An online signing method and device

By identifying the online signing requests of terminal devices, triggering authentication and updating network signing data, the problem of unupdated signing in NPN networks is solved, improving the applicability and flexibility of online signing and ensuring that terminal devices can smoothly access the enterprise network.

CN115299086BActive Publication Date: 2025-10-17HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201980103300.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-30
Publication Date
2025-10-17
Estimated Expiration
2039-12-30

AI Technical Summary

Technical Problem

In existing online signing schemes, the signing records stored in the NPN network are not updated in a timely manner, resulting in the signing records of terminal devices being unsuitable for devices that have completed online signing, thus affecting the flexibility and applicability of network connections.

Method used

The first core network element identifies the online subscription request of the terminal device, triggers authentication, and sends a message to the second core network element to request the generation or update of the network subscription. The second core network element generates or updates the network subscription data of the terminal device, including information such as DNN, NSSAI, and user group identifier. The third core network element updates the URSP policy to support the network access of the terminal device.

Benefits of technology

It enables timely updates of online contract signing, improves the applicability and flexibility of online contract signing methods, and ensures that terminal devices can successfully access the enterprise network and obtain the correct network resource configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115299086B_ABST
    Figure CN115299086B_ABST
Patent Text Reader

Abstract

An online subscription method and device, wherein the method comprises: a first core network element identifying that a terminal device needs to perform online subscription, triggering online subscription authentication of the terminal device, and sending a first message to a second core network element to request the second core network element to generate or update network subscription of the terminal device in the case that the online subscription authentication of the terminal device is successful. The above technical solution can enable the network to generate or update network subscription for the terminal device in time.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of wireless communication, in particular to an online subscription method and device. BACKGROUND

[0002] Online subscription refers to a subscription mode in which a network does not configure a terminal device in advance, and the network configures the subscription for the terminal device when the terminal device registers to the network. Figure 1 An existing online subscription scheme is shown in FIG. 1. As shown in FIG. 1, a terminal device sends an attachment request for online subscription only to a non-public network (NPN), and then the terminal device and an enterprise network perform mutual authentication through the NPN. After the authentication is passed, the terminal device and the NPN continue to complete the attachment process. After the attachment process is completed, the terminal device establishes a user plane connection with the enterprise network to obtain a subscription generated by the enterprise network online. After obtaining the subscription generated online, the terminal device performs a detachment process and then performs re-attachment to obtain normal services. Figure 1 As can be seen, in the existing online subscription scheme, only the enterprise network generates a subscription for the terminal device online, but the subscription stored in the NPN is not updated after the online subscription process is completed, which causes the subscription configured by default in the NPN for the terminal device to no longer be applicable to the terminal device after the online subscription is completed.

[0003] SUMMARY

[0004] Embodiments of the present application provide an online subscription method and device for generating a network subscription for a terminal device online.

[0005] In a first aspect, an online subscription method is provided, which can be executed by a first core network element, such as an AMF or an SMF. The method includes: the first core network element identifying that a terminal device needs to perform online subscription; the first core network element triggering online subscription authentication for the terminal device; and if the online subscription authentication for the terminal device is successful, the first core network element sending a first message to a second core network element, the first message including a first identifier of the terminal device, and the first message being used to request the second core network element to generate or update a network subscription for the terminal device.

[0006] By using the above technical scheme, the first core network element can identify that the terminal device needs to perform online subscription, trigger online subscription authentication for the terminal device, and after the online subscription authentication for the terminal device is successful, send a first message to the second core network element to request the second core network element to generate or update a network subscription for the terminal device, so that the network can generate or update a network subscription for the terminal device in time.

[0007] ​In combination with the first aspect, in a possible design of the first aspect, the first core network network element identifies that the terminal device needs to sign an online contract by receiving a second message from the terminal device or the access network device, where the second message includes a user group identifier or a network identifier. If the first core network network element confirms that the terminal device does not belong to the user group corresponding to the user group identifier or does not belong to the user group corresponding to the network identifier, it identifies that the terminal device needs to sign an online contract.

[0008] In combination with the first aspect, in a possible design of the first aspect, the first core network network element can also identify that the terminal device needs to sign an online contract by receiving a second message from the terminal device or the access network device, where the second message includes an online signing indication, and the first core network network element identifies that the terminal device needs to sign an online contract based on the online signing indication.

[0009] By adopting the above technical solution, the first core network element can identify that the terminal device needs to sign an online contract through a variety of possible methods, thereby effectively improving the applicability of the online signing method.

[0010] In combination with the first aspect, in a possible design of the first aspect, online contract authentication is a process of authenticating the identity information provided by the terminal device; the first core network network element triggers the online contract authentication of the terminal device by sending an authentication message to the authentication service function network element to trigger the authentication service function network element to perform online contract authentication on the terminal device; or the first core network network element sends an authentication message to the online registration authentication device to trigger the online registration authentication device to perform online contract authentication on the terminal device; or the first core network network element sends a first information to the terminal device, and the first information is used to instruct the terminal device to establish a connection with the online registration authentication device, and perform online contract authentication through the online registration authentication device.

[0011] By adopting the above technical solution, the first core network element can also trigger online signing authentication of the terminal device in a variety of possible ways, thus making the online signing method more flexible.

[0012] In combination with the first aspect, in a possible design of the first aspect, the first information may include one or more of the IP address of the online registration and authentication device, the data network name DNN, and the network slice selection auxiliary information NSSAI.

[0013] In combination with the first aspect, in a possible design of the first aspect, if the online contract authentication of the terminal device is successful, the first core network network element generates an online contract identifier for the terminal device and sends the online contract identifier to the terminal device.

[0014] In combination with the first aspect, in a possible design of the first aspect, the first message also includes a user group identifier or a network identifier; the first message is also used to notify the second core network network element to set the above-mentioned user group identifier as an allowed user group identifier in the contract data of the terminal device, or to set the user group identifier corresponding to the above-mentioned network identifier as an allowed user group identifier in the contract data of the terminal device.

[0015] In combination with the first aspect, in a possible design of the first aspect, the first core network element may also receive a network subscription of a terminal device from a second core network element. The network subscription may include one or more of the following information: the name of the data network available to the terminal device, network slice selection auxiliary information NSSAI, and a user group identifier.

[0016] In combination with the first aspect, in a possible design of the first aspect, the first core network network element may send an online signing notification message to the online registration device, where the online signing notification message includes a second identifier of the terminal device, and the online signing notification message is used to notify the online registration device of the online signing authentication result of the terminal device.

[0017] By adopting the above technical solution, the first core network network element can send an online signing notification message to the online registration device to notify the online registration device that the online signing authentication of the terminal device is successful. In this way, the online registration device can be triggered to generate the user context of the terminal device, thereby completing the signing in the enterprise network.

[0018] In combination with the first aspect, in a possible design of the first aspect, the first core network network element may also send a third message to the terminal device, where the third message includes the IP address of the online registration device, and the IP address of the online registration device is used by the terminal device to obtain the user context generated or updated for the terminal device from the online registration device.

[0019] In combination with the first aspect, in a possible design of the first aspect, if the online contract authentication of the terminal device fails, the first core network network element may send a fourth message to the terminal device, and the fourth message is used to reject the request of the second message.

[0020] In the second aspect, an embodiment of the present application provides an online signing method, which can be executed by a second core network network element, such as a UDR or UDM, and the method includes: the second core network network element receives a first message from a first core network network element or an online registration device, and the first message includes a first identifier of the terminal device, and the first message is used to request the second core network network element to generate or update the network signing of the terminal device; the second core network network element generates or updates the network signing of the terminal device.

[0021] The second core network element can receive the first message for requesting to generate or update the network subscription of the terminal device from the first core network element, and generate or update the network subscription of the terminal device, so as to complete the network subscription of the terminal device.

[0022] With reference to the second aspect, in a possible design of the second aspect, the first message further includes a user group identifier or a network identifier; and correspondingly, the second core network element generating or updating the network subscription of the terminal device can include that the second core network element sets the user group identifier as an allowed user group identifier in the subscription data of the terminal device, or the second core network element sets the user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device.

[0023] With reference to the second aspect, in a possible design of the second aspect, the second core network element generating or updating the network subscription of the terminal device can further include that the second core network element generates an online subscription identifier, and adds the online subscription identifier to the subscription data of the terminal device.

[0024] With reference to the second aspect, in a possible design of the second aspect, the first message can further include a certificate allocated by an online registration device or an online registration authentication device for the terminal device; and correspondingly, the second core network element generating or updating the network subscription of the terminal device can further include that the second core network element adds the certificate to the subscription data of the terminal device.

[0025] With reference to the second aspect, in a possible design of the second aspect, the second core network element generating or updating the network subscription of the terminal device can further include that the second core network element adds a data network name (DNN) and / or network slice selection assistance information (NSSAI) available for the terminal device in the subscription data of the terminal device.

[0026] With the above technical solutions, the second core network element generating or updating the network subscription of the terminal device can have multiple possible implementation manners, so that the network subscription information of the terminal device is more perfect and rich, and the flexibility of the online subscription method can be effectively improved.

[0027] With reference to the second aspect, in a possible design of the second aspect, the second core network element can send a subscription notification message to the third core network element, and the subscription notification message includes one or more of the following information: the data network name (DNN), the network slice selection assistance information (NSSAI), and the user group identifier added in the subscription data of the terminal device.

[0028] According to the technical solution, after the second core network element generates or updates network subscription of the terminal device, the second core network element can send a subscription notification message to the third core network element to trigger the third core network element to update the URSP policy of the terminal device.

[0029] With reference to the second aspect, in a possible design of the second aspect, the DNN and / or the NSSAI contained in the subscription notification message are DNN and / or NSSAI associated with the user group identifier.

[0030] In a third aspect, an embodiment of the present application provides an online subscription method, which can be executed by a third core network element, for example, a PCF. The method comprises the following steps: the third core network element receives a subscription notification message, wherein the subscription notification message comprises one or more of the following information added in subscription data of a terminal device: a data network name DNN available for the terminal device, network slice selection assistance information NSSAI, and a user group identifier; the third core network element generates or updates a terminal device routing selection policy URSP of the terminal device according to the subscription notification message, wherein the URSP comprises one or more of the following information: the DNN available for the terminal device, the NSSAI, and the user group identifier added in the subscription data of the terminal device; and the third core network element sends the URSP to the terminal device.

[0031] According to the technical solution, the third core network element updates the URSP policy of the terminal device according to the subscription notification message received from the second core network element, so that the terminal device can subsequently access the enterprise network according to the updated URSP policy.

[0032] With reference to the third aspect, in a possible design of the third aspect, the URSP further comprises an identifier of an application available for the terminal device, and an association relationship between the application and one or more of the DNN, the NSSAI, and the user group identifier.

[0033] In a fourth aspect, an embodiment of the present application provides an online subscription method, which can be executed by a terminal device. The method comprises the following steps: the terminal device receives a terminal device routing selection policy URSP from a third core network element, wherein the URSP comprises one or more of the following information: a data network name DNN available for the terminal device, network slice selection assistance information NSSAI, and a user group identifier added in subscription data of the terminal device; and the terminal device accesses a network according to the received URSP, wherein the network can be an enterprise network.

