Slice authentication and authorization method, apparatus, terminal and network device

By having the terminal proactively initiate slice authentication and authorization requests, the unavailability of slice services caused by slice authentication failures or user identity verification updates is resolved, thereby improving network service performance.

CN115996377BActive Publication Date: 2025-11-21CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111213875.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-19
Publication Date
2025-11-21
Estimated Expiration
2041-10-19

AI Technical Summary

Technical Problem

During the slice authentication and authorization process, slice authentication failure or user identity verification updates can render the slice service unavailable, impacting network service performance.

Method used

When the terminal detects an update to the user's identity certificate, it proactively initiates a slice authentication and authorization request to the network device, carrying the updated user identity certificate information. The network device then re-processes the slice authentication and authorization.

Benefits of technology

This avoids the problem of slice service unavailability caused by authentication failure during slice authentication and authorization, and improves the performance of slice service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115996377B_ABST
    Figure CN115996377B_ABST
Patent Text Reader

Abstract

The application provides a slice authentication and authorization method and device, a terminal and network equipment, and relates to the technical field of communication. The method comprises the following steps: if it is detected that the user identity certificate of a first slice is updated, sending request information for slice authentication and authorization of the first slice to the network equipment; wherein the first slice is a slice that has obtained a slice authentication and authorization result. The scheme of the application solves the problem that, in the current slice authentication and authorization process, when slice authentication fails or the user identity certificate of a slice is updated, the slice service becomes unavailable, and the network service performance is affected.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, in particular to a slice authentication and authorization method and device, a terminal and network equipment. BACKGROUND

[0002] Network slicing is a new capability defined by 5G standalone (SA), which is to provide end-to-end logical "dedicated network" based on unified network facilities. Through flexible allocation of network resources and flexible combination of network capabilities, a virtual network provides customized network services for different application scenarios based on a network.

[0003] Network slice-specific authentication and authorization is a security authentication method for slice services, which verifies whether the terminal has the qualification to use a certain slice service. This authentication method is mainly for external services (such as application business providers using operator slice services). In the current slice authentication and authorization process, when a certain slice fails in the slice authentication and authorization process, the slice service is unavailable; or when the user identity of the slice is updated, the terminal needs to actively initiate slice authentication and authorization in the network equipment, and can continue to use the slice service only after the authentication is successful, which affects the performance of network services. SUMMARY

[0004] The purpose of the present application is to provide a slice authentication and authorization method, device, terminal and network equipment to solve the problem that in the current slice authentication and authorization process, when the slice authentication fails or the user identity of the slice is updated, the slice service is unavailable, which affects the performance of network services.

[0005] To achieve the above purpose, the present application provides a slice authentication and authorization method applied to a terminal, which comprises:

[0006] If it is detected that the user identity of the first slice is updated, the terminal sends request information for slice authentication and authorization of the first slice to the network equipment.

[0007] Among them, the first slice is a slice that has obtained a slice authentication and authorization result.

[0008] Optionally, the step of sending request information for slice authentication and authorization of the first slice to the network equipment comprises:

[0009] sending first uplink signaling to the network device; wherein the first uplink signaling carries an identity of a second slice requesting slice authentication and authorization, and the identity of the second slice contains part or all of the identity of the first slice.

[0010] Optionally, after the sending first uplink signaling to the network device, the method further comprises:

[0011] receiving first downlink signaling sent by the network device; wherein the first downlink signaling is used to indicate a slice authentication and authorization result of a third slice; wherein the third slice includes part or all of the second slice.

[0012] Optionally, after the sending first uplink signaling to the network device, and before the receiving first downlink signaling sent by the network device, the method further comprises:

[0013] receiving second downlink signaling sent by the network device; wherein the second downlink signaling carries the identity of the third slice; and the identity of the third slice contains part or all of the identity of the second slice.

[0014] sending first response message to the network device according to the second downlink signaling; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries updated information of user identity proof of the first slice.

