Network element selection method, information transmission method, apparatus, and network element

By using AMF to select NSSAAF network elements based on information such as S-NSSAI, SUPI, and DNN, the problem of overly coarse granularity in network element selection in existing technologies is solved. This enables finer selection of network elements and AAA servers, improving the configuration efficiency of slice authentication and the effectiveness of user-level service isolation.

CN115941211BActive Publication Date: 2026-03-24CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-03
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, the granularity of network element selection is too coarse, resulting in a large workload for slice authentication configuration, difficulty in maintenance, and inability to achieve service isolation at different user levels.

Method used

By using AMF to select NSSAAF network elements based on S-NSSAI, SUPI home network identifiers, DNN, and number segment information, and obtaining the address information of the AAA server, the granularity of network element selection is refined, and service isolation at the slice level for user equipment is achieved.

Benefits of technology

It enables refined selection of network elements and AAA servers, reduces configuration workload, improves maintenance efficiency, and achieves service isolation for different user levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941211B_ABST
    Figure CN115941211B_ABST
Patent Text Reader

Abstract

The application provides a network element selection method, device and network element. The method comprises: a first network element selecting a network specific slice authentication and authorization function (NSSAAF) network element according to first information. The first information comprises at least one of the following: S-NSSAI of a network slice, a home network identifier in a SUPI (subscriber permanent identifier), a DNN (data network name), number segment information of a user equipment. The embodiment of the application refines the granularity of selecting the NSSAAF, so that service isolation on multiple NSSAAF network elements can be completed based on the slice of the user equipment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, in particular to a network element selection method, an information transmission method, a device and a network element. BACKGROUND

[0002] Slice authentication and authorization: on the basis of identity authentication completed by the operator, the access permission of the related slice of the industry customer can be flexibly controlled to meet the access control requirements of the vertical industry with high requirements for slice security.

[0003] This function requires the AMF (Access and Mobility Management Function) to interact with the AAA (Authentication, Authorization, and Accounting) server through the NSSAAF (Network Slice-Specific Authentication and Authorization) function, but currently the AMF in the existing network can only query the NSSAAF to be used by the user based on local configuration or using MCC (Mobile Country Code) + MNC (Mobile Network Code) to query the NRF (Network Repository Function), and the NSSAAF can only select the AAA-S / AAA-P based on the correspondence between the locally configured S-NSSAI (Single-Network Slice Selection Assistance Information) and the AAA-S / AAA-P.

[0004] With the increase of subsequent business volume, the number of NSSAAF deployments will also increase, and pure local configuration will greatly increase the configuration workload, and when the network element deployment changes, the related mapping relationship on all NSSAAs in the network also needs to be manually adjusted, which brings great difficulty to maintenance; if the NRF is based on MCC+MNC query, since the granularity of MCC+MNC is too coarse, it is necessary to configure the related mapping relationship on all NSSAAs in the network, which increases the configuration amount and is not conducive to completing the business configuration and isolation on each NSSAAF network element based on slices.

[0005] In addition, with the increase of subsequent traffic, the AAA-S / AAA-P deployed by a single customer will also increase, and users within the customer can also exist in different levels, i.e., two groups of users (such as gold users and ordinary users), and therefore, it is also necessary to implement the selection of different users to different AAA-S / AAA-P, so as to reduce the service configuration amount of the AAA-S / AAA-P on the one hand, and to realize the service isolation of different users on the other hand. However, the above requirements cannot be supported in the current network mechanism.

[0006] In summary, based on the local configuration or the MCC+MNC to select the NSSAAF, and / or based on the S-NSSAI to select the AAA-S / AAA-P, the granularity is too coarse, the service configuration is too complicated, and the subsequent slice authentication is affected. SUMMARY

[0007] Embodiments of the present application aim to provide a network element selection method, an information transmission method, a device and a network element, so as to solve the problem of coarse network element selection granularity affecting slice authentication in the prior art.

[0008] In order to solve the above problems, the embodiments of the present application provide a network element selection method, which is executed by a first network element, and includes:

[0009] According to the first information, a network specific slice authentication and authorization function (NSSAAF) network element is selected; wherein the first information includes at least one of the following:

[0010] S-NSSAI of a network slice;

[0011] home network identifier in a subscriber permanent identifier (SUPI);

[0012] data network name (DNN);

[0013] number segment information of a user equipment.

[0014] According to the first information, the NSSAAF network element is selected, including:

[0015] sending a first request message to a second network element, wherein the first request message includes the first information;

[0016] receiving a first response message sent by the second network element, wherein the first response message includes: full qualified domain name (FQDN) and / or address information of one or a group of NSSAAF;

[0017] selecting the NSSAAF according to the first response message and a preset selection strategy.

[0018] The number segment information of the user equipment includes at least one of the following:

[0019] Generic Public Subscription Identifier, GPSI;

[0020] Subscriber Permanent Identifier, SUPI;

[0021] Subscriber Concealed Identifier, SUCI;

[0022] External Group ID;

[0023] Internal Group ID;

[0024] Routing Identifier.

[0025] According to the first information, the method further comprises the following steps before selecting a Network Specific Slice Authentication and Authorization Function, NSSAAF, network element:

[0026] Obtaining subscription information of the user equipment from a third network element, wherein the subscription information carries target address information, and the target address information is address information of one or a group of AAA servers corresponding to a network slice.

[0027] According to the first information, the method further comprises the following steps after selecting a Network Specific Slice Authentication and Authorization Function, NSSAAF, network element:

[0028] Sending an authorization request message to the selected NSSAAF network element, wherein the authorization request message comprises the target address information.