[0034] In a possible design of the fourth aspect, the URSP further includes an identifier of an application available to the terminal device, and an association relationship between the application and one or more of the DNN, the NSSAI, and the user group identifier.

[0035] The terminal device accesses the network according to the received URSP. In this case, the terminal device accesses the network according to the DNN, the NSSAI, and the user group identifier associated with the currently used application according to the association relationship.

[0036] In a possible design of the fourth aspect, the terminal device can further obtain the generated or updated network subscription from the first core network element.

[0037] In the fifth aspect, an embodiment of the present application provides a communication apparatus, which has the function of the first core network element in the first aspect or any possible design of the first aspect, or has the function of the second core network element in the second aspect or any possible design of the second aspect, or has the function of the third core network element in the third aspect or any possible design of the third aspect. The apparatus can be a network device or a chip included in the network device. The function of the communication apparatus can be implemented by hardware, or by hardware executing corresponding software, and the hardware or software includes one or more modules corresponding to the functions.

[0038] The apparatus can also have the function of the terminal device in the fourth aspect or any possible design of the fourth aspect, and the apparatus can be a terminal device or a chip included in the terminal device. The function of the communication apparatus can be implemented by hardware, or by hardware executing corresponding software, and the hardware or software includes one or more modules corresponding to the functions.

[0039] In one possible design, the apparatus includes a processing module and a transceiver module in its structure. The processing module is configured to support the apparatus to perform the corresponding functions of the first core network element in the first aspect or in any of the designs of the first aspect, or to perform the corresponding functions of the second core network element in the second aspect or in any of the designs of the second aspect, or to perform the corresponding functions of the third core network element in the third aspect or in any of the designs of the third aspect, or to perform the corresponding functions of the terminal device in the fourth aspect or in any of the designs of the fourth aspect. The transceiver module is used to support the communication between the apparatus and other communication devices. For example, when the apparatus is the first core network element, the apparatus can send a first message to the second core network element, where the first message is used to request the second core network element to generate or update the network subscription of the terminal device. The apparatus can also include a storage module coupled to the processing module, which stores the necessary program instructions and data of the apparatus. As an example, the processing module can be a processor, the communication module can be a transceiver, and the storage module can be a memory. The memory can be integrated with the processor or can be separately arranged from the processor, and the disclosure does not limit this.

[0040] In another possible design, the apparatus includes a processor and can also include a memory. The processor is coupled to the memory and can be used to execute the computer program instructions stored in the memory, so that the apparatus performs the methods in the first aspect or in any of the designs of the first aspect, or performs the methods in the second aspect or in any of the designs of the second aspect, or performs the methods in the third aspect or in any of the designs of the third aspect, or performs the methods in the fourth aspect or in any of the designs of the fourth aspect. Optionally, the apparatus also includes a communication interface, and the processor is coupled to the communication interface. When the apparatus is a network device, the communication interface can be a transceiver or an input / output interface. When the apparatus is a chip included in a network device, the communication interface can be an input / output interface of the chip. Optionally, the transceiver can be a transceiver circuit, and the input / output interface can be an input / output circuit.

[0041] In a sixth aspect, an embodiment of the present application provides a chip system, including: a processor, and a memory coupled to the processor, where the memory is used to store a program or instructions, and when the program or instructions are executed by the processor, the chip system implements the methods in the first aspect or in any of the designs of the first aspect, or implements the methods in the second aspect or in any of the designs of the second aspect, or implements the methods in the third aspect or in any of the designs of the third aspect, or implements the methods in the fourth aspect or in any of the designs of the fourth aspect.

[0042] Optionally, the chip system further comprises an interface circuit for interacting code instructions to the processor.

[0043] Optionally, the processor in the chip system can be one or more, which can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in a memory.

[0044] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or set separately from the processor, which is not limited in the present application. For example, the memory can be a non-transient processor, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or set on different chips respectively, and the type of the memory and the setting mode of the memory and the processor are not limited in the present application.

[0045] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program or instructions, when the computer program or instructions are executed, causing a computer to execute the method in the first aspect or any possible design of the first aspect, or execute the method in the second aspect or any possible design of the second aspect, or execute the method in the third aspect or any possible design of the third aspect, or execute the method in the fourth aspect or any possible design of the fourth aspect.

[0046] In an eighth aspect, an embodiment of the present application provides a computer program product, when a computer reads and executes the computer program product, causing the computer to execute the method in the first aspect or any possible design of the first aspect, or execute the method in the second aspect or any possible design of the second aspect, or execute the method in the third aspect or any possible design of the third aspect, or execute the method in the fourth aspect or any possible design of the fourth aspect.

[0047] In a ninth aspect, an embodiment of the present application provides a communication system, which comprises the first core network device, the second core network device and the third core network device. Optionally, the communication system can further comprise an access network device and a terminal device. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 An existing online subscription scheme is shown in the figure;

[0049] Figure 2 A network architecture of a communication system to which an embodiment of the present application is applied is shown in the figure;

[0050] Figure 3 A flowchart of an online subscription method provided by an embodiment of the present application;

[0051] Figure 4a A specific example of the online subscription method provided by an embodiment of the present application; Figure 4b A specific example of the online subscription method provided by an embodiment of the present application;

[0052] Figure 5a A specific example of the online subscription method provided by an embodiment of the present application; Figure 5b A specific example of the online subscription method provided by an embodiment of the present application;

[0053] Figure 6a A specific example of the online subscription method provided by an embodiment of the present application; Figure 6b A specific example of the online subscription method provided by an embodiment of the present application;

[0054] Figure 7 A flowchart of an online subscription method provided by an embodiment of the present application;

[0055] Figure 8 A flowchart of an online subscription method provided by an embodiment of the present application;

[0056] Figure 9 A flowchart of an online subscription method provided by an embodiment of the present application;

[0057] Figure 10 A flowchart of an online subscription method provided by an embodiment of the present application;

[0058] Figure 11 A specific example of the online subscription method provided by an embodiment of the present application; A specific example of the online subscription method provided by an embodiment of the present application;

[0059] A specific example of the online subscription method provided by an embodiment of the present application; Figure 12a A specific example of the online subscription method provided by an embodiment of the present application; Figure 12b A specific example of the online subscription method provided by an embodiment of the present application;

[0060] Figure 13 A flowchart of an online subscription method provided by an embodiment of the present application;

[0061] Figure 14 A flowchart of an online subscription method provided by an embodiment of the present application;

[0062] Figure 15 A flowchart of an online subscription method provided by an embodiment of the present application;

[0063] Figure 16 A flowchart of an online subscription method provided by an embodiment of the present application; DETAILED DESCRIPTION

[0064] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.

[0065] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: a global system for mobile communications (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), a universal mobile telecommunications system (UMTS), a worldwide interoperability for microwave access (WIMAX) communication system, a 5th generation (5G) system or a new radio (NR), or a future communication system or other similar communication system, etc.

[0066] Please refer to Figure 2 A network architecture schematic diagram of a communication system to which the embodiments of the present application are applicable is shown in FIG. 1. The network architecture includes a terminal device, an NPN network and an enterprise network. The terminal device can access the enterprise network through the NPN network. The NPN network can be deployed and provided by an operator for the enterprise network to use, or can be deployed by the enterprise itself, which is not limited by the present application.

[0067] The terminal device is a device with wireless transceiver function, which can be deployed on land, including indoor or outdoor, handheld, wearable or vehicle-mounted; can also be deployed on the water surface (such as ships, etc.); can also be deployed in the air (such as airplanes, balloons and satellites, etc. The terminal device can communicate with the core network through a radio access network (RAN), and exchange voice and / or data with the RAN. The terminal device can be a mobile phone, a tablet computer (Pad), a computer with wireless transceiver function, a mobile internet device (MID), a wearable device, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The embodiments of the present application do not limit the application scenarios. The terminal device can also be called user equipment (UE), mobile station and remote station, etc. The embodiments of the present application do not limit the specific technology, device form and name of the terminal device.

[0068] The NPN network specifically includes an access network device, an access management network element, a session management network element, a user plane network element, a policy control network element, an authentication service function network element, a unified data management network element, a unified data storage network element, and a network capability exposure network element. The NPN network can also include other network elements, and the embodiments of the present application do not limit them.

[0069] The access network device is a device in a network for connecting a terminal device to a wireless network. The access network device can be a node in a wireless access network, and can also be referred to as a base station, and can also be referred to as a radio access network (RAN) node (or device). The network device can include an evolved Node B (eNB or e-NodeB, evolutional Node B) in a long term evolution (LTE) system or an evolved LTE system (LTE-Advanced, LTE-A), such as a conventional macro base station eNB and a micro base station eNB in a heterogeneous network scenario, or can also include a next generation Node B (gNB) in a 5th generation mobile communication technology (5th generation, 5G) new radio (new radio, NR) system, or can also include a radio network controller (RNC), a Node B (Node B, NB), a base station controller (base station controller, BSC), a base transceiver station (base transceiver station, BTS), a transmission reception point (transmission reception point, TRP), a home base station (for example, home evolved NodeB, or home Node B, HNB), a baseband unit (base band unit, BBU), a baseband pool BBU pool, or a WiFi access point (access point, AP), or can also include a centralized unit (centralized unit, CU) and a distributed unit (distributed unit, DU) in a cloud radio access network (cloud radio access network, CloudRAN) system, and the embodiments of the present application are not limited. In a separate deployment scenario of the access network device including the CU and the DU, the CU supports radio resource control (radio resource control, RRC), packet data convergence protocol (packet data convergence protocol, PDCP), service data adaptation protocol (service data adaptation protocol, SDAP) and other protocols; the DU mainly supports radio link control layer (radio link control, RLC), media access control layer (media access control, MAC) and physical layer protocols.

[0070] The access management network element is mainly used for the attachment of terminals in a mobile network, mobility management, tracking area update process, and the access management network element terminates non-access stratum (NAS) messages, completes registration management, connection management, and reachability management, allocates a tracking area list (TA list), and performs mobility management, and transparently routes session management (SM) messages to a session management network element. In a 5th generation (5G) communication system, the access management network element can be an access and mobility management function (AMF), and in a future communication system (such as a 6G communication system), the mobility management network element can still be an AMF network element, or can also have other names, which are not limited in the present application.

[0071] The session management network element is mainly used for session management in a mobile network, such as session establishment, modification, and release. Specific functions include allocating an internet protocol (IP) address for a terminal, selecting a user plane network element that provides message forwarding functions, and the like. In a 5G communication system, the session management network element can be a session management function (SMF), and in a future communication system (such as a 6G communication system), the session management network element can still be an SMF network element, or can also have other names, which are not limited in the present application.

[0072] The user plane network element is mainly used for processing user messages, such as forwarding, charging, lawful interception, and the like. The user plane network element can also be referred to as a protocol data unit (PDU) session anchor (PSA). In a 5G communication system, the user plane network element can be a user plane function (UPF), and in a future communication system (such as a 6G communication system), the user plane network element can still be a UPF network element, or can also have other names, which are not limited in the present application.

[0073] The policy control network element includes user subscription data management functions, policy control functions, charging policy control functions, quality of service (QoS) control, and the like. In a 5G communication system, the policy control network element can be a policy control function (PCF), and in a future communication system (such as a 6G communication system), the policy control network element can still be a PCF network element, or can also have other names, which are not limited in the present application.

