Communication method and communication device
By selecting the authentication device of the first network through the mobile management device, the problem of inconsistent authentication when the terminal device accesses the network that supports external credentials is solved, and successful registration and access are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2021-09-19
- Publication Date
- 2026-04-24
AI Technical Summary
When a terminal device accesses a network that supports external credentials, existing technologies may lead to errors or abnormal communication scenarios due to inconsistencies in the authentication devices of different networks, resulting in access failure.
By obtaining terminal device information through mobile management devices, selecting the authentication device of the first network, and avoiding sending registration rejection information due to the inability to find the authentication device of the second network, the terminal device can successfully access the first network.
This ensures that terminal devices avoid registration failures during the access process, improving the access success rate and reducing the occurrence of abnormal cases.
Smart Images

Figure CN115843027B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention application filed on September 19, 2021, with Chinese application number 202111101555.1 and entitled "Communication Method and Communication Device". Technical Field
[0002] This application relates to the field of communication technology, and more specifically, to a communication method and a communication device. Background Technology
[0003] When a terminal device uses credentials from a second network (also known as external credentials) to access a first network, the first network can be a network that supports external credentials, such as a standalone non-public network (SNPN). This means that during the process of the terminal device accessing the first network, a network different from the first network, such as a credential holder (CH), performs the terminal device's primary authentication or security procedures.
[0004] Because the devices performing authentication or security procedures on different terminal devices in the second network can be different, the devices interacting with the second network in the first network will also be different. Therefore, communication scenarios with error cases or abnormal cases frequently occur.
[0005] Therefore, there is an urgent need for a communication method that enables terminal devices to perform authentication. Summary of the Invention
[0006] This application provides a communication method and a communication device that enable terminal devices to perform authentication.
[0007] In a first aspect, a communication method is provided, comprising: a mobility management device acquiring first information of a terminal device, the first information including a home network identifier and / or routing indication of the terminal device, the first information instructing the mobility management device to select a second authentication device of a second network, the credentials of the terminal device belonging to the second network, and the second network not deploying the second authentication device; the mobility management device selecting a first authentication device based on the first information, the first authentication device belonging to the first network as well as the mobility management device.
[0008] Through the above technical solution, this application can achieve the following: when the terminal device uses the credentials of the second network and the second network uses an authentication, authorization, and billing server to perform authentication, the mobility management device of the first network will select the first authentication device of the first network, and will not send a registration rejection message to the terminal device because it cannot find the second authentication device of the second network, thus preventing the terminal device from being unable to register or access the first network, thereby enabling the terminal device to successfully register or access the first network.
[0009] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the mobility management device, based on the first information, does not detect the second authentication device.
[0010] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: the mobility management device selecting a first authentication device according to configuration information, wherein the configuration information instructs the mobility management device to select the first authentication device when no second authentication device is found according to the first information.
[0011] In conjunction with the first aspect, in some implementations of the first aspect, the mobility management device selects a first authentication device based on the first information, including: the mobility management device further obtaining indication information from the terminal device, the indication information indicating that the first network supports external credentials and / or the terminal device uses external credentials; the mobility management device selects the first authentication device based on the indication information.
[0012] By sending instruction information from the terminal device to the mobility management device of the first network, which instructs the first network to support external credentials or instructs the terminal device to use external credentials, the mobility management device of the first network can select the first authentication device of the first network when no second authentication device of the second network is found, thereby completing the access or registration process of the terminal device to the first network.
[0013] In conjunction with the first aspect, in certain implementations of the first aspect, the mobility management device selects a first authentication device based on the first information, comprising: the mobility management device sending request information to a network storage device, the request information being used to request the discovery of a second authentication device, the request information including the first information; the mobility management device obtaining response information from the network storage device, the response information being used to indicate that no second authentication device has been discovered, and / or, the response information including the identification information and / or address information of the first authentication device; and the mobility management device selecting the first authentication device based on the response information.
[0014] By sending a request message from the mobile management device of the first network to the network storage device, requesting the network storage device to discover the second authentication device of the second network, and selecting the first authentication device based on the response information returned by the network storage device, the mobile management device of the first network can select the first authentication device of the first network when it does not discover the second authentication device of the second network, thereby completing the access or registration process of the terminal device to the first network.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, the request information further includes first instruction information, which instructs the first network to support external credentials and / or the terminal device to use external credentials.
[0016] This instruction information helps the network storage device of the first network determine whether the first network supports external credentials or whether the terminal device uses external credentials. Therefore, when the second authentication device of the second network cannot be found, it reports the identity information and / or address information of the first authentication device to the mobility management device. This helps the mobility management device of the first network to select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0017] In conjunction with the first aspect, in some implementations of the first aspect, the mobility management device selects a first authentication device based on the first information, including: the mobility management device further obtaining a network identifier from an access network device, the network identifier indicating that the first network is a non-public network; the mobility management device selects the first authentication device based on the first network identifier and the first information.
[0018] Specifically, the mobility management device of the first network determines that the first network is a non-public network based on the network identifier, and determines that the terminal device's credentials belong to the second network based on the first information. Thus, the mobility management device of the first network determines that the first network supports external credentials or determines that the terminal device uses external credentials.
[0019] By sending the network identifier to the mobility management device, the mobility management device of the first network can determine whether the first network supports external credentials or whether the terminal device uses external credentials. Therefore, if a second authentication device of the second network cannot be found, the mobility management device of the first network will select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0020] In conjunction with the first aspect, in some implementations of the first aspect, the mobility management device selects a first authentication device based on the first information, including: the mobility management device selects a first authentication device based on configuration information, wherein the configuration information includes one or more home network identifiers and / or routing indications.
[0021] In conjunction with the first aspect, in some implementations of the first aspect, the mobility management device selects a first authentication device based on configuration information, including: when the home network identifier and / or routing indication of the terminal device matches one or more home network identifiers and / or routing indications, the mobility management device selects the first authentication device.
[0022] When the home network identifier and / or routing indication of the terminal device match the configuration information of the mobility management device of the first network, the mobility management device of the first network will select the first authentication device of the first network, thereby helping to complete the access or registration process of the terminal device to the first network.
[0023] In conjunction with the first aspect, in some implementations of the first aspect, the configuration information is pre-configured in the mobility management device, or the mobility management device obtains it from a control plane device, which includes a policy control device, a unified data management device, a user database device, an application function device, a network access device, or a network storage device.
[0024] In conjunction with the first aspect, in some implementations of the first aspect, the first authentication device is an authentication service function device.
[0025] In conjunction with the first aspect, in some implementations of the first aspect, the second authentication device is an authentication service function device.
[0026] Secondly, a communication method is provided, comprising: a network storage device receiving request information from a mobility management device, the request information including a home network identifier and / or routing indication of a terminal device, the request information being used to request the discovery of a second authentication device in a second network, the terminal device's credentials belonging to the second network, and the second network not deploying a second authentication device; the network storage device sending response information to the mobility management device, the response information including an indication that no second authentication device was found, and / or, the response information including the identifier information and / or address information of a first authentication device, wherein the first authentication device, the network storage device, and the mobility management device belong to a first network.
[0027] Through the above technical solution, this application can achieve the following: when the terminal device uses the credentials of the second network and the second network uses an authentication, authorization, and billing server to perform authentication, the mobility management device of the first network will select the first authentication device of the first network, and will not send a registration rejection message to the terminal device because it cannot find the second authentication device of the second network, thus preventing the terminal device from being unable to register or access the first network, thereby enabling the terminal device to successfully register or access the first network.
[0028] In conjunction with the second aspect, in some implementations of the second aspect, the request information further includes first instruction information, which instructs the first network to support external credentials and / or the terminal device to use external credentials.
[0029] This instruction information helps the network storage device of the first network determine whether the first network supports external credentials or whether the terminal device uses external credentials. Therefore, when the second authentication device of the second network cannot be found, it reports the identity information and / or address information of the first authentication device to the mobility management device. This helps the mobility management device of the first network to select the first authentication device of the first network, thereby completing the access or registration process of the terminal device to the first network.
[0030] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes: before the network storage device sends response information to the mobility management device, the network storage function element does not discover a second authentication device.
[0031] In conjunction with the second aspect, in some implementations of the second aspect, the network storage device sends response information to the mobility management device, including: determining to send response information when the home network identifier and / or routing indication of the terminal device matches the configuration information, wherein the configuration information includes one or more home network identifiers and / or routing indications; or, the network storage device determines to send response information based on first indication information; or, the network storage device determines to send the response information if it does not find a second authentication device.
[0032] In conjunction with the second aspect, in some implementations of the second aspect, the configuration information is pre-configured in the network storage device, or the network storage device obtains it from a control plane device, which includes a mobility management device, a unified data management device, a policy control device, a user database device, a network access device, or an application function device.
[0033] The various schemes described above help the network storage device of the first network to send response information to the mobility management device of the first network when it does not find the second authentication device of the second network. This helps the mobility management device of the first network to select the first authentication device of the first network, thereby facilitating the completion of the access or registration process of the terminal device to the first network.
[0034] Thirdly, a communication method is provided, comprising: a third authentication device acquiring second information, the second information instructing a terminal device to perform an online signing; the third authentication device determining a fourth authentication device based on the second information, the fourth authentication device being used to execute the authentication process of the terminal device.
[0035] This application, through a third authentication device, learns that when a terminal device is performing online signing, it selects a network slice and a non-public network authentication and authorization device or interacts directly with the default credential server. This enables the terminal device to successfully access the network and perform online signing. It also avoids situations where, after selecting a data management device and interacting with it, the data management device lacks signing data for the terminal device, preventing authentication from being performed or causing error or abnormal cases, thus preventing the terminal device from accessing the network.
[0036] In conjunction with the third aspect, in some implementations of the third aspect, the second information is sent by the mobility management device; or, the second information is sent by the terminal device.
[0037] In conjunction with the third aspect, in some implementations of the third aspect, when the second information is sent by the terminal device, the second information is the user-hidden identifier of the terminal device.
[0038] By sending second information from the terminal device to the third authentication device, the third authentication device can learn that the terminal device is performing online signing. It can then choose to use a network slice and non-public network authentication and authorization device or interact directly with the default credential server. This enables the terminal device to successfully access the network and perform online signing. It also avoids situations where the terminal device cannot perform authentication or causes errors or anomalies due to the lack of signing data for the terminal device after selecting and interacting with the unified data management device.
[0039] In conjunction with the third aspect, in some implementations of the third aspect, the fourth authentication device includes one or more of the following devices: network slice and independent non-public network authentication and authorization devices, default credential server and authentication, authorization and accounting server.
[0040] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the third authentication device skips the selection of the unified data management device.
[0041] This application, through a third authentication device, learns that when a terminal device is performing online signing, it selects a network slice and a non-public network authentication and authorization device or interacts directly with the default credential server. This enables the terminal device to successfully access the network and perform online signing. It also avoids situations where, after selecting a unified data management device and interacting with it, the unified data management device lacks signing data for the terminal device, resulting in authentication failure or error cases, thus preventing the terminal device from accessing the network.
