re-authentication message; or,

[0418] The receiving unit 1401 is further configured to: receive a third message from a second slice authentication network element; the apparatus further includes a processing unit 1404, configured to modify the stored authentication result corresponding to the first slice to an authentication failure according to the third message; or,

[0419] The receiving unit 1401 is further configured to: receive a fourth message from a second slice authentication network element; the apparatus further includes a processing unit 1404, configured to delete the stored authentication result corresponding to the first slice according to the fourth message.

[0420] Wherein,Figure 14 The dashed box in

[0421] It should be understood that all relevant content of each step involved in the above method embodiments can be cited in the function description of the corresponding functional modules, and will not be elaborated here.

[0422] Based on the same inventive concept, referring to Figure 15 , an embodiment of the present application further provides a communication device 1500, including:

[0423] At least one processor 1501; and a communication interface 1503 communicatively connected to the at least one processor 1501; the at least one processor 1501 makes the device execute the above Figures 3 to 11 method steps executed by any one of the network elements in the method embodiment shown.

[0424] Optionally, the memory 1502 is located outside the device 1500.

[0425] Optionally, the device 1500 includes the memory 1502, the memory 1502 is connected to the at least one processor 1501, and the memory 1502 stores instructions executable by the at least one processor 1501.

[0426] Optionally, the memory 1502 is located outside the device 1500.

[0427] Optionally, the device 1500 includes the memory 1502, the memory 1502 is connected to the at least one processor 1501, and the memory 1502 stores instructions executable by the at least one processor 1501. Attached Figure 15 It is represented by a dashed line that the memory 1502 is optional for the device 1500.

[0428] Wherein, the processor 1501 and the memory 1502 can be coupled through an interface circuit or integrated together, and there is no limitation here.

[0429] In the embodiments of the present application, the specific connection medium between the above-mentioned processor 1501, memory 1502 and communication interface 1503 is not limited. In the embodiments of the present application Figure 15 it is shown that the processor 1501, memory 1502 and communication interface 1503 are connected through a bus 1504, and the bus is in Figure 15is represented by a thick line. The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 15 is only represented by a thick line in the figure, but it does not mean that there is only one bus or one type of bus.

[0430] It should be understood that the processor mentioned in the embodiments of the present application can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor that realizes by reading the software code stored in the memory.

[0431] Exemplarily, the processor can be a Central Processing Unit (CPU), or can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0432] It should be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0433] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) may be integrated in the processor.

[0434] It should be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0435] Based on the same technical concept, the embodiments of the present application further provide a computer-readable storage medium, including a program or instruction, which, when running on a computer, causes the method executed by any one of the network elements in the method embodiments shown above Figures 3 to 11 to be executed.

[0436] Based on the same technical concept, the embodiments of the present application further provide a chip, which is coupled to the memory and is used to read and execute the program instructions stored in the memory, so that the method executed by any one of the network elements in the method embodiments shown above Figures 3 to 11 is executed.

[0437] Based on the same inventive concept, an embodiment of the present application further provides a computer program product, including instructions that, when running on a computer, cause the methods executed by any one of the network elements in the method embodiments shown above to be executed. Figures 3 to 11 to be executed.

[0438] Since the apparatuses 1200, 1300, 1400, and 1500 provided in the embodiments of the present application can be used to execute the methods provided in the corresponding embodiments in the embodiments shown above, the technical effects that can be obtained thereby can refer to the above method embodiments and will not be elaborated herein. Figures 3 to 11 to be executed.

[0439] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0440] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a digital versatile disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0441] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A slicing authentication method, characterized in that, it includes: After the terminal device moves from the second access management network element that does not support network slicing authentication function to the third access management network element that supports network slicing authentication function, the third access management network element sends a first request message to the first network element, where the first request message includes the identification information of the first slice, and the first slice is the slice that needs to be authenticated; The third access management network element receives a first response message from the first network element, and the first response message includes the authentication result corresponding to the first slice; Wherein, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports network slicing authentication function to the second access management network element.

2. The method according to claim 1, characterized in that, The first network element is a data management network element; The method further includes: The first access management network element or the first slicing authentication network element stores the authentication result corresponding to the first slice into the data management network element.