[0074] Authentication service function network element, mainly used for security authentication of terminal equipment. In the 5G communication system, the authentication service function network element can be an authentication server function (AUSF). In future communication systems (such as 6G communication systems), the authentication service function network element can still be an AUSF network element, or can also have other names, which are not limited by the present application.

[0075] Unified data management network element, mainly used for managing subscription information of terminal equipment. In the 5G communication system, the unified data management network element can be a unified data management (UDM). In future communication systems (such as 6G communication systems), the unified data management network element can still be a UDM network element, or can also have other names, which are not limited by the present application.

[0076] Unified data storage network element, mainly used for storing structured data information, including subscription information, policy information, and network data or service data with standard format definition. In the 5G communication system, the unified data storage network element can be a unified data repository (UDR). In future communication systems (such as 6G communication systems), the unified data storage network element can still be a UDR network element, or can also have other names, which are not limited by the present application.

[0077] Network capability exposure network element, which can expose part of the network functions to applications in a controlled manner. In the 5G communication system, the network capability exposure network element can be a network exposure function (NEF). In future communication systems (such as 6G communication systems), the network capability exposure network element can still be an NEF network element, or can also have other names, which are not limited by the present application.

[0078] Enterprise network includes online registration equipment (OSU server) and online registration authentication equipment (OSU AAA server). The online registration equipment is used to generate subscription data of the enterprise to the terminal equipment in the online subscription process, and the online registration authentication equipment is used to authenticate the terminal equipment in the online subscription process. In one example, the online registration equipment can be an online registration server, and the online registration authentication equipment can be an online registration authentication server. The online registration equipment and the online registration authentication equipment can be a combined deployment device, or can be two independent devices, which are not limited by the present application.

[0079] It should be understood that the above network elements or functions can be network elements in a hardware device, software functions running on a dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform).

[0080] For the convenience of description, in the following of the present application, the access management network element is referred to as an AMF network element, the session management network element is referred to as an SMF network element, the authentication service function network element is referred to as an AUSF network element, the unified data storage network element is referred to as a UDR network element, the unified data management network element is referred to as a UDM network element, and the policy control network element is referred to as a PCF network element. Further, the AMF network element is referred to as an AMF, the SMF network element is referred to as an SMF, the AUSF network element is referred to as an AUSF, the UDR network element is referred to as a UDR, the UDM network element is referred to as a UDM, and the PCF network element is referred to as a PCF. That is, the AMF described in the following of the present application can be replaced by an access management network element, the SMF can be replaced by a session management network element, the AUSF can be replaced by an authentication service function network element, the UDR can be replaced by a unified data storage network element, the UDM can be replaced by a unified data management network element, and the PCF can be replaced by a policy control network element.

[0081] It should be noted that the terms "system" and "network" in the embodiments of the present application can be used interchangeably. "Multiple" means two or more. In view of this, "multiple" in the embodiments of the present application can also be understood as "at least two". "At least one" can be understood as one or more, for example, as one, two or more. For example, "including at least one" means including one, two or more, and does not limit which ones are included. For example, including at least one of A, B and C means that A, B, C, A and B, A and C, B and C, or A and B and C can be included. Similarly, the understanding of "at least one" and the like is also similar. "And / or" describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / ", unless otherwise specified, generally represents an "or" relationship between the front and rear associated objects.

[0082] Unless otherwise stated, the ordinal numbers "first", "second", etc. mentioned in the embodiments of the present application are used to distinguish a plurality of objects, and are not used to limit the order, time sequence, priority or importance of the plurality of objects, and the description of "first", "second" does not necessarily mean that the objects are different.

[0083] Embodiment one

[0084] Please refer to Figure 3 A flowchart of an online signing method provided by the embodiments of the present application is shown in the figure, and the method specifically includes the following steps:

[0085] Step S301, the first core network element identifies that the terminal device needs to perform online subscription.

[0086] The first core network element, the second core network element and the third core network element mentioned in the embodiments of the present application are all network elements in the NPN network, specifically, the first core network element can be an AMF or an SMF, the second core network element can be a UDR or a UDM, and the third core network element can be a PCF.

[0087] In step S301, the first core network element can receive a second message from the terminal device or the access network device, and identify that the terminal device needs to perform online subscription authentication according to the user group identifier, the network identifier or the online subscription indication included in the second message. The second message can be a registration request message, or have other names, which are not limited by the present application.

[0088] For example, in the example shown in Figure 4a and Figure 4b , the first core network element is an AMF, and the terminal device can send a registration request message to the access network device, which includes the user group identifier or the network identifier of the user group to which the terminal device belongs. The user group identifier can be a closed access group identifier (CAG ID) for example. Then, the access network device performs AMF selection and forwards the received registration request message to the corresponding AMF. After receiving the registration request message, the AMF judges according to the user group identifier or the network identifier in the registration request message, and if it confirms that the terminal device does not belong to the user group corresponding to the user group identifier or confirms that the terminal device does not belong to the user group corresponding to the network identifier, it identifies that the terminal device needs to perform online subscription. It should be understood that, at this time, the AMF does not consider that the terminal device belongs to the user group corresponding to the user group identifier, or based on the current subscription of the terminal device, the AMF does not identify that the terminal device belongs to the group identified by the user group identifier. The AMF determines that the terminal device does not belong to the user group corresponding to the network identifier is similar. Optionally, after receiving the registration request message, the AMF can perform AUSF selection, perform SIM card authentication on the terminal device through the selected AUSF, and after the authentication is passed, identify that the terminal device needs to perform online subscription according to the user group identifier in the registration request message.

[0089] For another example, in Figure 5a and Figure 5b , the first core network element is an SMF, and the terminal device can send a registration request message to the access network device, which includes the user group identifier or the network identifier of the user group to which the terminal device belongs. Then, the access network device performs SMF selection and forwards the received registration request message to the corresponding SMF. After receiving the registration request message, the SMF judges according to the user group identifier or the network identifier in the registration request message, and if it confirms that the terminal device does not belong to the user group corresponding to the user group identifier or confirms that the terminal device does not belong to the user group corresponding to the network identifier, it identifies that the terminal device needs to perform online subscription.In the shown example, the first core network element is an AMF, and the terminal device can send a registration request message to the access network device, where the registration request message includes an online subscription indication (OSU indication). The online subscription indication can be explicit indication information, or a special data network name (DNN) or network slice selection assistance information (NSSAI), which is not limited in the present application. Subsequently, the access network device performs AMF selection and forwards the received registration request message to the corresponding AMF. After receiving the registration request message, the AMF can identify that the terminal device needs to perform online subscription authentication according to the online subscription indication in the registration request message.

[0090] In step S302, the first core network element triggers online subscription authentication of the terminal device. The online subscription authentication is a process of authenticating identity information provided by the terminal device.

[0091] In the embodiments of the present application, the online subscription authentication of the terminal device can have multiple possible implementation manners. In one implementation manner, the first core network element can send an authentication message to the AUSF to trigger the AUSF to perform online subscription authentication of the terminal device. The authentication message can be an authentication request message or an authentication response message. Optionally, the AUSF can obtain subscription data of the terminal device through the UDM when performing online subscription of the terminal device. After the online subscription authentication is completed, the AUSF can notify the first core network element of the online subscription authentication result of the terminal device.

[0092] In another implementation manner, the first core network element can send an authentication message to the online registration authentication device to trigger the online registration authentication device to perform online subscription authentication of the terminal device. After the online subscription authentication is completed, the online registration authentication device can notify the first core network element of the online subscription authentication result of the terminal device.

[0093] For example, in the example shown in Figure 4a and Figure 5a In the example shown in Figure 4b and Figure 5b In the example shown in

[0094] It should be understood that the network mentioned in the embodiments of the present application for online subscription authentication of the terminal device can be certificate-based device authentication (such as EAP-TLS), can be username and password-based authentication (such as EAP-TTLS), or can be other authentication manners, which are not limited by the present application.

[0095] In step S303, if the online subscription authentication of the terminal device is successful, the first core network element sends a first message to the second core network element, the first message including the first identifier of the terminal device, and the first message being used to request the second core network element to generate or update the network subscription of the terminal device.

[0096] The first message can be an online subscription request message, or have other names, which are not limited by the present application. The first identifier of the terminal device can be one or more of a subscription permanent identifier (SUPI), a subscription concealed identifier (SUCI), a mobile subscriber international ISDN / PSTN number (MSISDN), a permanent equipment identifier (PEI), a globally unique temporary identifier (GUTI), or an online subscription identifier, or any other identifier uniquely identifying the terminal device. Optionally, the first core network element can generate an online subscription identifier for the terminal device after determining that the online subscription authentication of the terminal device is successful. The first core network element can also send the generated online subscription identifier to the terminal device.

[0097] Optionally, the first message can also include a user group identifier or a network identifier of the terminal device, and the first message is also used to notify the second core network element to set the user group identifier as an allowed user group identifier in the subscription data of the terminal device, or to set the user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device. For example, if the first core network element identifies that the terminal device needs to perform online subscription through the user group identifier, the first message can also include the user group identifier of the terminal device, and the second core network element can perform corresponding processing on the subscription data of the terminal device according to the user group identifier.

[0098] In step S304, the second core network element receives the first message, and generates or updates the network subscription of the terminal device according to the first message. Figure 4a and Figure 4bIn the example shown, the first core network element is an AMF, and the second core network element is a UDR. The AMF identifies that the terminal device needs to be online signed according to the user group identifier (such as a CAG ID) in the registration request message. After the AMF determines that the terminal device is successfully authenticated for online signing, the AMF can send an online signing request message to the UDR, and the online signing request message carries the SUPI and / or MSISDN of the terminal device and the user group identifier (CAG ID).

[0099] In Figure 5a and Figure 5b In the example shown, the first core network element is an AMF, and the second core network element is a UDR. The AMF identifies that the terminal needs to be online signed according to the online signing indication (such as an OSU indication) in the registration request message. After the AMF determines that the terminal device is successfully authenticated for online signing, the AMF can generate an online signing identifier for the terminal device, and then send an online signing request message to the UDR, and the online signing request message carries the online signing identifier of the terminal device.

[0100] If the terminal device fails to be authenticated for online signing, the first core network element can send a fourth message to the terminal device through the access network device, and the fourth message is used to reject the request of the second message. The fourth message can be a registration rejection message (registration reject), or have other names, which are not limited by the present application.

[0101] In step S304, the second core network element receives the first message from the first core network element, and the first message can be an online signing request message.

[0102] In step S305, the second core network element generates or updates the network subscription of the terminal device.

[0103] In the embodiments of the present application, the second core network element can generate or update the network subscription of the terminal device after receiving the first message. The network subscription refers to the subscription generated by the NPN network for the terminal device, which includes some subscription data. The second core network element generating or updating the network subscription of the terminal device can be that the second core network element itself generates or updates the network subscription of the terminal device, or that the second core network element sends a request to the operation network element to generate or update the network subscription of the terminal device, and receives the generated or updated network subscription of the terminal device from the operation network element. The present application is not limited thereto.

[0104] Specifically, the second core network element generating or updating the network subscription of the terminal device can include: the second core network element adding a data network name (DNN) and / or network slice selection assistance information (NSSAI) available to the terminal device in the subscription data of the terminal device. The second core network element can generate the DNN and / or NSSAI available to the terminal device according to one or more of the user group identifier (such as CAG ID) of the terminal device, the identifier (such as SUPI) of the terminal device, and the network identifier.

