Method and apparatus for switching
By providing network slice-specific authentication and authorization status to the target AMF during the handover process, the problem of repeated authentication and authorization of the target AMF is solved, and the effect of rapid service response and reduced operational costs is achieved.
Patent Information
- Application Number
- CN202180020839.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-13
- Filing Date
- 2021-03-11
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2041-03-11
AI Technical Summary
During the handover process, the target access and mobility management entity cannot obtain the state that allows NSSAI that is subject to network slice-specific authentication and authorization, resulting in the target AMF having to perform network slice-specific authentication and authorization again, increasing signaling delay and resource consumption.
The source access and mobility management entity provides the target access and mobility management entity with a network slice-specific authentication and authorization state during the handover process, based on which the target AMF decides whether to skip the network slice-specific authentication and authorization process and store the state in the UE context.
The NSSAA process is optimized, unnecessary network signaling services are avoided, rapid service response time of the switching process is improved, and operational expenses are reduced.
Smart Images

Figure CN115299168B_ABST
Abstract
Description
Technical Field
[0001] The non - limiting and exemplary embodiments of the present disclosure generally relate to the field of communication technologies, and more particularly, to methods and apparatuses for handover. Background Art
[0002] This section introduces various aspects that may contribute to a better understanding of the present disclosure. Therefore, the statements in this section should be read from this perspective and should not be construed as an admission as to what is in the prior art or what is not in the prior art.
[0003] The handover process can use reference points (such as N2) between the RAN and the Access and Mobility Management Entity (such as AMF (Access and Mobility Management Function)) or reference points (such as Xn) between the source RAN and the target RAN to hand over a terminal device such as a User Equipment (UE) from a source Radio Access Network (RAN) (such as NG - RAN (Next Generation RAN)) node to a target RAN (such as NG - RAN) node. For example, due to new radio conditions, load balancing or due to a specific service (e.g., in the presence of a QoS (Quality of Service) flow for voice), the handover process can be triggered. The source NG - RAN node as an NR (New Radio) can trigger a handover to an E - UTRA (Evolved Universal Telecommunications Radio Access) connected to the 5GC (Fifth Generation Core Network).
[0004] When changing the Access and Mobility Management Entity during the handover process, the target Access and Mobility Management Entity may only perform a subset of the registration process. For example, in 5GS (Fifth Generation System), if the UE indicates in the UE MM (Mobility Management) core network capabilities in the registration request that it supports the network slice - specific authentication and authorization process (NSSAA), and any S - NSSAI (Single Network Slice Selection Assistance Information) of the HPLMN (Home PLMN (Public Land Mobile Network)) is subject to network slice - specific authentication and authorization, then the network slice - specific authentication and authorization process needs to be performed. Summary of the Invention
[0005] The Summary of the Invention is provided in a simplified form to introduce selected concepts that will be further described in the detailed description below. The Summary of the Invention is neither intended to identify the key features or essential features of the claimed subject matter nor intended to be used to limit the scope of the claimed subject matter.
[0006] When changing the access and mobility management entity, there are some problems in the handover process. For example, during the N2-based handover preparation phase, the source AMF can create a UE context in the target AMF, but the NSSAA status for the allowed NSSAI (Network Slice Selection Assistance Information) subject to network slice-specific authentication and authorization is not included in the UE context information. During the N2-based handover execution phase, it is explicitly specified that the target AMF only performs a subset of the registration process, specifically skipping the steps for context transfer between the source AMF and the target AMF in the registration process. Therefore, the target AMF cannot obtain the NSSAA status of the allowed NSSAI subject to network slice-specific authentication and authorization, and the target AMF must perform network slice-specific authentication and authorization again, even though the source AMF already has the NSSAA result.
[0007] To overcome or mitigate the above problems or other problems, embodiments of the present disclosure propose an improved handover solution.
[0008] In one embodiment, during the handover process, the source access and mobility management entity can provide the network slice-specific authentication and authorization status for the allowed network slices of the network subject to network slice-specific authentication and authorization to the target access and mobility management entity.
[0009] In one embodiment, during the handover process, based on the network slice-specific authentication and authorization status from the source access and mobility management entity, the target access and mobility management entity decides to skip the network slice-specific authentication and authorization for the network slice-specific authentication and authorization process in the registration process, and stores the network slice-specific authentication and authorization status for the allowed network slice(s) of the network subject to network slice-specific authentication and authorization from the source access and mobility management entity in the UE context.
[0010] In a first aspect of the present disclosure, a method at a first access and mobility management entity is provided. The method includes obtaining at least one authentication and authorization status for at least one network slice of the network for a terminal device. The method further includes sending, during a handover process, at least one authentication and authorization status for at least one network slice of the network for the terminal device to a second access and mobility management entity.
[0011] In one embodiment, each network slice of the at least one network slice of the network can be identified by a single Slice Network Slice Selection Assistance Information S-NSSAI.
[0012] In one embodiment, the handover process can be an N2-based handover process between next-generation radio access network NG-RAN nodes.
[0013] In one embodiment, the first access and mobility management entity may be an access and mobility management function (AMF) entity, and the second access and mobility management entity may be an AMF entity.
[0014] In one embodiment, at least one authentication and authorization status for a terminal device for at least one network slice of a network may be obtained from another access and mobility management entity and / or from an authentication server.
[0015] In one embodiment, the authentication server may be an authentication server function (AUSF) entity, and the said another access and mobility management entity may be an access and mobility management function (AMF) entity.
[0016] In one embodiment, during a handover process, at least one authentication and authorization status for a terminal device for at least one network slice of a network may be sent in a request for the first access and mobility management entity to create a context of the terminal device in the second access and mobility management entity.
[0017] In one embodiment, the request may be a Namf_Communication_CreateUEContext request.
[0018] In one embodiment, the method may further include storing at least one authentication and authorization status for a terminal device for at least one network slice of a network.
[0019] In a second aspect of the present disclosure, a method at a second access and mobility management entity is provided. The method includes: during a handover process, receiving at least one authentication and authorization status for a terminal device for at least one network slice of a network from a first access and mobility management entity. The method further includes determining to skip at least one network slice-specific authentication and authorization process for a terminal device for at least one network slice of a network based on the received at least one authentication and authorization status for a terminal device for at least one network slice of a network.
[0020] In one embodiment, the method may further include skipping at least one network slice-specific authentication and authorization process.
[0021] In one embodiment, determining to skip at least one network slice-specific authentication and authorization process further includes: if the received at least one authentication and authorization status indicates that the result of network slice-specific authentication and authorization is successful, determining to skip at least one network slice-specific authentication and authorization process for a terminal device for at least one network slice of a network.
[0022] In one embodiment, determining to skip at least one network slice-specific authentication and authorization process further includes: if at least one received authentication and authorization status indicates that the result of the network slice-specific authentication and authorization is a failure, determining to skip at least one network slice-specific authentication and authorization process for at least one network slice of the network for the terminal device.
[0023] In one embodiment, the method may further include: checking, based on the slice selection subscription data of the terminal device, whether there is one or more allowed network slices subject to network slice-specific authentication and authorization, and checking, based on at least one received authentication and authorization status for at least one network slice of the network for the terminal device, whether there is already one or more corresponding available authentication and authorization statuses.
[0024] In one embodiment, the method may further include storing at least one authentication and authorization status for at least one network slice of the network for the terminal device.
[0025] In a third aspect of the present disclosure, a first access and mobility management entity is provided. The first access and mobility management entity includes a processor; a memory coupled to the processor, the memory storing instructions executable by the processor, whereby the first access and mobility management entity is operable to obtain at least one authentication and authorization status for at least one network slice of the network for the terminal device. The first access and mobility management entity is further operable to send, during a handover process, at least one authentication and authorization status for at least one network slice of the network for the terminal device to a second access and mobility management entity.
[0026] In a fourth aspect of the present disclosure, a second access and mobility management entity is provided. The second access and mobility management entity includes a processor; a memory coupled to the processor, the memory storing instructions executable by the processor, whereby the second access and mobility management entity is operable to receive, during a handover process, at least one authentication and authorization status for at least one network slice of the network for the terminal device from the first access and mobility management entity. The second access and mobility management entity is further operable to determine to skip at least one network slice-specific authentication and authorization process for at least one network slice of the network for the terminal device based on the received at least one authentication and authorization status for at least one network slice of the network for the terminal device.