[0042] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the third authentication device obtaining the user permanent identifier of the terminal device based on the user hidden identifier of the terminal device.
[0043] When a third authentication device skips the selection of a unified data management device, the user-hidden identifier of the terminal device cannot be decrypted or restored to a permanent identifier by the unified data management device. However, during the registration process of the terminal device, signaling interactions between core network devices (or control plane devices) typically require the inclusion of the terminal device's identification information, which is usually a permanent identifier. Therefore, when the third authentication device learns that the terminal device is performing online signing or registering for online signing, it can obtain or restore the permanent identifier based on the user-hidden identifier, ensuring that signaling interactions between core network devices (or control plane devices) are not affected.
[0044] In conjunction with the third aspect, in some implementations of the third aspect, the method further includes: the third authentication device recovering the user permanent identifier of the terminal device from the user hidden identifier of the terminal device.
[0045] Fourthly, a communication device is provided, comprising: a transceiver unit, configured to acquire first information of a terminal device, the first information including a home network identifier and / or routing indication of the terminal device, the first information instructing a mobility management device to select a second authentication device of a second network, the credentials of the terminal device belonging to the second network, and the second network not deploying the second authentication device; and a processing unit, configured to select a first authentication device based on the first information, the first authentication device belonging to the first network as well as the mobility management device.
[0046] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the processing unit is also used to determine, based on the first information, that the second authentication device has not been detected.
[0047] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the processing unit is configured to select a first authentication device based on configuration information, wherein the configuration information instructs the mobility management device to select the first authentication device when no second authentication device is found based on the first information.
[0048] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the transceiver unit is further configured to obtain indication information from the terminal device, the indication information indicating that the first network supports external credentials and / or the terminal device uses external credentials; the processing unit is configured to select the first authentication device based on the indication information.
[0049] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the request information further includes first instruction information, which instructs the first network to support external credentials and / or the terminal device to use external credentials.
[0050] In conjunction with the fourth aspect, in some implementations of the fourth aspect, a transceiver unit is configured to send request information to a network storage device, the request information being used to request the discovery of a second authentication device, the request information including first information; the transceiver unit is configured to obtain response information from the network storage device, the response information being used to indicate that no second authentication device has been discovered, and / or, the response information including the identification information and / or address information of the first authentication device; and a processing unit is configured to select the first authentication device based on the response information.
[0051] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the transceiver unit is further configured to obtain a network identifier from the access network device, the network identifier indicating that the first network is a non-public network; the processing unit is configured to select a first authentication device based on the first network identifier and the first information.
[0052] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the processing unit is used to select a first authentication device based on configuration information, wherein the configuration information includes one or more home network identifiers and / or routing indications.
[0053] In conjunction with the fourth aspect, in some implementations of the fourth aspect, when the home network identifier and / or routing indication of the terminal device matches one or more home network identifiers and / or routing indications, the processing unit is used to select the first authentication device.
[0054] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the configuration information is pre-configured in the mobility management device or obtained by the mobility management device from a control plane device, which includes a policy control device, a unified data management device, a user database device, an application function device, a network access device, or a network storage device.
[0055] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the first authentication device is an authentication service function device.
[0056] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the second authentication device is an authentication service function device.
[0057] Fifthly, a communication device is provided, comprising: a transceiver unit, configured to acquire request information from a mobility management device, the request information including a home network identifier and / or routing indication of a terminal device, the request information being used to request the discovery of a second authentication device in a second network, the terminal device's credentials belonging to the second network, and the second network not deploying a second authentication device; and a processing unit, configured to send response information to the mobility management device, the response information including an indication that no second authentication device has been discovered, and / or, the response information including identification information and / or address information of a first authentication device, wherein the first authentication device, a network storage device, and the mobility management device belong to a first network.
[0058] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the request information includes first instruction information, which instructs the first network to support external credentials and / or the terminal device to use external credentials.
[0059] In conjunction with the fifth aspect, in some implementations of the fifth aspect, a processing unit is used to detect the absence of a second authentication device.
[0060] In conjunction with the fifth aspect, in some implementations of the fifth aspect, when the home network identifier and / or routing indication of the terminal device matches the configuration information, it is determined to send response information, the configuration information including one or more home network identifiers and / or routing indications; or, the processing unit is used to determine to send response information based on the first indication information; or, the processing unit is used to determine to send response information if no second authentication device is found.
[0061] In conjunction with the fifth aspect, in some implementations of the fifth aspect, the configuration information is pre-configured in the network storage device, or the network storage device obtains it from the control plane device, which includes a mobility management device, a unified data management device, a policy control device, a user database device, a network access device, or an application function device.
[0062] In a sixth aspect, a communication device is provided, comprising: a transceiver unit for acquiring second information, the second information instructing a terminal device to perform an online contract signing; and a processing unit for determining a fourth authentication device based on the second information, the fourth authentication device being used to execute the authentication process of the terminal device.
[0063] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the second information is sent by the mobile management device; or, the second information is sent by the terminal device.
[0064] In conjunction with the sixth aspect, in some implementations of the sixth aspect, when the second information is sent by the terminal device, the second information is the user-hidden identifier of the terminal device.
[0065] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the fourth authentication device includes one or more of the following devices: network slice and independent non-public network authentication and authorization devices, default credential server and authentication, authorization and accounting server.
[0066] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the processing unit is also used to skip the selection of a unified data management device.
[0067] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the processing unit is further configured to obtain the user permanent identifier of the terminal device based on the user hidden identifier of the terminal device.
[0068] In conjunction with the sixth aspect, in some implementations of the sixth aspect, the processing unit is also configured to recover the user permanent identifier of the terminal device from the user hidden identifier of the terminal device.
[0069] In a seventh aspect, a computer-readable storage medium is provided, storing a computer program or instructions for implementing the method described in the first aspect and any possible implementation thereof, or the method described in the second aspect and any possible implementation thereof; or the method described in any one of the third aspect and any possible implementation thereof.
[0070] Eighthly, a computer program product is provided, characterized in that, when the computer program product is run on a computer, the computer performs the method described in the first aspect and any possible implementation thereof, or the method described in the second aspect and any possible implementation thereof; or the method described in any one of the third aspect and any possible implementation thereof.
[0071] A ninth aspect provides a communication system, including a mobility management device for performing the first aspect and any possible implementation of the first aspect, and a network storage device for performing the second aspect and any possible implementation of the second aspect.
[0072] In a tenth aspect, a communication system is provided, comprising a mobility management device for performing the first aspect and any possible implementation of the first aspect, a network storage device for performing the second aspect and any possible implementation of the second aspect, and a third authentication device for performing the third aspect and any possible implementation of the third aspect. Attached Figure Description
[0073] Figure 1 This is a schematic diagram of a communication system.
[0074] Figure 2 This is a schematic flowchart of a communication method.
[0075] Figure 3 This is a schematic flowchart of a communication method provided in an embodiment of this application.
[0076] Figure 4 This is a schematic flowchart of another communication method provided in the embodiments of this application.
[0077] Figure 5This is a schematic flowchart of another communication method provided in the embodiments of this application.
[0078] Figure 6 This is a schematic flowchart illustrating another communication method provided in an embodiment of this application.
[0079] Figure 7 This is a schematic flowchart illustrating yet another communication method provided in the embodiments of this application.
[0080] Figure 8 This is a schematic block diagram of a communication device provided in an embodiment of this application.
[0081] Figure 9 This is a schematic block diagram of another communication device provided in the embodiments of this application. Detailed Implementation
[0082] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0083] The technical solutions of this application can be applied to various communication systems, such as: Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), General Packet Radio Service (GPRS), Long Term Evolution (LTE), LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX), 5th Generation (5G) systems or New Radio (NR), and other future communication systems.
[0084] In this application, the terminal device can refer to user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device. The terminal device can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal device in a 5G network, or terminal device in a public land mobile network (PLMN), etc. This application does not limit the scope of the terminal device to these specific types.
[0085] The network device in this application embodiment can be a device for communicating with terminal devices. The network device can be a base station (BTS) in a GSM or CDMA system, a base station (nodeB, NB) in a WCDMA system, an evolved NodeB (eNB or eNodeB) in an LTE system, or a radio controller in a cloud radio access network (CRAN) scenario. Alternatively, the network device can be a relay station, access point, vehicle-mounted device, wearable device, or a network device in a 5G network, a PLMN network, or a network device in a non-public network, etc. The embodiments of this application are not limited to these.
[0086] The technical solutions of the embodiments of this application will now be described with reference to the accompanying drawings.
[0087] Figure 1 This is a schematic diagram of a communication system. For example... Figure 1As shown, the network includes access and mobility management function (AMF), network exposure function (NEF), network repository function (NRF), unified data management (UDM), radio access network (RAN) equipment, policy control function (PCF), user equipment (UE), user plane function (UPF), data network (DN), authentication server function (AUSF), network slice selection function (NSSF), AAA server (authentication, authorization, and accounting server), and network slice-specific and SNPN authentication and authorization function (NSSAAF), etc.
[0088] It should be understood that Figure 1 This is merely an illustrative diagram, and the embodiments of this application do not limit the number and types of network elements (or devices) actually deployed in the network.
[0089] It should be noted that, in Figure 1In the diagram shown, the device enclosed by the dashed box belongs to the first network, while the device not selected by the dashed box belongs to the second network. The second network is different from the first network that the UE needs to access; it is used to perform security procedures for UEs accessing the first network. The first network can be a public land mobile network (PLMN) or a non-public network (NPN), such as an SNPN or a public network integrated non-public network (PNI-NPN); the second network can be a PLMN or an NPN. Since the UE's credentials belong to the second network, the second network can also be called the credential holder (CH).
[0090] in, Figure 1 The main functions of each device shown are described below:
[0091] UE: can be referred to as terminal equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user equipment.
[0092] Furthermore, the UE can also be a terminal device in an Internet of Things (IoT) system. IoT is an important component of future information technology development. Its main technical characteristic is connecting objects to networks via communication technologies, thereby achieving intelligent networks that enable human-machine and machine-to-machine interconnection. IoT technology can achieve massive connectivity, deep coverage, and low terminal power consumption through technologies such as narrowband (NB) technology.
[0093] In addition, the UE may also include sensors such as smart printers, train detectors, and gas stations. Its main functions include collecting data (for some terminal devices), receiving control information and downlink data from network devices, and sending electromagnetic waves to transmit uplink data to network devices.
[0094] It should be understood that a UE can be any device capable of accessing a network. The UE and the access network equipment can communicate with each other using some form of air interface technology.
[0095] Radio access network (RAN) equipment (also known as access network equipment) corresponds to different access networks in 5G, such as wired access, wireless base station access, and other methods. The RAN equipment in this application includes, but is not limited to: next-generation base stations (gnodeB, gNB), evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home-evolved nodeB, or home node B, HNB), base band unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc.
