Private network communication method and system

By associating the private network UPF network element with the AUSF network element and adding the AusfUrl field to the registration information of the NRF network element, the problem of difficulty in distinguishing and isolating the private network service element from the public network service element is solved, and the security performance and resource utilization of the private network service element are improved.

CN115065969BActive Publication Date: 2025-07-01IPLOOK NETWORKS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210096950.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-27
Publication Date
2025-07-01
Estimated Expiration
2042-01-27

AI Technical Summary

Technical Problem

The 5G core network in the prior art is difficult to distinguish and isolate the dedicated network service network element from the public network service network element, resulting in the low security performance of the dedicated network service network element.

Method used

By associating the private network UPF network element with the AUSF network element, the AUSF network element assists in identifying the terminal's private network access rights when the terminal establishes a 5GC session with the private network UPF network element, and adds the AusfUrl field to the registration information of the NRF network element to distinguish the private network UPF network element and the public network UPF network element.

Benefits of technology

The security performance of the dedicated network service network element is improved and the resource utilization rate of the dedicated network UPF network element is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115065969B_ABST
    Figure CN115065969B_ABST
Patent Text Reader

Abstract

The present application discloses a private network communication method and system to solve the technical problem of the low security performance of private network service network elements. Specifically, a private network communication solution includes the following steps: The AUSF network element records the private network access permission of the terminal; the private network UPF network element records the access address of the AUSF network element; during the process of establishing a 5GC session between the terminal and the private network UPF network element, the AUSF network element authenticates the private network access permission of the terminal; when the authentication of the private network access permission of the terminal passes, the terminal and the private network UPF network element establish a 5GC session. By associating the private network UPF network element with the AUSF network element, when the terminal and the private network UPF network element establish a 5GC session, the AUSF network element will assist in authenticating the private network access permission of the terminal, thereby improving the security performance of the private network service network element. The solution also adds the AusfUrl field to the registration information of the private network UPF network element through the NRF network element to distinguish the private network UPF network element from the public network UPF network element, thereby improving the resource utilization rate of the private network UPF network element.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a private network communication method and system. Background Art

[0002] With the continuous maturity of communication technologies, some enterprises or institutions use advanced communication mechanisms to deploy dedicated wireless networks to implement internal functional services. Generally, the public wireless communication network operated by telecom operators is called the public network, and the wireless network built by enterprises is called the private network.

[0003] In the process of implementing the prior art, the inventors found that:

[0004] The essence of the private network is a small proprietary network superimposed in the public network environment, and most private network environments are within the coverage of the public network environment. The private network service network elements in the prior art utilize the directional characteristics of the private network and only provide services to specific internal users. However, the current 5G core network is difficult to distinguish and isolate the private network service network elements from the public network service network elements, resulting in the risk that the private network service network elements can also be accessed by public network users. In other words, the security performance of the private network service network elements in the prior art is relatively low.

[0005] Therefore, a private network communication solution is needed to solve the technical problem of the relatively low security performance of private network service network elements. Summary of the Invention

[0006] Embodiments of this application provide a private network communication solution to solve the technical problem of the relatively low security performance of private network service network elements.

[0007] Specifically, a private network communication method includes the following steps:

[0008] The AUSF network element records the private network access permission of the terminal;

[0009] The private network UPF network element records the access address of the AUSF network element;

[0010] In the process of establishing a 5GC session between the terminal and the private network UPF network element, the AUSF network element authenticates the private network access permission of the terminal;

[0011] When the private network access permission of the terminal is authenticated successfully, the terminal establishes a 5GC session with the private network UPF network element.

[0012] Further, the method further includes:

[0013] The private network UPF network element sends a registration request to the NRF network element;

[0014] When the NRF network element responds to the private network UPF network element, the private network UPF network element sends the access address of the AUSF network element to the NRF network element;

[0015] The NRF network element adds an AusfUrl field to the registration information of the private network UPF network element to record the access address of the AUSF network element.

