Communication method and communication device
By selecting the first authentication device of the first network based on the first information of the terminal device, the authentication failure problem of the terminal device failing to deploy the second authentication device in the second network or using AAA server to perform authentication is solved, and the successful registration and access of the terminal device is achieved.
Patent Information
- Application Number
- CN202111101555.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-19
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-09-19
AI Technical Summary
When the terminal device uses the credentials of the second network to access the first network, since different devices of the second network perform main authentication or security procedures, an error or abnormal communication scenario occurs, and the devices interacting with the second network in the first network are different, resulting in authentication failure.
Provided a communication method, the mobile management device obtains first information of the terminal device, including a home network identification and/or a routing indication, and selects a first authentication device of the first network, even if the second network does not deploy the second authentication device or performs the authentication using an AAA server.
Ensure that the terminal device can successfully register or access the first network, avoid registration rejection information caused by not discovering the second authentication device of the second network, and improve communication success rate.
Smart Images

Figure CN115835207B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technology, and more specifically, to a communication method and a communication device. Background Art
[0002] When a terminal device uses the credentials of a second network (also referred to as external credentials) to access a first network, the first network may be a network that supports external credentials, such as a standalone non-public network (SNPN). This means that, during the process of the terminal device accessing the first network, a network different from the first network, such as a credentials holder (CH), performs the main authentication or security process of the terminal device.
[0003] Since different second networks may use different devices to perform the main authentication or security process of the terminal device, and different devices in the first network interacting with the second network may also be used, communication scenarios with error cases or abnormal cases often occur.
[0004] Therefore, there is an urgent need for a communication method that enables terminal equipment to perform authentication. Summary of the invention
[0005] The embodiments of the present application provide a communication method and a communication device, which can enable a terminal device to perform authentication.
[0006] In a first aspect, a communication method is provided, comprising: a mobile management device obtains first information of a terminal device, the first information comprising a home network identifier and / or a routing indication of the terminal device, the first information instructing the mobile management device to select a second authentication device of a second network, the credentials of the terminal device belong to the second network, and the second network is not deployed with the second authentication device; the mobile management device selects a first authentication device based on the first information, and the first authentication device and the mobile management device belong to the first network.
[0007] Through the above technical solution, the present application can achieve that when the terminal device uses the credentials of the second network and the second network uses the authentication authorization and billing server to perform authentication, the mobile management device of the first network will select the first authentication device of the first network, and will not send a registration rejection message to the terminal device when the second authentication device of the second network cannot be found, resulting in the terminal device being unable to register or access the first network, thereby enabling the terminal device to successfully register or access the first network.
[0008] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the mobility management device does not find the second authentication device based on the first information.
[0009] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the mobile management device selects the first authentication device according to configuration information, and the configuration information instructs the mobile management device to select the first authentication device when the second authentication device is not found according to the first information.
[0010] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects a first authentication device based on the first information, including: the mobile management device also obtains indication information from the terminal device, the indication information indicating that the first network supports external credentials and / or the terminal device uses external credentials; the mobile management device selects the first authentication device based on the indication information.
[0011] By sending indication information from the terminal device to the mobile management device of the first network, the indication information is used to indicate that the first network supports external credentials or instructs the terminal device to adopt external credentials. In this way, when the second authentication device of the second network is not found, the mobile management device of the first network will select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0012] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects a first authentication device based on the first information, including: the mobile management device sends a request message to a network storage device, the request message is used to request the discovery of a second authentication device, and the request message includes the first information; the mobile management device obtains response information from the network storage device, the response information is used to indicate that the second authentication device is not found, and / or the response information includes identification information and / or address information of the first authentication device; the mobile management device selects the first authentication device based on the response information.
[0013] By sending a request message from the mobile management device of the first network to the network storage device, requesting the network storage device to discover the second authentication device of the second network, and selecting the first authentication device based on the response information fed back by the network storage device, the mobile management device of the first network will select the first authentication device of the first network when the second authentication device of the second network is not found, thereby completing the access or registration process of the terminal device to the first network.
[0014] In combination with the first aspect, in some implementations of the first aspect, the request information further includes first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials.
[0015] Through this indication information, the network storage device of the first network helps to determine that the first network supports external credentials or determines that the terminal device uses external credentials, so that when the second authentication device of the second network cannot be found, it will feedback to the mobile management device that it has not found or feedback the identification information and / or address information of the first authentication device. In this way, the mobile management device of the first network will select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0016] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects a first authentication device based on the first information, including: the mobile management device also obtains a network identifier from an access network device, and the network identifier indicates that the first network is a non-public network; the mobile management device selects the first authentication device based on the first network identifier and the first information.
[0017] Specifically, the mobile management device of the first network determines that the first network is a non-public network based on the network identifier, and determines that the credentials of the terminal device belong to the second network based on the first information. Thus, the mobile management device of the first network determines that the first network supports external credentials or determines that the terminal device uses external credentials.
[0018] By sending the network identifier from the access network device to the mobile management device, the mobile management device of the first network can determine that the first network supports external credentials or that the terminal device uses external credentials. Therefore, when the second authentication device of the second network cannot be found, the mobile management device of the first network will select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0019] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects the first authentication device based on the first information, including: the mobile management device selects the first authentication device based on configuration information, wherein the configuration information includes one or more home network identifiers and / or routing indications.
[0020] In combination with the first aspect, in certain implementations of the first aspect, the mobile management device selects a first authentication device based on configuration information, including: when the home network identifier and / or routing indication of the terminal device matches one or more home network identifiers and / or routing indications, the mobile management device selects the first authentication device.
[0021] When the home network identifier and / or routing indication of the terminal device matches the configuration information of the mobile management device of the first network, the mobile management device of the first network will select the first authentication device of the first network, thereby helping to complete the access or registration process of the terminal device to the first network.
[0022] In combination with the first aspect, in some implementations of the first aspect, the configuration information is pre-configured in the mobile management device, or is obtained by the mobile management device from a control plane device, and the control plane device includes a policy control device, a unified data management device, a user database device, an application function device, a network open device or a network storage device.
[0023] In combination with the first aspect, in some implementations of the first aspect, the first authentication device is an authentication service function device.
[0024] In combination with the first aspect, in some implementations of the first aspect, the second authentication device is an authentication service function device.
[0025] In a second aspect, a communication method is provided, comprising: a network storage device receives request information from a mobile management device, the request information includes a home network identifier and / or a routing indication of a terminal device, the request information is used to request discovery of a second authentication device of a second network, the credentials of the terminal device belong to the second network, and the second network has not deployed the second authentication device; the network storage device sends response information to the mobile management device, the response information includes an indication that the second authentication device has not been found, and / or the response information includes identification information and / or address information of the first authentication device, wherein the first authentication device, the network storage device and the mobile management device belong to the first network.
[0026] Through the above technical solution, the present application can achieve that when the terminal device uses the credentials of the second network and the second network uses the authentication authorization and billing server to perform authentication, the mobile management device of the first network will select the first authentication device of the first network, and will not send a registration rejection message to the terminal device when the second authentication device of the second network cannot be found, resulting in the terminal device being unable to register or access the first network, thereby enabling the terminal device to successfully register or access the first network.
[0027] In combination with the second aspect, in some implementations of the second aspect, the request information further includes first indication information, and the first indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials.
[0028] Through this indication information, the network storage device of the first network helps to determine that the first network supports external credentials or determines that the terminal device uses external credentials, so that when the second authentication device of the second network cannot be found, it will feedback to the mobile management device that it has not found or feedback the identification information and / or address information of the first authentication device. In this way, the mobile management device of the first network will select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0029] In combination with the second aspect, in some implementations of the second aspect, before the network storage device sends response information to the mobile management device, the method further includes: the network storage function network element does not find the second authentication device.
[0030] In combination with the second aspect, in certain implementations of the second aspect, the network storage device sends response information to the mobile management device, including: when the home network identifier and / or routing indication of the terminal device matches the configuration information, determining to send the response information, the configuration information includes one or more home network identifiers and / or routing indications; or, the network storage device determines to send the response information based on the first indication information; or, the network storage device does not find the second authentication device, and determines to send the response information.
[0031] In combination with the second aspect, in certain implementations of the second aspect, the configuration information is pre-configured in the network storage device, or is obtained by the network storage device from a control plane device, and the control plane device includes a mobile management device, a unified data management device, a policy control device, a user database device, a network open device, or an application function device.
[0032] Through the various schemes described above, when the network storage device of the first network fails to find the second authentication device of the second network, it can feedback response information to the mobile management device of the first network, which helps the mobile management device of the first network to select the first authentication device of the first network, thereby helping to complete the access or registration process of the terminal device to the first network.
[0033] According to a third aspect, a communication method is provided, including: a third authentication device obtains second information, the second information instructs a terminal device to execute an online signing; the third authentication device determines a fourth authentication device based on the second information, and the fourth authentication device is used to execute an authentication process of the terminal device.
[0034] When the present application learns through a third authentication device that the terminal device is to execute an online contract, it selects a network slice and a non-public network authentication authorization device or directly interacts with a default credential server, thereby enabling the terminal device to successfully access the network to execute an online contract. It can also avoid the situation where, after selecting a data management device and interacting with the data management device, the data management device cannot execute authentication or causes error cases or abnormal cases because the data management device does not have contract data about the terminal device, resulting in the terminal device being unable to access the network.
[0035] In combination with the third aspect, in some implementations of the third aspect, the second information is sent by a mobile management device; or, the second information is sent by a terminal device.
[0036] In combination with the third aspect, in certain implementations of the third aspect, when the second information is sent by a terminal device, the second information is a hidden identifier of a user of the terminal device.
[0037] By sending the second information from the terminal device to the third authentication device, the third authentication device is informed that the terminal device is for executing online contract signing, selecting a network slice and a non-public network authentication authorization device or directly interacting with a default credential server, thereby enabling the terminal device to successfully access the network to execute online contract signing, and avoiding the situation where, after selecting a unified data management device and interacting with the unified data management device, the unified data management device cannot execute authentication or causes error cases or abnormal cases because the unified data management device does not have contract data about the terminal device, resulting in the terminal device being unable to access the network.
[0038] In combination with the third aspect, in certain implementations of the third aspect, the fourth authentication device includes one or more of the following devices: a network slice and an independent non-public network authentication and authorization device, a default credential server, and an authentication, authorization, and billing server.
[0039] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: the third authentication device skips selecting the unified data management device.
[0040] When the present application learns through a third authentication device that the terminal device is to execute an online contract, it selects a network slice and a non-public network authentication authorization device or directly interacts with a default credential server, thereby enabling the terminal device to successfully access the network to execute an online contract. It can also avoid the situation where, after selecting a unified data management device and interacting with the unified data management device, the unified data management device cannot execute authentication or causes error cases or abnormal cases because the unified data management device does not have contract data about the terminal device, resulting in the terminal device being unable to access the network.
[0041] In combination with the third aspect, in some implementations of the third aspect, the method further includes: a third authentication device obtains a user permanent identifier of the terminal device according to a hidden user identifier of the terminal device.
[0042] When the third authentication device skips selecting the unified data management device, the user hidden identifier of the terminal device cannot be decrypted or restored to a permanent identifier through the unified data management device. However, in the registration process of the terminal device, the signaling interaction between the core network devices (or control plane devices) usually needs to include the identification information of the terminal device, which is usually a permanent identifier. Therefore, when the third authentication device learns that the terminal device performs an online contract or learns that the terminal device performs registration for an online contract, it can obtain or restore the permanent identifier based on the user hidden identifier to ensure that the signaling interaction between the core network devices (or control plane devices) is not affected.