[0096] Unified data management (UDM) (also known as unified data management network element, unified data management entity, data management device, or unified data management equipment) is a type of core network equipment primarily used for handling terminal device identification, access authentication, registration, and mobility management. Unified data management equipment is a control plane device.
[0097] Policy control function (PCF) (also known as policy control network element, policy control function network element, policy control device, policy control function entity, etc.): It is mainly responsible for policy control functions such as billing at the session and service flow level, quality of service (QoS) bandwidth guarantee and mobility management, and UE policy decision-making.
[0098] Session management function (SMF): mainly performs functions such as session management, execution of control policies issued by PCF, selection of UPF, and allocation of UE IP address.
[0099] The access and mobility management function (AMF) (also known as access and mobility management function entity, access and mobility management equipment, access and mobility management network element, access management equipment, or mobility management equipment) is a type of core network equipment primarily used for mobility management and access management. It can implement functions of the mobility management entity (MME) other than session management, such as access authorization (or authentication), user equipment registration, mobility management, tracking area update procedures, reachability detection, selection of session management network elements, and mobility state transition management. For example, in 5G, the access and mobility management network element can be an access and mobility management function (AMF) network element. In future communications, such as 6G, the access and mobility management network element can still be an AMF network element, or it may have other names; this application does not limit this. When the access and mobility management network element is an AMF network element, the AMF can provide Namf services.
[0100] User plane function (UPF) (also known as user plane device, user plane function network element, user plane network element, user plane function entity): mainly includes the following functions: packet routing and transmission, packet inspection, service usage reporting, QoS processing, uplink packet inspection, downlink packet storage, and other user plane related functions.
[0101] The authentication server function (AUSF) (also referred to as the authentication server function network element, authentication server function entity, authentication service device, or authentication equipment) is primarily used for user authentication and to perform authentication, i.e., authentication between the UE and the operator's network. After receiving an authentication request from a subscribed user, the authentication server function network element can authenticate and / or authorize the subscribed user using the authentication and / or authorization information stored in the unified data management network element, or generate the subscribed user's authentication and / or authorization information through the unified data management network element. The authentication server function network element can then provide the authentication and / or authorization information back to the subscribed user. In one possible implementation, the authentication server function network element can also be co-located with the unified data management network element. In 5G communication systems, the authentication server function network element can be an authentication server function (AUSF) network element. In future communication systems, unified data management can still be an AUSF, or it can have other names; this application embodiment does not limit this.
[0102] Network repository function (NRF) (also known as network storage device, network repository function network element, or network repository function entity): Primarily used to support service discovery. It receives network element discovery requests from a network element function or service communication proxy (SCP) and can provide feedback on the request information. The NRF is also responsible for maintaining information on available network functions and the services they support. It can also be understood as a network storage device. The discovery process involves a requesting network function (NF) using the NRF to address a specific NF or service. The NRF provides the IP address, fully qualified domain name (FQDN), or unified resource identifier (URI) of the corresponding NF instance or NF service instance. Furthermore, the NRF can also facilitate cross-PLMN discovery by providing network identifiers (e.g., PLMNID). To achieve network element function addressing and discovery, each network element needs to register with the NRF; some network element functions can register with the NRF upon initial operation. The network repository function device can be a core network device.
[0103] Network exposure function (NEF) (also known as network exposure device, network exposure function entity, network exposure function network element, network capability exposure function entity, network capability exposure function device, network capability exposure function network element, network capability exposure device, etc.): It is mainly used to support the exposure of capabilities and events, such as to securely expose services and capabilities provided by 3GPP network functions to the outside world.
[0104] The user data repository (UDR) (also known as user database entity, user database network element, user database device, etc.) has different data access authentication mechanisms for different types of data, such as contract data and policy data, to ensure the security of data access.
[0105] An authentication, authorization, and accounting server (AAA server) (also known as an authentication and authorization server, authentication and authorization device, authentication device, authentication and authorization accounting device, etc.) is a server program that handles user access requests and provides authentication, authorization, and account services. AAA servers typically work in conjunction with network access control, gateway servers, databases, and user information directories. The network connection server interface that collaborates with the AAA server is the Remote Authentication Dial-In User Service (RADIUS).
[0106] The network slice-specific and SNPN authentication and authorization function is mainly used to support specific network slice authentication and authorization with AAA servers or AAA agents, and to support access to SNPN using credentials from a credential holder (CH) who uses the AAA server for authentication.
[0107] Among them, such as Figure 1 As shown, the terminal device accesses the network through the RAN device.
[0108] The terminal device communicates with the AMF through the N1 interface (N1 for short).
[0109] The RAN communicates with the AMF through the N2 interface (N2 for short).
[0110] The RAN communicates with the UPF through the N3 interface (N3 for short).
[0111] UPF communicates with UPF through the N9 interface (N9 for short).
[0112] UPF communicates with DN via the N6 interface (N6 for short).
[0113] also, Figure 1 The control plane functions shown, such as AMF, SMF, NEF, NRF, PCF, or UDM, can also be interacted with using service-oriented interfaces.
[0114] For example, the service interface provided by AMF can be Namf.
[0115] The service interface provided by NSSF can be Nnssf.
[0116] The service interface provided by UDM can be Nudm.
[0117] The service interface provided by NEF can be Nnef.
[0118] The service interface provided by NRF can be Nnrf.
[0119] The service interface provided by PCF can be Npcf.
[0120] The service interface provided by AF can be Naf.
[0121] The service interface provided by AUSF can be Nausf.
[0122] The service interface provided by NSSAAF can be Nnssaaf.
[0123] SMF provides Nsmf as its external service interface.
[0124] It should be understood that RAN, SMF, PCF or AF in the embodiments of this application may also be referred to as communication device or communication equipment. It may be a general device or a special device. This application does not make any specific limitation in this regard.
[0125] It should also be understood that the above naming is only for distinguishing different functions and does not mean that these devices are independent physical devices. This application does not limit the specific form of the above devices. For example, they can be integrated into the same physical device or they can be different physical devices. In actual deployment, network elements or devices can be co-located. For example, the access and mobility management network element can be co-located with the session management network element; the session management network element can be co-located with the user plane network element. When two network elements are co-located, the interaction between the two network elements provided in the embodiments of this application becomes the internal operation of the co-located network element or can be omitted.
[0126] It is understood that the above functions can be network elements in hardware devices, software functions running on dedicated hardware, a combination of hardware and software, or virtualization functions instantiated on a platform (e.g., a cloud platform).
[0127] It should be noted that, Figure 1 The names of the various devices (such as PCF, AMF, etc.) are merely names and do not limit the functionality of the devices themselves. In 5G networks and other future networks, the aforementioned devices may also have other names, and this application does not impose specific limitations on this. For example, in 6G networks, some or all of the aforementioned network elements may use the terminology from 5G, or they may have other names, etc. This is explained uniformly here and will not be elaborated further below.
[0128] It should be noted that the technical solutions of the embodiments of this application are applicable to 5G networks, as well as 4G, 6G networks, and future communication networks, etc.
[0129] To better describe the technical solutions of the embodiments of this application, the technical terms related to the technical solutions of the embodiments of this application will be described below.
[0130] First, NPN.
[0131] Depending on whether the core network (CN) is independent, NPN includes two types:
[0132] 1) SNPN. This network does not depend on the PLMN network and is operated by the SNPN operator.
[0133] 2) PNI-NPN. This network relies on the PLMN network and is operated by traditional operators. In other words, PNI-NPN is essentially equivalent to PLMN, except that PLMN provides special slices and / or data networks to provide NPN services. Furthermore, not all UEs can access these NPN services; only UEs that pass slice authentication and / or secondary authentication can access them.
[0134] Second, external authentication.
[0135] External authentication refers to a security procedure performed on the UE by a credential holder (CH) different from the first network before the UE accesses the first network. This security procedure may include primary authentication, authentication, and authorization processes. It should be understood that in this case, the UE uses external credentials (or external subscription) to access the first network.
[0136] The authentication gate (CH) includes an architecture that uses an AAA server to perform UE authentication. In this case, the core network equipment of the first network needs to interact with the CH's AAA server to complete the UE authentication process. One possible implementation involves the authentication and authorization equipment of the first network interacting with the CH's AAA server.
[0137] Figure 2 This is a schematic flowchart illustrating a communication method. Details are as follows: Figure 2 As shown.
[0138] S210, the RAN receives registration request information from the UE.
[0139] It should be understood that when a UE needs to register with the network, the UE sends registration request information, which includes the identification information of the terminal device. For example, the UE's identification information may include one or more of the following: globally unique temporary identity (GUTI), SUCI, and permanent equipment identifier (PEI).
[0140] S220, RAN performs AMF selection.
[0141] It should be understood that after receiving the registration request information from the UE, the RAN will select a suitable AMF and send the UE's registration request information to that AMF.
[0142] S230, AMF receives registration request information.
[0143] S240, AMF performs the selection of AUSF.
[0144] Specifically, the AMF selects an appropriate AUSF for authentication and other security processes.
[0145] S250 executes authentication or security procedures.
[0146] It should be understood that the execution of the above authentication or security process involves the interaction of UE, AMF, AUSF, and UDM.
[0147] S260, Obtain the UE's subscription data.
[0148] After the UE and the core network element successfully authenticate each other, the AMF can interact with the UDM to obtain the subscription data of the terminal device.
[0149] S270, AMF sends N2 information to RAN.
[0150] It should be understood that the N2 information sent by the AMF to the RAN includes non-access stratum (NAS) information, which includes registration acceptance information.
[0151] S280, the RAN sends a registration acceptance message to the UE.
[0152] After receiving the registration acceptance information from the AMF, the RAN forwards the registration acceptance information to the UE. Thus, the UE completes the registration process.
[0153] When a terminal device uses credentials from a second network (also known as external credentials) to access a first network, the first network can be a network that supports external credentials, such as a standalone non-public network (SNPN). This means that during the process of the terminal device accessing the first network, a second network different from the first network, such as a credentials holder (CH), performs the terminal device's primary authentication or security procedures.
[0154] Since different devices in the second network may perform the main authentication or security procedures for terminal devices, the devices in the first network that interact with the second network will also be different. In order to ensure that the second network can perform the authentication process for the terminal device, it is necessary to select the corresponding device in the first network according to the architecture of the second network. Otherwise, the first network may mistakenly identify it as an error case or an abnormal case communication scenario, causing the terminal device to fail to be authenticated by the second network.
[0155] More specifically, in scenarios where the second network does not deploy a second authentication device, this solution also fails to enable the terminal device to be authenticated by the second network.
[0156] In view of the above-mentioned technical problems, this application provides a communication method that enables terminal devices to perform authentication.
[0157] The following will combine Figures 3 to 7 The communication method provided in this application is described.