[0015] Optionally, after the receiving first downlink signaling sent by the network device, the method further comprises:

[0016] if there is a first target slice identity in the stored slice identity, updating a slice authentication and authorization result corresponding to the first target slice identity; wherein the first target slice identity is part or all of the identity of the third slice.

[0017] if there is no second target slice identity in the stored slice identity, storing a slice authentication and authorization result corresponding to the second target slice identity; wherein the second target slice identity is part or all of the identity of the third slice.

[0018] Optionally, the slice authentication and authorization result includes: slice authentication and authorization success, or slice authentication and authorization failure.

[0019] Optionally, the user identity proof update of the first slice includes: at least one of software update of the terminal, hardware update connected by the terminal, information writing, information update, and user input indication.

[0020] To achieve the above object, the embodiment of the present application provides a slice authentication and authorization method applied to a network device, and the method comprises the following steps:

[0021] receiving request information for slice authentication and authorization of a first slice sent by a terminal, wherein the request information is sent by the terminal when detecting that user identity information of the first slice is updated, and the first slice is a slice that has obtained a slice authentication and authorization result;

[0022] performing related processing of slice authentication and authorization according to the request information.

[0023] Optionally, the receiving request information for slice authentication and authorization of a first slice sent by a terminal comprises the following steps:

[0024] receiving first uplink signaling sent by the terminal, wherein the first uplink signaling carries an identifier of a second slice for which slice authentication and authorization is requested, and the identifier of the second slice contains part or all of an identifier of the first slice.

[0025] Optionally, the performing related processing of slice authentication and authorization according to the request information comprises the following steps:

[0026] sending first downlink signaling to the terminal, wherein the first downlink signaling is used to indicate a slice authentication and authorization result of a third slice, and the third slice comprises part or all of the second slice.

[0027] Optionally, the performing related processing of slice authentication and authorization according to the request information further comprises the following steps:

[0028] sending second downlink signaling to the terminal before sending the first downlink signaling to the terminal, wherein the second downlink signaling carries an identifier of the third slice, and the identifier of the third slice contains part or all of an identifier of the second slice;

[0029] receiving a first response message sent by the terminal according to the second downlink signaling, wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries related information of updated user identity information of the first slice.

[0030] Optionally, the slice authentication and authorization result comprises slice authentication and authorization success or slice authentication and authorization failure.

[0031] To achieve the above object, the embodiment of the present application provides a slice authentication and authorization device applied to a terminal, and the device comprises the following steps:

[0032] The first sending module is configured to send, to the network device, request information for slice authentication and authorization of the first slice if it is detected that the user identity of the first slice is updated.

[0033] The first slice is a slice that has obtained a slice authentication and authorization result.

[0034] To achieve the above object, an embodiment of the present application provides a terminal, comprising a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor implements the steps in the slice authentication and authorization method when executing the program or instructions.

[0035] To achieve the above object, an embodiment of the present application provides a slice authentication and authorization device applied to a network device, comprising:

[0036] The receiving module is configured to receive request information for slice authentication and authorization of a first slice sent by a terminal; the request information is sent by the terminal when it is detected that the user identity of the first slice is updated, and the first slice is a slice that has obtained a slice authentication and authorization result.

[0037] The processing module is configured to perform related processing of slice authentication and authorization according to the request information.

[0038] To achieve the above object, an embodiment of the present application provides a network device, comprising a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor implements the steps in the slice authentication and authorization method when executing the program or instructions.

[0039] To achieve the above object, an embodiment of the present application provides a readable storage medium having a program or instructions stored thereon; the program or instructions are executable on a processor to implement the steps in the slice authentication and authorization method.