[0105] In a possible design, the first message can further include the user group identifier or the network identifier of the terminal device, and the second core network element generating or updating the network subscription of the terminal device can further include: setting the user group identifier as an allowed user group identifier in the subscription data of the terminal device, or setting the user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device.

[0106] For example, the first core network element identifies that the terminal device needs to perform online subscription according to the user group identifier (such as CAG ID) in the registration request message, and the first core network element can send the user group identifier of the terminal device obtained from the registration request message to the second core network element through the first message. Accordingly, the second core network element can set the user group identifier as an allowed user group identifier in the subscription data of the terminal device when generating or updating the network subscription of the terminal device.

[0107] For another example, the first core network element identifies that the terminal device needs to perform online subscription according to the network identifier in the registration request message, and the first core network element can send the network identifier of the terminal device obtained from the registration request message to the second core network element through the first message. Accordingly, the second core network element can set the network identifier as an allowed user group identifier in the subscription data of the terminal device when generating or updating the network subscription of the terminal device.

[0108] Optionally, if the first core network element identifies that the terminal needs to perform online subscription according to the online subscription indication (such as OSU indication) in the registration request message, and generates an online subscription identifier for the terminal device, the first core network element can also send the online subscription identifier of the terminal device to the second core network element through the first message. Accordingly, the second core network element can also add the online subscription identifier to the subscription data of the terminal device when generating or updating the network subscription of the terminal device, and bind the network subscription generated for the terminal device to the online subscription identifier of the terminal device.

[0109] Optionally, the second core network element can also generate an online signup identifier for the terminal device, and add the generated online signup identifier into the subscription data of the terminal device. That is, the online signup identifier of the terminal device can be generated by the first core network element or by the second core network element.

[0110] Further, after generating or updating the network subscription of the terminal device, the second core network element can also send a fifth message to the first core network element, where the fifth message is used to respond to the first message sent by the first core network element. The fifth message can be an online signup response message, or can have other names, which are not limited by the present application.

[0111] Subsequently, the first core network element can receive the fifth message from the second core network element, and send a sixth message to the online registration device. The sixth message includes the second identifier of the terminal device, and the sixth message is used to notify the online registration device of the online signup authentication result of the terminal device. The sixth message can be an online signup announcement message, or have other names, which are not limited by the present application. The second identifier of the terminal device can be one or more of the SUPI or SUCI or MSISDN or online signup identifier of the terminal device, and the first identifier and the second identifier of the terminal device can be the same or different, which are not limited by the present application.

[0112] The online registration device can receive the sixth message, determine that the online signup authentication of the terminal device is successful according to the sixth message, and then generate a user context for the terminal device. After generating the user context of the terminal device, the online registration device can send a seventh message to the first core network element, where the seventh message is used to respond to the sixth message sent by the first core network element. The seventh message can be an online signup announcement response message, or have other names, which are not limited by the present application.

[0113] After the first core network element receives the seventh message, the first core network element can send a third message to the terminal device through the access network device, where the third message is used to accept the request in the second message. At this time, the registration process of the terminal device ends, and the network subscription of the terminal device is generated or updated in the NPN network, and the user context of the terminal device is generated in the enterprise network. The third message can be a registration accept message, or have other names, which are not limited in the present application. The third message can further include the IP address of the online registration device, so as to facilitate the terminal device to subsequently establish a connection with the online registration device and obtain the generated user context. The IP address of the online registration device can be pre-configured in the first core network element, or can be obtained by the first core network element through other manners, which are not limited in the present application.

[0114] It should be understood that in the embodiments of the present application, if the first core network element performs online subscription authentication on the terminal device through the online registration authentication device, the first core network element can also directly send the third message to the terminal device through the access network device after receiving the fifth message from the second core network element. This can also be understood as that, in the case that the first core network element performs online subscription authentication on the terminal device through the online registration authentication device, the actions of the first core network element sending the sixth message (i.e. the online subscription notification message) to the online registration device and receiving the seventh message (i.e. the online subscription notification response message) from the online registration device are optional, or the actions of the first core network element sending the sixth message (i.e. the online subscription notification message) to the online registration device and receiving the seventh message (i.e. the online subscription notification response message) from the online registration device can also be performed after the first core network device sends the third message to the terminal device through the access network device. Because in this case, the online registration device can directly obtain the online subscription authentication result of the terminal device, and the online registration device can generate the user context for the terminal device after determining that the terminal device is successfully authenticated for online subscription.

[0115] For example, in the case that the first core network element performs online subscription authentication on the terminal device through the online registration authentication device, the first core network element can send the third message to the terminal device through the access network device after receiving the fifth message from the second core network element, and the third message can include the IP address of the online registration device. Figure 4aIn the example shown, the first core network element is AMF, and the second core network element is UDR. AMF identifies that the terminal device needs to perform online contract signing based on the user group identifier (such as CAG ID) in the registration request message, and AMF performs online contract signing authentication on the terminal device through AUSF. After AMF determines that the online contract signing authentication of the terminal device is successful, it can send an online contract signing request message to UDR. The online contract signing request message includes the user group identifier (such as CAG ID) and the identifier of the terminal device (such as SUPI and / or MSISDN). Therefore, after receiving the online contract signing request message, UDR can generate or update the network contract of the terminal device, and then send an online contract signing response message to AMF. After receiving the online contract signing response message, AMF can obtain the generated or updated network contract of the terminal device from UDR. Subsequently, AMF can send an online contract signing notification message to the online registration device. The online contract signing notification message is used to notify the online registration device that the online contract signing authentication of the terminal device is successful. The online contract notification message also includes the identifier of the terminal device (such as SUPI or MSISDN), but the identifier of the terminal device in the online contract notification message and the identifier of the terminal device in the online contract request message may be the same or different. For example, the online contract request message includes the SUPI of the terminal device, and the online contract notification message also includes the SUPI of the terminal device, or the online contract request message includes the SUPI of the terminal device, and the online contract notification message includes the MSISDN of the terminal device. After receiving the online contract notification message, the online registration device may generate a user context for the terminal device and send an online contract notification response message to the AMF. Furthermore, the AMF may send a registration acceptance message to the terminal device through the access network device. The registration acceptance message includes the IP address of the online registration device, which is used by the terminal device to obtain the user context from the online registration device.

[0116] Figure 4b The example shown is the same as Figure 4a The process of the example shown is roughly similar. AMF uses the user group identifier (such as CAG ID) in the registration request message to identify the terminal device that needs to perform online contract authentication. However, the difference is that Figure 4bIn the example shown, the AMF identifies that the terminal device needs to be online signed up after receiving the online sign-up indication in the registration request message. The AMF performs online sign-up authentication on the terminal device through the online registration device. The AMF receives an online sign-up response message from the UDR, and obtains the network subscription generated or updated for the terminal device from the UDR. After that, the AMF can send a registration accept message to the terminal device through the access network device. The AMF can send an online sign-up notification message to the online registration device after sending the registration accept message to the terminal device, so as to trigger the online registration device to generate a user context for the terminal device. The AMF can also receive an online sign-up notification response message sent by the online registration device after the user context is generated. It should be noted that the actions of the AMF sending the online sign-up notification message to the online registration device and receiving the online sign-up notification response message from the online registration device are optional. The online registration device can directly generate a user context for the terminal device after determining that the online sign-up authentication of the terminal device is successful, without the AMF sending the online sign-up notification message.

[0117] Figure 5a The example shown is similar to the example shown in FIG. 6, but the difference is that Figure 4a The example shown is similar to the example shown in FIG. 6, but the difference is that Figure 5a In the example shown, the AMF identifies that the terminal device needs to be online signed up according to the online sign-up indication (such as the OSU indication) in the registration request message. The AMF generates an online sign-up identifier for the terminal device after determining that the online sign-up authentication of the terminal device is successful. The online sign-up identifier generated for the terminal device is included in the online sign-up request message sent by the AMF to the UDR, and the online sign-up notification message sent by the AMF to the online registration device.

[0118] In the example shown in FIG. 6, the AMF identifies that the terminal device needs to be online signed up according to the online sign-up indication (such as the OSU indication) in the registration request message. The AMF generates an online sign-up identifier for the terminal device after determining that the online sign-up authentication of the terminal device is successful. The online sign-up identifier generated for the terminal device is included in the online sign-up request message sent by the AMF to the UDR, and the online sign-up notification message sent by the AMF to the online registration device. Figure 5b The example shown is similar to the example shown in FIG. 6, but the difference is that Figure 5a The example shown is similar to the example shown in FIG. 6, but the difference is that Figure 5b In the example shown, the AMF identifies that the terminal device needs to be online signed up after receiving the online sign-up indication in the registration request message. The AMF performs online sign-up authentication on the terminal device through the online registration device.

[0119] It should be noted that, in the embodiments of the present application, the second core network element can also receive the first message from the online registration device, and generate or update the network subscription of the terminal device according to the first message received from the online registration device. If the second core network element receives the first message from the online registration device, the first message can further include a credential allocated by the online registration device or the online registration authentication device for the terminal device, in addition to the first identifier of the terminal device and the user group identifier. The second core network element can authenticate the terminal device according to the credential before generating or updating the network subscription of the terminal device. Accordingly, the second core network element generating or updating the network subscription of the terminal device can further include that the second core network element adds the credential allocated by the online registration device or the online registration authentication device for the terminal device into the subscription data of the terminal device.

[0120] If the second core network element receives the first message from the online registration device, the online registration device can generate the user context of the terminal device before sending the first message to the second core network element. Alternatively, the online registration device can allocate the credential for the terminal device in the process of generating the user context of the terminal device.

[0121] In a possible implementation, after determining that the online subscription authentication of the terminal device is successful, the first core network element sends a sixth message (i.e., an online subscription notification message) to the online registration device. After receiving the sixth message, the online registration device can generate the user context of the terminal device and send a seventh message (i.e., an online subscription notification response message) to the first core network element. Subsequently, the online registration device can send the first message to the second core network element to trigger the second core network element to generate or update the network subscription of the terminal device.

[0122] In another possible implementation, in the case that the first core network element performs online subscription authentication on the terminal device through the online registration device, the actions of the first core network element sending the sixth message (i.e., the online subscription notification message) to the online registration device and receiving the seventh message (i.e., the online subscription notification response message) from the online registration device can also be optional. That is, after determining that the online subscription authentication of the terminal device is successful, the online registration device can directly generate the user context of the terminal device, and then send the first message to the second core network element, without receiving the sixth message sent by the first core network element and then triggering the generation of the user context of the terminal device.