[0016] Further, the process for the terminal to establish a 5GC session with the private network UPF network element specifically includes:

[0017] The SMF network element receives the private network access request from the terminal;

[0018] The SMF network element searches for the registration information of the private network UPF network element in the NRF network element according to the private network access request;

[0019] The SMF network element determines the access address of the AUSF network element according to the registration information of the private network UPF network element;

[0020] The SMF network element requests the AUSF network element to authenticate the private network access permission of the terminal;

[0021] When the authentication of the private network access permission of the terminal passes, the SMF network element initiates a session establishment request to the private network UPF network element.

[0022] Further, the interface of the NRF network element for storing registration information adds an AusfUrl field to send the access address of the AUSF network element.

[0023] Further, when the terminal activates a service related to the private network access permission, the terminal is authorized to have the private network access permission.

[0024] The embodiment of the present application also provides a private network communication system.

[0025] Specifically, a private network communication system at least includes:

[0026] A terminal;

[0027] An AUSF network element, which is used to record the private network access permission of the terminal; and is also used to authenticate the private network access permission of the terminal;

[0028] A private network UPF network element, which is used to record the access address of the AUSF network element; and is also used to establish a 5GC session with the terminal.

[0029] Further, the system further includes an NRF network element, which is used to record the registration information of the private network UPF network element;

[0030] The private network UPF network element is also used to initiate a registration request to the NRF network element;

[0031] When the NRF network element responds to the private network UPF network element, the private network UPF network element sends the access address of the AUSF network element to the NRF network element;

[0032] The NRF network element adds an AusfUrl field to the registration information of the private network UPF network element to record the access address of the AUSF network element.

[0033] Further, the system further includes an SMF network element, which is used to receive the private network access request of the terminal; is further used to search for the registration information of the private network UPF network element in the NRF network element according to the private network access request; is further used to determine the AUSF network element access address according to the registration information of the private network UPF network element; is further used to request the AUSF network element to authenticate the private network access permission of the terminal; and is further used to initiate a session establishment request to the private network UPF network element when the private network access permission of the terminal is authenticated.

[0034] Further, the interface of the NRF network element for storing registration information adds an AusfUrl field to send the AUSF network element access address.

[0035] Further, when the terminal activates a service related to the private network access permission, the terminal is authorized to have the private network access permission.

[0036] The technical solution provided by the embodiments of the present application has at least the following beneficial effects:

[0037] By associating the private network UPF network element with the AUSF network element, when the terminal establishes a 5GC session with the private network UPF network element, the AUSF network element will assist in authenticating the private network access permission of the terminal, thereby improving the security performance of the private network service network element. By adding the AusfUrl field to the registration information of the private network UPF network element in the NRF network element to distinguish the private network UPF network element from the public network UPF network element, the resource utilization rate of the private network UPF network element is improved. Description of the Drawings

[0038] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0039] Figure 1 It is a flowchart of a private network communication method provided by an embodiment of the present application.

[0040] Figure 2 It is a flowchart of the registration of the private network UPF network element in the NRF network element provided by an embodiment of the present application.

[0041] Figure 3 It is a flowchart of the process of the terminal establishing a 5GC session with the private network UPF network element provided by an embodiment of the present application.

[0042] Figure 4 It is a schematic structural diagram of a private network communication system provided by an embodiment of the present application.

[0043] 100 Private network communication system

[0044] 11 Terminal

[0045] 12 AUSF network element

[0046] 13 Private network UPF network element

[0047] 14 NRF network element

[0048] 15 SMF network element Specific implementation manners

[0049] To make the objectives, technical solutions and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0050] Please refer to Figure 1 , this application provides a private network communication method, including the following steps:

[0051] S110: The AUSF network element records the private network access permission of the terminal.

[0052] It can be understood that the AUSF (Authentication Server Function) network element is an authentication network element used to verify the permissions of the terminal UE for the requester. Specifically, when the terminal UE subscribes to services related to private network access permissions, the terminal UE is authorized to have private network access permissions. At this time, the AUSF network element will record the information of the authorized terminal, including the private network access permission of the authorized terminal, the address of the authorized terminal, the ID of the authorized terminal, etc.