[0158] To facilitate the description of the technical solutions of the embodiments of this application, the embodiments of this application take SNPN as the first network and CH or default credential server as the second network as examples to describe the technical solutions of the embodiments of this application. However, this description method cannot limit the actual application scope of the technical solutions of the embodiments of this application.
[0159] It should be noted that, in the embodiments of this application, the mobility management device may correspond to AMF or other similar devices used to perform AMF functions, and the first authentication device and the second authentication device may correspond to AUSF or other similar devices used to perform AUSF functions. The embodiments of this application do not make specific limitations.
[0160] Figure 3 This is a schematic flowchart of a communication method provided in this application. The specific content of method #300 is as follows: Figure 3 As shown.
[0161] S310, the mobility management device obtains first information of the terminal device, the first information including the home network identifier and / or routing indication of the terminal device, the first information instructs the mobility management device to select the second authentication device of the second network, the credentials of the terminal device belong to the second network, and the second network has not deployed the second authentication device.
[0162] It should be understood that the home network identifier is used to identify the home network identifier of the terminal device or the subscribed user, or to identify the network or domain to which the terminal device belongs. For example, it can be the home network identifier (HNI). The HNI is used to select an authentication device or a unified data management device, or to indicate that the terminal device's credentials belong to a second network; for example, the terminal device's credentials belong to the CH (Central Access Center).
[0163] It should be understood that the routing indication is used to select an authentication device or a unified data management device, such as a routing indicator (RI).
[0164] As one possible implementation, the routing instruction can be combined with the home network identifier to route network signaling to the authentication device or the unified data management device.
[0165] It should be understood that the credentials of a terminal device are used to identify, verify, authorize, or authenticate the terminal device; for example, they may be credentials or digital certificates.
[0166] The second authentication device is used to execute the security procedures of the terminal device. This security procedure includes, but is not limited to, primary authentication, primary authorization, and authentication or authorization processes. In other words, the second authentication device is primarily used for user authentication and to perform authentication, i.e., authentication between the UE and the operator's network. After receiving an authentication request from a subscribed user, the second authentication device can authenticate and / or authorize the subscribed user using authentication and / or authorization information stored in the unified data management system, or generate the subscribed user's authentication and / or authorization information through the unified data management system. For example, the second authentication device could be an AUSF in a second network.
[0167] As one possible implementation, the first information refers to the HNI of the terminal device, or the RI of the terminal device, or both the HNI and RI of the terminal device. This can be specifically determined depending on the circumstances, and the embodiments of this application do not impose specific limitations. Optionally, the first information may also include other information.
[0168] As one possible implementation, the first information may refer to the subscription concealed identifier (SUCI) or subscription permanent identifier (SUPI) sent by the terminal device to the access network device, whereby the SUCI or SUPI includes the terminal device's HNI and / or RI.
[0169] The specific form of the first information can be varied, and is not limited to "the home network identifier and / or routing indication of the terminal device, wherein the first information instructs the mobility management device to select a second authentication device in the second network." For example, as a possible implementation, the first information could indicate that the terminal device belongs to the second network, or indicate that the terminal device's credentials belong to the second network, or indicate the second network. When discovering and selecting an authentication device, the mobility management device can obtain the information based on the first information to determine the need to discover and select a second authentication device in the second network.
[0170] As one possible implementation, the home network identifier can be the home network identifier or domain name information included in the terminal device's SUCI or Subscription Permanent Identifier (SUPI). For example, when the terminal device's SUPI type is International Mobile Subscriber Identity (IMSI), the home network identifier includes the Mobile Country Code (MCC) and the Mobile Network Code (MNC). When the SUPI type is Network Specific Identifier (NSI), the SUPI format is the Network Access Identifier (NAI) format, such as username@realm; where the realm part is the domain name information. In this case, the home network identifier indicates the domain name information, which can be, for example, a string. This domain name information corresponds to the realm part in the NAI-formatted SUPI. That is, as one possible implementation, the home network identifier is the realm part in the NAI-formatted SUPI. As one possible implementation, this realm part can include one or more of the MCC, MNC, or Network Identifier (NID). It should be understood that the domain name information is the domain name information of the second network to which the terminal device belongs, or it can be understood that the domain name information indicates the second network to which the terminal device belongs.
[0171] It should be understood that the mobility management device obtains the first information of the terminal device through the following means: the terminal device sends registration request information to the access network device, the registration request information including the first information; then, the access network device forwards the registration request information from the terminal device to the mobility management device, the registration request information including the first information. It should be understood that the registration request information is used to instruct the terminal device to request access to the first network.
[0172] It should be understood that the first information is used to instruct the mobility management device to select a second authentication device for the second network.
[0173] In one possible implementation, the home network identifier of the first information indicates the second network, thus enabling it to instruct the mobility management device of the first network to select the second authentication device of the second network.
[0174] It should be understood that the credentials of the terminal device belong to the second network, which can be understood as: the credentials of the terminal device are granted or distributed by the second network, or the credentials of the terminal device come from the second network, or the second network performs authentication on the terminal device.
[0175] In one possible implementation, the first information includes the home network identifier and / or routing indication of the terminal device, which indicates a second network, so that the mobility management device of the first network can know that the terminal device's credentials belong to the second network.
[0176] It should also be understood that the second network does not deploy a second authentication device. This can be interpreted as the second network corresponding to an architecture of the CH described above, which deploys an AAA server but does not deploy a second authentication device (or, in other words, does not deploy AUSF). Alternatively, it can be interpreted as the second network using an AAA server to perform authentication on terminal devices, rather than using AUSF to perform authentication on terminal devices.
[0177] S320, the mobility management device selects the first authentication device based on the first information, and the first authentication device and the mobility management device belong to the first network.
[0178] Specifically, after obtaining the first information, the mobility management device determines the second network based on the HNI and / or RI of the terminal device included in the first information. However, since the second network does not deploy a second authentication device, the mobility management device will select the first authentication device, which belongs to the first network along with the mobility management device.
[0179] It should be understood that the second network can be the CH mentioned above, or it can be other networks. The first network can be the SNPN mentioned above, or it can be other networks.
[0180] With the above technical solution, when the second network does not deploy the second authentication device, the mobility management device of the first network will select the first authentication device of the first network. The first authentication device is used to execute or participate in the authentication process of the terminal device. For example, the first authentication device can deduce, forward or send extensible authentication protocol (EAP) information to complete the access or registration process of the terminal device to the first network.
[0181] It should be understood that the participation of the first authentication device in the authentication process of the terminal device can also be understood as the first authentication device participating in part of the authentication process of the terminal device, not the entire process.
[0182] As one possible implementation, the mobile management device, based on the first information, does not detect a second authentication device.
[0183] As one possible implementation, the mobility management device obtains configuration information or configuration policy information that instructs the mobility management device to select the first authentication device when no second authentication device is found based on the first information. When the second network has a second authentication device deployed, or when the second network uses the second authentication device to perform the authentication process, the mobility management device should select the second authentication device of the second network based on the first information to perform the authentication process for the terminal device. The mobility management device selects the first authentication device based on the first information when no second authentication device is found.
[0184] In one possible implementation, the configuration information or configuration policy may be pre-configured in the mobility management device, or the mobility management device may obtain the configuration information or configuration policy from the control plane device. The control plane device may include a policy control device, a unified data management device, a user database device, an application function device, a network access device, or a network storage device.
[0185] As one possible implementation, if the mobility management device does not find a second authentication device based on the first information, it can know that the second network uses an AAA server to perform the authentication process, or it can know that the second network does not use a second authentication device to perform authentication. Therefore, the mobility management device will select the first authentication device of the first network to perform the authentication process of the terminal device (or trigger the authentication process of the terminal device).
[0186] Specifically, after obtaining the first information of the terminal device, the mobility management device determines the second network to which the terminal device's credentials belong based on the HNI and / or RI of the terminal device included in the first information, and searches for the second authentication device of the second network. However, since the second network has not deployed the second authentication device, or the second network has not used the second authentication device to perform the authentication process, or the second network uses an AAA server to perform the authentication process, the mobility management device does not find the second authentication device of the second network based on the first information.
[0187] As one possible implementation, the mobility management device selects a first authentication device based on the first information, including:
[0188] S320#a1, the mobility management device also obtains indication information from the terminal device, which indicates that the first network supports external credentials and / or the terminal device uses external credentials.
[0189] Specifically, the mobility management device can also determine, based on the instruction information from the terminal device, whether the first network supports external credentials and / or whether the terminal device uses external credentials. When the mobility management device does not find a second authentication device based on the first information, it can determine that the second network has not deployed a second authentication device, or that the second network uses an AAA server for authentication, or that the second network does not use a second authentication device for authentication. In this case, the mobility management device will select the first authentication device to execute the authentication process of the terminal device (or trigger the authentication process of the terminal device) to avoid mistaking the registration behavior of the terminal device as an incorrect or abnormal case and refusing the terminal device's access or registration.
[0190] S320#b1, the mobility management device selects the first authentication device based on the instruction information.
[0191] Specifically, the terminal device can also send an instruction message to the mobility management device, which instructs the terminal device to use external credentials or for the first network to support external credentials.
[0192] It should be understood that the terminal device using external credentials can be interpreted as the terminal device's credentials originating from a second network, meaning the terminal device's credentials do not originate from the first network. Alternatively, it can be understood as the terminal device's security process being executed by a device outside the first network. This security process should be understood to include, but is not limited to, primary authentication, primary authorization, and authentication or authorization procedures. Here, a device outside the first network can be understood as a device or server on a different network than the first network. Therefore, if the mobility management device does not discover a second authentication device based on the first information, and determines based on this indication information that the terminal device uses external credentials and / or the first network supports external credentials, it will select the first authentication device, which will then participate in the terminal device's authentication process.
[0193] As one possible implementation, the mobility management device selects a first authentication device based on the first information, including:
[0194] S320#a2, the mobility management device sends a request message to the network storage device. The request message is used to request the discovery of a second authentication device. The request message includes the first information.
[0195] S320#b2, the mobility management device obtains response information from the network storage device, the response information indicating that no second authentication device has been found, and / or the response information includes the identification information and / or address information of the first authentication device.
[0196] S320#c2, the mobility management device selects the first authentication device based on the response information.
[0197] Optionally, the request information may also include first indication information, which is used to instruct the first network to support external credentials and / or the terminal device to use external credentials.
[0198] Specifically, after acquiring the first information from the terminal device, the mobility management device sends a request message to the network storage device. This request message requests the discovery of a second authentication device for the second network. This request message can be an Nnrf_NFDiscovery_Request, and it includes the first information and the network function type. The network function type indicates the type of network function the mobility management device needs the network storage device to discover. For example, when the network function type indicates an authentication device or authentication function, the mobility management device requests the network storage device to discover the authentication device for the second network (or, requests the discovery of AUSF).