[0040] The above technical solution of the present application has the following advantages:

[0041] In the embodiment of the present application, for a first slice that has obtained a slice authentication and authorization result (such as including slice authentication and authorization success or failure), when the terminal detects that the user identity of the first slice is updated, the terminal can actively initiate a request for slice authentication or authorization of the first slice to the network device, so that the network device can re-perform slice authentication and authorization on the first slice after the user identity is updated, thereby avoiding the problem that when a slice fails in slice authentication and authorization, the network device cannot perceive the update of the user identity of the slice, and the slice service is unavailable, thereby improving the performance of the slice service. BRIEF DESCRIPTION OF DRAWINGS

[0042] Figure 1 a flowchart of a slice authentication and authorization method on a terminal side of an embodiment of the present application;

[0043] Figure 2 a slice authentication and authorization method on a terminal side of an embodiment of the present application;

[0044] Figure 3 a flowchart of a slice authentication and authorization method on a terminal side of an embodiment of the present application;

[0045] Figure 4 a flowchart of a slice authentication and authorization method on a terminal side of an embodiment of the present application;

[0046] Figure 5 a flowchart of a slice authentication and authorization method on a terminal side of an embodiment of the present application;

[0047] Figure 6 a flowchart of a slice authentication and authorization method on a terminal side of an embodiment of the present application;

[0048] Figure 7 a flowchart of a slice authentication and authorization method on a terminal side of an embodiment of the present application; DETAILED DESCRIPTION

[0049] To make the technical problems solved by the present application, technical solutions and advantages clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0050] It should be understood that the term "one embodiment" or "an embodiment" as referred to herein throughout the specification means that a particular feature, structure, or characteristic described is included in at least one embodiment of the present application. Thus, appearances of the phrases "in one embodiment" or "in an embodiment" in various places throughout the specification are not necessarily referring to the same embodiment. Furthermore, the particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.

[0051] In various embodiments of the present application, it should be understood that the size of the serial number of each process does not mean the order of execution, and the execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0052] In addition, the terms "system" and "network" are often used interchangeably herein.

[0053] In the embodiments provided in the present application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0054] AsFigure 1 As shown, the slice authentication and authorization method of an embodiment of the present application is applied to a terminal, and the method comprises the following steps:

[0055] Step 11: If it is detected that the user identity of the first slice is updated, sending, to a network device, request information for slice authentication and authorization of the first slice; wherein the first slice is a slice that has obtained a slice authentication and authorization result.

[0056] Optionally, for the first slice in step 11, the slice that has obtained a slice authentication and authorization result can be a slice with authentication failure or a slice with authentication success. For the slice identifier with authentication failure or the slice identifier with authentication success, the terminal detects the user identity of the slice. If the terminal detects that the user identity of the slice is changed, the terminal initiates a slice authentication and authorization request to the network device, that is, the terminal initiates a slice authentication and authorization request for the slice, which should be a slice with authentication failure or authentication success in the previous slice authentication and authorization, and the terminal detects that the user identity of the slice is changed.

[0057] Of course, when the terminal initiates a slice authentication and authorization request to the network device, it can also request other slices in addition to the slice with authentication failure or authentication success in the previous slice authentication and authorization (that is, when the terminal initiates a slice authentication and authorization request to the network device, it can also request other slices in addition to the first slice to perform slice authentication and authorization), and the embodiments of the present application are not limited thereto.

[0058] For example, after the terminal fails in slice authentication, the slice service is unavailable. If the slice with authentication failure is updated in user identity and the slice authentication and authorization are successful through re-authentication, the slice service is available. In this case, the terminal can initiate a slice authentication and authorization request when it detects that the slice with authentication failure is updated in user identity, so that the network device performs slice authentication and authorization for the slice, thereby avoiding the problem that the network device cannot perceive the update of the user identity of the slice with authentication failure in the slice authentication and authorization process, and the slice service is unavailable.

[0059] For example, for the slice whose authentication is successful, in the case that the user identity update occurs, the slice service can also be unavailable. In this case, for the slice whose authentication fails, the terminal can actively initiate a slice authentication and authorization request when detecting that the user identity update occurs, so that the network device performs slice authentication and authorization for the slice, thereby avoiding the problem that when a certain slice fails in the slice authentication and authorization process, the network device cannot perceive the user identity update of the slice, and the slice service becomes unavailable.