[0043] In combination with the third aspect, in some implementations of the third aspect, the method further includes: a third authentication device recovering a user permanent identifier of the terminal device from a user hidden identifier of the terminal device.
[0044] In a fourth aspect, a communication device is provided, comprising: a transceiver unit, used to obtain first information of a terminal device, the first information including a home network identifier and / or a routing indication of the terminal device, the first information instructing a mobile management device to select a second authentication device of a second network, the credentials of the terminal device belong to the second network, and the second network has not deployed the second authentication device; a processing unit, used to select a first authentication device according to the first information, the first authentication device and the mobile management device belong to the first network.
[0045] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further configured to: fail to find the second authentication device based on the first information.
[0046] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is used to select a first authentication device based on configuration information, and the configuration information instructs the mobile management device to select the first authentication device when the second authentication device is not found based on the first information.
[0047] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further used to obtain indication information from the terminal device, wherein the indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials; the processing unit is used to select the first authentication device based on the indication information.
[0048] In combination with the fourth aspect, in some implementations of the fourth aspect, the request information further includes first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials.
[0049] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is used to send a request message to the network storage device, the request message is used to request the discovery of the second authentication device, and the request message includes the first information; the transceiver unit is used to obtain response information from the network storage device, the response information is used to indicate that the second authentication device is not found, and / or the response information includes the identification information and / or address information of the first authentication device; the processing unit is used to select the first authentication device based on the response information.
[0050] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further used to obtain a network identifier from an access network device, where the network identifier indicates that the first network is a non-public network; the processing unit is used to select a first authentication device based on the first network identifier and the first information.
[0051] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is used to select a first authentication device based on configuration information, wherein the configuration information includes one or more home network identifiers and / or routing indications.
[0052] In combination with the fourth aspect, in certain implementations of the fourth aspect, when the home network identifier and / or routing indication of the terminal device matches one or more home network identifiers and / or routing indications, the processing unit is used to select the first authentication device.
[0053] In combination with the fourth aspect, in some implementations of the fourth aspect, the configuration information is pre-configured in the mobile management device, or is obtained by the mobile management device from a control plane device, and the control plane device includes a policy control device, a unified data management device, a user database device, an application function device, a network opening device or a network storage device.
[0054] In combination with the fourth aspect, in some implementations of the fourth aspect, the first authentication device is an authentication service function device.
[0055] In combination with the fourth aspect, in some implementations of the fourth aspect, the second authentication device is an authentication service function device.
[0056] In a fifth aspect, a communication device is provided, comprising: a transceiver unit, used to obtain request information from a mobile management device, the request information including a home network identifier and / or a routing indication of a terminal device, the request information being used to request discovery of a second authentication device of a second network, the credentials of the terminal device belonging to the second network, and the second network not deploying the second authentication device; a processing unit, used to send response information to the mobile management device, the response information including an indication that the second authentication device was not found, and / or the response information including identification information and / or address information of the first authentication device, wherein the first authentication device, the network storage device and the mobile management device belong to the first network.
[0057] In combination with the fifth aspect, in some implementations of the fifth aspect, the request information includes first indication information, and the first indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials.
[0058] In combination with the fifth aspect, in certain implementations of the fifth aspect, the processing unit is configured to detect that the second authentication device is not found.
[0059] In combination with the fifth aspect, in certain implementations of the fifth aspect, when the home network identifier and / or routing indication of the terminal device matches the configuration information, it is determined to send response information, and the configuration information includes one or more home network identifiers and / or routing indications; or, the processing unit is used to determine to send response information based on the first indication information; or, the processing unit is used to determine to send response information when the second authentication device is not found.
[0060] In combination with the fifth aspect, in certain implementations of the fifth aspect, the configuration information is pre-configured in the network storage device, or is obtained by the network storage device from a control plane device, and the control plane device includes a mobile management device, a unified data management device, a policy control device, a user database device, a network open device, or an application function device.
[0061] In a sixth aspect, a communication device is provided, including: a transceiver unit for obtaining second information, the second information instructing a terminal device to perform an online signing; a processing unit for determining a fourth authentication device based on the second information, the fourth authentication device being used to execute an authentication process of the terminal device.
[0062] In combination with the sixth aspect, in certain implementations of the sixth aspect, the second information is sent by a mobile management device; or, the second information is sent by a terminal device.
[0063] In combination with the sixth aspect, in certain implementations of the sixth aspect, when the second information is sent by a terminal device, the second information is a hidden identifier of a user of the terminal device.
[0064] In combination with the sixth aspect, in certain implementations of the sixth aspect, the fourth authentication device includes one or more of the following devices: a network slice and an independent non-public network authentication and authorization device, a default credential server, and an authentication, authorization, and billing server.
[0065] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing unit is further used to skip selecting a unified data management device.
[0066] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing unit is further used to obtain a user permanent identifier of the terminal device based on a hidden user identifier of the terminal device.
[0067] In combination with the sixth aspect, in certain implementations of the sixth aspect, the processing unit is further used to recover the user permanent identifier of the terminal device from the user hidden identifier of the terminal device.
[0068] In the seventh aspect, a computer-readable storage medium is provided, storing a computer program or instructions, wherein the computer program or instructions are used to implement the method described in the first aspect and any possible implementation of the first aspect, or the method described in the second aspect and any possible implementation of the second aspect; or any one of the methods described in the third aspect and any possible implementation of the third aspect.
[0069] In an eighth aspect, a computer program product is provided, characterized in that when the computer program product runs on a computer, the computer is caused to execute the method described in the first aspect and any possible implementation of the first aspect, or the method described in the second aspect and any possible implementation of the second aspect; or any one of the methods described in the third aspect and any possible implementation of the third aspect.
[0070] In a ninth aspect, a communication system is provided, comprising a mobile management device for executing the first aspect and any possible implementation method of the first aspect, and a network storage device for executing the second aspect and any implementation method of any possible implementation method of the second aspect.
[0071] In the tenth aspect, a communication system is provided, comprising a mobile management device for executing the first aspect and any possible implementation method of the first aspect, a network storage device for executing the second aspect and any possible implementation method of the second aspect, and a third authentication device for executing the third aspect and any possible implementation method of the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 It is a schematic diagram of a communication system.
[0073] Figure 2 is a schematic flow chart of a communication method.
[0074] Figure 3 It is a schematic flow chart of a communication method provided in an embodiment of the present application.
[0075] Figure 4 It is a schematic flow chart of another communication method provided in an embodiment of the present application.
[0076] Figure 5 It is a schematic flow chart of another communication method provided in an embodiment of the present application.
[0077] Figure 6 It is a schematic flow chart of another communication method provided in an embodiment of the present application.
[0078] Figure 7 This is a schematic flow chart of yet another communication method provided in an embodiment of the present application.
[0079] Figure 8 It is a schematic block diagram of a communication device provided in an embodiment of the present application.
[0080] Fig. 9 It is a schematic block diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0081] The technical solution in this application will be described below in conjunction with the accompanying drawings.
[0082] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: global system of mobile communication (GSM) system, code division multiple access (CDMA) system, wideband code division multiple access (WCDMA) system, general packet radio service (GPRS), long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), universal mobile telecommunication system (UMTS), worldwide interoperability for microwave access (WiMAX) communication system, fifth generation (5G) system or new radio (NR), and other future communication systems.
[0083] The terminal device in the embodiments of the present application may refer to a user device, an access terminal, a user unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user device. The terminal device may also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a 5G network or a terminal device in a public land mobile communication network (PLMN), etc., and the embodiments of the present application are not limited to this.
[0084] The network device in the embodiment of the present application can be a device for communicating with a terminal device. The network device can be a base station (base transceiver station, BTS) in a GSM system or a CDMA system, or a base station (nodeB, NB) in a WCDMA system, or an evolved base station (evolutional nodeB, eNB or eNodeB) in an LTE system, or a wireless controller in a cloud radio access network (cloud radio access network, CRAN) scenario, or the network device can be a relay station, an access point, a vehicle-mounted device, a wearable device, a network device in a 5G network, a network device in a PLMN network, or a network device in a non-public network, etc., and the embodiments of the present application are not limited.
[0085] The technical solution of the embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0086] Figure 1 is a schematic diagram of a communication system. Figure 1As shown, the network includes access and mobility management function (AMF), capability exposure function (NEF), network storage function (NRF), unified data management (UDM), radio access network (RAN) equipment, policy control function (PCF), user equipment (UE), policy control function (PCF), user plane function (UPF), data network (DN), authentication server function (AUSF), network slice selection function (NSSF), AAA server (authentication, authorization, and accounting server, AAA Server) and network slice and SNPN authentication and authorization function (NSSAAF), etc.
[0087] It should be understood that Figure 1 This is only a schematic description diagram, and the embodiments of the present application do not limit the number and types of network elements (or devices) actually deployed in the network.
[0088] It should be noted that in Figure 1In the schematic diagram shown, the device framed by the dotted box belongs to the first network, and the device not selected by the dotted box belongs to the second network. The second network is different from the first network that the UE needs to access, and is used to execute security procedures for the UE accessing the first network. Among them, the first network can be a public land mobile network (PLMN), a non-public network (NPN), such as SNPN, a public network integrated non-public network (PNI-NPN); the second network can be a PLMN, an NPN. Since the UE's credentials belong to the second network, the second network can also be called a credentials holder (credentials holder, CH).
[0089] in, Figure 1 The main functions of each device shown are described below:
[0090] UE: can be called terminal equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent or user device.
[0091] In addition, UE can also be a terminal device in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection. IoT technology can achieve massive connections, deep coverage, and terminal power saving through narrow band NB technology, for example.
[0092] In addition, UE can also include sensors such as smart printers, train detectors, and gas stations. Its main functions include collecting data (part of the terminal equipment), receiving control information and downlink data from network equipment, and sending electromagnetic waves to transmit uplink data to network equipment.
[0093] It should be understood that the UE may be any device that can access a network. The UE and the access network device may communicate with each other using a certain air interface technology.
[0094] Radio access network equipment (RAN) (also called access network equipment) corresponds to different access networks in 5G, such as wired access, wireless base station access and other methods. The RAN equipment in this application includes but is not limited to: the next generation base station (gnodeB, gNB) in 5G, evolved node B (evolved node B, eNB), radio network controller (radio network controller, RNC), node B (node B, NB), base station controller (base station controller, BSC), base transceiver station (base transceiver station, BTS), home base station (for example, home evolved node B, or home node B, HNB), base band unit (base band unit, BBU), transmission point (transmitting and receiving point, TRP), transmission point (transmitting point, TP), mobile switching center, etc.
[0095] Unified data management (UDM) (also called unified data management network element, unified data management entity, data management device, unified data management equipment) is a type of core network equipment, mainly used to process terminal equipment identification, access authentication, registration and mobility management, etc. Unified data management equipment is a control plane device.
[0096] Policy control function (PCF) (also known as policy control network element, policy control function network element, policy control equipment, policy control function entity, etc.): mainly responsible for policy control functions such as billing for sessions and service flows, quality of service (QoS) bandwidth guarantee and mobility management, and UE policy decision-making.
[0097] Session management function (SMF): mainly performs session management, execution of control policies issued by PCF, selection of UPF, UE IP address allocation and other functions.