[0199] After receiving the request information from the mobility management device, the network storage device will send a response information to the mobility management device. The response information may include information that no second authentication device has been found, or it may include the identification information and / or address information of the first authentication device. Alternatively, the response information may include information that no second authentication device has been found and the identification information and / or address information of the first authentication device.
[0200] As one possible implementation, the network storage device learns that the second authentication device to be discovered belongs to the second network based on the HNI and / or RI of the terminal device included in the first information, and sends the response information to the mobility management device if no second authentication device is found.
[0201] Optionally, the network storage device learns from the request information that the mobility management device needs to discover a second authentication device, and learns from the HNI and / or RI of the terminal device included in the first information that the second authentication device to be discovered belongs to the second network. Thus, it can also infer or know that the terminal device's credentials belong to the second network. If no second authentication device is found, the network storage device sends the response information to the mobility management device.
[0202] Optionally, the network storage device learns from the request information that the mobility management device needs to discover a second authentication device, and based on the HNI and / or RI of the terminal device included in the first information, it learns that the second authentication device to be discovered belongs to the second network. From this, it can also infer or know that the terminal device's credentials belong to the second network. When the request information also includes the first indication information sent by the mobility management device, if the network storage device does not discover the second authentication device, it can also infer or know that the second network has not deployed a second authentication device, or that the second network uses an AAA server to perform terminal device authentication, or that the second network does not use a second authentication device to perform terminal device authentication. The NRF can select the first authentication device of the first network and send the response information to the mobility management device.
[0203] After obtaining the response information from the network storage device, the mobility management device selects the first authentication device based on the response information.
[0204] As one possible implementation, the mobility management device selects a first authentication device based on the first information, including:
[0205] S320#a3, the mobility management device also obtains a network identifier from the access network device, which indicates that the first network is a non-public network.
[0206] S320#b3, the mobility management device selects a first authentication device based on the first network identifier and the first information.
[0207] Specifically, the mobility management device obtains a network identifier from the access network device. For example, this network identifier is a network identification code (NID), which indicates that the first network is an SNPN. When the mobility management device cannot find a second authentication device for the second network based on the terminal device's HNI and / or RI, the mobility management device selects a first authentication device for the first network.
[0208] Specifically, since the NID indicates that the first network to which the mobility management device belongs is an SNPN, and the HNI and / or RI of the terminal device indicate that the second network to which the terminal device's credentials belong is a network other than the SNPN, the mobility management device can infer or determine that the terminal device uses external credentials or that the first network supports external credentials. Therefore, when the mobility management device discovers that the second network indicated by the HNI and / or RI does not have a second authentication device deployed, the mobility management device can determine that the second network does not have a second authentication device deployed, or that the second network does not use a second authentication device to perform the terminal device's primary authentication or security process, or that the second network uses an AAA Server to perform the terminal device's primary authentication or security process. Therefore, the mobility management device will select the first authentication device of the first network.
[0209] As one possible implementation, the mobility management device selects a first authentication device based on the first information, including:
[0210] S320#a4, The mobile management device selects the first authentication device based on the configuration information.
[0211] It should be understood that the mobility management device can select a first authentication device based on configuration information, which includes one or more HNIs and / or RIs. For example, the one or more HNIs and / or RIs included in the configuration information are used to indicate one or more networks, other than the first network, that use an AAA server to perform authentication. Therefore, when the HNI and / or RI of the terminal device obtained by the mobility management device belongs to or matches one or more HNIs and / or RIs in the configuration information, the mobility management device selects the first authentication device of the first network based on the configuration information.
[0212] More specifically, when the HNI and / or RI of the terminal device belongs to or matches one or more HNIs and / or RIs, the mobility management device selects the first authentication device of the first network.
[0213] As one possible implementation, the configuration information can be pre-configured in the mobility management device, or the mobility management device can obtain the configuration information from the control plane device; the control plane device may include a policy control device, a unified data management device, a user database device, an application function device, a network access device, or a network storage device.
[0214] Through the above technical solution, this application can achieve the following: when the terminal device uses external credentials and the second network uses an AAA server to perform authentication, the mobility management device of the first network will select the first authentication device of the first network, and will not send a registration rejection message to the terminal device because it cannot find the second authentication device of the second network, thus preventing the terminal device from registering or accessing the first network. This allows the terminal device to successfully register or access the first network.
[0215] More specifically, when a UE accesses the first network using external credentials and the CH uses an AAA Server for authentication, if the mobility management device of the first network uses the aforementioned registration method to select a second authentication device, it may fail to discover the second authentication device through the network storage device. Since the HNI and / or RI in the UE's SUCI indicate the second network, and the second network uses an AAA Server for authentication instead of a second authentication device (e.g., when the second network deploys an AAA server for authentication but not a second authentication device), the network storage device does not have information about the second authentication device for that second network, or the network storage device of the first network cannot discover the second authentication device of the second network through the network storage device of the second network. Therefore, the mobility management device of the first network cannot discover and select the second authentication device through the HNI of the UE's SUCI. In this case, the network storage device will send feedback information such as query failure or 404 not found to the mobility management device of the first network. After receiving the feedback information, the mobility management device of the first network will send a registration request rejection message to the UE, preventing the UE from registering to the first network.
[0216] Therefore, through the above technical solution, when the mobility management device of the first network does not find the second authentication device of the second network, it will select the first authentication device of the first network, thereby enabling the terminal device to successfully register or access the first network, avoiding the normal registration behavior of the terminal device being regarded as an erroneous case and the terminal device's access or registration being rejected.
[0217] It should be understood that the above Figure 3 The overall flow of a communication method provided by an embodiment of this application is described below, and will be combined with Figures 4 to 7The application of a communication method provided in the embodiments of this application in a specific application scenario will be further described.
[0218] Figure 4 This is a schematic flowchart of another communication method provided in this application. The specific content of method #400 is as follows: Figure 4 As shown.
[0219] S401-S402 are the same as S310-S320, and will not be described again here.
[0220] S403, the mobility management device sends an authentication request to the first authentication device.
[0221] It should be understood that after the mobile management device sends the authentication request information to the first authentication device, it initiates the authentication / security process.
[0222] S404, the first authentication device sends an authentication request to the unified data management device.
[0223] Specifically, the first authentication device sends an authentication request (e.g., Nudm_UEAU_Get Request) to the unified data management device, which includes the terminal device's SUCI.
[0224] The unified data management device obtains the terminal device's SUPI based on the SUCI (e.g., by decrypting the SUCI to obtain the SUPI). The data management device then queries the authentication method applicable to the SUPI. Based on the subscription data or the realm portion (which can be understood as the domain name) in the network access identifier (NAI) format of the SUPI, the unified data management device determines which external entity will perform the primary authentication.
[0225] One possible implementation is that when the unified data management device cannot obtain the terminal device's subscription data (for example, the terminal device is not the terminal device performing external authentication, but may be the terminal device of a network outside the first network, and that network has not signed a roaming agreement with the first network, so the mobility management device in the first network cannot find the second authentication device of the second network to which the terminal device belongs), the unified data management device can also determine that the terminal device has failed to perform authentication; or when the unified data management device learns that the terminal device is not performing external authentication or the second network corresponding to the terminal device is not using an AAA server to perform authentication, the unified data management device can also determine that the terminal device has failed to perform authentication.
[0226] S405, the unified data management device sends authentication acquisition response information to the first authentication device.
[0227] Specifically, if the unified data management device can obtain the SUPI based on the SUCI, then the unified data management device sends the terminal device's authentication acquisition response information (e.g., Nudm_UEAU_Get Response) to the first authentication device. This information includes the SUPI and instructs the first authentication device to perform external authentication, i.e., to use an external entity (or external CH) to perform primary authentication. If the unified data management device cannot obtain the SUPI based on the SUCI or if the unified data management device learns that the UE cannot authenticate successfully, the unified data management device instructs the first authentication device that the UE's authentication process failed.
[0228] S406, the first authentication device sends an AAA interoperability authentication request to the authentication and authorization device.
[0229] Specifically, if the unified data management device sends the terminal device's SUPI or the realm part of the SUPI (i.e., domain name information) and the instruction information to the first authentication device, the first authentication device selects an authentication and authorization device (e.g., NSSAAF) according to the instruction information of the unified data management device, and sends AAA interoperability authentication request information (e.g., Nnssaaf_AAA interworking_Authentication Request) to the authentication and authorization device. This information includes the terminal device's SUPI or the realm part of the SUPI (i.e., domain name information).
[0230] S407, the authentication and authorization device sends an EAP request message to the AAA server.
[0231] Specifically, if the authentication and authorization device receives the SUPI of the terminal device in step S406, the authentication and authorization device selects an AAA server based on the domain name information corresponding to the realm portion of the terminal device's SUPI and sends EAP request information (e.g., an EAP request) to that AAA server. If the authentication and authorization device receives the realm portion (i.e., domain name information) of the terminal device's SUPI in step S406, the authentication and authorization device selects an AAA server based on the domain name information corresponding to that realm portion.
[0232] S408, AAA Server executes the EAP authentication process.
[0233] It should be understood that this process involves terminal devices, mobile management devices, primary authentication devices, authentication and authorization devices, and AAA servers.
[0234] Optionally, the EAP authentication process can be understood as the terminal device performing EAP authentication with the AAA server, where the AAA server acts as the EAP server and the terminal device acts as the EAP client; the mobility management device, the first authentication device, and the authentication and authorization device are used to forward EAP information between the terminal device and the AAA server.
[0235] S409, the AAA server sends EAP response information to the authentication and authorization device.
[0236] Once the terminal device is successfully authenticated, the AAA server sends an EAP response message (e.g., EAP-response) to the authenticated and authorized device. This response message includes EAP success information and the master session key (MSK).
[0237] S410, the authentication and authorization device sends AAA interoperability authentication response information to the first authentication device.
[0238] It should be understood that the AAA interoperability authentication response information (e.g., Nnssaaf_AAA interworking_Authentication Response) includes EAP success and MSK.
[0239] S411, the first authentication device performs key derivation.
[0240] Specifically, the first authentication device performs key derivation based on the MSK.
[0241] S412, the first authentication device sends authentication response information to the mobility management device.
[0242] It should be understood that the response information may be a Nausf_UEAU_Authenticate Response, which includes EAP success information, the derived key, and SUPI.
[0243] If, in step S405, the first authentication device receives an authentication failure message from the unified data management device, then the first authentication device skips steps S406 to S411 and directly sends the authentication failure message to the mobility management device.
[0244] S413, the mobility management device sends an EAP success message to the terminal device.
[0245] It should be understood that the EAP success message can be sent via non-access stratum (NAS) information.
[0246] It should be understood that this NAS information includes EAP success information.
[0247] It should be understood that if the mobility management device receives an authentication failure message from the first authentication device in step S412, the mobility management device may choose not to send the EAP success message, or it may send an authentication failure message or a registration rejection message to the terminal device.
[0248] S414, the mobility management device sends feedback information to the terminal device.