[0060] The above scheme of the application can actively initiate a request for the network device to perform slice authentication and authorization for the first slice when the terminal detects that the user identity update occurs, so that the network device can perform slice authentication and authorization for the first slice after the user identity update, thereby avoiding the problem that when a certain slice fails in the slice authentication and authorization process, the network device cannot perceive the user identity update of the slice, and the slice service becomes unavailable, and improving the slice service performance.

[0061] Optionally, before the step 11, the terminal can receive downlink signaling sent by the network device and used to indicate the slice authentication and authorization result of the first slice, so that the terminal can obtain the slice authentication and authorization result of the first slice.

[0062] For example, the downlink signaling can be sent by the network device to the terminal after the terminal completes the primary authentication and initial registration. Alternatively, the downlink signaling can be sent by the network device to the terminal after the terminal actively requests the network device to perform slice authentication and authorization for the first slice.

[0063] Optionally, the slice authentication and authorization result includes slice authentication and authorization success or slice authentication and authorization failure.

[0064] Optionally, after the terminal receives the downlink signaling sent by the network device and used to indicate the slice authentication and authorization result of the first slice, the terminal can further store the identifier of the first slice according to the downlink signaling.

[0065] Specifically, after the terminal completes the primary authentication and initial registration, the terminal returns slice authentication and authorization information on the terminal side according to the slice authentication and authorization requirement signaling sent by the network device, and stores the identifiers of the slices whose authentication is successful and the identifiers of the slices whose authentication fails according to the indication in the slice authentication and authorization result signaling sent by the network device.

[0066] For example, the premise of slice authentication and authorization is that the terminal has completed the primary authentication and key agreement (primary authentication and key agreement) and the initial registration process. After the terminal completes the primary authentication and initial registration, the network device can trigger slice authentication and authorization, such as an access and mobility management function (AMF) network element or an authentication, authorization, and accounting server (AAA-S) on the network device side. For example, the trigger conditions include: the AAA-S detects that the terminal requests certain slices for slice authentication during the registration process, or the AMF detects that the user subscription information changes, or the AAA-S requires to re-perform slice authentication, and the like. The slice authentication air interface signaling process is as shown in FIG. 1. Figure 2

[0067] After the network device triggers slice authentication and authorization, the terminal returns an extensible authentication protocol (EAP) response message (EAP-response message). The EAP-response message should carry an identity proof (user identity proof) that proves that the user can use the slice. The AAA-S can determine the result of slice authentication and authorization based on the EAP-response message returned by the terminal, and returns an EAP authentication success (EAP-success) or an EAP authentication failure (EAP-failure) according to the determination result, that is, the slice authentication and authorization result. If the result is a failure, the network device will notify the terminal of the authentication failed slice identifier, such as single network slice selection assistance information (S-NSSAI) or S-NSSAIs, through signaling sent by the AMF, and put the identifier into the rejected NSSAI (Rejected NSSAI) list of the corresponding signaling, and indicate that the S-NSSAI is not available due to the failed or revoked network slice-specific authentication and authorization (S-NSSAI not available due to the failed or revoked network slice-specific authentication and authorization).

[0068] ​Optionally, the user identity update of the first slice includes at least one of a software update of the terminal, a hardware update connected by the terminal, information writing, information update, and user input indication.

[0069] For example, the information writing or update can refer to writing or updating of SIM card related information (such as clearing corresponding information after plugging out the card) or other information writing or updating, and the user input indication can be user input of a user name, a password, or other information, and the embodiments of the present application are not limited thereto.

[0070] Optionally, the sending of the request information for slice authentication and authorization of the first slice to the network device includes:

[0071] sending first uplink signaling to the network device, wherein the first uplink signaling carries an identity of a second slice for which slice authentication and authorization are requested, and the identity of the second slice includes part or all of the identity of the first slice.