[0098] Access and mobility management function (AMF) (also known as access and mobility management function entity, access and mobility management equipment, access and mobility management network element, access management equipment, mobility management equipment) is a type of core network equipment, mainly used for mobility management and access management, etc. It can be used to implement other functions of mobility management entity (MME) functions except session management, such as lawful monitoring, or access authorization (or authentication), user equipment registration, mobility management, tracking area update process, reachability detection, selection of session management network element, mobile state transition management and other functions. For example, in 5G, the access and mobility management network element can be an access and mobility management function (AMF) network element. In future communications, such as 6G, the access and mobility management network element can still be an AMF network element, or have other names, which are not limited in this application. When the access and mobility management network element is an AMF network element, the AMF can provide Namf services.
[0099] User plane function (UPF) (also known as user plane equipment, user plane function network element, user plane network element, user plane function entity): mainly includes the following functions: data packet routing and transmission, packet detection, service usage reporting, QoS processing, legal monitoring, uplink packet detection, downlink data packet storage and other user-related functions.
[0100] Authentication service function (AUSF) (also known as authentication service function network element, authentication service function entity, authentication service equipment, authentication equipment): mainly used for user authentication and authentication execution, that is, authentication between UE and operator network. After the authentication service function network element receives the authentication request initiated by the contracted user, it can authenticate and / or authorize the contracted user through the authentication information and / or authorization information stored in the unified data management network element, or generate the authentication and / or authorization information of the contracted user through the unified data management network element. The authentication service function network element can feedback the authentication information and / or authorization information to the contracted user. In one possible implementation method, the authentication service function network element can also be co-located with the unified data management network element. In a 5G communication system, the authentication service function network element can be an authentication service function (AUSF) network element. In future communication systems, the unified data management can still be AUSF, or it can have other names, which are not limited in the embodiments of the present application.
[0101] Network repository function (NRF) (also known as network storage device, network storage function network element, network storage function entity): mainly used to support service discovery function. A network element discovery request is received from a network element function or service communication proxy (SCP), and the network element discovery request information can be fed back. At the same time, NRF is also responsible for maintaining information about available network functions and the services they support. It can also be understood as a network storage device. Among them, the discovery process is the process by which the demand network function (NF) uses NRF to implement addressing of a specific NF or a specific service. NRF provides the IP address or fully qualified domain name (FQDN) or unified resource identifier (URI) of the corresponding NF instance or NF service instance. In addition, NRF can also implement a cross-PLMN discovery process by providing a network identifier (such as PLMNID). In order to realize the addressing discovery of network element functions, each network element needs to be registered in NRF, and some network element functions can be registered in NRF when they are first run. The network storage function device can be a core network device.
[0102] Network exposure function (NEF) (also known as network exposure equipment, network exposure function entity, network exposure function network element, network capability exposure function entity, network capability exposure function equipment, network capability exposure function network element, network capability exposure equipment, etc.): mainly used to support the opening of capabilities and events, such as for securely opening the services and capabilities provided by 3GPP network functions to the outside world.
[0103] The user database (user data repository, UDR) (also known as user database entity, user database network element, user database device, etc.) can have different data access authentication mechanisms for different types of data such as contract data and policy data to ensure the security of data access.
[0104] An authentication authorization accounting server (AAA server) (also known as an authentication authorization server, authentication authorization device, authentication device, authentication authorization accounting device, etc.) is a server program that can process user access requests, provide verification authorization, and account services. AAA servers usually work in conjunction with network access control, gateway servers, databases, and user information directories. The network connection server interface that collaborates with AAA servers is the Remote Authentication Dial-In User Service (RADIUS).
[0105] The network slice-specific and SNPN authentication and authorization function is mainly used to support specific network slice authentication and authorization with the AAA server or AAA agent, and to support access to the SNPN using credentials from the credentials holder (CH), which is authenticated by the AAA server.
[0106] Among them, Figure 1 As shown, the terminal device accesses the network through the RAN device.
[0107] The terminal device communicates with the AMF through the N1 interface (N1 for short).
[0108] RAN communicates with AMF through the N2 interface (N2 for short).
[0109] RAN communicates with UPF through the N3 interface (N3 for short).
[0110] UPF communicates with UPF through N9 interface (referred to as N9).
[0111] The UPF communicates with the DN through the N6 interface (referred to as N6).
[0112] also, Figure 1 The control plane functions such as AMF, SMF, NEF, NRF, PCF or UDM shown can also interact using service-oriented interfaces.
[0113] For example, the service interface provided by AMF to the outside world may be Namf.
[0114] The service interface provided by NSSF to the outside world may be Nnssf.
[0115] The service interface provided by UDM to the outside world may be Nudm.
[0116] The service interface provided by NEF to the outside world may be Nnef.
[0117] The service interface provided by NRF to the outside world may be Nnrf.
[0118] The service interface provided by PCF to the outside world may be Npcf.
[0119] The service interface provided by AF to the outside world may be Naf.
[0120] The service interface provided by AUSF to the outside world may be Nausf.
[0121] The service interface provided by NSSAAF to the outside world may be Nnssaaf.
[0122] The service-oriented interface provided by SMF to the outside world may be Nsmf.
[0123] It should be understood that the RAN, SMF, PCF or AF in the embodiments of the present application may also be referred to as a communication device or a communication equipment, which may be a general device or a dedicated device, and the present application does not make any specific limitations on this.
[0124] It should also be understood that the above naming is only used to distinguish different functions, and does not mean that these devices are independent physical devices. The present application does not limit the specific form of the above devices. For example, they can be integrated into the same physical device or they can be different physical devices. In actual deployment, network elements or devices can be co-located. For example, the access and mobility management network element can be co-located with the session management network element; the session management network element can be co-located with the user plane network element. When two network elements are co-located, the interaction between the two network elements provided in the embodiment of the present application becomes the internal operation of the co-located network element or can be omitted.
[0125] It is understandable that the above functions can be network elements in hardware devices, software functions running on dedicated hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (e.g., a cloud platform).
[0126] It should be noted that Figure 1 The naming of each device (such as PCF, AMF, etc.) is just a name, and the name does not limit the function of the device itself. In 5G networks and other future networks, the above-mentioned devices may also have other names, and this application does not make specific restrictions on this. For example, in a 6G network, some or all of the above-mentioned network elements may use the terminology in 5G, or may be other names, etc., which are uniformly explained here and will not be repeated below.
[0127] It should be noted that the technical solution of the embodiment of the present application is applicable to 5G networks, and is also applicable to 4G, 6G networks, future communication networks, etc.
[0128] In order to better describe the technical solutions of the embodiments of the present application, the technical terms related to the technical solutions of the embodiments of the present application will be described below.
[0129] First, NPN.
[0130] NPN includes two types according to whether the core network (CN) is independent:
[0131] 1) SNPN. This network does not depend on the PLMN network and is operated by the SNPN operator.
[0132] 2) PNI-NPN. This network relies on the PLMN network and is operated by traditional operators. In other words, PNI-NPN is actually equivalent to PLMN, except that PLMN provides special slices and / or data networks to provide NPN services, and not all UEs can obtain the NPN service. Only when the UE passes the slice authentication and / or secondary authentication can it obtain the NPN service.
[0133] Second, external authentication.
[0134] External authentication means that before the UE accesses the first network, a credential holder (CH) different from the first network performs a security process on the UE. The security process may include processes such as primary authentication, authentication, and authorization. It should be understood that at this time, the UE uses external credentials (or external contract) to access the first network.
[0135] The CH includes an architecture that uses an AAA server to perform authentication on the UE. At this time, the core network device of the first network needs to interact with the AAA server of the CH to complete the UE authentication process. In a possible implementation, the authentication authorization device of the first network interacts with the AAA server of the CH.
[0136] Figure 2 It is a schematic flow chart of a communication method. Figure 2 shown.
[0137] S210, RAN receives registration request information from UE.
[0138] It should be understood that when the UE needs to register with the network, the UE sends a registration request message, which includes the identification information of the terminal device. Exemplarily, the identification information of the UE may include one or more of the following information: a globally unique temporary identity (GUTI), a SUCI, and a permanent equipment identifier (PEI).
[0139] S220, RAN performs AMF selection.
[0140] It should be understood that after receiving the registration request information from the UE, the RAN will select an appropriate AMF and send the UE's registration request information to the AMF.
[0141] S230, AMF receives registration request information.
[0142] S240, AMF executes the selection of AUSF.
[0143] Specifically, AMF selects the appropriate AUSF to perform security processes such as authentication.
[0144] S250, executing authentication or security process.
[0145] It should be understood that the execution process of the above authentication or security process involves the interaction of UE, AMF, AUSF and UDM.
[0146] S260, obtaining the subscription data of the UE.
[0147] After the UE successfully authenticates itself with the core network element, the AMF can interact with the UDM to obtain the subscription data of the terminal device.
[0148] S270, AMF sends N2 information to RAN.
[0149] It should be understood that the N2 information sent by the AMF to the RAN includes non-access stratum (NAS) information, and the NAS information includes registration acceptance information.
[0150] S280, RAN sends a registration acceptance message to the UE.
[0151] After receiving the registration acceptance message from AMF, RAN will forward the registration acceptance message to UE, thus completing the registration process of UE.
[0152] When a terminal device uses the credentials of a second network (also referred to as external credentials) to access a first network, the first network may be a network that supports external credentials, such as a standalone non-public network (SNPN). This means that, during the process of the terminal device accessing the first network, a second network different from the first network, such as a credentials holder (CH), performs the main authentication or security process of the terminal device.
[0153] Since different second networks may have different devices for executing the main authentication or security process of the terminal device, the devices in the first network that interact with the second network may also be different. In order to ensure that the second network can perform the authentication process on the terminal device, it is necessary to select the corresponding first network device according to the architecture of the second network, otherwise the first network will mistakenly regard it as an error case or abnormal case communication scenario, resulting in the terminal device being unable to be authenticated by the second network.
[0154] More specifically, when the second network is not deployed with a second authentication device, this solution also cannot enable the terminal device to be authenticated by the second network.
[0155] In view of the above technical problems, the present application provides a communication method, through which the present application can enable the terminal device to perform authentication.
[0156] The following will combine Figures 3 to 7 The communication method provided by this application is described.
[0157] To facilitate the description of the technical solution of the embodiment of the present application, the embodiment of the present application takes the first network as SNPN and the second network as CH or the default credential server as an example to describe the technical solution of the embodiment of the present application, but this description method cannot cause any limitation on the actual application scope of the technical solution of the embodiment of the present application.
[0158] It should be noted that in the embodiment of the present application, the mobile management device may correspond to AMF, or other similar devices for performing AMF functions, the first authentication device and the second authentication device may correspond to AUSF, or other similar devices for performing AUSF functions, and the embodiment of the present application does not make specific limitations.
[0159] Figure 3 is a schematic flow chart of a communication method provided by the present application. The specific contents of the method #300 are as follows Figure 3 shown.
[0160] S310, the mobile management device obtains first information of the terminal device, the first information includes a home network identifier and / or a routing indication of the terminal device, the first information indicates that the mobile management device selects a second authentication device of the second network, the credentials of the terminal device belong to the second network, and the second network has not deployed the second authentication device.
[0161] It should be understood that the home network identifier is used to identify the home network identifier of the terminal device or the subscriber or to identify the network or domain to which the terminal device belongs, for example, it can be a home network identifier (HNI). The HNI is used to select an authentication device or a unified data management device, or to indicate that the credentials of the terminal device belong to the second network, exemplarily, the credentials of the terminal device belong to the CH.