[0029] The authorization request message further comprises at least one of the following:

[0030] GPSI;

[0031] S-NSSAI of the network slice;

[0032] Extensible Authentication Protocol, EAP, information.

[0033] The embodiment of the application further provides an information transmission method, which is executed by a second network element and comprises the following steps:

[0034] Receiving a first request message sent by a first network element, wherein the first request message comprises the first information; and the first information comprises at least one of the following:

[0035] S-NSSAI of the network slice;

[0036] Home network identifier in a Subscriber Permanent Identifier, SUPI;

[0037] Data Network Name, DNN;

[0038] Number segment information of the user equipment;

[0039] Based on the first request message, a first response message is sent to the first network element; the first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0040] The number segment information of the user equipment includes at least one of the following:

[0041] General Public User Identifier (GPSI);

[0042] User permanent identifier SUPI;

[0043] User-hidden identifier SUCI;

[0044] External group ID;

[0045] Internal group ID;

[0046] Route identifier.

[0047] This invention also provides an information transmission method, executed by a network element with network-specific slice authentication and authorization function (NSSAAF), comprising:

[0048] The system receives an authorization request message sent by a first network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0049] The authorization request message further includes at least one of the following:

[0050] GPSI;

[0051] S-NSSAI for network slicing;

[0052] Extensible Authentication Protocol (EAP) information.

[0053] The method further includes:

[0054] Based on the target address information, select the corresponding AAA server for the user equipment.

[0055] Where the AAA server includes a fourth network element and a fifth network element, the method further includes:

[0056] An AAA protocol message is sent to the fifth network element, which then forwards the AAA protocol message to the fourth network element; wherein the AAA protocol message carries the target address information.

[0057] Where the AAA server includes a fourth network element, the method further includes:

[0058] Send an AAA protocol message to the fourth network element, the AAA protocol message carrying the target address information.

[0059] The AAA protocol message further includes at least one of the following:

[0060] GPSI;

[0061] S-NSSAI for network slicing;

[0062] Extensible Authentication Protocol (EAP) information.

[0063] The target address information is obtained by the first network element from the user equipment subscription information sent by the third network element.

[0064] This invention also provides an information transmission method, executed by a first network element, comprising:

[0065] Send an authorization request message to the NSSAAF network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0066] The authorization request message further includes at least one of the following:

[0067] GPSI;

[0068] S-NSSAI for network slicing;

[0069] Extensible Authentication Protocol (EAP) information.

[0070] Before sending the authorization request message to the NSSAAF network element, the method further includes:

[0071] The user equipment's subscription information is obtained from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0072] This invention also provides an information storage method, executed by a third network element, comprising:

[0073] The system stores user equipment subscription information, which includes target address information. The target address information is the address information of one or a group of AAA servers corresponding to a network slice.

[0074] The method further includes:

[0075] Send the user equipment's subscription information to the first network element.

[0076] This invention also provides a network element selection device, applied to a first network element, comprising:

[0077] The selection module is used to select a network element for network-specific slice authentication and authorization (NSSAAF) based on first information; wherein the first information includes at least one of the following:

[0078] S-NSSAI for network slicing;

[0079] The home network identifier in the user's permanent identifier SUPI;

[0080] Data network name: DNN;

[0081] User equipment number segment information.

[0082] This invention also provides a first network element, including a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, and the processor is used to perform the following operations:

[0083] Based on the first information, select a network element for network-specific slice authentication and authorization (NSSAAF); wherein the first information includes at least one of the following:

[0084] S-NSSAI for network slicing;

[0085] The home network identifier in the user's permanent identifier SUPI;

[0086] Data network name: DNN;

[0087] User equipment number segment information.

[0088] This invention also provides an information transmission device applied to a second network element, comprising:

[0089] A first receiving module is configured to receive a first request message sent by a first network element, the first request message including the first information; the first information including at least one of the following:

[0090] S-NSSAI for network slicing;

[0091] The home network identifier in the user's permanent identifier SUPI;

[0092] Data network name: DNN;

[0093] User equipment number segment information;

[0094] The first sending module is configured to send a first response message to the first network element according to the first request message; the first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0095] This invention also provides a second network element, including a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, and the processor is used to perform the following operations:

[0096] Receive a first request message sent by a first network element, the first request message including the first information; the first information includes at least one of the following:

[0097] S-NSSAI for network slicing;

[0098] The home network identifier in the user's permanent identifier SUPI;

[0099] Data network name: DNN;

[0100] User equipment number segment information;

[0101] Based on the first request message, a first response message is sent to the first network element; the first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0102] This invention also provides an information transmission device applied to an NSSAAF network element, comprising:

[0103] The second receiving module is used to receive an authorization request message sent by the first network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0104] This invention also provides an NSSAAF network element, including a processor and a transceiver. The transceiver receives and transmits data under the control of the processor, and the processor is used to perform the following operations:

[0105] The system receives an authorization request message sent by a first network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0106] This invention also provides an information transmission device applied to a first network element, comprising:

[0107] The second sending module is used to send an authorization request message to the NSSAAF network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0108] This invention also provides a first network element, including a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, and the processor is used to perform the following operations:

[0109] Send an authorization request message to the NSSAAF network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0110] This invention also provides an information determination device applied to a third network element, comprising:

[0111] The storage module is used to store the subscription information of the user equipment. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0112] This invention also provides a third network element, including a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, and the processor is used to perform the following operations:

[0113] The system stores user equipment subscription information, which includes target address information. The target address information is the address information of one or a group of AAA servers corresponding to a network slice.

[0114] This invention also provides a network element, including a memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the network element selection method as described above; or when the processor executes the program, it implements the information transmission method or information determination method as described above.

[0115] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps in the network element selection method described above; or, when executed by a processor, implements the information transmission method or information determination method described above.