3. The method according to claim 1, characterized in that, The first network element is a second slicing authentication network element.

4. The method according to claim 3, characterized in that, After the third access management network element sends a first request message to the first network element, the method further includes: The second slicing authentication network element sends the identification information of the first slice to the data management network element; The second slicing authentication network element receives the authentication result corresponding to the first slice from the data management network element; The second slicing authentication network element sends the authentication result corresponding to the first slice to the third access management network element.

5. The method according to claim 4, characterized in that, The method further includes: The first access management network element or the first slicing authentication network element stores the authentication result corresponding to the first slice into the data management network element.

6. The method according to claim 3, characterized in that, After the third access management network element sends a first request message to the first network element, the method further includes: The second slicing authentication network element sends the identification information of the first slice to the first slicing authentication network element; The second slicing authentication network element receives the authentication result corresponding to the first slice from the first slicing authentication network element; The second slicing authentication network element sends the authentication result corresponding to the first slice to the third access management network element.

7. The method according to claim 6, characterized in that, Before the second slicing authentication network element sends a third request message to the first slicing authentication network element, the method further includes: The second slicing authentication network element sends a request message to the data management network element; The second slicing authentication network element receives the identification of the first slicing authentication network element from the data management network element; The second slicing authentication network element sends a third request message to the first slicing authentication network element, including: The second slicing authentication network element sends the identification information of the first slice to the first slicing authentication network element according to the identification of the first slicing authentication network element.

8. The method according to claim 7, It is characterized in that, Before the terminal device moves from the second access management network element to the third access management network element, the method further includes: After the authentication corresponding to the first slice is completed, the first slice authentication network element saves the authentication result corresponding to the first slice, and registers the identifier of the first slice authentication network element to the data management network element.

9. The method according to claim 1, It is characterized in that, The first network element is the first slice authentication network element; The method further includes: The first slice authentication network element stores the authentication result corresponding to the first slice.

10. A slice authentication method, It is characterized in that, Including: After the terminal device moves from the second access management network element that does not support network slice authentication function to the third access management network element that supports network slice authentication function, the data management network element receives a request message from the third access management network element, and the request message includes the identifier information of the first slice, and the first slice is the slice that needs to be authenticated; The data management network element returns a response message to the third access management network element, and the response message includes the authentication result corresponding to the first slice; Wherein, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element that supports network slice authentication function to the second access management network element.

11. The method according to claim 10, It is characterized in that, The data management network element receives a request message from the third access management network element, including: The data management network element receives a request message sent by the second slice authentication network element, and the request message sent by the second slice authentication network element is sent by the third access management network element to the second slice authentication network element; The data management network element returns a response message to the third access management network element, including: The data management network element sends the response message to the second slice authentication network element, and the second slice authentication network element sends the response message to the third access management network element.

12. The method according to claim 11, It is characterized in that, The method further includes: The data management network element receives the authentication result corresponding to the first slice from the first access management network element or the first slice authentication network element; the data management network element stores the authentication result corresponding to the first slice.

13. A slice authentication system, It is characterized in that, Including: A terminal device, a second access management network element that does not support network slice authentication function, a third access management network element that supports network slice authentication function, and a first network element; Wherein, the third access management network element is configured to: after the terminal device moves from the second access management network element to the third access management network element, send a first request message to the first network element, and the first request message includes the identifier information of the first slice, and the first slice is the slice that needs to be authenticated; The first network element is configured to: receive the first request message, and send a first response message to the third access management network element, and the first response message includes the authentication result corresponding to the first slice; The third access management network element is further configured to: receive the first response message from the first network element; Wherein, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from the first access management network element supporting network slice authentication function to the second access management network element.

14. The system according to claim 13, Characterized in that, The first network element is a data management network element, and the system further includes a first access management network element and a first slice authentication network element; The first access management network element or the first slice authentication network element is configured to: store the authentication result corresponding to the first slice into the data management network element.

15. The system according to claim 13, Characterized in that, The first network element is a second slice authentication network element.