[0162] It should be understood that the routing indicator is used to select an authentication device or a unified data management device, and may be, for example, a routing indicator (RI).
[0163] As a possible implementation manner, the routing instruction may be combined with the home network identifier to route the network signaling to the authentication device or the unified data management device.
[0164] It should be understood that the credentials of the terminal device are used to identify the terminal device or verify, authorize or authenticate the terminal device, and may be, for example, credentials or a digital certificate.
[0165] The second authentication device is used to execute the security process of the terminal device. It should be understood that the security process includes but is not limited to: main authentication, main authentication, authentication, certification or authorization process. In other words, the second authentication device is mainly used for user authentication and authentication execution, that is, authentication between the UE and the operator network. After the second authentication device receives the authentication request initiated by the contracted user, it can authenticate and / or authorize the contracted user through the authentication information and / or authorization information stored in the unified data management, or generate the authentication and / or authorization information of the contracted user through the unified data management. For example, the second authentication device can be an AUSF in the second network.
[0166] As a possible implementation, the first information refers to the HNI of the terminal device, or the first information refers to the RI of the terminal device, or the first information refers to the HNI and RI of the terminal device, which may be determined according to the specific situation and is not specifically limited in the embodiment of the present application. Optionally, the first information may also include other information.
[0167] As a possible implementation manner, the first information may refer to a subscription concealed identifier (SUCI) or a subscription permanent identifier (SUPI) sent by the terminal device to the access network device, where the SUCI or SUPI includes the HNI and / or RI of the terminal device.
[0168] The specific form of the first information may be various, not limited to "the home network identifier and / or routing indication of the terminal device, the first information instructs the mobile management device to select the second authentication device of the second network". For example: as a possible implementation method, the first information may indicate that the terminal device belongs to the second network, or, indicate that the credentials of the terminal device belong to the second network, or, indicate the second network. When discovering and selecting an authentication device, the mobile management device may learn that it needs to discover and select the second authentication device of the second network based on the first information.
[0169] As a possible implementation, the home network identifier may be a home network identifier or domain name information included in the SUCI or subscription permanent identifier (SUPI) of the terminal device; for example, when the SUPI type of the terminal device is an international mobile subscriber identity (IMSI), the home network identifier includes a mobile country code (MCC) and a mobile network code (MNC); when the SUPI type is a network specific identifier (NSI), the format of the SUPI is a network access identifier (NAI) format, for example, the format of the SUPI is username@realm; wherein the realm part is the domain name information. At this time, the home network identifier indicates the domain name information, for example, it may be a character string. The domain name information corresponds to the realm part in the SUPI in the NAI format. That is, as a possible implementation, the home network identifier is the realm part in the SUPI in the NAI format. As a possible implementation, the realm part may include one or more of the MCC, the MNC or the network identifier (NID). It should be understood that the domain name information is the domain name information of the second network to which the terminal device belongs, or it can be understood that the domain name information indicates the second network to which the terminal device belongs.
[0170] It should be understood that the mobile management device obtains the first information of the terminal device in the following way: the terminal device sends a registration request message to the access network device, and the registration request message includes the first information; then, the access network device forwards the registration request message from the terminal device to the mobile management device, and the registration request message includes the first information. It should be understood that the registration request message is used to indicate that the terminal device requests to access the first network.
[0171] It should be understood that the first information is used to instruct the mobile management device to select the second authentication device of the second network.
[0172] In a possible implementation manner, the home network identifier of the first information indicates the second network, so it can instruct the mobility management device of the first network to select the second authentication device of the second network.
[0173] It should be understood that the credentials of the terminal device belong to the second network, which can be understood as: the credentials of the terminal device are granted or allocated by the second network, or the credentials of the terminal device come from the second network, or the second network performs authentication on the terminal device.
[0174] In one possible implementation, the first information includes a home network identifier and / or a routing indication of the terminal device, and the home network identifier and / or the routing indication indicates the second network, so that the mobile management device of the first network can know that the credentials of the terminal device belong to the second network.
[0175] It should also be understood that the second network does not deploy the second authentication device. It can be understood that the second network corresponds to an architecture of the CH described above, which deploys an AAA server but does not deploy a second authentication device (or, does not deploy an AUSF). Alternatively, it can also be understood that the second network uses an AAA server to perform authentication on the terminal device instead of using an AUSF to perform authentication on the terminal device.
[0176] S320: The mobility management device selects a first authentication device according to the first information, and the first authentication device and the mobility management device belong to the first network.
[0177] Specifically, after obtaining the first information, the mobile management device determines the second network based on the HNI and / or RI of the terminal device included in the first information. However, since the second network does not deploy the second authentication device, the mobile management device will select the first authentication device, and the first authentication device and the mobile management device belong to the first network.
[0178] It should be understood that the second network may be the CH mentioned above, or other networks. The first network may be the SNPN mentioned above, or other networks.
[0179] Through the above technical solution, when the second network has not deployed the second authentication device, the mobile management device of the first network will select the first authentication device of the first network. The first authentication device is used to execute or participate in the authentication process of the terminal device. For example, the first authentication device can derive, forward or send extensible authentication protocol (EAP) information for the key, thereby completing the access or registration process of the terminal device to access or register the first network.
[0180] It should be understood that the first authentication device participating in the authentication process of the terminal device can also be understood as: the first authentication device participating in a part of the authentication process of the terminal device, but not the whole process.
[0181] As a possible implementation manner, the mobility management device does not find the second authentication device according to the first information.
[0182] As a possible implementation, the mobile management device obtains configuration information or configuration policy information, and the configuration information or configuration policy information indicates that when the mobile management device does not find the second authentication device according to the first information, the first authentication device is selected. When the second network has deployed the second authentication device or when the second network uses the second authentication device to perform the authentication process, the mobile management device should select the second authentication device of the second network according to the first information to perform the authentication process of the terminal device. The mobile management device selects the first authentication device according to the first information when the second authentication device is not found.
[0183] As a possible implementation, the configuration information or configuration policy may be pre-configured in the mobile management device, or the mobile management device may obtain the configuration information or configuration policy from a control plane device. The control plane device may include a policy control device, a unified data management device, a user database device, an application function device, a network open device, or a network storage device.
[0184] As a possible implementation method, when the mobile management device does not find the second authentication device based on the first information, it can be learned that the second network uses the AAA server to perform the authentication process, or it can be learned that the second network does not use the second authentication device to perform authentication. Therefore, the mobile management device will select the first authentication device of the first network to execute the authentication process of the terminal device (or trigger the authentication process of the terminal device).
[0185] Specifically, after obtaining the first information of the terminal device, the mobile management device determines the second network to which the credentials of the terminal device belong based on the HNI and / or RI of the terminal device included in the first information, and searches for the second authentication device of the second network. However, since the second network has not deployed the second authentication device, or the second network has not used the second authentication device to perform the authentication process, or the second network uses the AAA server to perform the authentication process, the mobile management device does not find the second authentication device of the second network based on the first information.
[0186] As a possible implementation manner, the mobility management device selects the first authentication device according to the first information, including:
[0187] S320#a1, the mobility management device also obtains indication information from the terminal device, where the indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials.
[0188] Specifically, the mobile management device can also learn, based on the indication information from the terminal device, that the first network is a network that supports external credentials and / or that the terminal device uses external credentials. When the mobile management device does not find the second authentication device based on the first information, it can be learned that the second network has not deployed the second authentication device, or that the second network uses the AAA server to perform authentication, or that the second network does not use the second authentication device to perform authentication. At this time, the mobile management device will select the first authentication device to execute the authentication process of the terminal device (or trigger the authentication process of the terminal device) to avoid mistaking the registration behavior of the terminal device as an error case or an abnormal case, and denying the access or registration of the terminal device.
[0189] S320#b1, the mobile management device selects the first authentication device based on the indication information.
[0190] Specifically, the terminal device may also send indication information to the mobility management device, where the indication information indicates that the terminal device adopts the external credential or the first network supports the external credential.
[0191] It should be understood that the terminal device uses external credentials, which can be understood as the credentials of the terminal device coming from the second network, that is, the credentials of the terminal device are not from the first network, or, it can also be understood as the security process of the terminal device is executed by a device outside the first network. It should be understood that the security process includes but is not limited to: primary authentication, primary authentication, authentication, certification or authorization process. Among them, the device outside the first network can be understood as a device or server on a network different from the first network. Therefore, when the mobile management device does not find the second authentication device according to the first information, when it determines based on the indication information that the terminal device uses external credentials and / or the first network supports external credentials, the first authentication device will be selected, and the first authentication device will participate in the authentication process of the terminal device.
[0192] As a possible implementation manner, the mobility management device selects the first authentication device according to the first information, including:
[0193] S320#a2, the mobile management device sends a request message to the network storage device, where the request message is used to request to discover a second authentication device, and the request message includes the first information.
[0194] S320#b2, the mobile management device obtains response information from the network storage device, where the response information is used to indicate that the second authentication device is not found, and / or the response information includes identification information and / or address information of the first authentication device.
[0195] S320#c2, the mobile management device selects the first authentication device based on the response information.
[0196] Optionally, the request information also includes first indication information, where the first indication information is used to indicate that the first network supports external credentials and / or the terminal device adopts external credentials.
[0197] Specifically, after obtaining the first information of the terminal device, the mobile management device sends a request message to the network storage device, and the request message is used to request the discovery of the second authentication device of the second network. The request message may be Nnrf_NFDiscovery_Request, and the request message includes the first information and the network function type. The network function type is used to indicate the network function type that the mobile management device needs the network storage device to discover. For example, when the network function type indicates an authentication device or an authentication function, the mobile management device requests the network storage device to discover the authentication device of the second network (or, requests the discovery of AUSF).
[0198] After obtaining the request information from the mobile management device, the network storage device will send a response message to the mobile management device. The response information may include a feedback that the second authentication device was not found, and may also include the identification information and / or address information of the first authentication device. Alternatively, the response information may also include the information that the second authentication device was not found and the identification information and / or address information of the first authentication device.
[0199] As a possible implementation method, the network storage device learns that the second authentication device to be discovered belongs to the second network based on the HNI and / or RI of the terminal device included in the first information, and sends the response information to the mobile management device if the second authentication device is not found.
[0200] Optionally, the network storage device learns based on the request information that the mobile management device needs to discover a second authentication device, and learns based on the HNI and / or RI of the terminal device included in the first information that the second authentication device to be discovered belongs to the second network. From this, it can also be inferred or learned that the credentials of the terminal device belong to the second network. If the second authentication device is not found, the response information is sent to the mobile management device.
[0201] Optionally, the network storage device learns based on the request information that the mobile management device needs to discover a second authentication device, and learns based on the HNI and / or RI of the terminal device included in the first information that the second authentication device to be discovered belongs to the second network, thereby also being able to infer or learn that the credentials of the terminal device belong to the second network; when the request information also includes the first indication information sent by the mobile management device, the network storage device can also infer or learn that the second network has no second authentication device deployed, or that the second network uses an AAA server to perform terminal device authentication, or that the second network does not use the second authentication device to perform terminal device authentication, and the NRF can select the first authentication device of the first network and send the response information to the mobile management device.
[0202] After acquiring the response information from the network storage device, the mobile management device selects the first authentication device based on the response information.
[0203] As a possible implementation manner, the mobility management device selects the first authentication device according to the first information, including:
[0204] S320#a3, the mobility management device also obtains a network identifier from the access network device, where the network identifier indicates that the first network is a non-public network.
[0205] S320#b3, the mobile management device selects a first authentication device based on the first network identifier and the first information.