[0116] The above-described technical solution of the present invention has at least the following beneficial effects:

[0117] In the network element selection method, information transmission method, apparatus and network element of the present invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN and number segment information, which refines the granularity of NSSAAF selection, thereby enabling service isolation on multiple NSSAAF network elements based on the user equipment slice. Attached Figure Description

[0118] Figure 1 This diagram illustrates the steps of the network element selection method provided in this embodiment of the invention.

[0119] Figure 2 A schematic diagram illustrating the network element interaction of the network element selection method provided in this embodiment of the invention;

[0120] Figure 3 This represents one of the steps of the information transmission method provided in an embodiment of the present invention;

[0121] Figure 4 This is the second flowchart illustrating the steps of the information transmission method provided in this embodiment of the invention.

[0122] Figure 5 This is the third flowchart illustrating the steps of the information transmission method provided in this embodiment of the invention.

[0123] Figure 6 This diagram illustrates the principle of the slice authentication process provided in this embodiment of the invention.

[0124] Figure 7 This is a schematic diagram of the network element selection device provided in an embodiment of the present invention;

[0125] Figure 8 This represents one of the structural schematic diagrams of the first network element provided in an embodiment of the present invention;

[0126] Figure 9 This is a schematic diagram of the structure of an information transmission device provided in an embodiment of the present invention;

[0127] Figure 10 This is a schematic diagram of the structure of the second network element provided in an embodiment of the present invention;

[0128] Figure 11 This is a second schematic diagram illustrating the structure of the information transmission device provided in an embodiment of the present invention;

[0129] Figure 12 This is a schematic diagram of the structure of the NSSAAF network element provided in an embodiment of the present invention;

[0130] Figure 13 This is the third schematic diagram illustrating the structure of the information transmission device provided in this embodiment of the invention.

[0131] Figure 14 This is the second schematic diagram showing the structure of the first network element provided in the embodiment of the present invention. Detailed Implementation

[0132] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.

[0133] like Figure 1As shown, this embodiment of the invention provides a network element selection method, executed by a first network element, including:

[0134] Step 101: Select a network element for Network Specific Slice Authentication and Authorization Function (NSSAAF) based on the first information; wherein the first information includes at least one of the following:

[0135] S-NSSAI for network slicing;

[0136] The home network identifier in the user's permanent identifier SUPI;

[0137] Data Network Name (DNN);

[0138] User equipment number segment information.

[0139] Optionally, the first network element mentioned in the embodiments of the present invention includes: an AMF (Access and Mobility Management Function) network element, or an SMF (Session Management Function) network element, or other network elements with management functions.

[0140] In at least one embodiment of the present invention, step 101 includes:

[0141] Send a first request message to the second network element, the first request message including the first information; optionally, the first request message is used to request the second network element to query local information;

[0142] The second network element receives a first response message sent by the second network element. The first response message includes: the FQDN and / or address information of one or a group of NSSAAFs. Optionally, the second network element queries local information based on the first request message to obtain the FQDN and / or address information of one or a group of NSSAAFs corresponding to the first information.

[0143] Based on the first response message and the preset selection strategy, NSSAAF is selected.

[0144] Optionally, the second network element mentioned in the embodiments of the present invention includes: an NRF (NF Repository Function) network element, or an SCP (Service Control Point) network element, or other network elements with storage functions.

[0145] For example, the address information of NSSAAF includes: the IP address of NSSAAF.

[0146] Optionally, the first request message can be called an Nnrf_NFDiscovery_Request message; correspondingly, the first response message can be called an Nnrf_NFDiscovery_Reponse message.

[0147] As an optional embodiment, the number segment information of the user equipment includes at least one of the following:

[0148] Generic Public Subscription Identifier (GPSI);

[0149] User Permanent Identifier (SUPIO);

[0150] User-hidden identifier SUCI (Subscription Concealed Identifier);

[0151] External Group ID;

[0152] Internal Group ID;

[0153] Routing Indicator.

[0154] For example, such as Figure 2 The following is the selection scheme for NSSAAF based on the first piece of information:

[0155] Step 21: AMF sends a first request message to NRF to request NRF to query local information, which carries S-NSSAI, PLMN ID of the SUPI, DNN, and number segment information;

[0156] Step 22: NRF returns a first response message to AMF, which includes one or a group of NSSAAF FQDNs or IP addresses;

[0157] Step 23: AMF selects NSSAAF based on the local selection strategy.

[0158] In at least one embodiment of the present invention, prior to step 101, the method further includes:

[0159] The user equipment's subscription information is obtained from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0160] In this embodiment of the invention, the third network element adds target address information to the subscription information. The network slice is identified by S-NSSAI, meaning the address information of the AAA server corresponding to S-NSSAI is added to the subscription information. The third network element returns the target address information related to the slice to the first network element. This target address information is also called NSSAAAaaAddress.

[0161] Optionally, the third network element mentioned in the embodiments of the present invention includes: a UDM (Unified Data Management) network element, or a UDR (Unified Data Repository) network element, or an AUSF (Authentication Server Function) network element, or other network elements capable of storing user equipment subscription information.

[0162] After the user equipment passes the initial authentication, the AMF determines whether to initiate slice-level authentication based on the user equipment's subscription information obtained from the UDM or AUSF. This subscription information carries the address information of the AAA server corresponding to the slice.

[0163] Following the previous example, in at least one embodiment of the present invention, after step 101, the method further includes:

[0164] An authorization request message (which may be referred to as Nnssaaf_NSSAA_Authenticate Request) is sent to the selected NSSAAF network element. The authorization request message includes the target address information. Optionally, this authorization request message is used to trigger the slice authentication process.