[0072] For example, the request information for slice authentication and authorization of the first slice sent by the terminal can be carried in independent uplink signaling, that is, independent first uplink signaling. The first uplink signaling can carry an identity of one or more second slices for which slice authentication and authorization are requested, and the identity of the second slice can include the identity of the slice (that is, the first slice) for which authentication fails or succeeds in the previous slice authentication and authorization process, and can also include the identity of other slices, and the embodiments of the present application are not limited thereto.

[0073] Optionally, after the sending of the first uplink signaling to the network device, the method further includes:

[0074] receiving first downlink signaling sent by the network device, wherein the first downlink signaling is used to indicate a slice authentication and authorization result of a third slice, and the third slice includes part or all of the second slice.

[0075] For example, after the terminal sends the first uplink signaling carrying the identity of the second slice for which slice authentication and authorization are requested to the network device, the network device performs related processing of slice authentication and authorization according to the first uplink signaling, and sends first downlink signaling (which can be referred to as result signaling and used to indicate the slice authentication and authorization result) to the network device for indicating the slice authentication and authorization result of the third slice. Since the third slice includes part or all of the second slice, that is, the third slice can include part or all of the first slice, and of course the third slice can also include other slices in addition to the second slice, the embodiments of the present application are not limited thereto.

[0076] Optionally, after the sending of the first uplink signaling to the network device, and before the receiving of the first downlink signaling sent by the network device, the method further comprises:

[0077] receiving second downlink signaling sent by the network device; wherein the second downlink signaling carries the identity of the third slice; the identity of the third slice contains part or all of the identity of the second slice;

[0078] sending a first response message to the network device according to the second downlink signaling; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries the relevant information of the updated user identity certificate of the first slice.

[0079] The second downlink signaling can be slice authentication and authorization requirement signaling; the slice authentication and authorization requirement signaling can carry the identity of the third slice (which can be a slice to be authenticated and authorized), and can also carry information related to slice authentication and authorization, etc., without being limited thereto in the embodiments of the present application.

[0080] Specifically, after the terminal actively requests slice authentication and authorization, the network device sends the terminal the second downlink signaling (such as slice authentication and authorization requirement signaling) according to the request, the second downlink signaling carries the identity of the third slice to be authenticated and authorized (or can also carry information related to slice authentication and authorization on the network device side), and the identity of the third slice should contain the identity of one or more second slices requesting slice authentication and authorization in the first uplink signaling.

[0081] The terminal generates a new authentication and authorization response message (or reply information), i.e., a first response message, according to the updated user identity certificate, and feeds back the generated new authentication and authorization response message to the network device based on the slice authentication and authorization requirement signaling sent by the network device (such as sending through uplink signaling), the uplink signaling can carry the relevant information of the updated user identity certificate of the first slice (such as the identity information of the slice to be authenticated and authorized, the updated user identity certificate of the first slice, etc.), and the slice identity corresponding to the above new authentication and authorization response message, etc. The identity of the slice to be authenticated and authorized carried in the uplink signaling should be consistent with the identity information of the third slice carried in the downlink signaling sent by the network device.

[0082] The network device judges the result of slice authentication and authorization based on the EAP-response message replied by the terminal, and replies the first downlink signaling (such as slice authentication and authorization result signaling of authentication success or authentication failure) according to the judgment result, so that the terminal can determine the result of re-performing slice authentication and authorization for the updated slice according to the first downlink signaling.

[0083] Optionally, after receiving the first downlink signaling sent by the network device, the method further comprises:

[0084] If the first target slice identifier exists in the stored slice identifiers, the slice authentication and authorization result corresponding to the first target slice identifier is updated; wherein the first target slice identifier is the identifier of part or all of the third slice.