[0206] Specifically, the mobile management device obtains a network identifier from the access network device, exemplarily, the network identifier is a network identification code (NID), and the NID indicates that the first network is an SNPN. When the mobile management device cannot find the second authentication device of the second network according to the HNI and / or RI of the terminal device, the mobile management device selects the first authentication device of the first network.
[0207] Specifically, since the NID indicates that the first network to which the mobile management device belongs is SNPN, and the HNI and / or RI of the terminal device indicates that the second network to which the terminal device's credentials belong is a network other than SNPN, the mobile management device can infer or determine that the terminal device uses external credentials or determine that the first network supports external credentials. Therefore, when the mobile management device finds that the second network indicated by the HNI and / or RI does not deploy the second authentication device, the mobile management device can determine that the second network does not deploy the second authentication device, or the second network does not use the second authentication device to execute the main authentication or security process of the terminal device, or the second network uses the AAA Server to execute the main authentication or security process of the terminal device, so the mobile management device will select the first authentication device of the first network.
[0208] As a possible implementation manner, the mobility management device selects the first authentication device according to the first information, including:
[0209] S320#a4, the mobile management device selects the first authentication device based on the configuration information.
[0210] It should be understood that the mobile management device can select the first authentication device based on the configuration information, and the configuration information includes one or more HNIs and / or RIs. Exemplarily, the one or more HNIs and / or RIs included in the configuration information are used to indicate one or more networks other than the first network that use the AAA server to perform authentication. Therefore, when the HNI and / or RI of the terminal device obtained by the mobile management device belongs to or matches one or more HNIs and / or RIs in the configuration information, the mobile management device selects the first authentication device of the first network based on the configuration information.
[0211] More specifically, when the HNI and / or RI of the terminal device belongs to or matches the one or more HNIs and / or RIs, the mobility management device selects the first authentication device of the first network.
[0212] As a possible implementation method, the configuration information can be pre-configured in the mobile management device, or the mobile management device can obtain the configuration information from the control plane device; the control plane device may include a policy control device, a unified data management device, a user database device, an application function device, a network open device or a network storage device.
[0213] Through the above technical solution, the present application can achieve that, when the terminal device uses external credentials and the second network uses an AAA server to perform authentication, the mobile management device of the first network will select the first authentication device of the first network, and will not send a registration rejection message to the terminal device when the second authentication device of the second network cannot be found, causing the terminal device to be unable to register or access the first network, thereby allowing the terminal device to successfully register or access the first network.
[0214] More specifically, when the UE uses external credentials to access the first network, and the CH uses the AAA Server to perform authentication, if the mobile management device of the first network uses the above-mentioned registration method to perform the selection of the second authentication device, it will appear that the second authentication device cannot be discovered through the network storage device. Since the HNI and / or RI in the SUCI of the UE indicates the second network, and the second network uses the AAA Server to perform authentication instead of the second authentication device (for example, when the second network deploys the AAA server to perform authentication but does not deploy the second authentication device to perform authentication), the network storage device does not have the second authentication device information about the second network, or the network storage device of the first network cannot discover the second authentication device of the second network through the network storage device of the second network. Therefore, the mobile management device of the first network cannot discover and select the second authentication device through the HNI of the SUCI of the UE. At this time, the network storage device will send feedback information such as query failure (failure) or no discovery (404 not found) to the mobile management device of the first network. After receiving the feedback information, the mobile management device of the first network will send a registration request rejection message to the UE, resulting in the UE being unable to register with the first network.
[0215] Therefore, through the above technical solution, when the mobile management device of the first network does not find the second authentication device of the second network, it will select the first authentication device of the first network, so that the terminal device can successfully register or access the first network, avoiding treating the normal registration behavior of the terminal device as an error case and denying the terminal device access or registration.
[0216] It should be understood that the above Figure 3 The overall process of a communication method provided by an embodiment of the present application is described below. Figures 4 to 7The application of a communication method provided in an embodiment of the present application in a specific application scenario is further described.
[0217] Figure 4 is a schematic flow chart of another communication method provided by the present application. The specific contents of the method #400 are as follows Figure 4 shown.
[0218] S401-S402 are the same as S310-S320 and will not be described in detail here.
[0219] S403: The mobility management device sends authentication request information to the first authentication device.
[0220] It should be understood that after the mobile management device sends the authentication request information to the first authentication device, the authentication / security process is initiated.
[0221] S404: The first authentication device sends authentication acquisition request information to the unified data management device.
[0222] Specifically, the first authentication device sends authentication acquisition request information (eg, Nudm_UEAU_Get Request) of the terminal device to the unified data management device, where the request information includes the SUCI of the terminal device.
[0223] The unified data management device obtains the SUPI of the terminal device according to the SUCI (for example, obtains the SUPI after decrypting the SUCI), and then the data management device queries the authentication method applicable to the SUPI. The unified data management device determines to use an external entity to perform the primary authentication according to the contract data or the realm part (that is, it can be understood as the domain name part) in the SUPI in the network access identifier (NAI) format.
[0224] A possible implementation method is that when the unified data management device cannot obtain the contract data of the terminal device (for example, the terminal device is not a terminal device for performing external authentication, and may be a terminal device of a network other than the first network, and the network has not signed a roaming agreement with the first network, so the mobile management device in the first network cannot discover the second authentication device of the second network to which the terminal device belongs), the unified data management device can also determine that the terminal device has failed to perform authentication; or when the unified data management device learns that the terminal device does not perform external authentication or that the second network corresponding to the terminal device does not use an AAA server to perform authentication, the unified data management device can also determine that the terminal device has failed to perform authentication.
[0225] S405: The unified data management device sends authentication acquisition response information to the first authentication device.
[0226] Specifically, if the unified data management device can obtain SUPI according to SUCI, the unified data management device sends authentication acquisition response information (e.g., Nudm_UEAU_Get Response) of the terminal device to the first authentication device, where the information includes SUPI and indicates that the first authentication device is external authentication, that is, an external entity (or external CH) is used to perform primary authentication. If the unified data management device cannot obtain SUPI according to SUCI or the unified data management device learns that the UE cannot be successfully authenticated, the unified data management device indicates to the first authentication device that the UE fails to perform authentication.
[0227] S406: The first authentication device sends AAA interoperability authentication request information to the authentication authorization device.
[0228] Specifically, if the unified data management device sends the SUPI of the terminal device or the realm part in the SUPI (i.e., domain name information) and the indication information to the first authentication device, the first authentication device selects an authentication authorization device (for example, NSSAAF) according to the indication information of the unified data management device, and sends AAA interoperability authentication request information (for example, Nnssaaf_AAA interworking_Authentication Request) to the authentication authorization device, which includes the SUPI of the terminal device or the realm part in the SUPI (i.e., domain name information).
[0229] S407: The authentication and authorization device sends EAP request information to the AAA server.
[0230] Specifically, if the authentication and authorization device receives the SUPI of the terminal device in step S406, the authentication and authorization device selects an AAA server based on the domain name information corresponding to the realm part in the SUPI of the terminal device, and sends EAP request information (e.g., EAP request) to the AAA server. If the authentication and authorization device receives the realm part (i.e., domain name information) in the SUPI of the terminal device in step S406, the authentication and authorization device selects an AAA server based on the domain name information corresponding to the realm part.
[0231] S408: The AAA Server executes the EAP authentication process.
[0232] It should be understood that the process involves a terminal device, a mobility management device, a first authentication device, an authentication authorization device and an AAA server.
[0233] Optionally, the EAP authentication process can be understood as performing EAP authentication between the terminal device and the AAA server, with the AAA server acting as the EAP server and the terminal device acting as the EAP client; the mobile management device, the first authentication device, and the authentication authorization device are used to forward EAP information between the terminal device and the AAA server.
[0234] S409: The AAA server sends an EAP response message to the authentication authorization device.
[0235] When the authentication of the terminal device succeeds, the AAA server sends EAP response information (eg, EAP-response) to the authentication authorization device. The response information includes EAP success information (EAP success) and a master session key (MSK).
[0236] S410: The authentication authorization device sends AAA interoperability authentication response information to the first authentication device.
[0237] It should be understood that the AAA interworking authentication response information (eg, Nnssaaf_AAA interworking_Authentication Responset) includes EAP success and MSK.
[0238] S411: The first authentication device derives a key.
[0239] Specifically, the first authentication device derives the key according to the MSK.
[0240] S412: The first authentication device sends authentication response information to the mobility management device.
[0241] It should be understood that the response information may be Nausf_UEAU_Authenticate Response, which includes EAP success information, a derived key and SUPI.
[0242] If in step S405, the first authentication device receives authentication failure information from the unified data management device, the first authentication device skips steps S406 to S411 and directly sends authentication failure information to the mobile management device.
[0243] S413, the mobility management device sends EAP success information to the terminal device.
[0244] It should be understood that the EAP success information may be sent via non-access stratum (NAS) information.
[0245] It should be understood that the NAS information includes EAP success information.
[0246] It should be understood that if in step S412, the mobility management device receives authentication failure information sent by the first authentication device, the mobility management device may not send the EAP success information, and may also send authentication failure information or registration rejection information to the terminal device.
[0247] S414, the mobile management device sends feedback information to the terminal device.
[0248] Specifically, if the UE authentication succeeds, the mobility management device sends a registration acceptance message to the UE; if the UE authentication fails, the mobility management device sends a registration rejection message to the UE.
[0249] It should be understood that step S413 and step S414 may be sent via the same message or via different messages.
[0250] Through the above technical solution, when the mobile management device of the first network does not find the second authentication device of the second network, it will select the first authentication device of the first network, so that the terminal device can successfully register or access the first network, avoiding treating the normal registration behavior of the terminal device as an error case and denying the access or registration of the terminal device.
[0251] Figure 5 is a schematic flow chart of another communication method provided by the present application. The specific contents of the method #500 are as follows Figure 5 shown.
[0252] S510 is the same as the aforementioned step S310 and will not be described in detail here.
[0253] S520, the mobile management device sends a request message to the network storage device, the request message includes the HNI and / or RI of the terminal device, the request message is used to request to discover the second authentication device of the second network, the credentials of the terminal device belong to the second network, and the second network has not deployed the second authentication device.
[0254] Correspondingly, the network storage device receives the request information from the mobile management device.
[0255] As a possible implementation manner, the request information further includes first indication information, where the first indication information is used to indicate that the first network supports external credentials and / or the terminal device adopts external credentials.
[0256] Specifically, after the mobile management device obtains the first information of the terminal device, it sends a request message to the network storage device, and the request message is used to request the discovery of the second authentication device of the second network. The request message may be Nnrf_NFDiscovery_Request, and the request message includes the HNI and / or RI of the terminal device, and the network function type. The network function type is used to indicate the network function type that the mobile management device needs the network storage device to discover. For example, when the network function type indicates an authentication device, the request message indicates a second authentication device for requesting the discovery of the second network.
[0257] S530: The network storage device sends response information to the mobile management device, where the response information includes an indication that the second authentication device is not found, and / or the response information includes identification information and / or address information of the first authentication device.
[0258] It should be understood that the first authentication device, the network storage device and the mobile management device belong to the first network.
[0259] It should be understood that after obtaining the request information from the mobile management device, the network storage device will send a response message to the mobile management device. The response information may include information that the second authentication device is not found, and may also include information carrying the identification information and / or address information of the first authentication device, or the response information may also include information that the identification information and / or address information of the second authentication device and the first authentication device are not found.