[0123] For example, in the case that the first core network element performs online subscription authentication on the terminal device through the online registration device, the first core network element can send the sixth message (i.e., the online subscription notification message) to the online registration device, and the online registration device can receive the sixth message and then generate the user context of the terminal device, and then send the first message to the second core network element. Figure 6aIn the example shown, the AMF performs online subscription authentication on the terminal device through the AUSF. After determining that the terminal device passes the online subscription authentication, the AMF can send an online subscription notification message to the online registration device, where the online subscription notification message includes an identifier (such as SUPI or MSISDN) of the terminal device, and the online subscription notification message is used to notify the online registration device that the terminal device passes the online subscription authentication. Thus, after receiving the online subscription notification message, the online registration device can generate a user context of the terminal device, and then send an online subscription notification response message to the AMF. Subsequently, the online registration device can send an online subscription request message to the UDR, where the online subscription request message includes a user group identifier (such as CAGID), an identifier (such as SUPI or MSISDN) of the terminal device, and a credential allocated by the online registration device for the terminal device. After receiving the online subscription request message, the UDR can first verify the credential of the terminal device, and after verification, generate or update a network subscription for the terminal device, and then send an online subscription response message to the online registration device. After that, the AMF can obtain the network subscription of the terminal device from the UDR, and send a registration accept message to the terminal device through the access network device, where the registration accept message includes an IP address of the online registration device, and is used to enable the terminal device to obtain the user context from the online registration device.

[0124] In Figure 6b In the example shown, the AMF performs online subscription authentication on the terminal device through the online registration authentication device. The actions of the AMF, after determining that the terminal device passes the online subscription authentication, to send an online subscription notification message to the online registration device, and to receive an online subscription notification response message from the online registration device, are optional. That is, after determining that the terminal device passes the online subscription authentication, the online registration device can directly generate a user context of the terminal device, and send an online subscription request message to the UDR, without generating the user context of the terminal device and sending the online subscription request message to the UDR after receiving the online subscription notification message sent by the AMF. Figure 6b The subsequent procedures in the example shown are the same as those in Figure 6a and will not be described herein again.

[0125] In step S306, the second core network element sends a subscription notification message to the third core network element, where the subscription notification message includes one or more of the following information: a data network name DNN available to the terminal device, network slice selection assistance information NSSAI, and a user group identifier added in the subscription data of the terminal device.

[0126] In an embodiment of the present application, after the second core network element generates or updates the network subscription of the terminal device, the second core network element can send a subscription notification message to the third core network element, where the subscription notification message is used to notify the generation or update of the network subscription of the terminal device. The subscription notification message can also be referred to as a subscription generation message or a subscription update message, or can have other names, which are not limited in the present application.

[0127] The third identity of the terminal device is included in the subscription notification message, which can be one or more of the SUPI, SUCI, MSISDN, and online subscription identity of the terminal device, and the third identity can be the same as or different from the first identity and the second identity, which are not limited in the present application.

[0128] It should be noted that the data network name DNN and / or network slice selection assistance information NSSAI available to the terminal device included in the subscription notification message is the data network name DNN and / or network slice selection assistance information NSSAI associated with the user group identity. That is, the user group identity has an association relationship with the data network name DNN and / or network slice selection assistance information NSSAI, or it can also be understood that the user group identity has some corresponding applications, and the data of these applications can be transmitted through the network or network slice represented by the above-mentioned associated data network name DNN and / or network slice selection assistance information NSSAI, that is, the data network name DNN and / or network slice selection assistance information NSSAI available to the terminal device in the user group identified by the user group identity.

[0129] Therefore, in one possible implementation, the subscription notification message can include the third identity of the terminal device and the data network name DNN and / or network slice selection assistance information NSSAI available to the terminal device. Alternatively, in another possible implementation, the subscription notification message can include the third identity of the terminal device and the user group identity, and the third core network device determines the data network name DNN and / or network slice selection assistance information NSSAI available to the terminal device according to the association relationship between the user group identity (or application identity) obtained from the second core network element and the data network name DNN and / or network slice selection assistance information NSSAI. Alternatively, in another possible implementation, the subscription notification message can also include the third identity of the terminal device, the user group identity, and the data network name DNN and / or network slice selection assistance information NSSAI available to the terminal device.

[0130] In step S307, the third core network element receives the subscription notification message.

[0131] Step S308, the third core network element generates or updates a terminal device routing selection policy (URSP) of the terminal device according to the subscription notification message.

[0132] The URSP includes one or more of the following information: the data network name (DNN), the network slice selection assistance information (NSSAI) and the user group identifier that are added in the subscription data of the terminal device and are available to the terminal device.

[0133] Optionally, the URSP further includes the identifier of the application available to the terminal device and the association between the available application and one or more of the DNN, the NSSAI and the user group identifier.

[0134] Step S309, the third core network element sends the generated or updated URSP of the terminal device to the terminal device.

[0135] Step S310, the terminal device receives the URSP from the third core network element.

[0136] Step S311, the terminal device accesses the network according to the received URSP, and the network can be the enterprise network.

[0137] Specifically, as shown in Figure 8 the terminal device can initiate a protocol data unit (PDU) session establishment procedure according to the available DNN and / or the NSSAI obtained from the URSP to connect to the enterprise network. For example, the terminal device can access the network using the DNN, the NSSAI and the user group identifier associated with the currently used application according to the currently used application and the association between the application and one or more of the DNN, the NSSAI and the user group identifier.

[0138] Further, the terminal device can establish a connection with the online registration device according to the IP address of the online registration device obtained from the registration accept message in the registration procedure, and obtain the user context generated by the online registration device. The terminal device can also obtain the generated or updated network subscription from the first core network element, and obtain the online subscription identifier from the first core network element or the second core network element, which will not be described herein.

[0139] In this way, through the steps S306 to S311 described above, the terminal device can obtain the generated or updated network subscription and the URSP, and access the enterprise network.

[0140] For example, in Figure 7In the illustrated example, after the UDR generates the network subscription of the terminal device, the UDR can send a subscription update message to the PCF, where the subscription update message includes the identifier (such as SUPI or MSISDN) of the terminal device and the user group identifier (such as CAG ID), or the subscription update message can also include the identifier (such as SUPI or MSISDN) of the terminal device and the DNN and / or NSSAI available to the terminal device. After receiving the subscription update message, the PCF can decide to update the URSP of the terminal device. Then, the PCF can send the updated URSP to the terminal device through the AMF and the access network device. After receiving the updated URSP, the terminal device can send a response message to the PCF.

[0141] Embodiment Two

[0142] The embodiments of the present application also provide another online subscription method. The main difference between the online subscription method in Embodiment Two and the online subscription method in Embodiment One is that the online subscription authentication method for the terminal device is different. Alternatively, the online subscription authentication method in Embodiment Two can also be understood as another specific implementation of step S302 in Embodiment One.

[0143] For another online subscription method provided by the embodiments of the present application, refer to Figure 9 The flowchart of another online subscription method provided by the embodiments of the present application is shown in FIG. 9, and the method specifically includes the following steps:

[0144] Step S901: The first core network element identifies that the terminal device needs to perform online subscription.

[0145] In the embodiments of the present application, the specific implementation of step S901 can be the same as that of step S301, and thus is not described here again.

[0146] Step S902: The first core network element sends first information to the terminal device, where the first information is used to instruct the terminal device to establish a connection with the online registration authentication device and perform online subscription authentication through the online registration authentication device.

[0147] The first information can include the IP address of the online registration authentication device and the DNN and / or NSSAI available to the terminal device. The IP address of the online registration authentication device is used for the terminal device to subsequently establish a connection with the online registration authentication device and perform online subscription authentication. The DNN and / or NSSAI are used for the terminal device to establish a PDU session that can connect to the enterprise network.

[0148] In the embodiment of the present application, the first core network element can carry the first information in the registration accept message sent to the terminal device when the registration process is completed, and the registration accept message can also include the IP address of the online registration device, which is used by the terminal device to obtain the user context.

[0149] In this way, through steps S901 and S902, the first core network element can identify that the terminal device needs to be online subscribed only in the registration process, and instruct the terminal device to subsequently establish a connection with the online registration and authentication device, while the specific online registration and authentication process of the terminal device by the online registration and authentication device can be performed in the user plane.

[0150] Step S903, the terminal device establishes a PDU session capable of connecting to the enterprise network according to the DNN and / or NSSAI in the first information.

[0151] Step S904, the terminal device establishes a connection with the online registration and authentication device according to the IP address of the online registration and authentication device in the first information, and performs online subscription and authentication of the terminal device by the online registration and authentication device.

[0152] Similar to the first embodiment, the online subscription and authentication can be certificate-based device authentication (such as EAP-TLS), can be username and password-based authentication (such as EAP-TTLS), or can be other authentication manners, which are not limited by the present application.

[0153] Step S905, if the online subscription and authentication of the terminal device is successful, the online registration and authentication device can send an eighth message to the online registration device, which can include the identity (such as one or more of SUPI, SUCI, MSISDN, GUTI, and PEI) of the terminal device, and the eighth message is used to notify the online registration device that the online subscription and authentication of the terminal device is successful.

[0154] Step S906, the online registration device generates the user context of the terminal device after determining that the online subscription and authentication of the terminal device is successful.

[0155] Optionally, the online registration device can also allocate a certificate to the terminal device, so that the second core network element verifies the identity of the terminal device before generating or updating the network subscription of the terminal device.

[0156] Step S907, the online registration device sends the generated user context to the terminal device.

[0157] Step S908, the online registration device sends a first message to the second core network element, which includes the first identity of the terminal device, and the first message is used to request the second core network element to generate or update the network subscription of the terminal device.

[0158] The first message can be an online signup request, or have other names, which are not limited in the application. The first identifier of the terminal device can be one or more of SUPI, SUCI, MSISDN, GUTI, PEI, or any other identifier that uniquely identifies the terminal device. The first message can also include the user group identifier (such as CAG ID) of the terminal device, and / or the certificate generated by the online registration device for the terminal device.

[0159] Step S909, the second core network element generates or updates the network subscription of the terminal device.

[0160] The specific implementation of step S909 can be the same as that in S305, which will not be repeated here.

[0161] Step S910, after the second core network element generates or updates the network subscription of the terminal device, the second core network element sends a fifth message to the online authentication device, and the fifth message is used to respond to the first message sent by the online registration device. The fifth message can be an online signup response, or can have other names, which are not limited in the application.

[0162] In this way, the first core network element can obtain the generated or updated network subscription of the terminal device from the second core network element.

[0163] In the embodiments of the application, after the second core network element generates or updates the network subscription of the terminal device, the second core network element can also send a subscription notification message to the third core network element to trigger the URSP update process as shown in steps S306 to S308.

[0164] In step S904, if the online subscription authentication of the terminal device fails, the online registration authentication device can send a ninth message to the first core network element, and the ninth message includes the identifier (such as one or more of SUPI, SUCI, MSISDN) of the terminal device, and the ninth message is used to notify the first core network element that the online subscription authentication of the terminal device fails. After receiving the ninth message, the AMF can initiate a deregistration process.

[0165] It should be noted that if the terminal device succeeds in online subscription authentication, the online registration authentication device can also send an eighth message to the first core network element to notify the first core network element that the terminal device succeeds in online subscription authentication. In this way, the first core network element can send a first message (i.e., an online subscription request message) to the second core network element in the manner shown in step S303 to request the second core network device to generate or update the network subscription of the terminal device. Correspondingly, the second core network device will also send a fifth message (i.e., an online subscription response message) to the first core network device.