[0027] In a fifth aspect of the present disclosure, a first access and mobility management entity is provided. The first access and mobility management entity includes an obtaining module and a sending module. The obtaining module may be configured to obtain at least one authentication and authorization status for at least one network slice of a network for a terminal device. The sending module may be configured to send, during a handover process, at least one authentication and authorization status for at least one network slice of a network for a terminal device to a second access and mobility management entity.
[0028] In a sixth aspect of the present disclosure, a second access and mobility management entity is provided. The second access and mobility management entity includes a receiving module and a decision module. The receiving module may be configured to receive, during a handover process, at least one authentication and authorization status for at least one network slice of a network for a terminal device from a first access and mobility management entity. The decision module may be configured to decide, based on the received at least one authentication and authorization status for at least one network slice of a network for a terminal device, to skip at least one network slice-specific authentication and authorization process for at least one network slice of a network for a terminal device.
[0029] In a seventh aspect of the present disclosure, a computer program product including instructions is provided, and when the instructions are executed on at least one processor, the instructions cause the at least one processor to perform any step of the method according to any one of the first and second aspects of the present disclosure.
[0030] In an eighth aspect of the present disclosure, a computer-readable storage medium storing instructions is provided, and when the instructions are executed by at least one processor, the instructions cause the at least one processor to perform any step of the method according to any one of the first and second aspects of the present disclosure.
[0031] Embodiments herein provide many advantages, and the following is a non-exhaustive list of examples of advantages. In some embodiments herein, during an N2-based handover process, a target AMF may optimize the NSSAA process based on the NSSAA status of the permitted NSSAI subject to network slice-specific authentication and authorization provided by a source AMF during the N2-based handover process. In some embodiments herein, during an N2-based handover process, unnecessary network signaling traffic may be avoided. In some embodiments herein, for a user, a fast service response time and minimized latency for the N2-based handover process may be achieved. In some embodiments herein, for a network operator, an OPEX (operating expense) reduction may be achieved since unnecessary signaling is avoided and network performance is improved. Those skilled in the art will recognize additional features and advantages after reading the following detailed description. Description of the Drawings
[0032] The above and other aspects, features, and advantages of the various embodiments of the present disclosure will become more apparent from the following detailed description with reference to the accompanying drawings by way of example, in which like reference numerals or letters are used to designate like or equivalent elements. The illustrated drawings are not necessarily drawn to scale for the purpose of facilitating a better understanding of the embodiments of the present disclosure, where:
[0033] Figure 1 A system architecture in which embodiments of the present disclosure can be implemented is shown;
[0034] Figure 2 A flowchart showing a network slice-specific authentication and authorization process is shown;
[0035] Figure 3 A flowchart showing a handover preparation phase based on N2 is shown;
[0036] Figure 4 A flowchart showing a handover execution phase based on N2 is shown;
[0037] Figure 5 A flowchart showing a registration process is shown;
[0038] Figure 6 A flowchart showing a method according to an embodiment of the present disclosure is shown;
[0039] Figure 7 A flowchart showing a method according to another embodiment of the present disclosure is shown.
[0040] Figure 8a A flowchart depicting a UE registration process with a network slice-specific authentication and authorization (NSSAA) process in 5GS according to an embodiment of the present disclosure;
[0041] Figure 8b A flowchart depicting an N2-based handover with an optimized NSSAA process according to an embodiment of the present disclosure;
[0042] Figure 9 A block diagram showing an apparatus suitable for implementing some embodiments of the present disclosure;
[0043] Figure 10 A block diagram showing a first access and mobility management entity according to an embodiment of the present disclosure; and
[0044] Figure 11 A block diagram showing a second access and mobility management entity according to an embodiment of the present disclosure. Detailed Description of Specific Embodiments
[0045] Embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for the purpose of enabling those skilled in the art to better understand and thus implement the present disclosure, rather than suggesting any limitation to the scope of the present disclosure. References throughout the specification to features, advantages, or similar language do not imply that all features and advantages that can be realized with the present disclosure should be in or in any single embodiment of the present disclosure. Instead, language referring to features and advantages should be understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. Moreover, the features, advantages, and characteristics described in the present disclosure can be combined in any suitable manner in one or more embodiments. Those skilled in the relevant art will recognize that the present disclosure can be practiced without one or more specific features or advantages of a particular embodiment. In other cases, additional features and advantages may be recognized in certain embodiments, and the additional features and advantages may not be present in all embodiments of the present disclosure.
[0046] As used herein, the term "network" refers to a network that follows any suitable (wireless or wired) communication standard. For example, wireless communication standards can include: New Radio (NR), Long Term Evolution (LTE), LTE-Advanced, Wideband Code Division Multiple Access (WCDMA), High Speed Packet Access (HSPA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single Carrier Frequency Division Multiple Access (SC-FDMA). CDMA networks can implement radio technologies such as Universal Terrestrial Radio Access (UTRA). UTRA includes WCDMA and other variants of CDMA. TDMA networks can implement radio technologies such as Global System for Mobile Communications (GSM). OFDMA networks can implement radio technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, Ad-hoc networks, wireless sensor networks, etc. In the following description, the terms "network" and "system" can be used interchangeably. Moreover, the communication between two devices in the network can be performed according to any suitable communication protocol, including but not limited to wireless communication protocols or wired communication protocols defined by standard organizations such as the Third Generation Partnership Project (3GPP). For example, wireless communication protocols can include first generation (1G), 2G, 3G, 4G, 4.5G, 5G communication protocols and / or any other protocols known currently or developed in the future.
[0047] As used herein, the term "entity" refers to a network device or network node or network function in a communication network. For example, in a wireless communication network such as a cellular network of the 3GPP type, core network devices can provide multiple services to customers interconnected by access network devices. Each access network device can be connected to the core network device by a wired or wireless connection.
[0048] The term "network function (NF)" refers to any suitable function that can be implemented in a network node (physical or virtual) of a communication network. For example, a 5G system (5GS) can include multiple NFs, such as AMF (Access and Mobility Function), SMF (Session Management Function), AUSF (Authentication Service Function), UDM (Unified Data Management), PCF (Policy Control Function), AF (Application Function), NEF (Network Exposure Function), UPF (User Plane Function), and NRF (Network Repository Function), (R)AN ((Radio) Access Network), SCP (Service Communication Proxy), NWDAF (Network Data Analytics Function), etc. In other embodiments, for example depending on the specific type of network, the network functions can include different types of NFs.
[0049] The term "terminal device" refers to any end device that can access a wireless communication network and receive services from the wireless communication network. By way of example and not limitation, a terminal device refers to a mobile terminal, a user equipment (UE), or other suitable devices. A UE can be, for example, a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). A terminal device can include, but is not limited to, a portable computer, an image capture terminal device such as a digital camera, a game terminal device, a music storage and playback device, a mobile phone, a cellular phone, a smart phone, an IP voice (VoIP) phone, a wireless local loop phone, a tablet computer, a wearable terminal device, a personal digital assistant (PDA), a portable computer, a desktop computer, a wearable device, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop embedded device (LEE), a laptop mounted device (LME), a USB dongle, a smart device, a wireless customer premises equipment (CPE), etc. In the following description, the terms "terminal device", "terminal", "user equipment", and "UE" may be used interchangeably. As an example, a terminal device can represent a UE configured to communicate according to one or more communication standards released by 3GPP, such as the LTE standard or the NR standard of 3GPP. As used herein, a "user equipment" or "UE" may not necessarily have a "user" in terms of a human user who owns and / or operates the relevant device. In some embodiments, a terminal device can be configured to send and / or receive information without direct human interaction. For example, when triggered by an internal or external event, or in response to a request from a communication network, a terminal device can be designed to send information to the network according to a predetermined schedule. Alternatively, a UE can represent a device intended for sale to or operated by a human user but that may not initially be associated with a specific human user.