[0249] Specifically, if the UE authentication is successful, the mobility management device sends a registration acceptance message to the UE; if the UE authentication fails, the mobility management device sends a registration rejection message to the UE.
[0250] It should be understood that steps S413 and S414 can be sent using the same message or different messages.
[0251] With the above technical solution, when the mobility management device of the first network does not find the second authentication device of the second network, it will select the first authentication device of the first network, thereby enabling the terminal device to successfully register or access the first network, avoiding the normal registration behavior of the terminal device being regarded as an erroneous case and the access or registration of the terminal device being rejected.
[0252] Figure 5 This is a schematic flowchart illustrating yet another communication method provided in this application. The specific details of method #500 are as follows: Figure 5 As shown.
[0253] S510 is the same as step S310 mentioned above, and will not be described again here.
[0254] S520, the mobility management device sends a request message to the network storage device. The request message includes the HNI and / or RI of the terminal device. The request message is used to request the discovery of a second authentication device of the second network. The credentials of the terminal device belong to the second network, and the second network has not deployed a second authentication device.
[0255] Accordingly, the network storage device receives request information from the mobility management device.
[0256] As one possible implementation, the request information may also include first indication information, which is used to instruct the first network to support external credentials and / or the terminal device to use external credentials.
[0257] Specifically, after acquiring the first information from the terminal device, the mobility management device sends a request message to the network storage device. This request message requests the discovery of a second authentication device for a second network. The request message can be an Nnrf_NFDiscovery_Request, which includes the terminal device's HNI and / or RI, as well as the network function type. The network function type indicates the type of network function the mobility management device needs the network storage device to discover. For example, if the network function type indicates an authentication device, the request message indicates a second authentication device for requesting the discovery of a second network.
[0258] S530, the network storage device sends a response message to the mobility management device, the response message including an indication that no second authentication device was found, and / or, the response message including the identification information and / or address information of the first authentication device.
[0259] It should be understood that the first authentication device, network storage device, and mobility management device belong to the first network.
[0260] It should be understood that after obtaining the request information from the mobility management device, the network storage device will send response information to the mobility management device. The response information may include information that no second authentication device has been found, or it may include information carrying the identification information and / or address information of the first authentication device. Alternatively, the response information may also include information that no second authentication device and the identification information and / or address information of the first authentication device have been found.
[0261] As one possible implementation, the network storage device does not detect a second authentication device before sending a response message to the mobility management device.
[0262] Specifically, the network storage device determines, based on the HNI and / or RI, that the second authentication device to be discovered belongs to the second network. If no second authentication device is found in the second network, the network storage device sends a response message to the mobility management device. Subsequently, after receiving the response message from the network storage device, the mobility management device selects the first authentication device based on that response message.
[0263] As one possible implementation, the network storage device sends response information to the mobility management device, including:
[0264] When the HNI and / or RI of the terminal device match the configuration information, a response message is sent, which includes one or more HNIs and / or RIs.
[0265] For example, the configuration information includes one or more HNIs and / or RIs to indicate one or more networks other than the first network that use an AAA server to perform authentication or do not use a second authentication device to perform authentication. Therefore, when the HNI and / or RI of the terminal device obtained by the mobility management device belongs to or matches one or more HNIs and / or RIs in the configuration information, the network storage device sends a response information based on the configuration information.
[0266] More specifically, when the home network identifier and / or routing indication of the terminal device belong to or match one or more home network identifiers and / or routing indications, the network storage device sends response information to the mobility management device based on the configuration information.
[0267] As one possible implementation, the configuration information can be pre-configured in a network storage device, or the network storage device can obtain the configuration information from a control plane device. Control plane devices include mobility management devices, policy control devices, unified data management devices, user database devices, network access devices, or application function devices.
[0268] As one possible implementation, the network storage device sends response information to the mobility management device, including:
[0269] The network storage device sends a response message based on the first instruction.
[0270] Specifically, based on the first indication information, the network storage device determines that the first network to which the mobility management device belongs is an SNPN, or determines that the terminal device uses external credentials, or determines that the second authentication device requested by the mobility management device is used to perform external authentication. When the network storage device does not find or is unable to find the second authentication device of the second network corresponding to the HNI and / or RI of the terminal device, the network storage device sends the response information to the mobility management device.
[0271] As one possible implementation, the network storage device sends response information to the mobility management device, including:
[0272] The network storage device did not find a second authentication device and sent a response message.
[0273] Specifically, when the network storage device fails to discover or is unable to discover the second authentication device of the second network corresponding to the HNI and / or RI of the terminal device, the network storage device sends the response information to the mobility management device.
[0274] With the above technical solution, when the mobility management device of the first network does not find the second authentication device of the second network, it will select the first authentication device of the first network, thereby enabling the terminal device to successfully register or access the first network, avoiding the normal registration behavior of the terminal device being regarded as an erroneous case and the access or registration of the terminal device being rejected.
[0275] It should be understood that the above Figure 5 The overall flow of another communication method provided by the embodiments of this application is described below, which will be combined with Figure 6 Examples of this application Figure 5 The application of the provided communication method in specific application scenarios is described.
[0276] Figure 6 This is a schematic flowchart illustrating another communication method provided in this application. The specific details of method #600 are as follows: Figure 6 As shown.
[0277] S601-S603 are the same as steps S510-530 mentioned above, and will not be repeated here.
[0278] S604, the mobile management device selects the first authentication device.
[0279] Specifically, after obtaining the first information from the terminal device, the mobility management device sends a request message to the network storage device. This request message is used to request the discovery of a second authentication device for a second network. This request message can be an Nnrf_NFDiscovery_Request, which includes the first information and the network function type. The network function type indicates the type of network function the mobility management device needs the network storage device to discover. For example, when the network function type indicates an authentication device, the mobility management device requests the network storage device to discover the authentication device for the second network (or, requests the discovery of an AUSF).
[0280] After obtaining the request information from the mobility management device, the network storage device sends a response information to the mobility management device. The response information may include information that no second authentication device was found, or it may include the identification information and / or address information of the first authentication device. Alternatively, the response information may include information that no second authentication device was found and the identification information and / or address information of the first authentication device.
[0281] As one possible implementation, the network storage device determines that the second authentication device to be discovered belongs to the second network based on the HNI and / or RI of the terminal device included in the first information, and sends the response information to the mobility management device if no second authentication device is found.
[0282] Optionally, the network storage device learns from the request information that the mobility management device needs to discover a second authentication device, and learns from the HNI and / or RI of the terminal device included in the first information that the second authentication device to be discovered belongs to the second network. Thus, it can also infer or know that the terminal device's credentials belong to the second network. If no second authentication device is found, the network storage device sends the response information to the mobility management device.
[0283] Optionally, the network storage device learns from the request information that the mobility management device needs to discover a second authentication device, and based on the HNI and / or RI of the terminal device included in the first information, or the second authentication device to be discovered belongs to the second network, it can further infer or know that the terminal device's credentials belong to the second network; when the request information also includes the first indication information sent by the mobility management device, if the second authentication device is not discovered, the network storage device can further infer or know that the second network has not deployed a second authentication device, or that the second network does not use a second authentication device to perform terminal device authentication, or that the second network uses an AAA server to perform terminal device authentication. The network storage device can then select the first authentication device of the first network and send the response information to the mobility management device.
[0284] After obtaining the response information from the network storage device, the mobile management device selects the first authentication device based on the response information.
[0285] S605-616 are the same as steps S403-S414 mentioned above, and will not be repeated here.
[0286] Through the above technical solution, this application can achieve the following: when the terminal device uses external credentials and the second network does not deploy a second authentication device, or the second network does not use a second authentication device to perform terminal device authentication, or the second network uses an AAA server to perform terminal device authentication, the network storage device enables the mobility management device to select the first authentication device of the first network, and will not send failure or error indication information to the mobility management device because it cannot find or cannot find the second authentication device of the second network, causing the mobility management device to send registration rejection information to the terminal device, thus preventing the terminal device from registering or accessing the first network.
[0287] Figure 7 This is a schematic flowchart illustrating yet another communication method provided in this application. The specific details of method #700 are as follows: Figure 7 As shown.
[0288] S701, the terminal device sends a registration request to the access network device.
[0289] The registration request information includes access network (AN) parameters and NAS registration request information. The AN parameters include an onboarding indication. The registration type indicated in the NAS registration request information is SNPN onboarding.
[0290] S702, Select Mobility Management Equipment for Access Network Equipment.
[0291] Specifically, the access network equipment selects a mobile management device that supports online signing functionality based on the online signing instruction.
[0292] S703, the access network device sends a registration request to the mobility management device.
[0293] Specifically, after the access network device selects a mobility management device based on the online subscription instruction information, the access network device forwards the NAS registration request information to the selected mobility management device.
[0294] S704, the mobility management device sends an authentication request to the third authentication device.
[0295] It should be understood that the third authentication device may be similar to the aforementioned first authentication device, and may correspond to AUSF or other similar devices used to perform AUSF functions. This application embodiment does not make specific limitations.
[0296] Correspondingly, the third authentication device receives authentication request information from the mobile management device.
[0297] Specifically, the mobility management device determines that the terminal device registers for the SNPN to perform online signing based on the registration type of Independent Non-Public Network Onboarding (SNPN) in the NAS registration request information. The mobility management device then selects a suitable third authentication device based on the online signing configuration information (or configuration data or configuration policy) and sends authentication request information, including the terminal device's SUCI, to that first authentication device.
[0298] As one possible implementation, the configuration information is pre-configured in the mobility management device, or the configuration information is obtained by the mobility management device from a control plane device. Control plane devices include policy control devices, unified data management devices, user database devices, network storage devices, application function devices, or network access devices.
[0299] It should be understood that the authentication request information also includes second information, which is used to instruct the terminal device to perform online signing, or the second information instructs the terminal device to perform registration for online signing.
[0300] As one possible implementation, the second information could be instruction information or the SUCI or SUPI of the terminal device.
[0301] As one possible implementation, the SUCI or SUPI type of the terminal device can instruct the terminal device to perform online signing or instruct the terminal device to register for online signing.
[0302] As one possible implementation, the second information included in the authentication request information may be sent by the mobility management device to the third authentication device (or it can be understood that the second information comes from the mobility management device), or it may come from the terminal device, which is used to instruct the terminal device to perform online signing or to instruct the terminal device to perform registration for online signing.
[0303] As one possible implementation, when the second information is sent by or originates from the mobility management device, the second information may be generated by the mobility management device.
[0304] In one possible implementation, the request information is a Nausf_UEAU_Authenticate Request.
[0305] S705, the third authentication device determines the fourth authentication device based on the second information.
[0306] Specifically, the third authentication device determines that the terminal device is performing online signing based on the second information in the authentication request information sent by the mobile management device, and determines the fourth authentication device based on the second information.