[0053] S120: The private network UPF network element records the access address of the AUSF network element.

[0054] It should be noted that the UPF (User Plane Function) network element is a transit network element used to connect the uplink and downlink and transmit data packets. The private network UPF network element described in this application can be understood as a UPF network element that can establish a link with the private network service network element. In other words, the terminal UE can initiate access to the private network service network element through the private network UPF network element. Furthermore, whether the terminal UE can access the private network service network element depends on whether the terminal UE can establish a 5GC session with the private network UPF.

[0055] Here, by setting the private network UPF network element to record the access address of the AUSF network element, the private network UPF network element is actually associated with the AUSF network element, so as to facilitate the identification of the access permission of the terminal UE that sends a 5GC session establishment request.

[0056] Of course, to enable the private network UPF network element to work properly, that is, to be discovered by the terminal UE or other network elements, the private network UPF network element needs to be registered with the NRF (Network Repository Function) network element.

[0057] It can be understood that the NRF network element is responsible for registering various network elements. When all network elements are started, they must be registered with the NRF network element to provide services. Generally, the registration information of a network element registered with the NRF network element includes the network element type, address, service list, etc.

[0058] In the prior art, the 5GC core network does not effectively distinguish between the private network UPF network element and the public network UPF network element. The mixed use of the private network UPF network element and the public network UPF network element often causes private network users to be unable to access the private network service network element due to connecting to the public network UPF network element, or the public network users to connect to the private network UPF network element, resulting in low resource utilization rate of the private network UPF network element.

[0059] In order to distinguish and isolate the private network UPF network element and the public network UPF network element, in the registration phase of the private network UPF network element with the NRF network element in the private network communication method provided by this application, the private network UPF network element with the ability to access the private network service network element is marked, so as to distinguish it from the public network UPF network element.

[0060] Please refer to Figure 2 , in a specific embodiment provided by this application, the signaling process of the UPF network element registering with the NRF network element can be expressed as:

[0061] S210: The private network UPF network element sends a registration request to the NRF network element;

[0062] S220: When the NRF network element responds to the private network UPF network element, the private network UPF network element sends the access address of the AUSF network element to the NRF network element;

[0063] S230: The NRF network element adds an AusfUrl field to the registration information of the private network UPF network element to record the access address of the AUSF network element.

[0064] It can be understood that as mentioned above, the private network UPF network element has a need to identify the access permission of the terminal UE. Therefore, the private network UPF network element records the access address of the AUSF network element, so as to identify the access permission of the terminal UE through the AUSF network element.

[0065] It should be noted that, according to the setting of the access address of the AUSF network element recorded by the private network UPF network element here, the private network UPF network element and the public network UPF network element can be visually distinguished. That is, the UPF network element that records the access address of the AUSF network element is the private network UPF network element, and the UPF network element that does not record the access address of the AUSF network element is the public network UPF network element.

[0066] After the NRF network element responds to the registration request of the UPF network element, the UPF network element sends at least its own network element type, address, service list, and the access address of the AUSF network element recorded by the UPF network element to the NRF network element.

[0067] Of course, for the NRF network element to record the access address of the AUSF network element associated with the UPF network element, the NRF network element adds an AusfUrl field to the UPF Profile in the registration information of the private network UPF network element to fill in the access address of the AUSF network element associated with the UPF network element.

[0068] It should also be noted that the AusfUrl field can be filled with the access address of the AUSF network element associated with the UPF network element, or it can be unrecorded. When the AusfUrl field in the registration information of the UPF network element has the access address of the AUSF network element, it indicates that the UPF network element is a private network UPF network element. When the AusfUrl field does not exist in the registration information of the UPF network element, or the AusfUrl field is unrecorded, it indicates that the UPF network element is a public network UPF network element.

[0069] Thus, it is possible to determine whether the UPF network element is a private network UPF network element by reading the AusfUrl field of the UPF network element.

[0070] S130: In the process of establishing a 5GC session between the terminal and the private network UPF network element, the AUSF network element authenticates the terminal's private network access permission.