[0050] As another example, in an Internet of Things (IoT) scenario, a terminal device can represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or a network device. In this case, the terminal device can be a machine-to-machine (M2M) device, which in the 3GPP context can be referred to as a machine type communication (MTC) device. As a specific example, a terminal device can be a terminal device that implements the 3GPP narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (such as power meters), industrial machinery, or household or personal appliances (such as refrigerators, televisions), personal wearable devices (such as watches), etc. In other cases, a terminal device can represent a vehicle or other device that is capable of monitoring and / or reporting its operating status or other functions associated with its operation.
[0051] References to "an embodiment", "embodiment", "exemplary embodiment", etc. in the specification indicate that the described embodiments may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, whether or not explicitly described, it is considered within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments.
[0052] It should be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, the first element may be referred to as the second element, and similarly, the second element may be referred to as the first element. As used herein, the term "and / or" includes any combination and all combinations of one or more of the associated listed terms.
[0053] As used herein, the phrase "at least one of A and B" should be understood to mean "only A, only B, or both A and B". The phrase "A and / or B" should be understood to mean "only A, only B, or both A and B".
[0054] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the exemplary embodiments. As used herein, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are also intended to include the plural forms. It will be further understood that when used herein, the terms "comprises", "comprising", "has", "having", "contains", "containing", "covers", and / or "owns" specify the presence of the stated features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0055] It should be noted that these terms used herein are only for the convenience of description and to distinguish nodes, devices, or networks, etc. With the development of technology, other terms with similar / same meanings may also be used.
[0056] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.
[0057] It should be noted that some embodiments of the present disclosure are described primarily with respect to a 5G network used as a non-limiting example of certain exemplary network configurations and system deployments. Therefore, the description of the exemplary embodiments given here specifically refers to terms directly related thereto. Such terms are used only in the context of the non-limiting examples and embodiments presented, and naturally do not limit the present disclosure in any way. On the contrary, any other system configuration or radio technology may be used in the same manner as long as the exemplary embodiments described herein are applicable.
[0058] Figure 1 The system architecture of the embodiment of the present disclosure can be implemented. Figure 1 The system architecture depicts only some exemplary elements. In practice, the communication system may also include any additional elements suitable for supporting communication between terminal devices or between a wireless device and another communication device (e.g., a landline phone, a service provider, or any other network node or terminal device). The communication system may provide communication and various types of services to one or more terminal devices to facilitate the terminal devices to access and / or use services provided by or via the communication system.
[0059] Figure 1 and 3 GPP TS 23.501 V16.3.0 Figure 4 .2.3-1, the entire disclosure of which is incorporated herein by reference. Figure 1 The system architecture may include some exemplary elements, such as AMF, SMF, AUSF, UDM, PCF, AF, NEF, UPF and NRF, (R)AN, SCP, etc. Figure 1 The network elements, reference points and interfaces shown may be the same as the corresponding network elements, reference points and interfaces described in 3GPP TS 23.501 V16.3.0.
[0060] Figure 2 A flowchart showing the network slice specific authentication and authorization process, which is consistent with 3GPP TS 23.502 V16.3.0 Figure 4 .Same as 2.9.2-1. Figure 2The steps shown are the same as the corresponding steps described in clause 4.2.9.2 of 3GPP TS 23.502 V16.3.0. For an S-NSSAI that requires network slice-specific authentication and authorization, the EAP (Extensible Authentication Protocol) framework described in 3GPP TS 33.501 V16.1.0 (the disclosure of which is incorporated herein by reference in its entirety) can be used to trigger a network slice-specific authentication and authorization process with an AAA (Authentication, Authorization, and Accounting) server (AAA-S), which can be hosted by the H-PLMN operator or a third party having a business relationship with the H-PLMN. For example, if the AAA server belongs to a third party, an AAA proxy (AAA-P) in the HPLMN may be involved.
[0061] When some network slices require slice-specific authentication and authorization, when the AMF determines that a network slice-specific authentication and authorization is required for an NSSAI in the currently permitted NSSAI (e.g., a subscription change), or when the AAA server for the authenticated network slice triggers re-authentication, the AMF can trigger a network slice-specific authentication and authorization process during the registration process.
[0062] The AMF performs the role of an EAP authenticator and communicates with the AAA-S via the AUSF. The AUSF undertakes any AAA protocol interoperability with the AAA protocol supported by the AAA-S.
[0063] The serving PLMN can perform network slice-specific authentication and authorization for the S-NSSAI of the HPLMN subject to network slice-specific authentication and authorization based on the subscription information. The UE can indicate in the UE 5GMM core network capabilities in the registration request message whether it supports this feature. If the UE does not support this feature, the AMF may not trigger this process for the UE, and if the UE requests these S-NSSAIs subject to network slice-specific authentication and authorization, they will be rejected for that PLMN.
[0064] If the UE is configured with an S-NSSAI that is subject to network slice-specific authentication and authorization, the UE stores the association between the S-NSSAI and the corresponding credentials for network slice-specific authentication and authorization.
[0065] To perform network slice-specific authentication and authorization for an S-NSSAI, the AMF invokes the EAP-based network slice-specific authorization process documented in clause 4.2.9 of 3GPP TS 23.502 V16.3.0 for the S-NSSAI (see also 3GPP TS 33.501 V16.1.0).
[0066] The AMF can invoke this process at any time for supported UEs, for example, when:
[0067] a. The UE registers with the AMF, and the S-NSSAI in the S-NSSAI of the HPLMN (which is mapped to the S-NSSAI in the requested NSSAI) is requesting network slice specific authentication and authorization (see section 5.15.5.2.1 for details), and once the network slice specific authentication and authorization for this S-NSSAI is successful, the AMF can add it to the allowed NSSAI; or
[0068] b. The network slice specific AAA server triggers UE re-authentication and re-authorization for the S-NSSAI; or
[0069] C. The AMF decides to initiate the network slice specific authentication and authorization process for a previously authorized S-NSSAI based on operator policies or subscription changes.
[0070] In the case of re-authentication and re-authorization (b. and c. above), the following applies:
[0071] - If the S-NSSAI for which network slice specific authentication and authorization is being requested is included in the allowed NSSAI for each access type, the AMF selects, according to network policies, the access type to be used for performing the network slice specific authentication and authorization process.
[0072] - If the network slice specific authentication and authorization for some S-NSSAIs in the allowed NSSAI is not successful, the AMF can update the allowed NSSAI for each access type for the UE through the UE configuration update process.
[0073] - If the network slice specific authentication and authorization for all S-NSSAIs in the allowed NSSAI fails, the AMF can perform the network-initiated deregistration process described in section 4.2.2.3.3 of 3GPP TS 23.502 V16.3.0, and can include in the explicit deregistration request message a list of the rejected S-NSSAIs, each with an appropriate rejection reason value.
[0074] After successful or unsuccessful UE network slice specific authentication and authorization, when the UE remains RM-REGISTERED in the PLMN, the UE context in the AMF can maintain the authentication and authorization status for the UE for the relevant specific S-NSSAI of the HPLMN, so that the AMF does not need to perform network slice specific authentication and authorization for the UE in each periodic registration update or mobile registration process with the PLMN.
[0075] The network slice-specific AAA server can revoke the authorization or challenge the authentication and authorization of the UE at any time. When the authorization is revoked for the NSSAI (which is in the currently permitted NSSAI for the access type), the AMF can provide the UE with a new permitted NSSAI and trigger the release of all PDU (Protocol Data Unit) sessions associated with the S-NSSAI for that access type.
[0076] The AMF provides the GPSI (Generic Public Subscription Identifier) of the UE related to the S-NSSAI to the AAA server to allow the AAA server to initiate network slice-specific authentication and authorization, or the authorization revocation process, where the current AMF of the UE needs to be identified by the system, so the authorization status of the UE can be challenged or revoked.
[0077] Network slice-specific authentication and authorization require that the primary authentication and authorization of the UE with the SUPI (Subscription Permanent Identifier) have been successfully completed. If the SUPI authorization is revoked, then the network slice-specific authorization is also revoked.
[0078] Figure 3 A flowchart of the N2-based handover preparation phase is shown, which is the same as that in 3GPP TS 23.502 V16.3.0 Figure 4 .9.1.3.2-1. Figure 3 The steps shown are the same as the corresponding steps described in clause 4.9.1.3.2 of 3GPP TS 23.502 V16.3.0.