[0165] Optionally, the authorization request message may further include at least one of the following:

[0166] General Public User Identifier (GPSI);

[0167] S-NSSAI for network slicing;

[0168] Extensible Authentication Protocol (EAP) information.

[0169] Furthermore, the NSSAAF network element selects the corresponding AAA server for the user based on the target address information in the authorization request message, and executes the subsequent slice secondary authentication process.

[0170] In summary, in this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection. This allows for service isolation across multiple NSSAAF network elements based on user equipment slices. Furthermore, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, further refining the granularity of AAA server selection and enabling the routing of users of different levels to different AAA servers.

[0171] like Figure 3 As shown, this embodiment of the invention also provides an information transmission method, executed by a second network element, comprising:

[0172] Step 301: Receive a first request message sent by the first network element, the first request message including the first information; the first information includes at least one of the following:

[0173] S-NSSAI for network slicing;

[0174] The home network identifier in the user's permanent identifier SUPI;

[0175] Data Network Name (DNN);

[0176] User equipment number segment information;

[0177] Step 302: Based on the first request message, send a first response message to the first network element; the first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0178] Optionally, the first request message is used to request the NRF to query local information; the second network element queries the local information based on the first request message to obtain one or a group of NSSAAF FQDNs and / or address information corresponding to the first information.

[0179] For example, the address information of NSSAAF includes: the IP address of NSSAAF.

[0180] Optionally, the first network element mentioned in the embodiments of the present invention includes: an AMF (Access and Mobility Management Function) network element, or an SMF (Session Management Function) network element, or other network elements with management functions.

[0181] Optionally, the first request message can be called an Nnrf_NFDiscovery_Request message; correspondingly, the first response message can be called an Nnrf_NFDiscovery_Reponse message.

[0182] As an optional embodiment, the number segment information of the user equipment includes at least one of the following:

[0183] Generic Public Subscription Identifier (GPSI);

[0184] User Permanent Identifier (SUPIO);

[0185] User-hidden identifier SUCI (Subscription Concealed Identifier);

[0186] External Group ID;

[0187] Internal Group ID;

[0188] Routing Indicator.

[0189] In summary, in this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection and enabling service isolation on multiple NSSAAF network elements based on user equipment slices.

[0190] like Figure 4 As shown, this embodiment of the invention also provides an information transmission method, executed by a network element with network-specific slice authentication and authorization function (NSSAAF), including:

[0191] Step 401: Receive an authorization request message (referred to as Nnssaaf_NSSAA_Authenticate Request) sent by the first network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment. Optionally, this authorization request message is used to trigger the slice authentication process.

[0192] Optionally, this target address information is also referred to as NSSAAAaaAddress.

[0193] Optionally, the authorization request message may further include at least one of the following:

[0194] General Public User Identifier (GPSI);

[0195] S-NSSAI for network slicing;

[0196] Extensible Authentication Protocol (EAP) information.

[0197] Optionally, the first network element mentioned in the embodiments of the present invention includes: an AMF (Access and Mobility Management Function) network element, or an SMF (Session Management Function) network element, or other network elements with management functions.

[0198] The target address information is obtained by the first network element from the user equipment subscription information sent by the third network element.

[0199] Optionally, the third network element mentioned in the embodiments of the present invention includes: a UDM (Unified Data Management) network element, or a UDR (Unified Data Repository) network element, or an AUSF (Authentication Server Function) network element, or other network elements capable of storing user equipment subscription information.

[0200] Furthermore, in the above embodiments of the present invention, the method further includes:

[0201] Based on the target address information, select the corresponding AAA server for the user equipment.

[0202] In other words, the NSSAAF network element selects the corresponding AAA server for the user based on the target address information in the authorization request message and executes the subsequent slice secondary authentication process.

[0203] In the above embodiments of the present invention, when the AAA server includes a fourth network element and a fifth network element, the method further includes:

[0204] An AAA protocol message is sent to the fifth network element, which then forwards the AAA protocol message to the fourth network element; wherein the AAA protocol message carries the target address information.

[0205] The fourth network element is the AAA-S server, which is the AAA server that provides services, and can also be directly called the AAA server; the fifth network element is the AAA-P server, which is the AAA server that acts as a proxy.

[0206] Alternatively, if the AAA server includes a fourth network element (in other words, if it does not include a proxy AAA server), the method further includes:

[0207] Send an AAA protocol message to the fourth network element, the AAA protocol message carrying the target address information.

[0208] The fourth network element is the AAA-S server, which is the AAA server or simply the AAA server.

[0209] As an optional embodiment, the AAA protocol message further includes at least one of the following:

[0210] GPSI;

[0211] S-NSSAI for network slicing;

[0212] Extensible Authentication Protocol (EAP) information.

[0213] In summary, in this embodiment of the invention, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0214] like Figure 5 As shown, this embodiment of the invention also provides an information transmission method, executed by a first network element, comprising:

[0215] Step 501: Send an authorization request message (which may be called Nnssaaf_NSSAA_Authenticate Request) to the NSSAAF network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0216] Optionally, this authorization request message can be used to trigger the slice authentication process.

[0217] Optionally, the authorization request message may further include at least one of the following:

[0218] General Public User Identifier (GPSI);

[0219] S-NSSAI for network slicing;

[0220] Extensible Authentication Protocol (EAP) information.

[0221] Furthermore, the NSSAAF network element selects the corresponding AAA server for the user based on the target address information in the authorization request message, and executes the subsequent slice secondary authentication process.