[0260] As a possible implementation manner, before the network storage device sends the response information to the mobile management device, the network storage device does not find the second authentication device.
[0261] Specifically, the network storage device determines that the second authentication device to be discovered belongs to the second network according to the HNI and / or RI, and sends a response message to the mobile management device if the second authentication device of the second network is not discovered. Then, after obtaining the response message from the network storage device, the mobile management device selects the first authentication device based on the response message.
[0262] As a possible implementation manner, the network storage device sends a response message to the mobile management device, including:
[0263] When the HNI and / or RI of the terminal device matches the configuration information, a response message is sent, where the configuration information includes one or more HNIs and / or RIs.
[0264] Exemplarily, the one or more HNIs and / or RIs included in the configuration information are used to indicate one or more networks other than the first network that use the AAA server to perform authentication or do not use the second authentication device to perform authentication. Therefore, when the HNI and / or RI of the terminal device obtained by the mobile management device belongs to or matches one or more HNIs and / or RIs in the configuration information, the network storage device sends a response message based on the configuration information.
[0265] More specifically, when the home network identifier and / or routing indication of the terminal device belongs to or matches the one or more home network identifiers and / or routing indications, the network storage device sends response information to the mobility management device based on the configuration information.
[0266] As a possible implementation, the configuration information can be pre-configured in the network storage device, or the network storage device can obtain the configuration information from the control plane device. The control plane device includes a mobile management device, a policy control device, a unified data management device, a user database device, a network open device or an application function device.
[0267] As a possible implementation manner, the network storage device sends a response message to the mobile management device, including:
[0268] The network storage device sends response information according to the first indication information.
[0269] Specifically, the network storage device determines, based on the first indication information, that the first network to which the mobile management device belongs is SNPN, or determines that the terminal device uses external credentials, or determines that the second authentication device requested to be discovered by the mobile management device is used to perform external authentication. When the network storage device does not find or cannot find the second authentication device of the second network corresponding to the HNI and / or RI of the terminal device, the network storage device sends the response information to the mobile management device.
[0270] As a possible implementation manner, the network storage device sends a response message to the mobile management device, including:
[0271] The network storage device does not find the second authentication device and sends a response message.
[0272] Specifically, when the network storage device does not find or cannot find the second authentication device of the second network corresponding to the HNI and / or RI of the terminal device, the network storage device sends the response information to the mobility management device.
[0273] Through the above technical solution, when the mobile management device of the first network does not find the second authentication device of the second network, it will select the first authentication device of the first network, so that the terminal device can successfully register or access the first network, avoiding treating the normal registration behavior of the terminal device as an error case and denying the access or registration of the terminal device.
[0274] It should be understood that the above Figure 5 Describes the overall process of another communication method provided by an embodiment of the present application. Figure 6 Embodiments of this application Figure 5 The application of the provided communication method in a specific application scenario is described.
[0275] Figure 6 is a schematic flow chart of another communication method provided by the present application. The specific contents of the method #600 are as follows Figure 6 shown.
[0276] S601-S603 are the same as the aforementioned steps S510-530 and will not be repeated here.
[0277] S604: The mobile management device selects a first authentication device.
[0278] Specifically, after the mobile management device obtains the first information of the terminal device, it sends a request message to the network storage device, and the request message is used to request the discovery of the second authentication device of the second network. The request message may be Nnrf_NFDiscovery_Request, which includes the first information and the network function type. The network function type is used to indicate the type of network function that the mobile management device needs the network storage device to discover. For example, when the network function type indicates the authentication device, the mobile management device requests the network storage device to discover the authentication device of the second network (or, requests the discovery of AUSF).
[0279] After the network storage device obtains the request information from the mobile management device, it sends a response message to the mobile management device. The response information may include information that the second authentication device is not found, and may also include identification information and / or address information of the first authentication device. Alternatively, the response information may also include information that the second authentication device is not found and identification information and / or address information of the first authentication device.
[0280] As a possible implementation method, the network storage device learns that the second authentication device to be discovered belongs to the second network based on the HNI and / or RI of the terminal device included in the first information, and sends the response information to the mobile management device if the second authentication device is not found.
[0281] Optionally, the network storage device learns based on the request information that the mobile management device needs to discover a second authentication device, and learns based on the HNI and / or RI of the terminal device included in the first information that the second authentication device to be discovered belongs to the second network. From this, it can also be inferred or learned that the credentials of the terminal device belong to the second network. If the second authentication device is not found, the response information is sent to the mobile management device.
[0282] Optionally, the network storage device learns from the request information that the mobile management device needs to discover a second authentication device, and based on the HNI and / or RI of the terminal device included in the first information, or the second authentication device that needs to be discovered belongs to the second network, it can also infer or learn that the credentials of the terminal device belong to the second network; when the request information also includes the first indication information sent by the mobile management device, the network storage device can also infer or learn that the second network has no second authentication device deployed, or the second network does not use the second authentication device to perform terminal device authentication, or the second network uses an AAA server to perform terminal device authentication, and the network storage device can select the first authentication device of the first network and send the response information to the mobile management device.
[0283] After the mobile management device obtains the response information from the network storage device, the mobile management device selects the first authentication device based on the response information.
[0284] S605-616 are the same as the aforementioned steps S403-S414 and will not be repeated here.
[0285] Through the above technical solution, the present application can realize that when the terminal device uses external credentials and the second network does not deploy a second authentication device, or the second network does not use the second authentication device to perform terminal device authentication, or the second network uses an AAA server to perform terminal device authentication, the network storage device enables the mobile management device to select the first authentication device of the first network, and does not send a failure or error indication message to the mobile management device because the second authentication device of the second network is not found or cannot be found, causing the mobile management device to send a registration rejection message to the terminal device, making the terminal device unable to register or access the first network.
[0286] Figure 7 is a schematic flow chart of yet another communication method provided by the present application. The specific contents of the method #700 are as follows Figure 7 shown.
[0287] S701, the terminal device sends a registration request message to the access network device.
[0288] The registration request information includes access network (AN) parameters and NAS registration request information. The AN parameters include an onboarding indication. The registration type indicated in the NAS registration request information is SNPN onboarding.
[0289] S702: The access network device selects a mobility management device.
[0290] Specifically, the access network device selects a mobility management device that supports the online signing function according to the online signing indication.
[0291] S703: The access network device sends a registration request message to the mobility management device.
[0292] Specifically, after the access network device selects a mobility management device based on the online subscription indication information, the access network device forwards the NAS registration request information to the selected mobility management device.
[0293] S704: The mobility management device sends authentication request information to the third authentication device.
[0294] It should be understood that the third authentication device may be similar to the aforementioned first authentication device, may correspond to AUSF, or may correspond to other similar devices for performing AUSF functions, and the embodiments of the present application do not make specific limitations.
[0295] Correspondingly, the third authentication device receives the authentication request information from the mobility management device.
[0296] Specifically, the mobile management device determines that the terminal device registers the SNPN for performing online signing according to the registration type in the NAS registration request information being an independent non-public network online signing (SNPN Onboarding) type. The mobile management device selects a suitable third authentication device according to the configuration information (or configuration data or configuration policy) of the online signing, and sends an authentication request message to the first authentication device, the message including the SUCI of the terminal device.
[0297] As a possible implementation, the configuration information is pre-configured in the mobility management device, or the configuration information is obtained by the mobility management device from a control plane device. The control plane device includes a policy control device, a unified data management device, a user database device, a network storage device, an application function device or a network open device.
[0298] It should be understood that the authentication request information also includes second information, and the second information is used to indicate that the terminal device is performing online signing, or the second information indicates that the terminal device performs registration for online signing.
[0299] As a possible implementation manner, the second information may be indication information or SUCI or SUPI of the terminal device.
[0300] As a possible implementation manner, the type of the SUCI or SUPI of the terminal device may indicate that the terminal device performs online signing or indicates that the terminal device is registered for online signing.
[0301] As a possible implementation method, the second information included in the authentication request information can be sent by the mobile management device to the third authentication device (or it can be understood that the second information comes from the mobile management device), or, is from the terminal device, which is used to instruct the terminal device to perform online signing or instruct the terminal device to perform registration for online signing.
[0302] As a possible implementation manner, when the second information is sent by the mobility management device or comes from the mobility management device, the second information may be generated by the mobility management device.
[0303] In a possible implementation manner, the request information is Nausf_UEAU_Authenticate Request.
[0304] S705: The third authentication device determines a fourth authentication device according to the second information.
[0305] Specifically, the third authentication device determines that the terminal device is to perform online signing based on the second information in the authentication request information sent by the mobility management device, and determines the fourth authentication device based on the second information.
[0306] The fourth authentication device is used to execute the security process of the terminal device. It should be understood that the security process includes but is not limited to: primary authentication, primary authentication, authentication, authentication or authorization process. As a possible implementation, the fourth authentication device can be used to perform EAP authentication. For example, the fourth authentication device acts as an EAP server to authenticate the EAP client.
[0307] As a possible implementation manner, when the second information is sent by or comes from the mobile management device, the second information may be indication information for indicating that the terminal device is performing online contract signing or indicating that the terminal device is performing registration for online contract signing.
[0308] As a possible implementation manner, when the second information comes from the terminal device, the second information may be the SUCI or SUPI of the terminal device.
[0309] Optionally, the domain name information (or realm part or home network identifier and / or routing indication) in the SUPI or SUCI of the terminal device indicates a default credential domain name, or indicates that the terminal device performs online signing, or indicates that the terminal device performs registration for online signing.
[0310] As a possible implementation manner, the third authentication device determines, based on the configuration information and the second information, that the terminal device is to perform online signing or determines that the terminal device performs registration for the purpose of online signing.
[0311] In a possible implementation, the configuration information includes one or more domain name information, and the one or more domain name information indicates one or more default credential domain names. When the second information belongs to or matches the configuration information, the second information can be used to indicate that the terminal device performs online signing or indicates that the terminal device performs registration for online signing.
[0312] It should be understood that the second information belonging to or matching the configuration information can be understood as the second information belonging to or matching the one or more domain name information.
[0313] As a possible implementation manner, the domain name information includes one or more of a home network identifier, a routing indication, an MCC, an MNC, and an NID.
[0314] As a possible implementation, the configuration information can be pre-configured in the third authentication device, or obtained by the third authentication device from a control plane device. The control plane device includes a mobile management device, a policy control device, a unified data management device, a user database device, an application function device, and a network opening device.
[0315] As a possible implementation manner, the third authentication device may also obtain the SUPI according to the SUCI of the terminal device.
[0316] It should be understood that the third authentication device acquiring the SUPI according to the SUCI may be understood as the third authentication device recovering the SUPI from the SUCI, or may be understood as the third authentication device decrypting the SUCI into the SUPI.
[0317] When the third authentication device skips selecting the unified data management device, the SUCI of the terminal device cannot be decrypted or restored to SUPI by the unified data management device. However, in the registration process of the terminal device, the signaling interaction between the core network devices (or control plane devices) usually needs to include the identification information of the terminal device, which is usually SUPI. Therefore, when the third authentication device learns that the terminal device performs online signing or learns that the terminal device performs registration for online signing, it can obtain or restore SUPI based on SUCI to ensure that the signaling interaction between the core network devices (or control plane devices) is not affected.
[0318] As a possible implementation, the fourth authentication device includes a network slice and an independent non-public network authentication authorization device and a default credentials server (DCS).
[0319] Optionally, the DCS is an authentication, authorization and accounting server.