[0166] Figure 10 The example shown is the registration process of the terminal device in the second embodiment. In Figure 10 , the first core network element is an AMF, the second core network element is a UDR, the online registration device is an OSU server, and the online registration authentication is an OSU AAA server. As Figure 10 shown, the registration process specifically includes the following steps: step 1001, the terminal device sends a registration request message to the access network device (i.e., the RAN shown in the figure), and the registration request message includes the user group identifier of the terminal device, i.e., the CAG ID in the figure. Step 1002, the access network device performs AMF selection, and then forwards the registration request message to the corresponding AMF in step 1003. Step S1004, after receiving the registration request message, the AMF performs AUSF selection. Step S1005, the AMF performs SIM card authentication on the terminal device through the selected AUSF. Step S1006, the AMF identifies that the terminal device needs to perform online subscription. In this step, the AMF identifying that the terminal device needs to perform online subscription can be that the AMF determines that the user group identifier is not allowed, i.e., the AMF considers that the user group identifier does not belong to the user group corresponding to the user group identifier. Step S1007, the AMF performs UDM selection, and in step S1008, the AMF obtains the initial subscription of the terminal device through the selected UDM. Step S1009, the AMF performs PCF selection, and in step S1010, the AMF obtains the session management policy of the terminal device through the selected PCF. Step S1010, the AMF sends the obtained session management policy of the terminal device to the SMF. Step S1011, the AMF sends a registration acceptance message to the terminal device through the access network device, and the registration process ends. The registration acceptance message includes the IP address of the OSU server, the IP address of the OSU AAA server, the DNN, and / or the NSSAI.

[0167] Figure 11 The example shown is the process of generating or updating the network subscription of the terminal device in the second embodiment, and Figure 10 , in Figure 11In the example, the first core network element is AMF, the second core network element is UDR, the online registration device is OSU server, and the online registration authentication is OSU AAA server. Figure 11 As shown, generating or updating the network contract of a terminal device specifically includes the following steps: Step S1101: The terminal device establishes a PDU session capable of connecting to the enterprise network based on the DNN and / or NSSAI obtained from the registration acceptance message. Step S1102: The terminal device establishes a connection with the OSU AAA server based on the IP address of the OSU AAA server obtained from the registration acceptance message, and the OSU AAA server performs online contract authentication on the terminal device. Steps S1103 and S1104: If the online contract authentication of the terminal device fails, the OSU AAA server sends an indication to the AMF, indicating that the online contract authentication of the terminal device has failed. Step S1105: The AMF initiates a deregistration process. Steps S1106 and S1107: If the online contract authentication of the terminal device succeeds, the OSU AAA server sends the online contract authentication result of the terminal device to the OSU server, notifying the OSU server that the online contract authentication of the terminal device has succeeded. In step S1108, the OSU server generates a user context for the terminal device. Optionally, the OSU server may also assign credentials to the terminal device in this step. In step S1109, the OSU server sends the generated user context to the terminal device. In step S1110, the OSU server sends an online contract request message to the UDR through the NEF. The online contract request message includes the terminal device identifier (such as MSISDN), the user group identifier CAG ID, and the credentials assigned by the OSU server to the terminal device. In step S1111, the UDR generates or updates the network contract for the terminal device. In step S1112, the UDR sends an online contract response message to the OSU server through the NEF. At this point, the process of generating or updating the network contract for the terminal device ends.

[0168] Figure 12a The example shown is a process for a terminal device to establish a PDU session in an embodiment of the present application. The process can be Figure 11 A specific implementation of step S1101 in FIG. Figure 12a As shown, the process of generating a PDU session may include the following steps: Step S1201, registration process, which refers to the establishment of a PDU session in Figure 10The registration procedure shown in FIG. 12 is performed. In step S1202, the terminal device sends a PDU session establishment request to the AMF, and the PDU session establishment request includes the identity of the terminal device. Optionally, the PDU session establishment request can also include an online subscription indication, and the AMF can identify in this step that the terminal device needs to perform online subscription. In step S1203, the AMF performs SMF selection, and then in step S1204, the AMF forwards the received PDU session establishment request to the selected SMF. Optionally, the AMF can consider the online subscription indication when performing SMF selection. In step S1205, the AMF obtains the session subscription information of the terminal device from the UDM. In step S1206, session granularity authentication and authorization are performed. In step S1207, the SMF performs PCF and UPF selection. In step S1208, session policy authorization is performed. In step S1209, the SMF sends an N4 session establishment request message to the UPF, and the N4 session establishment request message includes IP filters, which are used to limit the data transmission of the terminal device, that is, the currently established PDU session only allows the transmission of IP data in the online subscription process. In step S1210, the UPF sends an N4 session establishment response message to the SMF. In step S1211, the SMF performs resource configuration of the access network and the terminal device.

[0169] Figure 12b The example shown in FIG. 12 is another process of establishing a PDU session by a terminal device in an embodiment of the present application, which is different from the process of establishing a PDU session shown in FIG. 11 in that the terminal device can be authenticated for online subscription in the session granularity authentication and authorization shown in step S1205. Thus, when the PDU session establishment is completed, the terminal device can perform the process of generating or updating the network subscription of the terminal device shown in FIG. 11. Figure 12a Figure 11 In the process of generating or updating the network subscription of the terminal device shown in FIG. 11, step S1102 can be omitted, that is, there is no need to perform online subscription authentication of the terminal device again through the OSU AAA server after the PDU session is established.

[0170] An embodiment of the present application provides a communication apparatus, which can be used in the process of establishing a PDU session by a terminal device. Figure 13 ​A structural schematic diagram of a communication apparatus is provided for an embodiment of the present application. The communication apparatus 1300 comprises a transceiver module 1310 and a processing module 1320. The communication apparatus can be used to implement the functions of the first core network element in any of the above method embodiments, or to implement the functions of the second core network element in any of the above method embodiments, or to implement the functions of the third core network element in any of the above method embodiments. For example, the communication apparatus can be an AMF network element, an SMF network element in the core network, or also can be a UDR network element, a UDM network element, or also can be a PCF network element. The network element or network function can be a network element in a hardware device, can be a software function running on a special hardware, or can be a virtualized function instantiated on a platform (for example, a cloud platform).

[0171] The communication apparatus 1300 can serve as a first core network element and perform the steps performed by the first core network element in the above method embodiments. The transceiver module 1310 can be used to support the communication apparatus 1300 to communicate, for example, to perform the sending and / or receiving actions performed by the first core network element in Figure 3 and Figure 9 . The processing module 1320 can be used to support the communication apparatus 1300 to perform the processing actions in the above method embodiments, for example, to perform the processing actions performed by the first core network element in Figure 4a , Figure 4b , Figure 5a , Figure 5b , Figure 6a , Figure 6b , Figure 7 , Figure 8 , Figure 10 , Figure 11 , Figure 12a and Figure 12b . The processing module 1320 can be used to support the communication apparatus 1300 to perform the processing actions in the above method embodiments, for example, to perform the processing actions performed by the first core network element in Figure 3 and Figure 9 . The processing module 1320 can be used to support the communication apparatus 1300 to perform the processing actions in the above method embodiments, for example, to perform the processing actions performed by the AMF in Figure 4a , Figure 4b , Figure 5a , Figure 5b , Figure 6a , Figure 6b , Figure 7 , Figure 8 , Figure 10 , Figure 11 , Figure 12a and Figure 12b . Optionally, the communication apparatus 1300 can further comprise a storage module 1330 (not shown in Figure 13 ), used to store the program code and data of the communication apparatus 1300. Specifically, reference can be made to the following description:

[0172] The processing module 1320 is configured to identify that the terminal device needs to perform online subscription, and trigger online subscription authentication of the terminal device; and the transceiver module 1310 is configured to send, to the second core network element, a first message including a first identifier of the terminal device, if the online subscription authentication of the terminal device succeeds, the first message being used to request the second core network element to generate or update network subscription of the terminal device.

[0173] In a possible design, the transceiver module 1310 is further configured to receive, from the terminal device or the access network device, a second message including a user group identifier or a network identifier; and the processing module 1320 is specifically configured to identify that the terminal device needs to perform online subscription, if it is confirmed that the terminal device does not belong to a user group corresponding to the user group identifier or does not belong to a user group corresponding to the network identifier.

[0174] In a possible design, the transceiver module 1310 is further configured to receive, from the terminal device or the access network device, a second message including an online subscription indication; and the processing module 1320 is specifically configured to identify that the terminal device needs to perform online subscription according to the online subscription indication.

[0175] In a possible design, the online subscription authentication is a process of authenticating identity information provided by the terminal device; the processing module 1320 is specifically configured to send, to an authentication service function network element, an authentication message through the transceiver module 1310, to trigger the authentication service function network element to perform online subscription authentication of the terminal device; or the processing module 1320 is specifically configured to send, to an online registration authentication device, an authentication message through the transceiver module 1310, to trigger the online registration authentication device to perform online subscription authentication of the terminal device; or the processing module 1320 is specifically configured to send, to the terminal device, first information through the transceiver module 1310, the first information being used to instruct the terminal device to establish a connection with the online registration authentication device and perform online subscription authentication through the online registration authentication device.

[0176] In a possible design, the first information can include one or more of an IP address of the online registration authentication device, a data network name DNN, and network slice selection assistance information NSSAI.

[0177] In a possible design, the processing module 1320 is further configured to generate an online subscription identifier for the terminal device, if the online subscription authentication of the terminal device succeeds, and send the online subscription identifier to the terminal device through the transceiver module 1310.

[0178] In a possible design, the first message further includes a user group identifier or a network identifier, and the first message is further used to notify the second core network element to set the user group identifier as an allowed user group identifier in subscription data of the terminal device, or to set a user group identifier corresponding to the network identifier as an allowed user group identifier in subscription data of the terminal device.

[0179] In a possible design, the transceiver 1310 is further configured to receive, from the second core network element, a network subscription of the terminal device, where the network subscription can include one or more of the following information: a data network name available to the terminal device, network slice selection assistance information (NSSAI), and a user group identifier.

[0180] In a possible design, the transceiver 1310 is further configured to send, to the online registration device, an online subscription notification message including a second identifier of the terminal device, where the online subscription notification message is used to notify the online registration device of an online subscription authentication result of the terminal device.

[0181] In a possible design, the transceiver 1310 is further configured to send, to the terminal device, a third message including an IP address of the online registration device, where the IP address of the online registration device is used by the terminal device to obtain, from the online registration device, a user context generated or updated for the terminal device.

[0182] In a possible design, the transceiver 1310 is further configured to send, to the terminal device, a fourth message used to reject the request in the second message, if the online subscription authentication of the terminal device fails.

[0183] The communication apparatus 1300 can also serve as the second core network element, and perform steps performed by the second core network element in the method embodiments. The transceiver 1310 can be configured to support the communication apparatus 1300 to communicate, for example, perform the sending and / or receiving actions performed by the second core network element in Figure 3 and Figure 9 , or perform the processing actions performed by the second core network element in Figure 4a , Figure 4b , Figure 5a , Figure 5b , Figure 6a , Figure 6b , Figure 7 , Figure 10 and Figure 11 performed by the UDR. The processing module 1320 can be configured to support the communication apparatus 1300 to perform processing actions in the method embodiments, for example, perform the processing actions performed by the second core network element in Figure 3 and Figure 9 , or perform the processing actions performed by the second core network element in Figure 4a , Figure 4b, Figure 5a , Figure 5b , Figure 6a , Figure 6b , Figure 7 , Figure 10 and Figure 11 the UDR. Optionally, the communication apparatus 1300 can further include a storage module 1330 (not shown in Figure 13 ) for storing program codes and data of the communication apparatus 1300. For details, refer to the following description:

[0184] The transceiver module 1310 is configured to receive a first message from the first core network element or the online registration device, the first message including a first identifier of the terminal device, the first message being used to request the second core network element to generate or update a network subscription of the terminal device; and the processing module 1320 is configured to generate or update the network subscription of the terminal device.