[0222] In at least one embodiment of the present invention, before sending an authorization request message to the NSSAAF network element, the method further includes:

[0223] The user equipment's subscription information is obtained from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0224] In this embodiment of the invention, the third network element adds target address information to the subscription information. The network slice is identified by S-NSSAI, meaning the address information of the AAA server corresponding to S-NSSAI is added to the subscription information. The third network element returns the target address information related to the slice to the first network element. This target address information is also called NSSAAAaaAddress.

[0225] After the user equipment passes the initial authentication, the AMF determines whether to initiate slice-level authentication based on the user equipment's subscription information obtained from the UDM or AUSF. This subscription information carries the address information of the AAA server corresponding to the slice.

[0226] In summary, in this embodiment of the invention, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0227] This invention also provides an information determination method, executed by a third party, characterized in that it includes:

[0228] The system stores user equipment subscription information, which includes target address information. The target address information is the address information of one or a group of AAA servers corresponding to a network slice.

[0229] Optionally, the third network element mentioned in the embodiments of the present invention includes: a UDM (Unified Data Management) network element, or a UDR (Unified Data Repository) network element, or an AUSF (Authentication Server Function) network element, or other network elements capable of storing user equipment subscription information.

[0230] Optionally, in this embodiment of the invention, the user equipment's subscription information carries not only the relevant information in the prior art, but also the address information of one or a group of AAA servers corresponding to the network slice; for example, the network slice may be a network slice subscribed to by the user.

[0231] In at least one embodiment of the present invention, the method further includes:

[0232] The user equipment's subscription information is sent to the first network element. This allows the first network element to transmit the address information of the AAA server corresponding to each network slice obtained from the subscription information to the NSSAAF, thereby assisting the NSSAAF in selecting the AAA server.

[0233] In summary, in this embodiment of the invention, UDM or AUSFU sends the subscription information to AMF. AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and passes it to NSSAAF through relevant messages. NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0234] like Figure 6 As shown, the slice authentication process provided in this embodiment of the invention is as follows:

[0235] Step 61: The UE initiates a registration request, carrying the requested NSSAI and UE capability information;

[0236] Step 62, UE's first authentication is successful;

[0237] Step 63: The AMF determines whether to initiate slice-level authentication based on the contract information, which includes the address information of one or a group of AAA servers corresponding to the network slice.

[0238] Step 64, registration successful, carrying the allowed NSSAI and the extended NSSAI;

[0239] Step 65: AMF queries NRF for NSSAAF based on the first information; the first information includes at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information;

[0240] Step 66: Perform non-access stratum mobility management transmission;

[0241] Step 67: AMF sends an authorization request message to NSSAAF. The authorization request message carries target address information, EAP information, GPSI, S-NSSAI, etc. The target address information is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0242] Step 68: NSSAAF selects the corresponding AAA server based on the target address information;

[0243] Step 69: AMF enables slice-based EAP authentication between UE and AAA-S.

[0244] Step 70: Based on the authentication result, the AMF initiates a UE configuration update to update the Allowed NSSAI.

[0245] In this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection. This allows for service isolation across multiple NSSAAF network elements based on user equipment slices. Furthermore, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, further refining the granularity of AAA server selection and enabling the routing of users of different levels to different AAA servers.

[0246] like Figure 7 As shown, this embodiment of the invention also provides a network element selection device, applied to a first network element, comprising:

[0247] Selection module 701 is used to select a network element for network-specific slice authentication and authorization function (NSSAAF) based on first information; wherein the first information includes at least one of the following:

[0248] S-NSSAI for network slicing;

[0249] The home network identifier in the user's permanent identifier SUPI;

[0250] Data network name: DNN;

[0251] User equipment number segment information.

[0252] As an optional embodiment, the selection module includes:

[0253] The first submodule is used to send a first request message to the second network element, the first request message including the first information;

[0254] The second submodule is used to receive a first response message sent by the second network element. The first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0255] The third submodule is used to select NSSAAF based on the first response message and the preset selection strategy.

[0256] As an optional embodiment, the number segment information of the user equipment includes at least one of the following:

[0257] General Public User Identifier (GPSI);

[0258] User permanent identifier SUPI;

[0259] User-hidden identifier SUCI;

[0260] External group ID;

[0261] Internal group ID;

[0262] Route identifier.

[0263] As an optional embodiment, the apparatus further includes:

[0264] The acquisition module is used to acquire the subscription information of the user equipment from the third AUSF network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0265] As an optional embodiment, the apparatus further includes:

[0266] The third sending module is used to send an authorization request message to the selected NSSAAF network element, the authorization request message including the target address information.

[0267] As an optional embodiment, the authorization request message further includes at least one of the following:

[0268] GPSI;

[0269] S-NSSAI for network slicing;

[0270] Extensible Authentication Protocol (EAP) information.

[0271] In this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection. This allows for service isolation across multiple NSSAAF network elements based on user equipment slices. Furthermore, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, further refining the granularity of AAA server selection and enabling the routing of users of different levels to different AAA servers.

[0272] It should be noted that the network element selection device provided in the embodiments of the present invention is a device capable of executing the above-described network element selection method. Therefore, all embodiments of the above-described network element selection method are applicable to this device and can achieve the same or similar beneficial effects.

[0273] like Figure 8 As shown, this embodiment of the invention also provides a first network element, including a processor 800 and a transceiver 810. The transceiver 810 receives and transmits data under the control of the processor 800, and the processor 800 is used to perform the following operations:

[0274] Based on the first information, select a network element for network-specific slice authentication and authorization (NSSAAF); wherein the first information includes at least one of the following:

[0275] S-NSSAI for network slicing;

[0276] The home network identifier in the user's permanent identifier SUPI;

[0277] Data network name: DNN;

[0278] User equipment number segment information.