[0071] S140: When the authentication of the terminal's private network access permission is passed, the terminal establishes a 5GC session with the private network UPF network element.

[0072] Please refer to Figure 3 , and the following details the process of establishing a 5GC session between the terminal and the private network UPF network element:

[0073] S310: The SMF network element receives the terminal's private network access request;

[0074] S320: The SMF network element searches for the registration information of the private network UPF network element in the NRF network element according to the private network access request;

[0075] S330: The SMF network element determines the AUSF network element access address based on the registration information of the private network UPF network element;

[0076] S340: The SMF network element requests the AUSF network element to authenticate the terminal's private network access permission;

[0077] S350: When the authentication of the terminal's private network access permission is passed, the SMF network element initiates a session establishment request to the private network UPF network element.

[0078] It can be understood that the SMF (Session Management Function) network element is mainly responsible for creating, updating, and deleting PDU sessions.

[0079] Usually in the signaling process of 5GC session establishment, the access request of the terminal UE is forwarded to the SMF network element through the AMF (Access and Mobility Management Function) network element. The signaling process of this part is elaborated in detail in relevant literature and will not be introduced in detail here.

[0080] After receiving the private network access request of the terminal, the SMF network element obtains the UPF network element registration list from the NRF network element. The UPF network element registration list records the registration information of several UPF network elements. Usually, the SMF will select a suitable UPF network element to send a session establishment request according to factors such as the service scope of the UPF network element, the DN list supported by the UPF network element, the SSC mode supported by the UPF network element, the UPF network element load, and the current location of the terminal UE.

[0081] In a preferred embodiment provided by the present application, the preference level of the SMF network element for selecting the private network UPF network element is higher than that for selecting the public network UPF network element. The SMF network element searches for the registration information of the private network UPF network element in the NRF network element according to the private network access request, specifically manifested as:

[0082] The SMF network element filters out the private network UPF network element from the NRF network element according to the private network access request of the terminal, that is, the UPF network element whose registration information AusfUrl field records the AUSF network element access address.

[0083] It should also be pointed out that for the convenience of the NRF network element to send the AUSF network element access address to the SMF network element, the interface of the NRF network element for storing registration information adds an AusfUrl field for sending the AUSF network element access address. Specifically, the interface of the NRF network element for storing UPF Info adds an AusfUrl field.

[0084] After that, the SMF network element obtains the access address of the AUSF network element associated with the private network UPF network element in the AusfUrl field by reading the registration information of the private network UPF network element.

[0085] According to the access address of the AUSF network element, the SMF network element sends information of the terminal UE, such as the address of the terminal, the ID of the terminal, etc., to the AUSF network element. The AUSF network element determines the private network access permission of the terminal UE.

[0086] When the terminal UE has the private network access permission, the AUSF network element sends a response message to the SMF network element to notify that the private network access permission of the terminal UE is verified.

[0087] When the SMF network element receives the response message from the AUSF network element, the SMF network element initiates a session establishment request to the private network UPF network element.

[0088] In summary, the private network communication method provided by this application associates the private network UPF network element with the AUSF network element, so that when the terminal establishes a 5GC session with the private network UPF network element, the AUSF network element will assist in verifying the private network access permission of the terminal, thereby improving the security performance of the private network service network element. By adding the AusfUrl field to the registration information of the private network UPF network element through the NRF network element, the private network UPF network element and the public network UPF network element are distinguished, thereby improving the resource utilization rate of the private network UPF network element.

[0089] Please refer to Figure 4 , to support the private network communication method, this application also provides a private network communication system 100, including:

[0090] Terminal 11;

[0091] AUSF network element 12, which is used to record the private network access permission of the terminal 11; and is also used to verify the private network access permission of the terminal 11;

[0092] Private network UPF network element 13, which is used to record the access address of the AUSF network element 12; and is also used to establish a 5GC session with the terminal 11.