[0079] As Figure 3 shown in step 3 of, the (conditional) S-AMF to T-AMF: Namf_Communication_CreateUEContext request (N2 information (destination ID (identifier), source-to-destination transparent container, SM (Session Management) N2 information list, PDU session ID), UE context information (SUPI, service area restriction, permitted NSSAI for each access type (if any), tracking requirement, LTE M indication, list of PDU session IDs and corresponding SMF information and corresponding S-NSSAI(s), PCF ID(s), DNN (Data Network Name), UE radio capability ID and UE radio capability information). If the subscription information includes a tracking requirement, the old AMF provides the tracking requirement to the target AMF.
[0080] In the case of inter-PLMN mobility, the UE context information includes the HPLMN S-NSSAI corresponding to the permitted NSSAI for each access type, without the permitted NSSAI of the source PLMN. The target AMF can be based on the Figure 3Determine the allowed NSSAI based on the HPLMN S-NSSAI received in step 3, or the target AMF queries the NSSF by invoking the Nnssf_NSSelection_Get service operation with the PLMN ID of the HPLMN S-NSSAI and the SUPI. As Figure 4 described, when performing a mobility registration update during the handover execution phase, the target AMF may trigger an AMF reallocation.
[0081] The S-AMF initiates the handover resource allocation process by invoking the Namf_Communication_CreateUEContext service operation towards the T-AMF.
[0082] When the S-AMF is still able to serve the UE, steps 3 and 12 Figure 3 are not required.
[0083] As described in clause 5.3.4.1.2 of 3GPP TS 23.501 V16.3.0, if service area restrictions are available in the S-AMF, they may be forwarded to the T-AMF.
[0084] If both the home and visited PCF IDs are provided by the S-AMF, the T-AMF contacts the (V-)PCF identified by the (V-)PCF ID. If the (V-)PCF identified by the (V-)PCF ID is not in use or no PCF ID is received from the S-AMF, the T-AMF may select the PCF(s) as described in section 6.3.7.1 of 3GPP TS 23.501 V16.3.0 and according to the V-NRF to H-NRF interaction described in section 4.3.2.2.3.3 of 3GPP TS23.502V16.3.0. As Figure 3 defined in step 12, the T-AMF notifies the S-AMF that the PCF ID is not in use, and then the S-AMF terminates the AM policy association with the PCF identified by the PCF ID.
[0085] As Figure 3 described in step 3, during the N2-based handover preparation phase, the source AMF creates a UE context in the target AMF, but does not include the NSSAA status of the allowed NSSAI for network slice-specific authentication and authorization in the UE context information.
[0086] Figure 4 shows the flowchart of the N2-based handover execution phase, which is the same as Figure 4 .9.1.3.3-1 of 3GPP TS 23.502 V16.3.0. Figure 4The steps shown are the same as the corresponding steps described in clause 4.9.1.3.3 of 3GPP TS 23.502 V16.3.0.
[0087] As Figure 4 shown in step 12, the UE initiates a mobility registration update procedure as described in clause 4.2.2.2.2 of 3GPP TS 23.502 V16.3.0. The target AMF knows that it is a handover procedure, so the target AMF only performs a subset of the registration procedure, specifically skipping the steps used for context transfer between the source AMF and the target AMF during the registration procedure (i.e., Figure 5 steps 4, 5, and 10).
[0088] Figure 5 shows the flowchart of the registration procedure, which is the same as Figure 4 .2.2.2.2-1 of 3GPP TS 23.502 V16.3.0. Figure 5 The steps shown are the same as the corresponding steps described in clause 4.2.2.2.2 of 3GPP TS 23.502 V16.3.0.
[0089] As Figure 5 shown in step 4, [conditional] new AMF to old AMF: Namf_Communication_UEContextTransfer (complete registration request) or new AMF to UDSF (Unstructured Data Storage Function): Nudsf_UnstructuredDataManagement_Query().
[0090] (with UDSF deployment): If the 5G-GUTI (5G Globally Unique Temporary Identifier) of the UE is included in the registration request and the serving AMF has changed since the last registration procedure, and the new AMF and the old AMF are in the same AMF set and UDSF is deployed, the new AMF retrieves the stored SUPI and UE context of the UE directly from the UDSF using the Nudsf_UnstructuredDataManagement_Query service operation, or if UDSF is not deployed, they can share the stored UE context in an implementation-specific way. This also includes the event subscription information for each NF consumer of the given UE. In this case, the new AMF uses an integrity-protected complete registration request NAS message to perform and verify integrity protection.
[0091] (No UDSF Deployment): If the 5G-GUTI of the UE is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation to the old AMF (which includes the complete registration request NAS message (which may be integrity protected) and the access type) to request the SUPI of the UE and the UE context. For detailed information on this service operation, see Section 5.2.2.2.2 of 3GPP TS 23.502 V16.3.0. In this case, if the context transfer service operation invocation corresponds to the requested UE, the old AMF uses the 5G-GUTI and the complete integrity protected registration request NAS (non-access stratum) message, or the SUPI and the indication that the UE has been authenticated by the new AMF, to verify the integrity protection. The old AMF also transfers the event subscription information for each NF consumer of the UE to the new AMF. If the old AMF has not reported a non-zero MO (Mobile Originated) exception data counter to the (H-)SMF, the context response also includes the MO exception data counter.
[0092] If the old AMF has PDU sessions for another access type (different from the access type indicated in this step) and if the old AMF determines that it is not possible to relocate the N2 interface to the new AMF, the old AMF returns the SUPI of the UE and indicates that the registration request has passed integrity protection verification, but does not include the rest of the UE context.
[0093] In the case where the new AMF has successfully performed UE authentication after the previous integrity check in the old AMF has failed, the new AMF sets the indication that the UE has been authenticated according to Figure 5 Step 9a.
[0094] After the UE has successfully registered at the new AMF, the NF consumers do not need to subscribe to events at the new AMF again.
[0095] If the new AMF has received the UE context from the old AMF during the handover procedure, steps 4, 5, and 10 of Figure 5 shall be skipped.
[0096] For emergency registration, if the UE identifies itself with a 5G-GUTI unknown to the AMF, steps 4 and 5 are skipped and the AMF immediately requests the SUPI from the UE. If the UE identifies itself with the PEI, the SUPI request shall be skipped. Allowing emergency registration without a user identity depends on local regulations.
[0097] As Figure 5As shown in step 5, Conditional old AMF to new AMF: Response to Namf_Communication_UEContextTransfer (SUPI, UE context in the AMF (according to Table 5.2.2.2.2-1 of 3GPP TS 23.502 V16.3.0)) or UDSF to new AMF: Nudsf_Unstructured Data Management_Query(). The old AMF may start an implementation-specific (protection) timer for the UE context.
[0098] If the UDSF is queried in Figure 5 step 4, the UDSF responds to the Nudsf_Unstructured Data Management_Query call to the new AMF with the relevant context including the established PDU sessions. The old AMF includes SMF information DNN, S-NSSAI(s), and PDU session ID(s), the active NGAP (Next Generation Application Protocol) UE-TNLA (Transport Network Layer Association) bound to the N3IWF / TNGF / W-AGF, and the old AMF includes information about the NGAP UE-TNLA binding. If in Figure 5 step 4 the old AMF is queried, the old AMF responds to the Namf_Communication_UEContextTransfer call to the new AMF by including the SUPI of the UE and the UE context.
[0099] If the old AMF holds information about the established PDU sessions, the old AMF includes SMF information, DNN(s), S-NSSAI(s), and PDU session ID(s).
[0100] If the old AMF holds the UE context established via N3IWF (Non-3GPP Interworking Function), W-AGF (Wired Access Gateway Function), or TNGF (Trusted Non-3GPP Gateway Function), the old AMF includes the CM (Connection Management) state via N3IWF, W-AGF, or TNGF. If the UE is in the CM-CONNECTED state via N3IWF, W-AGF, or TNGF, the old AMF contains information about the NGAP UE-TNLA binding.
[0101] If the old AMF fails the integrity check of the registration request NAS message, the old AMF shall indicate the integrity check failure.
[0102] If the old AMF holds information on AM policy association and information on UE policy association (i.e., the policy control request trigger for updating UE policies as defined in 3GPP TS 23.503 V16.3.0, the disclosure of which is incorporated herein by reference in its entirety), the old AMF includes information on AM policy association, UE policy association, and PCF ID. In the case of roaming, it includes V-PCF ID and H-PCF ID.