[0085] If the second target slice identifier does not exist in the stored slice identifiers, the slice authentication and authorization result corresponding to the second target slice identifier is stored; wherein the second target slice identifier is the identifier of part or all of the third slice.

[0086] Specifically, the terminal can store the corresponding slice identifier and the corresponding slice authentication and authorization result for the slice for which the slice authentication and authorization is obtained. In this way, after the terminal completes the slice authentication and authorization process initiated by the terminal, for the slice (such as the first target slice identifier existing in the stored slice identifier) explicitly indicated in the first downlink signaling (i.e. slice authentication and authorization result signaling), the corresponding slice authentication information is updated. In addition, after the terminal completes the slice authentication and authorization process initiated by the terminal, the authentication result of the slice identifier not involved in the first downlink signaling in the stored slice identifier is kept unchanged, and for the slice identifier (i.e. the second target slice identifier) not stored in the terminal involved in the first downlink signaling, a storage operation is performed, i.e. the slice identifier and the corresponding slice authentication and authorization result are stored. That is, when the terminal updates the authentication result of the stored slice identifier of authentication success and authentication failure, the update is only for the slice explicitly indicated in the slice authentication and authorization result signaling sent by the network device, and the authentication result stored by the terminal remains unchanged for the slice not involved in the signaling.

[0087] It should be noted that the above slice authentication and authorization method in the embodiments of the present application can have multiple parallel processes, such as the terminal actively sending multiple re-performing slice authentication and authorization request information, or the terminal actively sending re-performing slice authentication and authorization request information once and not completing the slice authentication and authorization process, and the terminal actively sending re-performing slice authentication and authorization request information once or multiple times, etc. The embodiments of the present application are not limited thereto.

[0088] The above embodiment describes the slice authentication and authorization method of the embodiment of the present application, and the corresponding device and terminal are described below with reference to the drawings.

[0089] As shown in Figure 3 , a slice authentication and authorization device 300 of an embodiment of the present application is applied to a terminal, and the device comprises:

[0090] A first sending module 310 is configured to send, to a network device, request information for slice authentication and authorization of a first slice if it is detected that the user identity of the first slice is updated.

[0091] The first slice is a slice that has obtained a slice authentication and authorization result.

[0092] Optionally, the slice authentication and authorization result comprises slice authentication and authorization success or slice authentication and authorization failure.

[0093] Optionally, the user identity update of the first slice comprises at least one of software update of the terminal, hardware update connected to the terminal, information writing, information update and user input indication.

[0094] Optionally, the first sending module 320 comprises:

[0095] A sending unit is configured to send first uplink signaling to the network device; wherein the first uplink signaling carries an identity of a second slice for which slice authentication and authorization is requested, and the identity of the second slice contains part or all of the identity of the first slice.

[0096] Optionally, the device 300 further comprises:

[0097] A first receiving module is configured to receive first downlink signaling sent by the network device; wherein the first downlink signaling is used to indicate a slice authentication and authorization result of a third slice; wherein the third slice comprises part or all of the second slice.

[0098] Optionally, the device 300 further comprises:

[0099] A second receiving module is configured to receive second downlink signaling sent by the network device; wherein the second downlink signaling carries an identity of the third slice; the identity of the third slice contains part or all of the identity of the second slice.

[0100] A second sending module is configured to send a first response message to the network device according to the second downlink signaling; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries relevant information of the updated user identity of the first slice.

[0101] Optionally, the apparatus 300 further comprises:

[0102] an updating module, configured to update a stored slice authentication and authorization result corresponding to a first target slice identifier if the first target slice identifier exists in the stored slice identifiers; the first target slice identifier is an identifier of part or all of the third slice.

[0103] a storage module, configured to store a slice authentication and authorization result corresponding to a second target slice identifier if the second target slice identifier does not exist in the stored slice identifiers; the second target slice identifier is an identifier of part or all of the third slice.