[0279] As an optional embodiment, the processor is also configured to perform the following operations:

[0280] Send a first request message to the second network element, the first request message including the first information;

[0281] Receive a first response message sent by the second network element, the first response message including: one or a group of NSSAAF FQDN and / or address information;

[0282] Based on the first response message and the preset selection strategy, NSSAAF is selected.

[0283] As an optional embodiment, the number segment information of the user equipment includes at least one of the following:

[0284] General Public User Identifier (GPSI);

[0285] User permanent identifier SUPI;

[0286] User-hidden identifier SUCI;

[0287] External group ID;

[0288] Internal group ID;

[0289] Route identifier.

[0290] As an optional embodiment, the processor is also configured to perform the following operations:

[0291] The user equipment's subscription information is obtained from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0292] As an optional embodiment, the processor is also configured to perform the following operations:

[0293] Send an authorization request message to the selected NSSAAF network element, the authorization request message including the target address information.

[0294] As an optional embodiment, the authorization request message further includes at least one of the following:

[0295] GPSI;

[0296] S-NSSAI for network slicing;

[0297] Extensible Authentication Protocol (EAP) information.

[0298] In this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection. This allows for service isolation across multiple NSSAAF network elements based on user equipment slices. Furthermore, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, further refining the granularity of AAA server selection and enabling the routing of users of different levels to different AAA servers.

[0299] It should be noted that the first network element provided in the embodiments of the present invention is a network element capable of performing the above-described network element selection method. Therefore, all embodiments of the above-described network element selection method are applicable to the first network element and can achieve the same or similar beneficial effects.

[0300] like Figure 9 As shown, this embodiment of the invention also provides an information transmission device applied to a second network element, comprising:

[0301] The first receiving module 901 is configured to receive a first request message sent by a first network element, the first request message including the first information; the first information including at least one of the following:

[0302] S-NSSAI for network slicing;

[0303] The home network identifier in the user's permanent identifier SUPI;

[0304] Data network name: DNN;

[0305] User equipment number segment information;

[0306] The first sending module 902 is configured to send a first response message to the first network element according to the first request message; the first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0307] As an optional embodiment, the number segment information of the user equipment includes at least one of the following:

[0308] General Public User Identifier (GPSI);

[0309] User permanent identifier SUPI;

[0310] User-hidden identifier SUCI;

[0311] External group ID;

[0312] Internal group ID;

[0313] Route identifier.

[0314] In this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection and enabling service isolation on multiple NSSAAF network elements based on user equipment slices.

[0315] It should be noted that the information transmission device provided in the embodiments of the present invention is a device capable of executing the above-described information transmission method. Therefore, all embodiments of the above-described information transmission method are applicable to this device and can achieve the same or similar beneficial effects.

[0316] like Figure 10 As shown, this embodiment of the invention also provides a second network element, including a processor 1000 and a transceiver 1010. The transceiver 1010 receives and transmits data under the control of the processor 1000, and the processor 1000 is used to perform the following operations:

[0317] Receive a first request message sent by a first network element, the first request message including the first information; the first information includes at least one of the following:

[0318] S-NSSAI for network slicing;

[0319] The home network identifier in the user's permanent identifier SUPI;

[0320] Data network name: DNN;

[0321] User equipment number segment information;

[0322] Based on the first request message, a first response message is sent to the first network element; the first response message includes: one or a group of NSSAAF FQDN and / or address information.

[0323] As an optional embodiment, the number segment information of the user equipment includes at least one of the following:

[0324] General Public User Identifier (GPSI);

[0325] User permanent identifier SUPI;

[0326] User-hidden identifier SUCI;

[0327] External group ID;

[0328] Internal group ID;

[0329] Route identifier.

[0330] In this embodiment of the invention, the AMF obtains the NSSAAF to be used by the current user equipment based on at least one of S-NSSAI, the home network identifier in SUPI, DNN, and number segment information, thus refining the granularity of NSSAAF selection and enabling service isolation on multiple NSSAAF network elements based on user equipment slices.

[0331] It should be noted that the second network element provided in the embodiments of the present invention is a second network element capable of performing the above information transmission method. Therefore, all embodiments of the above information transmission method are applicable to the second network element and can achieve the same or similar beneficial effects.

[0332] like Figure 11 As shown, this embodiment of the invention also provides an information transmission device applied to an NSSAAF network element, comprising:

[0333] The second receiving module 1100 is used to receive an authorization request message sent by the first network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0334] As an optional embodiment, the authorization request message further includes at least one of the following:

[0335] GPSI;

[0336] S-NSSAI for network slicing;

[0337] Extensible Authentication Protocol (EAP) information.

[0338] As an optional embodiment, the apparatus further includes:

[0339] The second selection module is used to select the corresponding AAA server for the user equipment based on the target address information.

[0340] As an optional embodiment, when the AAA server includes a fourth network element and a fifth network element, the apparatus further includes:

[0341] The fourth sending module is used to send an AAA protocol message to the fifth network element, and the fifth network element forwards the AAA protocol message to the fourth network element; wherein the AAA protocol message carries the target address information.

[0342] As an optional embodiment, when the AAA server includes a fourth network element, the method further includes:

[0343] The fifth sending module is used to send an AAA protocol message to the fourth network element, wherein the AAA protocol message carries the target address information.

[0344] As an optional embodiment, the AAA protocol message further includes at least one of the following:

[0345] GPSI;

[0346] S-NSSAI for network slicing;

[0347] Extensible Authentication Protocol (EAP) information.

[0348] In this embodiment of the invention, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0349] It should be noted that the information transmission device provided in the embodiments of the present invention is a device capable of executing the above-described information transmission method. Therefore, all embodiments of the above-described information transmission method are applicable to this device and can achieve the same or similar beneficial effects.