[0307] The fourth authentication device is used to execute the security process of the terminal device. It should be understood that this security process includes, but is not limited to, primary authentication, primary authorization, and authentication or authorization processes. As one possible implementation, the fourth authentication device can be used to perform EAP authentication; for example, the fourth authentication device acts as an EAP server to authenticate EAP clients.
[0308] As one possible implementation, when the second information is sent by or from the mobility management device, the second information can be instruction information used to indicate whether the terminal device is performing online signing or to indicate whether the terminal device is performing registration for online signing.
[0309] As one possible implementation, when the second information comes from the terminal device, the second information can be the terminal device's SUCI or SUPI.
[0310] Optionally, the domain name information (or realm portion or home network identifier and / or routing indication) in the SUPI or SUCI of the terminal device indicates the default credential domain name, or instructs the terminal device to perform online signing, or instructs the terminal device to perform registration for online signing.
[0311] As one possible implementation, the third authentication device determines, based on the configuration information and the second information, whether the terminal device is performing online signing or whether the terminal device is performing registration for online signing.
[0312] In one possible implementation, the configuration information includes one or more domain name information, which indicates one or more default credential domain names. When the second information belongs to or matches the configuration information, the second information can be used to instruct the terminal device to perform online signing or to instruct the terminal device to perform registration for online signing.
[0313] It should be understood that the second information belonging to or matching the configuration information can be interpreted as the second information belonging to or matching the one or more domain name information.
[0314] As one possible implementation, the domain name information includes one or more of the following: home network identifier, routing indication, MCC, MNC, and NID.
[0315] As one possible implementation, the configuration information can be pre-configured in the third authentication device, or it can be obtained by the third authentication device from the control plane device. The control plane device includes mobility management device, policy control device, unified data management device, user database device, application function device, and network access device.
[0316] As one possible implementation, the third authentication device can also obtain the SUPI based on the SUCI of the terminal device.
[0317] It should be understood that the third authentication device obtaining SUPI based on SUCI can be interpreted as the third authentication device recovering SUPI from SUCI, or as the third authentication device decrypting SUCI into SUPI.
[0318] When the third authentication device skips the selection of the unified data management device, the SUCI of the terminal device cannot be decrypted or restored to SUPI by the unified data management device. However, in the registration process of the terminal device, the signaling interaction between core network devices (or control plane devices) usually needs to include the terminal device's identification information, which is usually SUPI. Therefore, when the third authentication device learns that the terminal device is performing online signing or that the terminal device is registering for online signing, it can obtain or restore the SUPI based on the SUCI, ensuring that the signaling interaction between core network devices (or control plane devices) is not affected.
[0319] As one possible implementation, the fourth authentication device includes network slicing and stand-alone non-public network authentication and authorization devices and a default credentials server (DCS).
[0320] Optionally, the DCS is an authentication, authorization, and accounting server.
[0321] When the fourth authentication device is a network slice and a non-public network authentication and authorization device, the method includes the following:
[0322] S706, the third authentication device sends an AAA interoperability authentication request to the fourth authentication device.
[0323] It should be understood that the third authentication device determines the fourth authentication device based on the second information.
[0324] Specifically, after determining that the terminal device is performing an online contract signing, the third authentication device determines the fourth authentication device based on the second information. The fourth authentication device is used to execute the authentication process of the terminal device.
[0325] As one possible implementation, the first authentication device skips the selection of the unified data management device.
[0326] Specifically, the third authentication device learns from the second information that the terminal device is performing an online contract signing, or learns that the terminal device is performing registration for an online contract signing, and the third authentication device does not need to select a unified data management device or skips the selection of a unified data management device.
[0327] It should be understood that if the network slicing and non-public network authentication and authorization devices interact with the DCS, the third authentication device sends authentication request information to the network slicing and non-public network authentication and authorization devices. This information includes the terminal device's identification information, such as one or more of the terminal device's SUCI, SUPI, or EAP identifier. If the terminal device's identification information includes SUPI, the first authentication device can also obtain the SUPI based on the terminal device's SUCI before sending the request information to the network slicing and non-public network authentication and authorization devices.
[0328] It should be understood that the third authentication device obtaining SUPI based on SUCI can be interpreted as the third authentication device recovering SUPI from SUCI, or as the third authentication device decrypting SUCI into SUPI.
[0329] It should be understood that if the terminal device's identification information includes an EAP identifier, the third authentication device can also send domain name information to network slice and non-public independent network authentication and authorization devices. This domain name information can come from the realm part of the terminal device's SUCI or SUPI (which can be understood as the Home Network Identifier or HNI), thus enabling network slice and non-public network authentication and authorization devices to know which domain or network's DCS they need to interact with.
[0330] S707, network slices and non-public network authentication and authorization devices send EAP request information to DCS.
[0331] As one possible implementation, network slicing and non-public network authentication and authorization devices select a DCS based on the domain name information sent by the third authentication device. The network slicing and non-public network authentication and authorization devices send EAP request information to the DCS, which includes EAP start and EAP identity.
[0332] S708, DCS executes the EAP authentication process.
[0333] It should be understood that this process involves interaction between terminal devices, mobility management devices, third-party authentication devices, network slicing, non-public network authentication and authorization devices, and DCS.
[0334] Optionally, network slicing and non-public network authentication and authorization devices can forward EAP information.
[0335] S709, DCS sends EAP response information (EAPresponse) to network slice and non-public network authentication and authorization devices.
[0336] After the terminal device is successfully authenticated, the DCS sends EAP response information (such as EAP-response) to the network slice and non-public network authentication and authorization devices. This response information includes EAP success information.
[0337] Optionally, the response information may also include the master session key (MSK).
[0338] S710, network slices and non-public network authentication and authorization devices send AAA interoperability authentication response information to third authentication devices.
[0339] It should be understood that the AAA interoperability authentication response information includes EAP success information.
[0340] Optionally, the AAA interoperability authentication response information may also include MSK.
[0341] Optionally, S711, the third authentication device performs key derivation.
[0342] Specifically, when the third authentication device receives an MSK, the third authentication device performs key deduction based on the MSK.
[0343] S712, the third authentication device sends authentication response information to the mobility management device.
[0344] It should be understood that the response information includes EAP success and UE identification information (the identification information can be SUCI or SUPI).
[0345] Optionally, the response information may also include a derived key.
[0346] As one possible implementation, the response information is Nausf_UEAU_Authenticate Response.
[0347] S713, the mobility management device sends an EAP success message to the terminal device.
[0348] As one possible implementation, the EAP success message is sent via NAS information.
[0349] It should be understood that this NAS information includes EAP success information.
[0350] S714, the mobility management device sends feedback information to the terminal device.
[0351] Specifically, if UE authentication is successful, the mobility management device sends a registration acceptance message to the UE; if UE authentication fails, the mobility management device sends a registration rejection message to the UE.
[0352] It should be understood that the above technical solution is for the fourth authentication device to be a network slice or a non-public network authentication and authorization device. When the fourth authentication device is a DCS, the method includes the following:
[0353] S706#a, the third authentication device sends an EAP request message to the DCS.
[0354] Specifically, if the fourth authentication device is DCS, the third authentication device sends EAP request information (e.g., EAPrequest) to DCS. This request information includes EAP start and EAP identifier.
[0355] S707#a, DCS executes the EAP authentication process.
[0356] It should be understood that this process involves interaction between the terminal device, the mobility management device, the third authentication device, and the DCS.
[0357] S708#a, DCS sends EAP response information to the third authentication device.
[0358] Specifically, the DCS sends an EAP response message to the authentication and authorization device, which includes information indicating that the EAP was successful.
[0359] Optionally, this information may also include MSK.
[0360] Optionally, in S709#a, a third authentication device performs key derivation.
[0361] Specifically, when the third authentication device receives an MSK, the third authentication device performs key deduction based on the MSK.
[0362] S710#a, the third authentication device sends authentication response information to the mobility management device.
[0363] It should be understood that the response information includes EAP success and UE identification information (the identification information can be SUCI or SUPI).
[0364] Optionally, the response information may also include a derived key.
[0365] As one possible implementation, the response information is Nausf_UEAU_Authenticate Response.
[0366] S711#a, the mobility management device sends an EAP success message to the terminal device.
[0367] As one possible implementation, the EAP success message is sent via NAS information.
[0368] It should be understood that this NAS information includes EAP success information.
[0369] S712#a, the mobility management device sends feedback information to the terminal device.
[0370] Specifically, if UE authentication is successful, the mobility management device sends a registration acceptance message to the UE; if UE authentication fails, the mobility management device sends a registration rejection message to the UE.
[0371] This application, through a third authentication device, learns that the terminal device is performing an online contract signing or that the terminal device is registered for online contract signing. It then selects a fourth authentication device, which performs the authentication process for the terminal device. This ensures the terminal device successfully accesses the network and avoids situations where, after selecting a unified data management device and interacting with it, the unified data management device lacks the contract signing data for the terminal device, preventing authentication from being performed or causing errors or anomalies that would prevent the terminal device from accessing the network.
[0372] It should be understood that the information in the embodiments of this application can also be understood as messages. For example, EAP request information can be understood as an EAP request message, response information can be understood as a response message, NAS information can be understood as a NAS message, and so on.
[0373] Figure 8 This is a schematic block diagram of the communication device 800 provided in this application. As shown in the figure, the communication device 800 may include a transceiver unit 810 and a processing unit 820.
[0374] In one possible design, the communication device 800 can be the mobility management device in the above method embodiments, or it can be a chip used to implement the functions of the mobility management device in the above method embodiments.
[0375] It should be understood that the communication device 800 may correspond to the mobility management device according to the embodiments of this application, and the communication device 800 may include functions for performing... Figures 3 to 7 The communication device 800 is a unit that executes a method for mobile management. Furthermore, each unit in the communication device 800 and the other operations and / or functions described above are respectively for implementing... Figures 3 to 7 The corresponding process in the process.
[0376] As an example, the communication device 800 can implement the actions, steps, or methods related to the mobility management device in S310, S320, S330, and S340 of the aforementioned method embodiments, and can also implement the actions, steps, or methods related to the mobility management device in S510, S520, and S530 of the aforementioned method embodiments.
[0377] It should be understood that the above content is only for illustrative purposes. The communication device 800 can also implement other steps, actions or methods related to the mobility management device in the above method embodiments, which will not be described in detail here.
[0378] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0379] In another possible design, the communication device 800 may be a network storage device in the above method embodiment, or it may be a chip used to implement the functions of the network storage device in the above method embodiment.
[0380] It should be understood that the communication device 800 may correspond to a network storage device according to the embodiments of this application, and the communication device 800 may include functions for performing... Figures 3 to 8 The communication device 800 is a unit that executes a method in a network storage device. Furthermore, each unit in the communication device 800 and the other operations and / or functions described above are respectively for implementing... Figures 3 to 7 The corresponding processes are described above. It should be understood that the specific processes by which each unit performs the above-mentioned steps have been described in detail in the above method embodiments, and for the sake of brevity, they will not be repeated here.