[0093] It can be understood that the terminal 11 has a usage requirement for accessing the private network service network element. The AUSF (Authentication Server Function) network element 12 is an authentication network element used to verify the permissions of the requester for the terminal 11. Specifically, when the terminal 11 subscribes to a service related to private network access permissions, the terminal 11 is authorized to have private network access permissions. At this time, the AUSF network element 12 will record information of the authorized terminal 11, including the private network access permissions of the authorized terminal 11, the address of the authorized terminal 11, the ID of the authorized terminal 11, etc. The UPF (User Plane Function) network element is a transit network element used to connect the uplink and downlink and transmit data packets. And the private network UPF network element 13 in this application can be understood as a UPF network element that can establish a link with the private network service network element. In other words, the terminal 11 can initiate an access to the private network service network element through the private network UPF network element 13. Furthermore, whether the terminal 11 can access the private network service network element depends on whether the terminal 11 can establish a 5GC session with the private network UPF.

[0094] Here, by setting the private network UPF network element 13 to record the access address of the AUSF network element 12, in fact, the private network UPF network element 13 is associated with the AUSF network element 12, so as to facilitate the authentication of the access permissions of the terminal 11 that sends a 5GC session establishment request.

[0095] Of course, this private network communication system also includes other network elements to enable the private network UPF network element 13 to work properly. Specifically, the system further includes an NRF network element 14 for recording the registration information of the private network UPF network element 13;

[0096] The private network UPF network element 13 is further configured to initiate a registration request to the NRF network element 14;

[0097] When the NRF network element 14 responds to the private network UPF network element 13, the private network UPF network element 13 sends the access address of the AUSF network element 12 to the NRF network element 14;

[0098] The NRF network element 14 adds an AusfUrl field to the registration information of the private network UPF network element 13 for recording the access address of the AUSF network element 12.

[0099] It can be understood that to enable the private network UPF network element 13 to work properly, that is, to be discoverable by the terminal 11 or other network elements, the private network UPF network element 13 needs to be registered in the NRF (Network Repository Function) network element.

[0100] The NRF network element 14 is responsible for registering various network elements. When all network elements are started, they must register with the NRF network element 14 before they can provide services. Generally, the registration information of a network element with the NRF network element 14 includes the network element type, address, service list, etc.

[0101] In the prior art, the 5GC core network does not effectively distinguish between the private network UPF network element 13 and the public network UPF network element. The mixed use of the private network UPF network element 13 and the public network UPF network element often causes private network users to be unable to access private network service network elements due to connecting to the public network UPF network element, or public network users to connect to the private network UPF network element 13, resulting in low resource utilization of the private network UPF network element 13.

[0102] In order to distinguish and isolate the private network UPF network element 13 and the public network UPF network element, during the registration phase of the private network UPF network element 13 with the NRF network element 14 in the private network communication system 100 provided by this application, the private network UPF network element 13 with the ability to access private network service network elements is marked to distinguish it from the public network UPF network element.

[0103] Specifically, in a specific embodiment provided by this application, the signaling process of the UPF network element registering with the NRF network element 14 can be expressed as:

[0104] The private network UPF network element 13 sends a registration request to the NRF network element 14;

[0105] When the NRF network element 14 responds to the private network UPF network element 13, the private network UPF network element 13 sends the access address of the AUSF network element 12 to the NRF network element 14;

[0106] The NRF network element 14 adds an AusfUrl field to the registration information of the private network UPF network element 13 to record the access address of the AUSF network element 12.

[0107] It can be understood that as mentioned above, the private network UPF network element 13 has a need to authenticate the access rights of the terminal 11. For this reason, the private network UPF network element 13 records the access address of the AUSF network element 12 in order to authenticate the access rights of the terminal 11 through the AUSF network element 12.

[0108] It should be noted that according to the setting of the private network UPF network element 13 recording the access address of the AUSF network element 12 here, the private network UPF network element 13 and the public network UPF network element can be intuitively distinguished. That is, the UPF network element that records the access address of the AUSF network element 12 is the private network UPF network element 13, and the UPF network element that does not record the access address of the AUSF network element 12 is the public network UPF network element.