[0185] In a possible design, the first message further includes a user group identifier or a network identifier; and correspondingly, the processing module 1320 is specifically configured to set the user group identifier as an allowed user group identifier in the subscription data of the terminal device, or set a user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device.

[0186] In a possible design, the processing module 1320 is further specifically configured to generate an online subscription identifier by the second core network element, and add the online subscription identifier into the subscription data of the terminal device.

[0187] In a possible design, the first message can further include a certificate allocated by the online registration device or the online registration authentication device for the terminal device; and correspondingly, the processing module 1320 is further specifically configured to add the certificate into the subscription data of the terminal device.

[0188] In a possible design, the processing module 1320 is further specifically configured to add a data network name (DNN) and / or network slice selection assistance information (NSSAI) available for the terminal device into the subscription data of the terminal device.

[0189] In a possible design, the transceiver module 1310 is further configured to send a subscription notification message to the third core network element, the subscription notification message including one or more of the following information: the DNN, the NSSAI and the user group identifier added into the subscription data of the terminal device.

[0190] In a possible design, the DNN and / or the NSSAI included in the subscription notification message are the DNN and / or the NSSAI associated with the user group identifier.

[0191] The communication device 1300 can also serve as a third core network element and execute the steps executed by the third core network element in the above method embodiment. The transceiver module 1310 can be used to support the communication device 1300 to communicate, for example, to execute Figure 3 The sending and / or receiving action performed by the third core network element in the Figure 4a 、 Figure 4b 、 Figure 5a 、 Figure 5b 、 Figure 6a 、 Figure 6b 、 Figure 7 、 Figure 8 、 Figure 10 、 Figure 11 、 Figure 12a and Figure 12b The processing module 1320 can be used to support the communication device 1300 to perform the processing actions in the above method embodiment, such as performing Figure 3 The processing action performed by the third core network element in the Figure 4a 、 Figure 4b 、 Figure 5a 、 Figure 5b 、 Figure 6a 、 Figure 6b 、 Figure 7 、 Figure 8 、 Figure 10 、 Figure 11 、 Figure 12a and Figure 12b Optionally, the communication device 1300 may further include a storage module 1330 ( Figure 13 ), which is not shown in the figure, and is used to store program codes and data of the communication device 1300. Specifically, please refer to the following description:

[0192] The transceiver module 1310 is used to receive a contract notification message, which includes one or more of the following information added in the contract data of the terminal device: the name of the data network DNN available to the terminal device, network slice selection auxiliary information NSSAI and user group identifier; the processing module 1320 is used to generate or update the terminal device routing policy URSP of the terminal device according to the contract notification message, and the URSP may include one or more of the following information: the name of the data network DNN available to the terminal device, network slice selection auxiliary information NSSAI and user group identifier added in the contract data of the terminal device; the transceiver module 1310 is also used to send the URSP to the terminal device.

[0193] In one possible design, the URSP also includes identifiers of applications available to the terminal device, and associations between the applications and one or more of the DNN, NSSAI, and user group identifiers.

[0194] It should be noted that the processing module 1320 involved in the communication device 1300 can be implemented by a processor or a processor-related circuit component, which can be a processor or a processing unit; the transceiver module 1310 can be implemented by a transceiver or a transceiver-related circuit component, which can be a transceiver or a transceiver unit.

[0195] Please refer to Figure 14 , is another structural diagram of a communication device provided in an embodiment of the present application. The communication device 1400 can be used to implement the method described in the above method embodiment. The communication device 1400 can be a chip or a network device.

[0196] The communication device 1400 includes one or more processors 1401, which can support the communication device 1400 to implement Figure 3 to Figure 12b The method of the first core network element, the second core network element, or the third core network element in the communication device 1400 is provided. The processor 1401 can be a general-purpose processor or a dedicated processor. For example, the processor 1401 can be a central processing unit (CPU) or a baseband processor. The baseband processor can be used to process communication data, and the CPU can be used to control a communication device (for example, a network device, a terminal device, or a chip), execute a software program, and process data of the software program. The communication device 1400 can also include a transceiver unit 1405 to implement signal input (reception) and output (transmission).

[0197] For example, the communication device 1400 can be a chip, the transceiver unit 1405 can be the input and / or output circuit of the chip, or the transceiver unit 1405 can be the communication interface of the chip, and the chip can be used as a component of a terminal device, a network device, or other wireless communication device.

[0198] The communication device 1400 may include one or more memories 1402, on which a program 1404 is stored. The program 1404 can be executed by the processor 1401 to generate instructions 1403, so that the processor 1401 performs the method described in the above method embodiment according to the instructions 1403. Optionally, data may also be stored in the memory 1402. Optionally, the processor 1401 may also read the data stored in the memory 1402. The data may be stored at the same storage address as the program 1404, or the data may be stored at a different storage address than the program 1404.

[0199] The processor 1401 and the memory 1402 can be separately arranged, or integrated together, for example, integrated on a single board or a system on chip (SOC).

[0200] The communication apparatus 1400 can further include a transceiver 1405 and an antenna 1406. The transceiver 1405 can be referred to as a transceiver, a transceiving circuit or a transceiver, and is configured to realize the transceiving function of the communication apparatus through the antenna 1406.

[0201] It should be understood that each step of the above method embodiments can be completed by a logic circuit in the form of hardware or instructions in the form of software in the processor 1401. The processor 1401 can be a CPU, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, for example, a discrete gate, a transistor logic device or a discrete hardware component.

[0202] The embodiment of the present application also provides another communication apparatus. Please refer to Figure 15 The structure diagram of another communication apparatus provided by the embodiment of the present application is shown in FIG. 15. The communication apparatus 1500 includes a transceiving module 1510 and a processing module 1520. The communication apparatus can be used to realize the functions of the terminal device in any of the above method embodiments. For example, the communication apparatus can be a terminal device, for example, a handheld terminal device or a vehicle-mounted terminal device; the communication apparatus can also be a chip included in a terminal device, or an apparatus including a terminal device, for example, various types of vehicles, etc.

[0203] The communication apparatus 1500 can also be a terminal device, and perform the steps performed by the terminal device in the above method embodiments. The transceiving module 1510 can be used to support the communication apparatus 1500 to communicate, for example, to perform the sending and / or receiving actions performed by the terminal device in Figure 3 and Figure 9 The processing module 1520 can be used to support the communication apparatus 1500 to perform the steps performed by the terminal device in the above method embodiments, for example, to perform the steps of Figure 4a 、 Figure 4b 、 Figure 5a 、 Figure 5b 、 Figure 6a 、 Figure 6b 、 Figure 7 、 Figure 8 、 Figure 10 、 Figure 11 、 Figure 12a and Figure 12bThe processing module 1520 can be configured to support the communication device 1500 in performing the processing actions in the above method embodiments, e.g., performing the processing actions in the method embodiments described above with respect to the network element and / or the terminal device. Figure 3 and Figure 9 the processing actions performed by the terminal device in the method embodiments described above with respect to the network element and / or the terminal device, or performing the processing actions in the method embodiments described above with respect to the network element and / or the terminal device. Figure 4a , Figure 4b , Figure 5a , Figure 5b , Figure 6a , Figure 6b , Figure 7 , Figure 8 , Figure 10 , Figure 11 , Figure 12a and Figure 12b the processing actions performed by the UE in the method embodiments described above with respect to the network element and / or the terminal device. Optionally, the communication device 1500 can further include a storage module 1530 (not shown in the figure), configured to store program codes and data of the communication device 1500. For details, please refer to the following description: Figure 13

[0204] The transceiver module 1510 is configured to receive a terminal device route selection policy (URSP) from a third core network element, the URSP including one or more of the following information: a data network name (DNN) available to the terminal device, network slice selection assistance information (NSSAI), and a user group identifier added in subscription data of the terminal device; and the processing module 1520 is configured to access a network according to the URSP.

[0205] In a possible design, the URSP further includes an identifier of an application available to the terminal device, and an association relationship between the application and one or more of the DNN, the NSSAI, and the user group identifier; and the processing module 1520 is specifically configured to cause the terminal device to access the network using the DNN, the NSSAI, and the user group identifier associated with a currently used application according to the association relationship.

[0206] In a possible design, the transceiver module 1510 is further configured to acquire a generated or updated network subscription from a first core network element.

[0207] Please refer to Figure 16 for another structure diagram of another communication device provided in the embodiments of the present application. The communication device can specifically be a terminal device. For the convenience of understanding and illustration, in Figure 16 , the terminal device takes a mobile phone as an example. As Figure 16 ​As shown, the terminal device includes a processor, and can further include a memory, and of course, can further include a radio frequency circuit, an antenna, and an input and output device, etc. The processor is mainly used for processing communication protocols and communication data, and controlling the terminal device, executing software programs, processing data of the software programs, etc. The memory is mainly used for storing software programs and data. The radio frequency circuit is mainly used for conversion between a baseband signal and a radio frequency signal, and processing of the radio frequency signal. The antenna is mainly used for receiving and transmitting a radio frequency signal in the form of an electromagnetic wave. The input and output device, such as a touch screen, a display screen, a keyboard, etc., is mainly used for receiving data input by a user and outputting data to the user. It should be noted that some types of terminal devices can not have an input and output device.

[0208] When data needs to be sent, the processor performs baseband processing on the data to be sent, and outputs a baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal, and transmits a radio frequency signal in the form of an electromagnetic wave through the antenna. When data is sent to the terminal device, the radio frequency circuit receives a radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor. The processor converts the baseband signal into data and processes the data. For the sake of illustration, Figure 16 Only one memory and one processor are shown in FIG. 1. In actual terminal device products, there can be one or more processors and one or more memories. The memory can also be referred to as a storage medium or a storage device, etc. The memory can be independent of the processor, or can be integrated with the processor. The embodiments of the present application do not limit this.

[0209] In the embodiments of the present application, the antenna and the radio frequency circuit having a transceiving function can be regarded as a transceiving unit of the terminal device, and the processor having a processing function can be regarded as a processing unit of the terminal device. As shown in FIG. 1, Figure 16 As shown, the terminal device includes a transceiving unit 1610 and a processing unit 1620. The transceiving unit can also be referred to as a transceiver, a transceiver, a transceiving device, etc. The processing unit can also be referred to as a processor, a processing board, a processing module, a processing device, etc. Optionally, the devices in the transceiving unit 1610 for implementing the receiving function can be regarded as a receiving unit, and the devices in the transceiving unit 1610 for implementing the sending function can be regarded as a sending unit, that is, the transceiving unit 1610 includes the receiving unit and the sending unit. The transceiving unit can also be referred to as a transceiver, a transceiver, or a transceiving circuit, etc. The receiving unit can also be referred to as a receiver, a receiver, or a receiving circuit, etc. The sending unit can also be referred to as a transmitter, a transmitter, or a transmitting circuit, etc. It should be understood that the transceiving unit 1610 is used to perform the sending operation and the receiving operation of the terminal device side in the above method embodiments, and the processing unit 1620 is used to perform other operations of the terminal device in addition to the transceiving operation in the above method embodiments.