[0104] In the apparatus 300 of this embodiment, for a first slice for which a slice authentication and authorization result (such as including slice authentication and authorization success or failure) has been obtained, when the terminal detects that the user identity proof of the first slice is updated, the terminal can actively initiate a request to the network device for slice authentication or authorization of the first slice, so that the network device can re-perform slice authentication and authorization for the first slice after the update of the user identity proof, thereby avoiding the problem that when a slice fails in the slice authentication and authorization process, the network device cannot perceive the update of the user identity proof of the slice, resulting in the unavailability of the slice service, and improving the slice service performance.

[0105] The embodiments of the present application also provide a terminal, as shown in the accompanying drawings, comprising a transceiver 410, a processor 400, a memory 420, and a program or instruction stored in the memory 420 and executable on the processor 400; the processor 400 implements the steps in the above-mentioned slice authentication and authorization method applied to the terminal side when executing the program or instruction. Figure 4

[0106] The transceiver 410 is configured to receive and send data under the control of the processor 400.

[0107] In the above-mentioned slice authentication and authorization method applied to the terminal side, the slice authentication and authorization result of the first slice can be obtained by the terminal, and the terminal can actively initiate a request to the network device for slice authentication or authorization of the first slice when the terminal detects that the user identity proof of the first slice is updated, so that the network device can re-perform slice authentication and authorization for the first slice after the update of the user identity proof, thereby avoiding the problem that when a slice fails in the slice authentication and authorization process, the network device cannot perceive the update of the user identity proof of the slice, resulting in the unavailability of the slice service, and improving the slice service performance. Figure 4 ​In particular embodiments, the bus architecture can include any number of interconnecting buses and bridges, depending on the specific application of the processor 400 and the overall design constraints. The bus architecture can link together various circuits such as the processor 400, the memory 420, and various other circuits including peripheral devices, voltage regulators, and power management circuits, all of which are well known in the art, and therefore, will not be described in further detail herein. The bus interface provides an interface to the bus architecture. The transceiver 410 can be a plurality of elements, including a transmitter and a receiver, that together provide a communication interface to the bus architecture for communicating with a plurality of other devices. The user interface 430 can also be an interface to other devices such as keyboards, displays, speakers, microphones, joysticks, and the like, depending on the particular user device.

[0108] The processor 400 is responsible for managing the bus architecture and general processing, while the memory 420 can store data used by the processor 400 during execution of operations.

[0109] The above embodiment describes the slice authentication and authorization method on the terminal side. The slice authentication and authorization method on the network device side is described below in combination with the drawings:

[0110] As shown in Figure 5 The embodiment of the present application provides a slice authentication and authorization method, which is applied to a network device, and the method comprises the following steps:

[0111] Step 51: receiving request information for slice authentication and authorization of a first slice sent by a terminal; wherein the request information is sent by the terminal when detecting that the user identity certificate of the first slice is updated, and the first slice is a slice that has obtained a slice authentication and authorization result.

[0112] Optionally, for the first slice, the slice that has obtained a slice authentication and authorization result can be a slice with authentication failure or a slice with authentication success; for the slice identifier with authentication failure or the slice identifier with authentication success, the terminal detects the user identity certificate of the slice. If the terminal detects that the user identity certificate of the slice changes, the terminal actively sends a slice authentication and authorization request to the network device, that is, the terminal actively sends a slice authentication and authorization request for the slice, which should be the slice with authentication failure or authentication success in the previous slice authentication and authorization, and the terminal detects that the user identity certificate of the slice changes.

[0113] Of course, when the terminal initiates the slice authentication and authorization request to the network device, it can also request other slices in addition to the slice whose authentication fails or succeeds in the previous slice authentication and authorization (i.e., when the terminal initiates the slice authentication and authorization request to the network device, it can also request other slices in addition to the first slice to perform the slice authentication and authorization request), and the embodiments of the present application are not limited thereto.