[0103] During the inter-PLMN move, the handling of the UE radio capability ID in the new AMF is as defined in 3GPP TS 23.501 V16.3.0.
[0104] When the new AMF uses the UDSF for context retrieval, the interaction between the old AMF, the new AMF, and the UDSF due to UE signaling on the old AMF simultaneously is an implementation issue.
[0105] As Figure 5 shown in step 10 of , [conditional] new AMF to old AMF: Namf_Communication_RegistrationCompleteNotify (the PDU session ID(s) will be released due to non-support of slices).
[0106] If the AMF has changed, the new AMF notifies the old AMF that the UE's registration in the new AMF has been completed by invoking the Namf_Communication_RegistrationCompleteNotify service operation.
[0107] If the authentication / security process fails, the registration shall be rejected, and the new AMF invokes the Namf_Communication_RegistrationCompleteNotify service operation with a rejection indication reason code to the old AMF. The old AMF continues as if it had never received the UE context transfer service operation.
[0108] If one or more S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU sessions cannot be supported in the new registration area. The new AMF invokes the Namf_Communication_RegistrationCompleteNotify service operation to the old AMF, which includes the rejected PDU session ID and the rejection reason (e.g., S-NSSAI is no longer available). Then the new AMF modifies the PDU session state accordingly. The old AMF notifies the corresponding SMF to locally release the UE's SM context by invoking the Nsmf_PDUSession_ReleaseSMContext service operation.
[0109] If the new AMF receives information on AM policy association and UE policy association in the UE context transfer in step 2 and decides not to use the PCF identified by the PCF ID for AM policy association and UE policy association based on the local policy, it will notify the old AMF that the AM policy association and UE policy association in the UE context are no longer used, and then perform PCF selection in step 15 of Figure 5 the procedure.
[0110] During the N2-based handover execution phase, Figure 4 step 12 of Figure 5 the procedure clearly specifies that the target AMF only executes a subset of the registration procedure. Specifically, steps 4, 5, and 10 used for context transfer between the source AMF and the target AMF in the registration procedure of
[0111] Based on the above information, the target AMF cannot obtain the NSSAA status of the permitted NSSAI subject to network slice-specific authentication and authorization. The target AMF may have to execute step 25 of Figure 5 the procedure again, even if the source AMF already has the NSSAA result.
[0112] To overcome or mitigate the above problems or other problems, embodiments of the present disclosure propose an improved handover solution. In one embodiment, the source AMF may provide the NSSAA status of the permitted NSSAI subject to network slice-specific authentication and authorization to the target AMF during the N2-based handover procedure preparation phase. In one embodiment, based on the NSSAA status from the source AMF, the target AMF may decide to skip the network slice-specific authentication and authorization process used for network slice-specific authentication and authorization in the registration procedure, and store the NSSAA status of the permitted S-NSSAI subject to network slice-specific authentication and authorization from the source AMF in the UE context during the N2-based handover procedure execution phase.
[0113] Figure 6 FIG. shows a flowchart of a method 600 according to an embodiment of the present disclosure. The method may be executed by a device in or as a first access and mobility management entity such as an AMF or communicatively coupled to the first access and mobility management entity. In this way, the first access and mobility management entity may provide components or modules for completing various parts of method 600, as well as components or modules for completing other processes in combination with other components.
[0114] At block 602, a first access and mobility management entity obtains at least one authentication and authorization status for a terminal device for at least one network slice of a network. A network slice may be a logical network that provides specific network capabilities and network characteristics. A network slice instance may be a set of network function instances and resources (such as computing, storage, and network resources) required to constitute a deployed network slice. The network may be any suitable network that includes one or more network slices. For example, the network may be a 5GS or other wireless communication system.
[0115] The network slices may be identified in various ways. For example, a network slice may be identified by a network slice identifier. In one embodiment, each network slice of at least one network slice of the network may be identified by a single network slice selection assistance information (S-NSSAI). The term "S-NSSAI" may be the same as the corresponding term described in 3GPP TS 23.501 V16.3.0.
[0116] The at least one authentication and authorization status for a terminal device for at least one network slice of a network may be obtained in a variety of ways. In one embodiment, the at least one authentication and authorization status for a terminal device for at least one network slice of a network may be obtained from another access and mobility management entity and / or from an authentication server. For example, when the first access and mobility management entity is the target access and mobility management entity during a handover process, where the access and mobility management entity serving the terminal device switches from a source access and mobility management entity to the target access and mobility management entity, the first access and mobility management entity may obtain the at least one authentication and authorization status for a terminal device for at least one network slice of a network from the source access and mobility management entity. When the first access and mobility management entity triggers a network slice-specific authentication and authorization process, the first access and mobility management entity may obtain the at least one authentication and authorization status for a terminal device for at least one network slice of a network from the authentication server. In one embodiment, the authentication server may be an AUSF entity, and the other access and mobility management entity may be an AMF entity. The AUSF may obtain at least one authentication and authorization status from the AAA-S.
[0117] In one embodiment, the first access and mobility management entity may obtain the at least one authentication and authorization status for a terminal device for at least one network slice of a network according to a network slice-specific authentication and authorization process as described in clause 4.2.9 of 3GPP TS 23.502 V16.3.0.
[0118] The authentication and authorization status of a network slice may include information on whether network slice-specific authentication and authorization is required for the network slice and the result of the network slice-specific authentication and authorization (such as success or failure).
[0119] At block 604 (optionally), the first access and mobility management entity may store at least one authentication and authorization status for the terminal device for at least one network slice of the network. For example, the first access and mobility management entity may store at least one authentication and authorization status for the terminal device for at least one network slice of the network in the terminal device context for the terminal device, which may be used later for optimization of the UE re-registration process or to provide (the most recent authentication and authorization status, if updated) to another new target access and mobility management entity during a handover process where the access and mobility management entity has changed.
[0120] At block 606, the first access and mobility management entity may send at least one authentication and authorization status for the terminal device for at least one network slice of the network to the second access and mobility management entity during a handover process.
[0121] The handover process may be any suitable handover process in which the access and mobility management entity serving the terminal device may change from the first access and mobility management entity to the second access and mobility management entity. In one embodiment, the handover process may be an N2-based handover process between next generation radio access network (NG-RAN) nodes as described in clause 4.9.1.3 of 3GPP TS 23.502 V16.3.0.
[0122] The first and second access and mobility management entities may be any suitable network entities capable of implementing the access and mobility management functions. In one embodiment, the first access and mobility management entity may be an AMF entity and the second access and mobility management entity may be an AMF entity.
[0123] The at least one authentication and authorization status for the terminal device for at least one network slice of the network may be sent in any suitable message that can be sent from the first access and mobility management entity to the second access and mobility management entity during a handover process. In one embodiment, during a handover process, the at least one authentication and authorization status for the terminal device for at least one network slice of the network may be sent in a request for the first access and mobility management entity to create a context for the terminal device in the second access and mobility management entity. In one embodiment, the request may be a Namf_Communication_CreateUEContext request as described in clause 4.9.1.3.2 of 3GPP TS 23.502 V16.3.0.
[0124] Figure 7FIG. 700 shows a flow chart of a method 700 according to another embodiment of the present disclosure, which may be performed by a device in or as a second access and mobility management entity such as an AMF or communicatively coupled to the second access and mobility management entity. Thus, the second access and mobility management entity may provide components or modules for completing various parts of the method 700, as well as components or modules for completing other processes in combination with other components. For parts that have been described in the above embodiments, for the sake of brevity, their detailed descriptions will not be repeated here.
[0125] At block 702, the second access and mobility management entity receives, during a handover procedure, at least one authentication and authorization status for the terminal device for at least one network slice of the network. For example, the first access and mobility management entity may send, at block 606 Figure 6 at least one authentication and authorization status for the terminal device, and then the second access and mobility management entity may receive the at least one authentication and authorization status.
[0126] At block 704 (optionally), the second access and mobility management entity may store at least one authentication and authorization status for the terminal device for at least one network slice of the network. Block 704 is similar to Figure 6 block 604.