[0350] like Figure 12 As shown, this embodiment of the invention also provides an NSSAAF network element, including a processor 1200 and a transceiver 1210. The transceiver 1210 receives and transmits data under the control of the processor 1200, and the processor 1200 is used to perform the following operations:

[0351] The system receives an authorization request message sent by a first network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0352] As an optional embodiment, the authorization request message further includes at least one of the following:

[0353] GPSI;

[0354] S-NSSAI for network slicing;

[0355] Extensible Authentication Protocol (EAP) information.

[0356] As an optional embodiment, the processor is also configured to perform the following operations:

[0357] Based on the target address information, select the corresponding AAA server for the user equipment.

[0358] As an optional embodiment, when the AAA server includes a fourth network element and a fifth network element, the processor is further configured to perform the following operations:

[0359] An AAA protocol message is sent to the fifth network element, which then forwards the AAA protocol message to the fourth network element; wherein the AAA protocol message carries the target address information.

[0360] As an optional embodiment, when the AAA server includes a fourth network element, the processor is also configured to perform the following operations:

[0361] Send an AAA protocol message to the fourth network element, the AAA protocol message carrying the target address information.

[0362] As an optional embodiment, the AAA protocol message further includes at least one of the following:

[0363] GPSI;

[0364] S-NSSAI for network slicing;

[0365] Extensible Authentication Protocol (EAP) information.

[0366] In this embodiment of the invention, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0367] It should be noted that the NSSAAF network element provided in the embodiments of the present invention is an NSSAAF network element capable of performing the above information transmission method. Therefore, all embodiments of the above information transmission method are applicable to the NSSAAF network element and can achieve the same or similar beneficial effects.

[0368] like Figure 13 As shown, this embodiment of the invention also provides an information transmission device applied to a first network element, comprising:

[0369] The second sending module 1300 is used to send an authorization request message to the NSSAAF network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0370] As an optional embodiment, the authorization request message further includes at least one of the following:

[0371] GPSI;

[0372] S-NSSAI for network slicing;

[0373] Extensible Authentication Protocol (EAP) information.

[0374] As an optional embodiment, the apparatus further includes:

[0375] The information acquisition module is used to acquire the user equipment's subscription information from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0376] In this embodiment of the invention, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0377] It should be noted that the information transmission device provided in the embodiments of the present invention is a device capable of executing the above-described information transmission method. Therefore, all embodiments of the above-described information transmission method are applicable to this device and can achieve the same or similar beneficial effects.

[0378] like Figure 14 As shown, this embodiment of the invention also provides a first network element, including a processor 1400 and a transceiver 1410. The transceiver 1410 receives and transmits data under the control of the processor 1400, and the processor 1400 is used to perform the following operations:

[0379] Send an authorization request message to the NSSAAF network element. The authorization request message includes target address information, which is the address information of one or a group of AAA servers corresponding to the network slice requested by the user equipment.

[0380] As an optional embodiment, the authorization request message further includes at least one of the following:

[0381] GPSI;

[0382] S-NSSAI for network slicing;

[0383] Extensible Authentication Protocol (EAP) information.

[0384] As an optional embodiment, the processor is also configured to perform the following operations:

[0385] The user equipment's subscription information is obtained from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0386] In this embodiment of the invention, the AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and transmits it to the NSSAAF through relevant messages. The NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0387] It should be noted that the first network element provided in the embodiments of the present invention is a network element capable of executing the above information transmission method. Therefore, all embodiments of the above information transmission method are applicable to the first network element and can achieve the same or similar beneficial effects.

[0388] This invention also provides an information determination device applied to a third network element, comprising:

[0389] The storage module is used to store the subscription information of the user equipment. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

[0390] As an optional embodiment, the apparatus further includes:

[0391] The fifth sending module is used to send the user equipment's subscription information to the first network element.

[0392] In this embodiment of the invention, UDM or AUSFU sends the subscription information to AMF. AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and passes it to NSSAAF through relevant messages. NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0393] It should be noted that the information storage device provided in the embodiments of the present invention is a device capable of executing the above-described information storage method. Therefore, all embodiments of the above-described information storage method are applicable to this device and can achieve the same or similar beneficial effects.

[0394] This invention also provides a third network element, including a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, and the processor is used to perform the following operations:

[0395] The system stores user equipment subscription information, which includes target address information. The target address information is the address information of one or a group of AAA servers corresponding to a network slice.

[0396] As an optional embodiment, the processor is also configured to perform the following operations:

[0397] Send the user equipment's subscription information to the first network element.

[0398] In this embodiment of the invention, UDM or AUSFU sends the subscription information to AMF. AMF obtains the address information of the AAA server corresponding to each slice from the subscription information and passes it to NSSAAF through relevant messages. NSSAAF can select the corresponding AAA server based on the received AAA server address information, which refines the granularity of AAA server selection and enables the diversion of users of different levels to different AAA servers.

[0399] It should be noted that the third network element provided in the embodiments of the present invention is a third network element capable of executing the above information storage method. Therefore, all embodiments of the above information storage method are applicable to the third network element and can achieve the same or similar beneficial effects.

[0400] This invention also provides a network element, which is a first network element, a second network element, or an NSSAAF network element, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the various processes in the network element selection method embodiment, the information transmission method embodiment, or the information storage method embodiment as described above, and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0401] This invention also provides a computer-readable storage medium storing a computer program. When executed by a processor, this program implements the various processes in the network element selection method embodiment, the information transmission method embodiment, or the information storage method embodiment described above, and achieves the same technical effect. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.

[0402] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0403] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 A device for one or more processes and / or the functions specified in one or more boxes.