16. The system according to claim 15, Characterized in that, The second slice authentication network element is configured to: after the third access management network element sends a first request message to the first network element, send the identification information of the first slice to the data management network element; receive the authentication result corresponding to the first slice from the data management network element; send the authentication result corresponding to the first slice to the third access management network element.

17. The system according to claim 16, Characterized in that, The system further includes a first access management network element and a first slice authentication network element; The first access management network element or the first slice authentication network element is configured to: store the authentication result corresponding to the first slice into the data management network element.

18. The system according to claim 15, Characterized in that, The system further includes a first slice authentication network element; The second slice authentication network element is configured to: after the third access management network element sends a first request message to the first network element, send the identification information of the first slice to the first slice authentication network element; The first slice authentication network element is configured to: receive the identification information of the first slice from the second slice authentication network element, and send the authentication result corresponding to the first slice to the second slice authentication network element; The second slice authentication network element is further configured to: receive the authentication result corresponding to the first slice from the first slice authentication network element; send the authentication result corresponding to the first slice to the third access management network element.

19. The system according to claim 18, Characterized in that, The second slice authentication network element is further configured to: before the second slice authentication network element sends a third request message to the first slice authentication network element, send a request message to the data management network element; Receive the identification of the first slice authentication network element from the data management network element; When the second slice authentication network element sends a third request message to the first slice authentication network element, specifically configured to: according to the identification of the first slice authentication network element, send the identification information of the first slice to the first slice authentication network element.

20. The system according to claim 19, Characterized in that, The first slice authentication network element is further configured to: before the terminal device moves from the second access management network element to the third access management network element, after the authentication corresponding to the first slice is completed, save the authentication result corresponding to the first slice, and register the identifier of the first slice authentication network element to the data management network element.

21. The system according to claim 13, wherein, the first network element is a first slice authentication network element; the first slice authentication network element is further configured to: store the authentication result corresponding to the first slice.

22. A slice authentication device, wherein, comprises: a sending unit, configured to: after the terminal device moves from a second access management network element that does not support network slice authentication function to the device that supports network slice authentication function, send a first request message to a first network element, wherein the first request message includes identifier information of a first slice, and the first slice is a slice that needs to be authenticated; a receiving unit, configured to receive a first response message from the first network element, and the first response message includes the authentication result corresponding to the first slice; wherein, before the terminal device moves from the second access management network element to the device, the terminal device moves from a first access management network element that supports network slice authentication function to the second access management network element.

23. The device according to claim 22, wherein, the first network element is a data management network element, a first slice authentication network element, or a second slice authentication network element.

24. A slice authentication device, wherein, comprises: a receiving unit, configured to, after the terminal device moves from a second access management network element that does not support network slice authentication function to a third access management network element that supports network slice authentication function, receive a request message from the third access management network element, and the request message includes identifier information of a first slice, and the first slice is a slice that needs to be authenticated; a sending unit, configured to send a response message to the third access management network element, and the response message includes the authentication result corresponding to the first slice; wherein, before the terminal device moves from the second access management network element to the third access management network element, the terminal device moves from a first access management network element that supports network slice authentication function to the second access management network element.

25. The device according to claim 24, wherein, the receiving unit is configured to: receive a request message sent by a second slice authentication network element, and the request message sent by the second slice authentication network element is sent by the third access management network element to the second slice authentication network element; the sending unit is configured to: send the response message to the second slice authentication network element, and send the response message to the third access management network element through the second slice authentication network element.

26. The device according to claim 24, wherein; the receiving unit is further configured to: receive the authentication result corresponding to the first slice from a first access management network element or a first slice authentication network element; the device further comprises a storage unit, configured to store the authentication result corresponding to the first slice.

27. A communication device, It is characterized in that including: at least one processor; and a memory and a communication interface communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the at least one processor, by executing the instructions stored in the memory, causes the apparatus to execute the method according to any one of claims 10-12 through the communication interface.

28. A computer-readable storage medium characterized in that it includes a program or instructions which, when run on a computer, cause the method according to any one of claims 10-12 to be executed.

Citation Information

Patent Citations

  • Authentication method and device

    CN111031538A