[0127] At block 706 (optionally), the second access and mobility management entity may select subscription data based on the slice of the terminal device, check whether there is one or more allowed network slices subject to network slice specific authentication and authorization, and check whether there is already one or more corresponding available authentication and authorization statuses based on the at least one authentication and authorization status of the terminal device for at least one network slice of the network received. The slice selection subscription data of the terminal device may be obtained from a data management entity such as the UDM, or the slice selection subscription data of the terminal device may be obtained from the first access and mobility management entity. For example, the second access and mobility management entity may request slice selection subscription data from the UDM. The request may only obtain the slice selection subscription data, or may be able to obtain user access and mobility management data including the slice selection subscription data. The UDM may return the user slice selection subscription data to the second access and mobility management entity, and the UDM shall include information on whether network slice specific authentication and authorization is required for each subscribed network slice such as the S-NSSAI. The slice selection subscription data may include the subscribed network slices of the terminal device, such as the S-NSSAI. In the case of roaming, the subscribed network slices may indicate that the subscribed network slices are applicable to the serving PLMN. The slice selection subscription data may also include the default network slice(s), for example, the subscribed network slice(s) marked as the default network slice. The slice selection subscription data may also include the network slice(s) subject to network slice specific authentication and authorization, for example, the subscribed network slice(s) marked as subject to network slice specific authentication and authorization. In one embodiment, the slice selection subscription data may be the same as the slice selection subscription data described in clause 5.2.3.3 of 3GPP TS 23.502 V16.3.0.
[0128] At block 708, the second access and mobility management entity may decide to skip the at least one network slice specific authentication and authorization process of the terminal device for at least one network slice of the network based on the at least one authentication and authorization status of the terminal device for at least one network slice of the network received. For example, assume that the authentication and authorization status for the terminal device is as follows: for the S-NSSAI that requires NSSAA: {S-NSSAI1: success, S-NSSAI2: success, S-NSSAI3: failure}, for the S-NSSAI that does not require NSSAA: S-NSSAI4, the second access and mobility management entity may decide to skip the network slice specific authentication and authorization process of the terminal device for S-NSSAI1, S-NSSAI2, and S-NSSAI3, where S-NSSAIx represents network slice x, "success" means that the network slice specific authentication and authorization is successful, and "failure" means that the network slice specific authentication and authorization is failed.
[0129] In one embodiment, the method further includes skipping at least one network slice specific authentication and authorization process.
[0130] In one embodiment, determining to skip at least one network slice specific authentication and authorization process further includes: if at least one received authentication and authorization status indicates that the result of the network slice specific authentication and authorization is successful, determining to skip at least one network slice specific authentication and authorization process for at least one network slice of the network for the terminal device.
[0131] In one embodiment, determining to skip at least one network slice specific authentication and authorization process further includes: if at least one received authentication and authorization status indicates that the result of the network slice specific authentication and authorization is failed, determining to skip at least one network slice specific authentication and authorization process for at least one network slice of the network for the terminal device.
[0132] In one embodiment, for at least one network slice that requires network slice specific authentication and authorization, at least one network slice specific authentication and authorization process with an AAA server hosted by an operator of the network or a third party having a business relationship with the network can be triggered.
[0133] In one embodiment, the network slice specific authentication and authorization process can be the same as the corresponding network slice specific authentication and authorization process described in clause 4.2.9.2 of 3GPP TS 23.502 V16.3.0.
[0134] Figure 8a A flowchart of a UE registration process with an NSSAA process in 5GS according to an embodiment of the present disclosure is depicted. For example, the UE has subscribed to 4 S-NSSAIs, where 3 S-NSSAIs are subject to network slice specific authentication and authorization, and one S-NSSAI is a default S-NSSAI that does not require network slice specific authentication and authorization.
[0135] In step 801, the UE sends a registration request to the AMF (i.e., the source AMF in Figure 8a ) via the access network (the source NG-RAN in Figure 8a ). The information included in the request may include user identity, such as SUPI or 5G-GUTI, and the requested NSSAI: S-NSSAI1, S-NSSAI2, S-NSSAI3, S-NSSAI4. For example,
[0136] SUPI: imsi-xxxx, associated GPSI: msisdn-yyyy
[0137] List of S-NSSAIs subscribed by the user, where S-NSSAI4 is the default S-NSSAI:
[0138] S-NSSAI1:
[0139]
[0140] S-NSSAI2:
[0141]
[0142] S-NSSAI3:
[0143]
[0144] S-NSSAI4:
[0145]
[0146] The UE may indicate in the registration request message in the UE 5GMM core network capabilities whether it supports network slice-specific authentication and authorization. If the UE does not support this feature, the AMF will not trigger the NSSAA process for the UE. If the UE requests these S-NSSAIs that are subject to network slice-specific authentication and authorization, they will be rejected for this PLMN.
[0147] For simplicity in the following steps, it is assumed that the UE supports the network slice-specific authentication and authorization feature.
[0148] The following is also possible: the requested S-NSSAI may need to be mapped to the S-NSSAI subscribed by the HPLMN. However, for simplicity in this embodiment, it is assumed that the mapping is straightforward because standardized SST (slice / service type) values are used in this embodiment.
[0149] In step 802, if it is an initial registration and the user identity is SUCI, the AMF shall decide to trigger the primary authentication and authorization process for PLMN access. Once network-authenticated, the SUPI corresponding to the SUCI is returned and the AMF can retain this mapping in the context; or if it is not an initial registration and the user identity is 5G-GUTI, the AMF can obtain the SUPI from the AMF context through the 5G-GUTI and skip the primary authentication and authorization process.
[0150] In step 803, the AMF requests slice selection subscription data from the UDM. This request can only obtain slice selection subscription data, or it can obtain user access and mobility management data that includes slice selection subscription data.
[0151] In step 804, the UDM returns the user slice selection subscription data to the AMF. The UDM shall include information on whether network slice-specific authentication and authorization are required for each subscribed S-NSSAI, as shown in the following examples (true indicates required, false indicates not required):
[0152] S-NSSAI1 requiredAuthnAuthz: true
[0153] S-NSSAI2 requiredAuthnAuthz: true
[0154] S-NSSAI3 requiredAuthnAuthz: true
[0155] S-NSSAI4 requiredAuthnAuthz: false
[0156] In step 805: The AMF parses the user slice selection subscription data to determine whether to trigger network slice-specific authentication and authorization for each requested S-NSSAI. For example, S-NSSAI1, S-NSSAI2, and S-NSSAI3 are subject to network slice-specific authentication and authorization.
[0157] In step 806, the AMF sends a registration acceptance message to the UE via the access network. As an example, the allowed NSSAI only includes S-NSSAI4 because it is subscribed by the user and does not require network slice-specific authentication and authorization.
[0158] The AMF triggers the network slice-specific authentication and authorization process for S-NSSAI1, S-NSSAI2, and S-NSSAI3 because they require network slice-specific authentication and authorization.
[0159] In step 807, for the case where the AAA server (AAA-S) is hosted by the H-PLMN operator, the AMF sends a network slice-specific authentication and authorization request for S-NSSAI1 to the AAA server via the AUSF, for example.
[0160] In step 808, for the case where, for example, if the AAA server belongs to a third party, the AAA proxy (AAA-P) in the serving PLMN may be involved, the AMF sends a network slice-specific authentication and authorization request for S-NSSAI2 to the AAA server via the AUSF and the AAA proxy, for example.
[0161] In step 809, for a case where, for example, if the AAA server belongs to a third party, it may involve an AAA proxy (AAA-P) in the serving PLMN, the AMF sends a network slice-specific authentication and authorization request for S-NSSAI3 to the AAA server, for example, via the AUSF and the AAA proxy.
[0162] In step 810, the AMF obtains the result (e.g., success) of the network slice-specific authentication and authorization for S-NSSAI1 from the AAA server, the AUSF to the AMF.
[0163] In step 811, the AMF stores the NSSAA status for S-NSSAI1 in the UE context: {S-NSSAI1: success}.
[0164] In step 812, the AMF sends a UE configuration update to the UE via the access network, for example, updating the allowed NSSAI to include the allowed S-NSSAI1.
[0165] In step 813, the AMF obtains the result (e.g., success) of the network slice-specific authentication and authorization for S-NSSAI2 from the AAA server, the AAA proxy, the AUSF to the AMF.