[0109] After the NRF network element 14 responds to the registration request of the UPF network element, the UPF network element sends at least its own network element type, address, service list, and the access address of the AUSF network element 12 recorded by the UPF network element to the NRF network element 14.

[0110] Of course, for the NRF network element 14 to record the access address of the AUSF network element 12 associated with the UPF network element, the NRF network element 14 adds an AusfUrl field to the UPF Profile in the registration information of the private network UPF network element 13 to fill in the access address of the AUSF network element 12 associated with the UPF network element.

[0111] It should also be noted that the AusfUrl field can be filled with the access address of the AUSF network element 12 associated with the UPF network element, or there can be no record. When the AusfUrl field in the registration information of the UPF network element has the access address of the AUSF network element 12, it indicates that the UPF network element is the private network UPF network element 13. When the AusfUrl field does not exist in the registration information of the UPF network element, or the AusfUrl field has no record, it indicates that the UPF network element is a public network UPF network element.

[0112] Thus, it is possible to determine whether the UPF network element is the private network UPF network element 13 by reading the AusfUrl field of the UPF network element.

[0113] Furthermore, this private network communication system further includes other network elements to cooperate with the terminal 11 to establish a 5GC session with the private network UPF network element 13. Specifically, the system further includes an SMF network element 15, which is used to receive the private network access request of the terminal 11; is also used to search for the registration information of the private network UPF network element 13 in the NRF network element 14 according to the private network access request; is also used to determine the access address of the AUSF network element 12 according to the registration information of the private network UPF network element 13; is also used to request the AUSF network element 12 to authenticate the private network access permission of the terminal 11; and is also used to initiate a session establishment request to the private network UPF network element 13 when the private network access permission of the terminal 11 is authenticated.

[0114] It can be understood that the SMF (Session Management Function) network element is mainly responsible for creating, updating, and deleting PDU sessions.

[0115] Usually in the signaling process of establishing a 5GC session, the access request of the terminal 11 is forwarded to the SMF network element 15 through the AMF (Access and Mobility Management Function) network element. This part of the signaling process is elaborated in detail in relevant literature and will not be introduced in detail here.

[0116] After the SMF network element 15 receives the private network access request from the terminal 11, it obtains the UPF network element registration list from the NRF network element 14. The UPF network element registration list records the registration information of several UPF network elements. Usually, the SMF selects a suitable UPF network element to send a session establishment request based on factors such as the service scope of the UPF network element, the DN list supported by the UPF network element, the SSC mode supported by the UPF network element, the UPF network element load, and the current location of the terminal 11.

[0117] In a preferred implementation provided by this application, the preference level of the SMF network element 15 for selecting the private network UPF network element 13 is higher than that for selecting the public network UPF network element. The SMF network element 15 searches for the registration information of the private network UPF network element 13 in the NRF network element 14 according to the private network access request, specifically:

[0118] The SMF network element 15 filters out the private network UPF network element 13 from the NRF network element 14 according to the private network access request of the terminal 11, that is, the UPF network element whose AusfUrl field in the registration information records the access address of the AUSF network element 12.

[0119] It should also be noted that, to facilitate the NRF network element 14 to send the access address of the AUSF network element 12 to the SMF network element 15, the interface of the NRF network element 14 for storing registration information adds an AusfUrl field for sending the access address of the AUSF network element 12. Specifically, the interface of the NRF network element 14 for storing UPF Info adds an AusfUrl field.

[0120] After that, the SMF network element 15 obtains the access address of the AUSF network element 12 associated with the private network UPF network element 13 in the AusfUrl field by reading the registration information of the private network UPF network element 13.

[0121] According to the access address of the AUSF network element 12, the SMF network element 15 sends the information of the terminal 11, such as the address of the terminal 11 and the ID of the terminal 11, to the AUSF network element 12. The AUSF network element 12 determines the private network access permission of the terminal 11.

[0122] When the terminal 11 has the private network access permission, the AUSF network element 12 sends a response message to the SMF network element 15 to notify that the private network access permission authentication of the terminal 11 has passed.

[0123] When the SMF network element 15 receives the response message from the AUSF network element 12, the SMF network element 15 initiates a session establishment request to the private network UPF network element 13.