[0320] When the fourth authentication device is a network slice and non-public network authentication authorization device, the method includes the following steps:
[0321] S706: The third authentication device sends AAA interoperability authentication request information to the fourth authentication device.
[0322] It should be understood that the third authentication device determines the fourth authentication device according to the second information.
[0323] Specifically, after determining that the terminal device is to perform online signing, the third authentication device determines a fourth authentication device according to the second information, and the fourth authentication device is used to perform the authentication process of the terminal device.
[0324] As a possible implementation manner, the first authentication device skips selecting the unified data management device.
[0325] Specifically, the third authentication device learns from the second information that the terminal device is performing online signing, or learns that the terminal device performs registration for online signing, and the third authentication device does not need to select a unified data management device or skips selecting a unified data management device.
[0326] It should be understood that if the network slice and the non-public network authentication and authorization device interact with the DCS, the third authentication device sends authentication request information to the network slice and the non-public network authentication and authorization device, and the information includes identification information of the terminal device, such as one or more of the SUCI, SUPI or EAP identification of the terminal device. If the identification information of the terminal device includes SUPI, the first authentication device may also obtain SUPI according to the SUCI of the terminal device before sending the request information to the network slice and the non-public network authentication and authorization device.
[0327] It should be understood that the third authentication device acquiring the SUPI according to the SUCI may be understood as the third authentication device recovering the SUPI from the SUCI, or may be understood as the third authentication device decrypting the SUCI into the SUPI.
[0328] It should be understood that if the identification information of the terminal device includes an EAP identifier, the third authentication device may also send domain name information to the network slice and the non-public independent network authentication authorization device. The domain name information may come from the realm part (which may be understood as the home network identifier or HNI) in the SUCI or SUPI of the terminal device, so that the network slice and the non-public network authentication authorization device may know which domain or network the DCS needs to interact with.
[0329] S707, the network slice and non-public network authentication and authorization device send EAP request information to DCS.
[0330] As a possible implementation method, the network slice and the non-public network authentication and authorization device select the DCS according to the domain name information sent by the third authentication device. The network slice and the non-public network authentication and authorization device send an EAP request message (EAP request) to the DCS, which includes an EAP start (EAP start) and an EAP identity (EAP identity).
[0331] S708: DCS executes the EAP authentication process.
[0332] It should be understood that the process involves interaction between the terminal device, the mobile management device, the third authentication device, the network slice and the non-public network authentication authorization device and the DCS.
[0333] Optionally, the network slice and non-public network authentication and authorization device forward EAP information.
[0334] S709, DCS sends EAP response information (EAPresponse) to the network slice and non-public network authentication and authorization device.
[0335] After the terminal device is successfully authenticated, the DCS sends EAP response information (e.g., EAP-response) to the network slice and the non-public network authentication authorization device, and the response information includes EAP success information (EAP success).
[0336] Optionally, the response information may also include a master session key (MSK).
[0337] S710, the network slice and non-public network authentication authorization device sends AAA interoperability authentication response information to the third authentication device.
[0338] It should be understood that the AAA interoperability authentication response information includes EAP success information.
[0339] Optionally, the AAA interoperability authentication response information may also include MSK.
[0340] Optionally, in S711, a third authentication device performs key derivation.
[0341] Specifically, when the third authentication device receives the MSK, the third authentication device derives the key according to the MSK.
[0342] S712: The third authentication device sends authentication response information to the mobility management device.
[0343] It should be understood that the response information includes EAP success and UE identification information (the identification information may be SUCI or SUPI).
[0344] Optionally, the response information may also include a derived key.
[0345] As a possible implementation manner, the response information is Nausf_UEAU_Authenticate Response.
[0346] S713, the mobility management device sends EAP success information to the terminal device.
[0347] As a possible implementation manner, the EAP success information is sent via NAS information.
[0348] It should be understood that the NAS information includes EAP success information.
[0349] S714, the mobile management device sends feedback information to the terminal device.
[0350] Specifically, if the UE authentication succeeds, the mobility management device sends a registration acceptance message to the UE; if the UE authentication fails, the mobility management device sends a registration rejection message to the UE.
[0351] It should be understood that the above technical solution is for when the fourth authentication device is a network slice and a non-public network authentication authorization device. When the fourth authentication device is a DCS, the method includes the following:
[0352] S706#a, the third authentication device sends EAP request information to the DCS.
[0353] Specifically, if the fourth authentication device is a DCS, the third authentication device sends EAP request information (eg, EAPRequest) to the DCS, where the request information includes an EAP start and an EAP identifier.
[0354] S707#a, DCS executes the EAP authentication process.
[0355] It should be understood that this process involves the interaction between the terminal device, the mobility management device, the third authentication device and the DCS.
[0356] S708#a, DCS sends EAP response information to the third authentication device.
[0357] Specifically, the DCS sends an EAP response message (EAP response) to the authentication authorization device, and the information includes EAP success.
[0358] Optionally, the information may also include MSK.
[0359] Optionally, in S709#a, a third authentication device performs key derivation.
[0360] Specifically, when the third authentication device receives the MSK, the third authentication device derives the key according to the MSK.
[0361] S710#a, the third authentication device sends authentication response information to the mobility management device.
[0362] It should be understood that the response information includes EAP success and UE identification information (the identification information may be SUCI or SUPI).
[0363] Optionally, the response information may also include a derived key.
[0364] As a possible implementation manner, the response information is Nausf_UEAU_Authenticate Response.
[0365] S711#a, the mobile management device sends EAP success information to the terminal device.
[0366] As a possible implementation manner, the EAP success information is sent via NAS information.
[0367] It should be understood that the NAS information includes EAP success information.
[0368] S712#a, the mobile management device sends feedback information to the terminal device.
[0369] Specifically, if the UE authentication succeeds, the mobility management device sends a registration acceptance message to the UE; if the UE authentication fails, the mobility management device sends a registration rejection message to the UE.
[0370] When the present application learns through the third authentication device that the terminal device is for executing an online contract or that the terminal device is registered for an online contract, a fourth authentication device is selected, and the fourth authentication device executes the authentication process of the terminal device, thereby achieving successful access of the terminal device to the network, and avoiding the situation where, after selecting a unified data management device and interacting with the unified data management device, the unified data management device cannot execute authentication or causes error cases or abnormal cases because the unified data management device does not have the contract data about the terminal device, resulting in the terminal device being unable to access the network.
[0371] It should be understood that the information in the embodiments of the present application can also be understood as messages, for example, EAP request information can be understood as EAP request message, response information can be understood as response message, NAS information can be understood as NAS message, and so on.
[0372] Figure 8 800 is a schematic block diagram of a communication device 800 provided in the present application. As shown in the figure, the communication device 800 may include: a transceiver unit 810 and a processing unit 820.
[0373] In one possible design, the communication device 800 may be the mobility management device in the above method embodiment, or may be a chip for implementing the functions of the mobility management device in the above method embodiment.
[0374] It should be understood that the communication device 800 may correspond to the mobile management device according to the embodiment of the present application, and the communication device 800 may include a method for executing Figures 3 to 7 Furthermore, each unit in the communication device 800 and the above-mentioned other operations and / or functions are respectively for implementing Figures 3 to 7 The corresponding process in .
[0375] As an exemplary description, the communication device 800 can implement the actions, steps or methods related to the mobile management device in S310, S320, S330 and S340 in the aforementioned method embodiments, and can also implement the actions, steps or methods related to the mobile management device in S510, S520, S530 in the aforementioned method embodiments.
[0376] It should be understood that the above content is only understood as an example, and the communication device 800 can also implement other steps, actions or methods related to the mobile management device in the above method embodiment, which will not be repeated here.
[0377] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0378] In another possible design, the communication device 800 may be the network storage device in the above method embodiment, or may be a chip for implementing the functions of the network storage device in the above method embodiment.
[0379] It should be understood that the communication device 800 may correspond to a network storage device according to an embodiment of the present application, and the communication device 800 may include a device for executing Figures 3 to 8 Furthermore, each unit in the communication device 800 and the above-mentioned other operations and / or functions are respectively for implementing Figures 3 to 7 It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0380] It should be understood that the above content is only understood as an example, and the communication device 800 can also implement other steps, actions or methods related to the network storage device in the above method embodiment, which will not be repeated here.
[0381] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0382] It should be understood that the above content is only understood as an example, and the communication device 800 can also implement other steps, actions or methods related to the first authentication device in the above method embodiment, which will not be repeated here.
[0383] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0384] It should be understood that the above content is only understood as an example, and the communication device 800 can also implement other steps, actions or methods related to the second authentication device in the above method embodiment, which will not be repeated here.
[0385] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0386] It should be understood that the above content is only understood as an example, and the communication device 800 can also implement other steps, actions or methods related to the third authentication device in the above method embodiment, which will not be repeated here.
[0387] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0388] It should be understood that the above content is only understood as an example, and the communication device 800 can also implement other steps, actions or methods related to the fourth authentication device in the above method embodiment, which will not be repeated here.
[0389] It should be understood that the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0390] It should also be understood that the transceiver unit 810 in the communication device 800 may correspond to Fig. 9 The transceiver 920 in the communication device 900 shown in FIG. 8 may correspond to the processing unit 820 in the communication device 800. Fig. 9 The processor 910 in the communication device 900 is shown in FIG.
[0391] It should also be understood that when the communication device 800 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface; the processing unit may be a processor or a microprocessor or an integrated circuit integrated on the chip.
[0392] The transceiver unit 810 is used to implement the signal transceiver operation of the communication device 800, and the processing unit 820 is used to implement the signal processing operation of the communication device 800.
[0393] Optionally, the communication device 800 further includes a storage unit 830, and the storage unit 830 is used to store instructions.
[0394] Fig. 9 is a schematic block diagram of a communication device 900 provided in an embodiment of the present application. As shown in the figure, the communication device 900 includes: at least one processor 910 and a transceiver 920. The processor 910 is coupled to a memory and is used to execute instructions stored in the memory to control the transceiver 920 to send signals and / or receive signals. Optionally, the communication device 900 also includes a memory 930 for storing instructions.
[0395] It should be understood that the processor 910 and the memory 930 may be combined into one processing device, and the processor 910 is used to execute the program code stored in the memory 930 to implement the above functions. In specific implementation, the memory 930 may also be integrated into the processor 910 or independent of the processor 910.
[0396] It should also be understood that the transceiver 920 may include a receiver (or receiver) and a transmitter (or transmitter). The transceiver 920 may further include an antenna, and the number of antennas may be one or more. The transceiver 920 may also be a communication interface or an interface circuit.
[0397] When the communication device 900 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input / output circuit or a communication interface; the processing unit may be a processor or a microprocessor or an integrated circuit integrated on the chip. The embodiment of the present application also provides a processing device including a processor and an interface. The processor may be used to execute the method in the above method embodiment.
[0398] It should be understood that the above-mentioned processing device can be a chip. For example, the processing device can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD) or other integrated chips.
[0399] In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in a processor or an instruction in the form of software. The steps of the method disclosed in conjunction with the embodiment of the present application can be directly embodied as a hardware processor for execution, or a combination of hardware and software modules in a processor for execution. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it is not described in detail here.
[0400] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the method executed by the mobile management device in the above method embodiment are stored.
[0401] For example, when the computer program is executed by a computer, the computer can implement the method performed by the mobile management device in the above method embodiment.
[0402] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the method executed by the network storage device in the above method embodiment are stored.
[0403] For example, when the computer program is executed by a computer, the computer can implement the method performed by the network storage device in the above method embodiment.