[0404] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce a paper article including an instruction means, the instruction means being implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0405] These computer program instructions can also be loaded onto a computer or other programmable data processing equipment, causing the computer or other programmable equipment to perform a series of operational steps to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0406] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A network element selection method, executed by a first network element, characterized in that, include: Based on the first information, select a network element for network-specific slice authentication and authorization (NSSAAF); wherein the first information includes at least one of the following: Single network slice selection auxiliary information (S-NSSAI) for network slices; The home network identifier in the user's permanent identifier SUPI; Data network name: DNN; User equipment number segment information; The step of selecting NSSAAF network elements based on the first information includes: Send a first request message to the second network element, the first request message including the first information; Receive a first response message sent by the second network element, the first response message including: one or a group of NSSAAF fully qualified domain name (FQDN) and / or address information; Based on the first response message and the preset selection strategy, NSSAAF is selected; The first network element includes an Access and Mobility Management Function (AMF), and the second network element includes a Network Storage Function (NRF) network element.

2. The method according to claim 1, characterized in that, The number segment information of the user equipment includes at least one of the following: General Public User Identifier (GPSI); User permanent identifier SUPI; User-hidden identifier SUCI; External group ID; Internal group ID; Route identifier.

3. The method according to claim 1, characterized in that, Before selecting the NSSAAF network element based on the first information, the method further includes: The user equipment's subscription information is obtained from the third network element. The subscription information carries target address information, which is the address information of one or a group of AAA servers corresponding to the network slice.

4. The method according to claim 3, characterized in that, After selecting the NSSAAF network element, the method further includes: Send an authorization request message to the selected NSSAAF network element, the authorization request message including the target address information.

5. The method according to claim 4, characterized in that, The authorization request message also includes at least one of the following: GPSI; S-NSSAI for network slicing; Extensible Authentication Protocol (EAP) information.

6. An information transmission method, executed by a second network element, characterized in that, include: Receive a first request message sent by a first network element, the first request message including first information; the first information includes at least one of the following: Network Slicing S-NSSAI; The home network identifier in the user's permanent identifier SUPI; Data network name: DNN; User equipment number segment information; Based on the first request message, send a first response message to the first network element; The first response message includes: one or a set of NSSAAF FQDN and / or address information; wherein, the first response message is used to select an NSSAAF; The first network element includes an Access and Mobility Management Function (AMF), and the second network element includes a Network Storage Function (NRF) network element.

7. The method according to claim 6, characterized in that, The number segment information of the user equipment includes at least one of the following: General Public User Identifier (GPSI); User permanent identifier SUPI; User-hidden identifier SUCI; External group ID; Internal group ID; Route identifier.

8. A network element selection device, applied to a first network element, characterized in that, include: The selection module is used to select a network element for network-specific slice authentication and authorization (NSSAAF) based on first information; wherein the first information includes at least one of the following: S-NSSAI for network slicing; The home network identifier in the user's permanent identifier SUPI; Data network name: DNN; User equipment number segment information; The selection module includes: The first submodule is used to send a first request message to the second network element, the first request message including the first information; The second submodule is used to receive a first response message sent by the second network element. The first response message includes: one or a group of NSSAAF FQDN and / or address information. The third submodule is used to select NSSAAF based on the first response message and the preset selection strategy; The first network element includes an Access and Mobility Management Function (AMF), and the second network element includes a Network Storage Function (NRF) network element.

9. A first network element, comprising a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, characterized in that, The processor is used to perform the following operations: Based on the first information, select a network element for network-specific slice authentication and authorization (NSSAAF); wherein the first information includes at least one of the following: S-NSSAI for network slicing; The home network identifier in the user's permanent identifier SUPI; Data network name: DNN; User equipment number segment information; The step of selecting NSSAAF network elements based on the first information includes: Send a first request message to the second network element, the first request message including the first information; Receive a first response message sent by the second network element, the first response message including: one or a group of NSSAAF fully qualified domain name (FQDN) and / or address information; Based on the first response message and the preset selection strategy, NSSAAF is selected; The first network element includes an Access and Mobility Management Function (AMF), and the second network element includes a Network Storage Function (NRF) network element.

10. An information transmission device applied to a second network element, characterized in that, include: A first receiving module is configured to receive a first request message sent by a first network element, the first request message including first information; the first information including at least one of the following: S-NSSAI for network slicing; The home network identifier in the user's permanent identifier SUPI; Data network name: DNN; User equipment number segment information; The first sending module is configured to send a first response message to the first network element according to the first request message; The first response message includes: one or a set of NSSAAF FQDN and / or address information; wherein, the first response message is used to select an NSSAAF; The first network element includes an Access and Mobility Management Function (AMF), and the second network element includes a Network Storage Function (NRF) network element.

11. A second network element, comprising a processor and a transceiver, wherein the transceiver receives and transmits data under the control of the processor, characterized in that, The processor is used to perform the following operations: Receive a first request message sent by a first network element, the first request message including first information; the first information includes at least one of the following: S-NSSAI for network slicing; The home network identifier in the user's permanent identifier SUPI; Data network name: DNN; User equipment number segment information; Based on the first request message, send a first response message to the first network element; The first response message includes: one or a set of NSSAAF FQDN and / or address information; wherein, the first response message is used to select an NSSAAF; The first network element includes an Access and Mobility Management Function (AMF), and the second network element includes a Network Storage Function (NRF) network element.

12. A network element, comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that, When the processor executes the program, it implements the network element selection method as described in any one of claims 1-5; or when the processor executes the program, it implements the information transmission method as described in any one of claims 6-7.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the network element selection method as described in any one of claims 1-5; or when the program is executed by the processor, it implements the information transmission method as described in any one of claims 6-7.

Citation Information

Patent Citations

  • Communication method and network element

    CN112291784A