[0124] In summary, by associating the private network UPF network element 13 with the AUSF network element 12 in the private network communication system 100 provided in this application, when the terminal 11 establishes a 5GC session with the private network UPF network element 13, the AUSF network element 12 will assist in authenticating the private network access permission of the terminal 11, thereby improving the security performance of the private network service network element. By adding the AusfUrl field to the registration information of the private network UPF network element 13 by the NRF network element 14 to distinguish the private network UPF network element 13 from the public network UPF network element, the resource utilization rate of the private network UPF network element 13 is improved.

[0125] It should be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, commodity or device including the said element.

[0126] Those skilled in the art should understand that the embodiments of this application can be provided as a method, a system or a computer program product. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0127] The above are only the embodiments of this application and are not used to limit this application. For those skilled in the art, various changes and modifications can be made to this application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the scope of the claims of this application.

Claims

1. A private network communication method, characterized in that, It includes the following steps: The AUSF network element records the private network access permission of the terminal; The private network UPF network element records the access address of the AUSF network element; In the process of establishing a 5GC session between the terminal and the private network UPF network element, the AUSF network element authenticates the private network access permission of the terminal; When the private network access permission of the terminal is authenticated, the terminal and the private network UPF network element establish a 5GC session; Among them, the private network UPF network element recording the access address of the AUSF network element includes the following steps: The private network UPF network element sends a registration request to the NRF network element; When the NRF network element responds to the private network UPF network element, the private network UPF network element sends the access address of the AUSF network element to the NRF network element; The NRF network element adds an AusfUrl field to the registration information of the private network UPF network element for recording the access address of the AUSF network element.

2. The private network communication method according to claim 1, characterized in that, The process of establishing a 5GC session between the terminal and the private network UPF network element specifically includes: The SMF network element receives the private network access request of the terminal; The SMF network element searches for the registration information of the private network UPF network element in the NRF network element according to the private network access request; The SMF network element determines the access address of the AUSF network element according to the registration information of the private network UPF network element; The SMF network element requests the AUSF network element to authenticate the private network access permission of the terminal; When the private network access permission of the terminal is authenticated, the SMF network element sends a session establishment request to the private network UPF network element.

3. The private network communication method according to claim 1, wherein The interface of the NRF network element for storing registration information adds an AusfUrl field for sending the access address of the AUSF network element.

4. The private network communication method according to claim 1, wherein When the terminal enables a service related to the private network access permission, the terminal is authorized to have the private network access permission.

5. A private network communication system, characterized in that, It at least includes: The terminal; The AUSF network element, which is used to record the private network access permission of the terminal; and is also used to authenticate the private network access permission of the terminal; The private network UPF network element, which is used to record the access address of the AUSF network element; and is also used to establish a 5GC session with the terminal; The system further includes an NRF network element, which is used to record the registration information of the private network UPF network element; The private network UPF network element is also used to send a registration request to the NRF network element; When the NRF network element responds to the private network UPF network element, the private network UPF network element sends the access address of the AUSF network element to the NRF network element; The NRF network element adds an AusfUrl field to the registration information of the private network UPF network element for recording the access address of the AUSF network element.

6. The private network communication system according to claim 5, wherein The system further includes an SMF network element, which is used to receive the private network access request of the terminal; and is also used to search for the registration information of the private network UPF network element in the NRF network element according to the private network access request; and is also used to determine the access address of the AUSF network element according to the registration information of the private network UPF network element; and is also used to request the AUSF network element to authenticate the private network access permission of the terminal; and is also used to send a session establishment request to the private network UPF network element when the private network access permission of the terminal is authenticated.

7. The private network communication system according to claim 5, wherein The interface of the NRF network element for storing registration information adds an AusfUrl field for sending the access address of the AUSF network element.

8. The private network communication system according to claim 5, characterized in that, When the terminal enables a service related to the private network access permission, the terminal is authorized to have the private network access permission.

Citation Information

Patent Citations

  • Security private network architecture system based on 5G network slice

    CN111131258A