[0381] It should be understood that the above content is only for illustrative purposes. The communication device 800 can also implement other steps, actions or methods related to network storage devices in the above method embodiments, which will not be described in detail here.
[0382] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0383] It should be understood that the above content is only for illustrative purposes. The communication device 800 can also implement other steps, actions or methods related to the first authentication device in the above method embodiments, which will not be repeated here.
[0384] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0385] It should be understood that the above content is only for illustrative purposes. The communication device 800 can also implement other steps, actions or methods related to the second authentication device in the above method embodiments, which will not be repeated here.
[0386] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0387] It should be understood that the above content is only for illustrative purposes. The communication device 800 can also implement other steps, actions or methods related to the third authentication device in the above method embodiments, which will not be described in detail here.
[0388] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0389] It should be understood that the above content is only for illustrative purposes. The communication device 800 can also implement other steps, actions or methods related to the fourth authentication device in the above method embodiments, which will not be repeated here.
[0390] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0391] It should also be understood that the transceiver unit 810 in the communication device 800 may correspond to Figure 9 The transceiver 920 in the communication device 900 shown in the figure, and the processing unit 820 in the communication device 800 may correspond to Figure 9 The processor 910 in the communication device 900 shown in the figure.
[0392] It should also be understood that when the communication device 800 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit can be an input / output circuit or a communication interface; the processing unit can be a processor, microprocessor, or integrated circuit integrated on the chip.
[0393] The transceiver unit 810 is used to implement the signal transmission and reception operations of the communication device 800, and the processing unit 820 is used to implement the signal processing operations of the communication device 800.
[0394] Optionally, the communication device 800 further includes a storage unit 830 for storing instructions.
[0395] Figure 9 This is a schematic block diagram of a communication device 900 provided in an embodiment of this application. As shown, the communication device 900 includes at least one processor 910 and a transceiver 920. The processor 910 is coupled to a memory and is used to execute instructions stored in the memory to control the transceiver 920 to transmit and / or receive signals. Optionally, the communication device 900 also includes a memory 930 for storing instructions.
[0396] It should be understood that the processor 910 and memory 930 described above can be combined into a single processing device, with the processor 910 executing the program code stored in the memory 930 to achieve the aforementioned functions. In specific implementations, the memory 930 can be integrated into the processor 910 or independent of the processor 910.
[0397] It should also be understood that transceiver 920 may include a receiver (or receiver unit) and a transmitter (or transmitter unit). Transceiver 920 may further include antennas, and the number of antennas may be one or more. Transceiver 920 may have a communication interface or interface circuitry.
[0398] When the communication device 900 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit can be an input / output circuit or a communication interface; the processing unit can be a processor, microprocessor, or integrated circuit integrated on the chip. This application also provides a processing apparatus, including a processor and an interface. The processor can be used to execute the methods described in the above method embodiments.
[0399] It should be understood that the aforementioned processing device can be a chip. For example, the processing device can be a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system-on-chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0400] In implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software. The steps of the method disclosed in the embodiments of this application can be directly implemented by a hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, detailed descriptions are omitted here.
[0401] This application also provides a computer-readable storage medium storing computer instructions for implementing the method executed by the mobility management device in the above method embodiments.
[0402] For example, when the computer program is executed by the computer, it enables the computer to implement the method executed by the mobile management device in the above method embodiments.
[0403] This application also provides a computer-readable storage medium storing computer instructions for implementing the methods executed by the network storage device in the above method embodiments.
[0404] For example, when the computer program is executed by a computer, it enables the computer to implement the method executed by the network storage device in the above method embodiments.
[0405] This application also provides a computer-readable storage medium storing computer instructions for implementing the method executed by the first authentication device in the above method embodiments.
[0406] For example, when the computer program is executed by the computer, it enables the computer to implement the method executed by the first authentication device in the above method embodiments.
[0407] This application also provides a computer-readable storage medium storing computer instructions for implementing the method executed by the second authentication device in the above method embodiments.
[0408] For example, when the computer program is executed by the computer, it enables the computer to implement the method executed by the second authentication device in the above method embodiments.
[0409] This application also provides a computer-readable storage medium storing computer instructions for implementing the method executed by the third authentication device in the above method embodiments.
[0410] For example, when the computer program is executed by a computer, it enables the computer to implement the method executed by the third authentication device in the above method embodiments.
[0411] This application also provides a computer-readable storage medium storing computer instructions for implementing the method executed by the fourth authentication device in the above method embodiments.
[0412] For example, when the computer program is executed by the computer, it enables the computer to implement the method executed by the fourth authentication device in the above method embodiments.
[0413] This application also provides a computer program product containing instructions that, when executed by a computer, cause the computer to implement the method executed by the mobile management device, the network storage device, the first authentication device, the second authentication device, the third authentication device, or the fourth authentication device in the above-described method embodiments.
[0414] This application provides a communication system, including a mobility management device for performing the aforementioned method executed by the mobility management device, and a network storage device for performing the aforementioned method executed by the network storage device.
[0415] This application provides a communication system, including a mobility management device for executing the aforementioned method executed by the mobility management device, a network storage device for executing the aforementioned method executed by the network storage device, and a third authentication device for executing the aforementioned method executed by the third authentication device.
[0416] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the explanations and beneficial effects of the relevant content in any of the communication devices provided above can be referred to the corresponding method embodiments provided above, and will not be repeated here.
[0417] This application does not impose any particular limitation on the specific structure of the execution subject of the method provided in this application embodiment. As long as it is possible to communicate according to the method provided in this application embodiment by running a program that records the code of the method provided in this application embodiment. For example, the execution subject of the method provided in this application embodiment can be a terminal device or a network device, or a functional module in a terminal device or network device that can call and execute a program.
[0418] Various aspects or features of this application may be implemented as methods, apparatus, or articles of manufacture using standard programming and / or engineering techniques. As used herein, the term "article of manufacture" may encompass any computer program accessible from any computer-readable device, carrier, or medium.
[0419] The computer-readable storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. Available media (or computer-readable media) can include, but are not limited to: magnetic media or magnetic storage devices (e.g., floppy disks, hard disks (such as portable hard drives), magnetic tapes), optical media (e.g., optical discs, compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards and flash memory devices (e.g., erasable programmable read-only memory (EPROM), cards, sticks, or key drives, etc.), or semiconductor media (e.g., solid-state disks (SSDs), USB flash drives, read-only memory (ROM), random access memory (RAM), and various other media capable of storing program code).
[0420] The various storage media described herein may represent one or more devices and / or other machine-readable media used for storing information. The term "machine-readable media" may include, but is not limited to, wireless channels and various other media capable of storing, containing and / or carrying instructions and / or data.
[0421] It should be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM can include a variety of forms, such as: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0422] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0423] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0424] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of the apparatus or units may be electrical, mechanical, or other forms.
[0425] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to implement the solution provided in this application, depending on actual needs.
[0426] In addition, the functional units in the various embodiments of this application can be integrated into one unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0427] In the above embodiments, it can be implemented entirely or partially by software, hardware, firmware, or any combination thereof.
[0428] When implemented using software, it can be implemented wholly or partially as a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. For information on computer-readable storage media, please refer to the description above.
[0429] It should be understood that in the embodiments of this application, the designations "first", "second", etc. are only for distinguishing different objects, such as different network devices, and do not constitute a limitation on the scope of the embodiments of this application. The embodiments of this application are not limited thereto.
[0430] It should also be understood that in this application, “when…”, “if” and “if” all refer to the network element making a corresponding processing under certain objective circumstances, and are not time-limited, nor do they require the network element to make a judgment when it is implemented, nor do they mean that there are other limitations.
[0431] It should also be understood that in the embodiments of this application, "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean that B is determined solely based on A; B can also be determined based on A and / or other information.
[0432] It should also be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0433] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method, characterized in that, include: The authentication service function obtains information instructing the terminal device to perform online signing; The authentication service function determines the network slice and non-public network authentication and authorization functions based on the information indicating that the terminal device should perform online signing. The network slice and non-public network authentication and authorization functions are used to execute the authentication process of the terminal device. The authentication service function sends authentication request information to the network slice and non-public network authentication and authorization functions; The information instructing the terminal device to perform online signing is sent by the terminal device. The information instructing the terminal device to perform online signing is the user hidden identifier of the terminal device. The authentication service function obtains the user permanent identifier of the terminal device based on the user hidden identifier of the terminal device. The authentication request information includes the user permanent identifier.
2. The method according to claim 1, characterized in that, The domain name information in the hidden user identifier indicates the default credential domain name.
3. The method according to claim 1 or 2, characterized in that, The method further includes: The authentication service function determines that the terminal device is to perform online signing based on the configuration information and the information indicating that the terminal device is to perform online signing.
4. The method according to claim 3, characterized in that, The configuration information includes one or more domain name information; the one or more domain name information indicates one or more default credential domain names.
5. The method according to claim 1 or 2, characterized in that, The method further includes: The authentication service function skips the selection of a unified data management device.
6. The method according to claim 1 or 2, characterized in that, The authentication request information includes authentication, authorization, billing, and interoperability authentication request information.
7. A communication device, characterized in that, include: The transceiver unit is used to acquire information instructing the terminal device to perform online contract signing; The processing unit is configured to determine network slicing and non-public network authentication and authorization functions based on the information indicating that the terminal device should perform online signing. The network slicing and non-public network authentication and authorization functions are used to execute the authentication process of the terminal device. The transceiver unit is also used to send authentication request information to the network slice and non-public network authentication and authorization functions; The information instructing the terminal device to perform online signing is sent by the terminal device, and the information instructing the terminal device to perform online signing is the user-hidden identifier of the terminal device; The processing unit is further configured to: Based on the user hidden identifier of the terminal device, the permanent user identifier of the terminal device is obtained, and the authentication request information includes the permanent user identifier.
8. The communication device according to claim 7, characterized in that, The domain name information in the hidden user identifier indicates the default credential domain name.
9. The communication device according to claim 7 or 8, characterized in that, The processing unit is further configured to: Based on the configuration information and the information indicating that the terminal device should perform online signing, it is determined that the terminal device should perform online signing.
10. The communication device according to claim 9, characterized in that, The configuration information includes one or more domain name information; the one or more domain name information indicates one or more default credential domain names.
11. The communication device according to claim 7 or 8, characterized in that, The processing unit is further configured to: Skip the selection of unified data management device.
12. The communication device according to claim 7 or 8, characterized in that, The authentication request information includes authentication, authorization, billing, and interoperability authentication request information.
13. A communication device, characterized in that, Includes a processor for executing a computer program or instructions in memory to cause the device to perform the method of any one of claims 1 to 6.
14. A computer-readable storage medium, characterized in that, The device contains a computer program or instructions for implementing the method of any one of claims 1 to 6.
15. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method of any one of claims 1 to 6.