[0166] In step 814, the AMF stores the NSSAA status for S-NSSAI2 in the UE context: {S-NSSAI2: success}.
[0167] In step 815, the AMF sends a UE configuration update to the UE via the access network, for example, updating the allowed NSSAI to include the allowed S-NSSAI2.
[0168] In step 816: The AMF obtains the result (e.g., failure) of the network slice-specific authentication and authorization for S-NSSAI3 from the AAA server, the AAA proxy, the AUSF to the AMF.
[0169] In step 817, the AMF stores the NSSAA status for S-NSSAI3 in the UE context: {S-NSSAI3: failure}.
[0170] In step 818, the AMF sends a UE configuration update to the UE via the access network, for example, updating the allowed NSSAI to include the rejected S-NSSAI3 and the reason.
[0171] Note that in this embodiment, the network slice-specific authentication and authorization results for S-NSSAI1, S-NSSAI2, and S-NSSAI3 are respectively updated to the UE, and multiple results can also be included in one configuration update to the UE.
[0172] Figure 8b Depicts a flowchart of N2-based handover with an optimized NSSAA process according to an embodiment of the present disclosure. 8b is the continued call flow for the same user due to mobility Figure 8a of the ongoing call.
[0173] Introduce Figure 8b step 822 for the source AMF to provide the NSSAA state obtained during the registration process as described in Figure 8a to the target AMF, so that after the N2-based handover during the UE-initiated mobility registration update, the target AMF can optimize Figure 8b the NSSAA process in steps 831 - 832 of Figure 8a to skip Figure 8a the network slice-specific authentication and authorization processes that have been performed in
[0174] and store the NSSAA state in the UE context in the target AMF, which avoids unnecessary signaling traffic ( Figure 8a steps 807 - 818 of
[0174] ) and improves the handover performance measured in terms of latency.
[0174] In step 819, the source NG-RAN decides to initiate an N2-based handover to the target NG-RAN. For example, the N2-based handover can be triggered due to new radio conditions or load balancing.
[0175] In step 820, source RAN to source AMF: Handover required (target ID, source-to-target transparent container, SM N2 information list, PDU session ID, intra-system handover indication).
[0176] Step 821, target AMF selection: When the source AMF can no longer serve the UE, the source AMF selects the target AMF.
[0177] In step 822, source AMF to target AMF: Namf_Communication_CreateUEContext request.
[0178] For the UE context information, in addition to the allowed NSSAI for each access type, it also includes the NSSAA state (e.g., success / failure) of the allowed NSSAI subject to network slice-specific authentication and authorization.
[0179] For example:
[0180] - For S-NSSAIs that require NSSAA: {S-NSSAI1: success, S-NSSAI2: success, S-NSSAI3: failure}.
[0181] - For S-NSSAIs that do not require NSSAA: S-NSSAI4.
[0182] In step 823, other operations for N2-based handover preparation, such as PDU session management context update between the SMF, UPF (target UPF, source UPF, anchor UPF), etc.
[0183] In step 824, target AMF to source AMF: Namf_Communication_CreateUEContext response.
[0184] In step 825, source AMF to source RAN to UE: handover command.
[0185] In step 826, the source RAN sends an uplink RAN status transfer message to the source AMF. The target AMF sends this information to the target RAN via downlink RAN status transfer.
[0186] In step 827, UE to target RAN: handover confirmation. After the UE has successfully synchronized to the target cell, the UE sends a handover confirmation message to the target RAN. Through this message, the handover is considered successful by the UE.
[0187] Target RAN to target AMF: handover notification. Through this message, the handover is considered successful in the target-RAN.
[0188] In step 828, other operations for N2-based handover execution, such as PDU session management context update between the SMF, UPF (source UPF, target UPF, anchor UPF), etc.
[0189] In step 829, the UE initiates a mobility registration update process.
[0190] In step 830, the target AMF can decide whether to initiate the main authentication and authorization process based on local policies and security context.
[0191] Compared with the prior art, steps 831 - step 833 are new steps.
[0192] In step 831, the target AMF checks, based on the slice selection subscription data from Figure 8a step 804, whether there is a permitted NSSAI subject to network slice-specific authentication and authorization, and checks whether there is already an available corresponding NSSAA status (with the help of step 822 from the source AMF).
[0193] In step 832, based on the availability of the NSSAA status from step 22, the target AMF decides to skip the network slice-specific authentication and authorization process for the S-NSSAI subject to network slice-specific authentication and authorization.
[0194] If the source AMF does not provide the NSSAA status during the N2-based handover procedure, the target AMF must perform the network slice specific authentication and authorization procedure. In this embodiment, the steps 807 - 818 of Figure 8a must be performed again. Thus, it is obvious that the proposed step 822 of using the source AMF to provide the NSSAA status to the target AMF can optimize the NSSAA procedure at the target AMF, avoiding unnecessary network signaling traffic for the NSSAA procedure during the N2-based handover. The advantages of the proposed solution can include: for the user, a fast service response time and minimized latency for the N2-based handover procedure can be achieved; for the network operator, OPEX reduction can be achieved as unnecessary signaling is avoided and network performance is improved.
[0195] In step 833, the target AMF stores the NSSAA status in the UE context for the UE, which can be used later to optimize the UE re-registration procedure or to provide the latest NSSAA status (if updated) to another new target AMF during the N2-based handover procedure.
[0196] In step 834, a registration acceptance with the NSSAA status is sent back to the UE, for example:
[0197] - For S-NSSAIs that require NSSAA: {S-NSSAI1: Success, S-NSSAI2: Success, S-NSSAI3: Failure},
[0198] - For S-NSSAIs that do not require NSSAA: S-NSSAI4.
[0199] As Figure 8a and 8b Some of the messages shown in are the same as the corresponding messages described in 3GPP TS 23.502 V16.3.0.
[0200] Figure 6 、 7 The various boxes shown in, 8a and 8b can be regarded as method steps, and / or operations resulting from the operation of computer program code, and / or multiple coupled logic circuit elements configured to perform the relevant function(s). The schematic flowcharts described above are generally presented as logic flowcharts. Thus, the depicted order and labeled steps indicate specific embodiments of the presented method. Other steps and methods can be envisioned that are equivalent in function, logic, or effect to one or more steps or portions thereof of the shown method. Additionally, the order in which a particular method occurs may or may not strictly adhere to the order of the corresponding steps shown.
[0201] Embodiments of the present disclosure provide many advantages, and the following is a non-exhaustive list of examples of advantages. In some embodiments of the present disclosure, during an N2-based handover process, the target AMF may optimize the NSSAA process based on the NSSAA status of the allowed NSSAI for network slice-specific authentication and authorization provided by the source AMF during the N2-based handover process. In some embodiments of the present disclosure, during an N2-based handover process, unnecessary network signaling traffic can be avoided. In some embodiments of the present disclosure, for a user, a fast service response time and minimized latency for the N2-based handover process can be achieved. In some embodiments of the present disclosure, for a network operator, OPEX reduction can be achieved due to the avoidance of unnecessary signaling and the improvement of network performance. Those skilled in the art will recognize additional features and advantages after reading the following detailed description.
[0202] Figure 9 is a block diagram showing a device suitable for practicing some embodiments of the present disclosure. For example, any one of the above-mentioned first access and mobility management entity and second access and mobility management entity can be implemented as or by device 900.
[0203] Device 900 includes at least one processor 921, such as a DP, and at least one memory 922 coupled to processor 921. Device 920 may also include a transmitter TX and a receiver RX 923 coupled to processor 921. Memory 922 stores program 924. Program 924 may include instructions that, when executed on the associated processor 921, enable device 920 to operate according to embodiments of the present disclosure. The combination of at least one processor 921 and at least one memory 922 may form a processing device 925 suitable for implementing various embodiments of the present disclosure.
[0204] Various embodiments of the present disclosure may be implemented by a computer program executable by one or more of processor 921, software, firmware, hardware, or a combination thereof.
[0205] Memory 922 may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, for example, as non-limiting examples, semiconductor-based storage devices, magnetic storage devices and systems, optical storage devices and systems, fixed memory, and removable memory.
[0206] Processor 921 may be of any type suitable for the local technical environment and may include, as non-limiting examples, a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture.