[0404] The embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the method executed by the first authentication device in the above method embodiment are stored.
[0405] For example, when the computer program is executed by a computer, the computer can implement the method performed by the first authentication device in the above method embodiment.
[0406] The embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the method executed by the second authentication device in the above method embodiment are stored.
[0407] For example, when the computer program is executed by a computer, the computer can implement the method performed by the second authentication device in the above method embodiment.
[0408] The embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the method executed by the third authentication device in the above method embodiment are stored.
[0409] For example, when the computer program is executed by a computer, the computer can implement the method performed by the third authentication device in the above method embodiment.
[0410] The embodiment of the present application also provides a computer-readable storage medium on which computer instructions for implementing the method executed by the fourth authentication device in the above method embodiment are stored.
[0411] For example, when the computer program is executed by a computer, the computer can implement the method performed by the fourth authentication device in the above method embodiment.
[0412] An embodiment of the present application also provides a computer program product comprising instructions, which, when executed by a computer, enables the computer to implement the method executed by the mobile management device in the above method embodiment, or the method executed by the network storage device, or the method executed by the first authentication device, or the method executed by the second authentication device, or the method executed by the third authentication device, or the method executed by the fourth authentication device.
[0413] An embodiment of the present application provides a communication system, including a mobile management device, which is used to execute the method executed by the mobile management device, and a network storage device, which is used to execute the method executed by the network storage device.
[0414] An embodiment of the present application provides a communication system, including a mobile management device, which is used to execute the method aforementioned executed by the mobile management device, and a network storage device, which is used to execute the method aforementioned executed by the network storage device, and a third authentication device, which is used to execute the method aforementioned executed by the third authentication device.
[0415] Those skilled in the art can clearly understand that, for the sake of convenience and brevity of description, the explanation of the relevant contents and beneficial effects in any of the communication devices provided above can refer to the corresponding method embodiments provided above, and will not be repeated here.
[0416] The embodiments of the present application do not specifically limit the specific structure of the execution subject of the method provided in the embodiments of the present application, as long as it is possible to communicate according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application. For example, the execution subject of the method provided in the embodiments of the present application may be a terminal device or a network device, or a functional module in the terminal device or the network device that can call and execute a program.
[0417] Various aspects or features of the present application may be implemented as a method, apparatus, or article of manufacture using standard programming and / or engineering techniques. The term "article of manufacture" as used herein may encompass a computer program accessible from any computer-readable device, carrier, or media.
[0418] The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more available media. Available media (or computer-readable media) may include, but are not limited to: magnetic media or magnetic storage devices (e.g., floppy disks, hard disks (such as mobile hard disks), magnetic tapes), optical media (e.g., optical disks, compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards and flash memory devices (e.g., erasable programmable read-only memory (EPROM), cards, sticks or key drives, etc.), or semiconductor media (e.g., solid state disks (SSDs), etc.), USB flash drives, read-only memories (ROMs), random access memories (RAMs), and other media that can store program codes.
[0419] The various storage media described herein may represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing and / or carrying instructions and / or data.
[0420] It should be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM may include the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus random access memory (DR RAM).
[0421] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated into the processor.
[0422] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0423] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the above units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0424] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to implement the solution provided by this application.
[0425] In addition, each functional unit in each embodiment of the present application may be integrated into one unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0426] In the above embodiments, all or part of them may be implemented by software, hardware, firmware or any combination thereof.
[0427] When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When loading and executing computer program instructions on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instruction can be stored in a computer-readable storage medium, or transmitted from a computer-readable storage medium to another computer-readable storage medium, for example, the computer instruction can be transmitted from a website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. About computer-readable storage medium, it can be referred to the above description.
[0428] It should be understood that in the embodiments of the present application, the numbers "first", "second"... are only for distinguishing different objects, such as distinguishing different network devices, and do not constitute a limitation on the scope of the embodiments of the present application. The embodiments of the present application are not limited to this.
[0429] It should also be understood that in the present application, "when", "if" and "if" all mean that the network element will take corresponding actions under certain objective circumstances, and do not limit the time, nor do they require the network element to have a judgment action when implementing it, nor do they mean that there are other limitations.
[0430] It should also be understood that in each embodiment of the present application, "A corresponds to B" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information.
[0431] It should also be understood that the term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0432] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A communication method, characterized in that: include: The mobile management device obtains first information of the terminal device, the first information includes a home network identifier and / or a routing indication of the terminal device, the first information indicates that the mobile management device selects a second authentication device of a second network, the credential of the terminal device belongs to the second network, and the second network is not deployed with the second authentication device; The mobile management device selects a first authentication device according to the first information, and the first authentication device and the mobile management device belong to a first network.
2. The method according to claim 1, characterized in that The method further comprises: The mobile management device does not find the second authentication device according to the first information.
3. The method according to claim 1 or 2, characterized in that: The mobile management device selects a first authentication device according to the first information, including: The mobility management device further acquires indication information from the terminal device, the indication information indicating that the first network supports external credentials and / or the terminal device adopts external credentials; The mobile management device selects the first authentication device based on the indication information.
4. The method according to claim 1 or 2, characterized in that: The mobile management device selects a first authentication device according to the first information, including: The mobile management device sends a request message to the network storage device, where the request message is used to request to discover the second authentication device, and the request message includes the first information; The mobile management device obtains response information from the network storage device, where the response information is used to indicate that the second authentication device is not found, and / or the response information includes identification information and / or address information of the first authentication device; The mobile management device selects the first authentication device based on the response information.
5. The method according to claim 4, characterized in that The request information further includes first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device uses external credentials.
6. The method according to claim 1 or 2, characterized in that: The mobile management device selects a first authentication device according to the first information, including: The mobility management device further acquires a network identifier from an access network device, where the network identifier indicates that the first network is a non-public network; The mobile management device selects the first authentication device based on the network identifier and the first information.
7. The method according to claim 1 or 2, characterized in that: The mobile management device selects a first authentication device according to the first information, including: The mobile management device selects the first authentication device based on the configuration information, The configuration information includes one or more home network identifiers and / or routing instructions.
8. The method according to claim 7, characterized in that The mobile management device selects the first authentication device based on the configuration information, including: When the home network identifier and / or routing indication of the terminal device matches the one or more home network identifiers and / or routing indications, the mobility management device selects the first authentication device.
9. The method according to claim 1 or 2, characterized in that: The first network is an independent non-public network SNPN, and the first authentication device and the second authentication device are authentication service functions AUSF.
10. A communication method, characterized in that: include: The network storage device receives request information from the mobile management device, the request information including the home network identifier and / or routing indication of the terminal device, the request information being used to request discovery of a second authentication device of a second network, the credentials of the terminal device belonging to the second network, and the second network not deploying the second authentication device; The network storage device sends a response message to the mobile management device, the response message includes an indication that the second authentication device is not found, and / or the response message includes identification information and / or address information of the first authentication device, The first authentication device, the network storage device and the mobile management device belong to a first network.
11. The method according to claim 10, characterized in that The request information further includes first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device uses external credentials.
12. The method according to claim 10 or 11, characterized in that: Before the network storage device sends the response information to the mobile management device, the method further includes: The network storage function network element did not find the second authentication device.
13. The method according to claim 10, characterized in that The network storage device sends response information to the mobile management device, including: When the home network identifier and / or routing indication of the terminal device matches the configuration information, sending the response information, the configuration information including one or more home network identifiers and / or routing indications; or, The network storage device sends the response information according to first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device uses external credentials; or The network storage device does not find the second authentication device and sends the response information.
14. The method according to claim 10 or 11, characterized in that: The first network is an independent non-public network SNPN, and the first authentication device and the second authentication device are authentication service functions AUSF.
15. A communication device, characterized in that: include: a transceiver unit, configured to obtain first information of a terminal device, the first information including a home network identifier and / or a routing indication of the terminal device, the first information instructing a mobility management device to select a second authentication device of a second network, the credentials of the terminal device are from the second network, and the second network is not deployed with the second authentication device; The processing unit is configured to select a first authentication device according to the first information, wherein the first authentication device and the mobility management device belong to a first network.
16. The communication device according to claim 15, characterized in that The processing unit is further configured to: detect, based on the first information, that the second authentication device is not found.
17. The communication device according to claim 15 or 16, characterized in that: The transceiver unit is further configured to obtain indication information from the terminal device, wherein the indication information indicates that the first network supports external credentials and / or the terminal device uses external credentials; The processing unit is used to select the first authentication device based on the indication information.
18. The communication device according to claim 15 or 16, characterized in that: The transceiver unit is used to send a request message to the network storage device, wherein the request message is used to request to discover the second authentication device, and the request message includes the first information; The transceiver unit is used to obtain response information from the network storage device, the response information is used to indicate that the second authentication device is not found, and / or the response information includes identification information and / or address information of the first authentication device; The processing unit is configured to select the first authentication device based on the response information.
19. The communication device according to claim 18, characterized in that The request information further includes first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device uses external credentials.
20. The communication device according to claim 15 or 16, characterized in that: The transceiver unit is further used to obtain a network identifier from an access network device, where the network identifier indicates that the first network is a non-public network; The processing unit is configured to select the first authentication device based on the network identifier and the first information.
21. The communication device according to claim 15 or 16, characterized in that: The processing unit is configured to select the first authentication device based on the configuration information, The configuration information includes one or more home network identifiers and / or routing instructions.
22. The communication device according to claim 21, characterized in that When the home network identifier and / or routing indication of the terminal device matches the one or more home network identifiers and / or routing indications, the processing unit is configured to select the first authentication device.
23. The communication device according to claim 15 or 16, characterized in that: The first network is an independent non-public network SNPN, and the first authentication device and the second authentication device are authentication service functions AUSF.
24. A communication device, characterized in that: include: a transceiver unit, configured to obtain request information from a mobile management device, the request information including a home network identifier and / or a routing indication of a terminal device, the request information being used to request discovery of a second authentication device of a second network, the credentials of the terminal device being from the second network, and the second network not deploying the second authentication device; a processing unit, configured to send a response message to the mobility management device, the response message including an indication that the second authentication device is not found, and / or the response message including identification information and / or address information of the first authentication device, The first authentication device, the network storage device and the mobile management device belong to a first network.
25. The communication device according to claim 24, characterized in that The request information further includes first indication information, where the first indication information indicates that the first network supports external credentials and / or the terminal device uses external credentials.
26. The communication device according to claim 24 or 25, characterized in that: The processing unit is configured to detect that the second authentication device is not found.
27. The communication device according to claim 24, characterized in that When the home network identifier and / or routing indication of the terminal device matches the configuration information, the transceiver unit is used to send the response information, and the configuration information includes one or more home network identifiers and / or routing indications; or, The transceiver unit is configured to send the response information according to first indication information, wherein the first indication information indicates that the first network supports external credentials and / or the terminal device adopts external credentials; or, The transceiver unit is used to send the response information when the second authentication device is not found.
28. The communication device according to claim 24 or 25, characterized in that: The first network is an independent non-public network SNPN, and the first authentication device and the second authentication device are authentication service functions AUSF.
29. A computer-readable storage medium, characterized in that: A computer program or instruction is stored, wherein the computer program or instruction is used to implement the method according to any one of claims 1 to 9, or the computer program or instruction is used to implement the method according to any one of claims 10 to 14.
30. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 9, or the computer is enabled to execute the method according to any one of claims 10 to 14.
Citation Information
Patent Citations
Communication method and communication device
CN115843027A
Cited By
Communication method and communication device
EP4727187A2