[0210] The chip system further includes a processor coupled with the memory, and the memory is configured to store programs or instructions, and the programs or instructions, when executed by the processor, cause the chip system to implement the method in any of the method embodiments.

[0211] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, and the implementation is achieved by reading software codes stored in the memory.

[0212] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or arranged separately from the processor, and the application does not make any limitation. For example, the memory can be a non-transient processor, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or arranged on different chips respectively, and the application does not make any limitation on the type of the memory and the arrangement of the memory and the processor.

[0213] For example, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD) or other integrated chip.

[0214] It should be understood that each step in the above method embodiments can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The method steps disclosed in the embodiments of the application can be directly embodied as hardware processor execution or executed by the combination of hardware and software modules in the processor.

[0215] The embodiment of the present application further provides a computer readable storage medium, wherein the computer readable storage medium stores computer readable instructions, and when the computer readable instructions are read and executed by a computer, the computer executes the method in any of the method embodiments.

[0216] The embodiment of the present application further provides a computer program product, and when the computer program product is read and executed by a computer, the computer executes the method in any of the method embodiments.

[0217] The embodiment of the present application further provides a communication system, which comprises a first core network element, a second core network element and a third core network element. Optionally, the communication system further comprises an access network device and a terminal device.

[0218] It should be understood that the processor mentioned in the embodiment of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0219] It should also be understood that the memory mentioned in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).

[0220] It should be noted that when the processor is a general processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) is integrated in the processor.

[0221] It should be noted that the memory described herein is intended to include, but not limited to, these and any other suitable types of memory.

[0222] It should be understood that in various embodiments of the present application, the size of the sequence number of each process described above does not mean the order of execution, the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0223] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0224] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0225] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0226] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0227] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.

[0228] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the parts that contribute to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0229] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An online signing method, characterized in that: The method comprises: The first core network element recognizes that the terminal device needs to sign an online contract; The first core network element triggers online contract authentication for the terminal device; If the online subscription authentication of the terminal device succeeds, the first core network element sends a first message to the second core network element, where the first message includes a first identifier of the terminal device, and the first message is used to request the second core network element to generate or update a network subscription for the terminal device; The first core network element recognizes that the terminal device needs to sign an online contract, including: The first core network element receives a second message from the terminal device or the access network device, where the second message includes a user group identifier or a network identifier; If the first core network element confirms that the terminal device does not belong to the user group corresponding to the user group identifier or does not belong to the user group corresponding to the network identifier, it identifies that the terminal device needs to sign an online contract.

2. The method according to claim 1, characterized in that The online signing authentication is a process of authenticating the identity information provided by the terminal device; The first core network element triggering online contract authentication for the terminal device includes: The first core network element sends an authentication message to the authentication service function element, triggering the authentication service function element to perform online contract authentication on the terminal device; or The first core network element sends an authentication message to an online registration and authentication device, triggering the online registration and authentication device to perform online contract authentication on the terminal device; or The first core network element sends first information to the terminal device, where the first information is used to instruct the terminal device to establish a connection with the online registration and authentication device and perform online contract authentication through the online registration and authentication device.

3. The method according to claim 2, characterized in that The first information includes one or more of the IP address of the online registration and authentication device, the data network name DNN, and the network slice selection auxiliary information NSSAI.

4. The method according to claim 1, wherein The method further comprises: If the online contract authentication of the terminal device is successful, the first core network element generates an online contract identifier for the terminal device and sends the online contract identifier to the terminal device.

5. The method according to claim 1, wherein The first message also includes a user group identifier or a network identifier; The first message is also used to notify the second core network element to set the user group identifier as an allowed user group identifier in the subscription data of the terminal device, or to set the user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device.

6. The method according to claim 1, characterized in that The method further comprises: The first core network element sends an online contract signing notification message to the online registration device, where the online contract signing notification message includes the second identifier of the terminal device. The online contract signing notification message is used to notify the online registration device of an online contract signing authentication result of the terminal device.

7. The method according to claim 6, characterized in that The method further comprises: The first core network element sends a third message to the terminal device, where the third message includes the IP address of the online registration device. The IP address of the online registration device is used by the terminal device to obtain the user context generated or updated for the terminal device from the online registration device.

8. The method according to any one of claims 1 to 7, characterized in that The method further comprises: If the online contract authentication of the terminal device fails, the first core network element sends a fourth message to the terminal device, and the fourth message is used to reject the request of the second message.

9. An online signing method, characterized in that: The method comprises: The second core network element receives a first message from the first core network element or the online registration device, where the first message includes a first identifier of the terminal device, and the first message is used to request the second core network element to generate or update a network subscription for the terminal device; The second core network element generates or updates the network subscription of the terminal device; The first message also includes a user group identifier or a network identifier; The second core network element generating or updating the network subscription of the terminal device includes: The second core network element sets the user group identifier in the subscription data of the terminal device as an allowed user group identifier; or The second core network network element sets the user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device.

10. The method according to claim 9, characterized in that The second core network element generating or updating the network subscription of the terminal device includes: The second core network element generates an online signing identifier and adds the online signing identifier to the signing data of the terminal device.

11. The method according to claim 9, characterized in that The first message also includes a certificate allocated to the terminal device by the online registration device or the online registration authentication device; The second core network element generating or updating the network subscription of the terminal device further includes: The second core network element adds the certificate to the subscription data of the terminal device.

12. The method according to any one of claims 9 to 11, characterized in that The second core network element generating or updating the network subscription of the terminal device further includes: The second core network element adds the data network name DNN and / or network slice selection auxiliary information NSSAI available to the terminal device in the subscription data of the terminal device.

13. The method according to claim 12, characterized in that The method further comprises: The second core network element sends a contract notification message to the third core network element, and the contract notification message includes one or more of the following information: the data network name DNN available to the terminal device added in the contract data of the terminal device, the network slice selection auxiliary information NSSAI and the user group identifier.

14. The method according to claim 13, wherein: The DNN and / or the NSSAI included in the subscription notification message is the DNN and / or NSSAI associated with the user group identifier.

15. A communication device, characterized in that: The device comprises: A processing module, used to identify that the terminal device needs to perform online signing; The processing module is further configured to trigger online contract authentication for the terminal device; a transceiver module, configured to send a first message to a second core network element if the online contract authentication of the terminal device succeeds, wherein the first message includes a first identifier of the terminal device, and the first message is used to request the second core network element to generate or update a network contract for the terminal device; The transceiver module is further configured to receive a second message from the terminal device or the access network device, where the second message includes a user group identifier or a network identifier; The processing module is specifically configured to, if it is determined that the terminal device does not belong to the user group corresponding to the user group identifier or does not belong to the user group corresponding to the network identifier, identify that the terminal device needs to perform online signing.

16. The device according to claim 15, characterized in that The online signing authentication is a process of authenticating the identity information provided by the terminal device; The processing module is specifically used for: Sending an authentication message to the authentication service function network element through the transceiver module to trigger the authentication service function network element to perform online contract authentication on the terminal device; or Sending an authentication message to an online registration and authentication device through the transceiver module to trigger the online registration and authentication device to perform online contract authentication on the terminal device; or, The first information is sent to the terminal device through the transceiver module, where the first information is used to instruct the terminal device to establish a connection with the online registration and authentication device, and to perform online contract authentication through the online registration and authentication device.

17. The device according to claim 16, characterized in that The first information includes one or more of the IP address of the online registration and authentication device, the data network name DNN, and the network slice selection auxiliary information NSSAI.

18. The device according to claim 15, characterized in that The processing module is further configured to: If the online contract authentication of the terminal device is successful, an online contract identification is generated for the terminal device, and the online contract identification is sent to the terminal device through the transceiver module.

19. The device according to claim 15, characterized in that The first message also includes a user group identifier or a network identifier; The first message is also used to notify the second core network element to set the user group identifier as an allowed user group identifier in the subscription data of the terminal device, or to set the user group identifier corresponding to the network identifier as an allowed user group identifier in the subscription data of the terminal device.

20. The device according to claim 15, characterized in that The transceiver module is also used for: An online signing notification message is sent to the online registration device, where the online signing notification message includes the second identifier of the terminal device, and the online signing notification message is used to notify the online registration device of an online signing authentication result of the terminal device.

21. The device according to claim 20, characterized in that The transceiver module is also used for: A third message is sent to the terminal device, where the third message includes the IP address of the online registration device, and the IP address of the online registration device is used by the terminal device to obtain the user context generated or updated for the terminal device from the online registration device.

22. The device according to any one of claims 15 to 21, characterized in that The transceiver module is also used for: If the online contract authentication of the terminal device fails, a fourth message is sent to the terminal device, where the fourth message is used to reject the request of the second message.

23. A communication device, characterized in that: The device comprises: a transceiver module, configured to receive a first message from a first core network element or an online registration device, wherein the first message includes a first identifier of a terminal device, and the first message is used to request the apparatus to generate or update a network subscription for the terminal device; A processing module, configured to generate or update a network contract for the terminal device; The first message also includes a user group identifier or a network identifier; The processing module is specifically configured to set the user group identifier in the subscription data of the terminal device as an allowed user group identifier; or set the user group identifier corresponding to the network identifier in the subscription data of the terminal device as an allowed user group identifier.

24. The device according to claim 23, characterized in that The processing module is further specifically configured to generate an online signing identifier and add the online signing identifier to the signing data of the terminal device.

25. The device according to claim 23, characterized in that The first message also includes a certificate allocated to the terminal device by the online registration device or the online registration authentication device; The processing module is further specifically configured to add the certificate to the contract data of the terminal device.

26. The device according to any one of claims 23 to 25, characterized in that The processing module is also specifically used to add the data network name DNN and / or network slice selection auxiliary information NSSAI available to the terminal device to the subscription data of the terminal device.

27. The device according to claim 26, characterized in that The transceiver module is further configured to send a subscription notification message to the third core network element, where the subscription notification message includes one or more of the following information: The data network name DNN, network slice selection auxiliary information NSSAI and user group identifier available to the terminal device are added in the subscription data of the terminal device.

28. The device according to claim 27, characterized in that The DNN and / or the NSSAI included in the subscription notification message is the DNN and / or NSSAI associated with the user group identifier.

29. A communication device, characterized in that: The apparatus comprises at least one processor coupled to at least one memory: The at least one processor is configured to execute a computer program or instruction stored in the at least one memory, so that the apparatus performs the method according to any one of claims 1 to 8, or the apparatus performs the method according to any one of claims 9 to 14.

30. A computer-readable storage medium, characterized in that Used to store instructions, which, when executed, enable the method according to any one of claims 1 to 8 to be implemented, or enable the method according to any one of claims 9 to 14 to be implemented.

31. A communication device, characterized in that: including a processor and an interface circuit; The interface circuit is used to exchange code instructions with the processor; The processor is configured to execute the code instructions to perform the method according to any one of claims 1 to 8, or the processor is configured to execute the code instructions to perform the method according to any one of claims 9 to 14.

32. A computer program product, characterized in that When a computer reads and executes the computer program product, the computer is enabled to execute the method according to any one of claims 1 to 8 or the method according to any one of claims 9 to 14.

Citation Information

Patent Citations

  • Online subscription data configuration method, apparatus and system

    CN108200570A