[0207] In an embodiment where the apparatus is implemented as a first access and mobility management entity or implemented at a first access and mobility management entity, the memory 922 stores instructions executable by the processor 921, whereby the first access and mobility management entity operates according to any of the methods in method 600 as described in reference Figure 6 and described in method 600.
[0208] In an embodiment where the apparatus is implemented as a second access and mobility management entity or implemented at a second access and mobility management entity, the memory 922 stores instructions executable by the processor 921, whereby the second access and mobility management entity operates according to method 700 as described in the reference Figure 7 and described in method 700.
[0209] Figure 10 is a block diagram showing a first access and mobility management entity according to an embodiment of the present disclosure. As shown, the first access and mobility management entity 1000 includes an obtaining module 1002 and a sending module 1004. The obtaining module 1002 may be configured to obtain at least one authentication and authorization status for at least one network slice of the network for a terminal device. The sending module 1004 may be configured to send, during a handover process, at least one authentication and authorization status for at least one network slice of the network for the terminal device to a second access and mobility management entity.
[0210] Figure 11 is a block diagram showing a second access and mobility management entity according to an embodiment of the present disclosure. As shown, the second access and mobility management entity 1100 includes a receiving module 1102 and a decision module 1104. The receiving module 1102 may be configured to receive, during a handover process, at least one authentication and authorization status for at least one network slice of the network for the terminal device from a first access and mobility management entity. The decision module 1104 may be configured to decide, based on the received at least one authentication and authorization status for at least one network slice of the network for the terminal device, to skip at least one network slice specific authentication and authorization process for at least one network slice of the network for the terminal device.
[0211] The term unit or module may have a conventional meaning in the field of electronics, electrical equipment, and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, output, and / or display functions, etc. (such as those described herein).
[0212] Through functional units, the first access and mobility management entity and the second access and mobility management entity may not require a fixed processor or memory, and any computing resources and storage resources can be arranged from the first access and mobility management entity and the second access and mobility management entity in the communication system. The introduction of virtualization technology and network computing technology can improve the utilization efficiency of network resources and the flexibility of the network.
[0213] According to one aspect of the present disclosure, there is provided a computer program product, which is tangibly stored on a computer-readable storage medium and includes instructions that, when executed on at least one processor, cause the at least one processor to execute any of the methods described above.
[0214] According to one aspect of the present disclosure, there is provided a computer-readable storage medium storing instructions that, when executed by at least one processor, cause the at least one processor to execute any of the methods described above.
[0215] In addition, the present disclosure may also provide a carrier containing the computer program described above, where the carrier is one of the following: an electrical signal, an optical signal, a radio signal, or a computer-readable storage medium. The computer-readable storage medium may be, for example, an optical disc or an electronic storage device (such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory), magnetic tape, CD-ROM, DVD, Blu-ray Disc, etc.
[0216] The techniques described herein can be implemented by various components such that a device that implements one or more functions of the corresponding device described in the embodiments includes not only the components of the prior art but also components for implementing one or more functions of the corresponding device described in the embodiments, and it may include separate components for each individual function or may be configured to execute one or more functions. For example, these techniques can be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules), or a combination thereof. For firmware or software, it can be implemented by modules (such as procedures, functions, etc.) that execute the functions described herein.
[0217] The exemplary embodiments herein have been described above with reference to block diagrams and flowchart illustrations of methods and apparatuses. It will be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, can be implemented respectively by various components including computer program instructions. These computer program instructions can be loaded onto a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions executed on the computer or other programmable data processing apparatus create components for implementing the functions specified in the flowchart block or blocks.
[0218] Moreover, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in a sequential order, or that all of the illustrated operations be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although a number of specific implementation details are included in the above discussion, these specific implementation details should not be construed as limitations on the scope of the subject matter described herein, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, the various features that are described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination.
[0219] Although this specification contains many specific implementation details, these should not be construed as limitations on the scope of any implementation or of what may be claimed, but rather as descriptions of features that may be specific to particular embodiments of a particular implementation. Certain features that are described in this specification in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, the various features that are described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. Moreover, although the features may be described above as acting in certain combinations and even initially claimed as such, in some cases, one or more features from a claimed combination may be removed from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0220] It will be apparent to those skilled in the art that, as technology progresses, the inventive concept can be implemented in various ways. The above embodiments are given to describe the present disclosure rather than to limit the present disclosure, and it should be understood that modifications and variations can be made without departing from the spirit and scope of the present disclosure, as will be readily understood by those skilled in the art. Such modifications and variations are considered to be within the scope of the present disclosure and the appended claims. The scope of protection of the present disclosure is defined by the appended claims.
Claims
1. A method at a second access and mobility management entity, comprising: Receiving, during a handover procedure for a terminal device, at least one authentication and authorization status of at least one subscribed network slice for the terminal device from a first access and mobility management entity; Determining, based on the received at least one authentication and authorization status of at least one subscribed network slice, whether to skip at least one network slice specific authentication and authorization procedure for the terminal device for the at least one subscribed network slice; And Skipping the at least one network slice specific authentication and authorization procedure.
2. The method according to claim 1, wherein, The determining whether to skip at least one network slice specific authentication and authorization procedure further comprises: Determining to skip at least one network slice specific authentication and authorization procedure for the terminal device for the at least one subscribed network slice if the received at least one authentication and authorization status indicates that the result of network slice specific authentication and authorization is successful.
3. The method according to claim 1, wherein, The determining whether to skip at least one network slice specific authentication and authorization procedure further comprises: Determining to skip at least one network slice specific authentication and authorization procedure for the terminal device for the at least one subscribed network slice if the received at least one authentication and authorization status indicates that the result of network slice specific authentication and authorization is failed.
4. The method according to claim 1, further comprising: Checking, based on the slice selection subscription data of the terminal device, whether there is one or more allowed network slices subject to network slice specific authentication and authorization, and checking, based on the received at least one authentication and authorization status of at least one subscribed network slice, whether there is already one or more corresponding available authentication and authorization statuses.
5. The method according to any one of claims 1-4, wherein, Each subscribed network slice of the at least one subscribed network slice is identified by a single network slice selection assistance information S-NSSAI.
6. The method according to any one of claims 1-4, wherein The handover procedure is an N2-based handover procedure between next generation radio access network NG-RAN nodes.
7. The method according to any one of claims 1-4, wherein, The first access and mobility management entity is an access and mobility management function AMF entity, and the second access and mobility management entity is an AMF entity.
8. The method according to any one of claims 1-4, wherein Obtaining the at least one authentication and authorization status of at least one subscribed network slice from another access and mobility management entity and / or from an authentication server.
9. The method according to claim 8, wherein, The authentication server is an authentication server function AUSF entity, and the another access and mobility management entity is an access and mobility management function AMF entity.
10. The method according to any one of claims 1-4 and 9, wherein, Receiving, during the handover procedure, the at least one authentication and authorization status of at least one subscribed network slice in a request for the first access and mobility management entity to create a context of the terminal device in the second access and mobility management entity.
11. The method according to claim 10, wherein, The request is a Namf_Communication_CreateUEContext request.
12. The method according to any one of claims 1-4, 9 and 11, further comprising: Store the at least one authentication and authorization status for the network slice(s) of at least one subscription.
13. The method according to any one of claims 1 - 4, 9 and 11, wherein, For the network slice(s) of the at least one subscription that require network slice-specific authentication and authorization, trigger the at least one network slice-specific authentication and authorization process with the at least one authentication, authorization, and accounting (AAA) server hosted by the operator of the network or by a third party having a business relationship with the network.
14. A second access and mobility management entity, comprising: A processor; and A memory coupled to the processor, the memory storing instructions executable by the processor, whereby the second access and mobility management entity is operable to: During a handover process for a terminal device, receive from a first access and mobility management entity at least one authentication and authorization status for the network slice(s) of at least one subscription for the terminal device; Based on the received at least one authentication and authorization status for the network slice(s) of at least one subscription, determine whether to skip at least one network slice-specific authentication and authorization process for the network slice(s) of at least one subscription for the terminal device; and Skip the at least one network slice-specific authentication and authorization process.
15. The second access and mobility management entity according to claim 14, wherein, The second access and mobility management entity is further operable to perform the method according to any one of claims 2 to 13.