[0114] For example, after the slice authentication fails, the slice service is unavailable. When the user identity of the authentication-failed slice is updated, if the slice authentication and authorization are successful through re-authentication, the slice service is available. At this time, the terminal, which has completed the primary authentication and initial registration, can actively initiate the slice authentication and authorization request when detecting that the user identity of the authentication-failed slice is updated. Alternatively, when the user identity of the authentication-successful slice is updated, the slice service can also be unavailable. At this time, the terminal, which has completed the primary authentication and initial registration, can actively initiate the slice authentication and authorization request when detecting that the user identity of the authentication-failed slice is updated.

[0115] Optionally, the user identity update of the first slice includes at least one of software update of the terminal, hardware update connected to the terminal, information writing, information update, and user input indication.

[0116] For example, the information writing or update can be writing or updating of SIM card related information (such as clearing the corresponding information after plugging out the card) or other information writing or updating. The user input indication can be user input of a username, a password, or other user input, and the embodiments of the present application are not limited thereto.

[0117] Step 52: performing the slice authentication and authorization related processing according to the request information.

[0118] In the above scheme, when the terminal detects that the user identity of the first slice, which has obtained the slice authentication and authorization result (such as including slice authentication and authorization success or failure), is updated, it can actively initiate the request for slice authentication and authorization of the first slice, so that the network device can re-perform the slice authentication and authorization for the updated slice, thereby avoiding the problem that when a slice fails in the slice authentication and authorization process, the network device cannot perceive the user identity update of the slice, resulting in unavailable slice service, and improving the slice service performance.

[0119] Optionally, before the step 51, the network device can send, to the terminal, downlink signaling for indicating a slice authentication and authorization result of the first slice, so that the terminal can obtain the slice authentication and authorization result of the first slice.

[0120] For example, the downlink signaling can be sent by the network device to the terminal after the terminal completes primary authentication and initial registration. Alternatively, the downlink signaling can also be sent by the network device to the terminal after the terminal actively requests the network device to perform slice authentication and authorization on the first slice.

[0121] Optionally, the slice authentication and authorization result includes: slice authentication and authorization success, or slice authentication and authorization failure.

[0122] For example, the slice authentication and authorization is used on the premise that the terminal has completed primary authentication and initial registration. After the terminal completes primary authentication and initial registration, the network device can trigger slice authentication and authorization, such as an AMF network element or AAA-S triggering slice authentication and authorization. For example, the triggering conditions include: the AAA-S detects that some slices requested by the terminal need to be authenticated during the registration process, or the AMF detects that the user subscription information changes, or the AAA-S requires to re-perform slice authentication, and the like.

[0123] After the network device triggers slice authentication and authorization, the terminal returns an EAP-response message, which should carry an identity certificate (i.e., user identity certificate) proving that the user can use the slice. The slice authentication and authorization result can be determined by the AAA-S based on the EAP-response message returned by the terminal, and an EAP authentication success (EAP-success) or EAP authentication failure (EAP-failure) is returned according to the determination result, i.e., the slice authentication and authorization result.

[0124] Optionally, the receiving of the request information for performing slice authentication and authorization on the first slice sent by the terminal includes:

[0125] Receiving first uplink signaling sent by the terminal; wherein the first uplink signaling carries an identity of a second slice for which slice authentication and authorization is requested, and the identity of the second slice contains part or all of the identity of the first slice.

[0126] For example, the terminal sends the request information for slice authentication and authorization of the first slice in independent uplink signaling, i.e., the first uplink signaling. The first uplink signaling can carry the identification of one or more second slices for which slice authentication and authorization is requested. The identification of the second slice can include the identification of the slice (i.e., the first slice) for which authentication fails or succeeds in the previous slice authentication and authorization process, and can also include the identification of other slices, etc. The embodiments of the present application are not limited in this regard.

[0127] Optionally, the performing of the slice authentication and authorization related processing according to the request information comprises:

[0128] sending the first downlink signaling to the terminal; wherein the first downlink signaling is used to indicate the slice authentication and authorization result of the third slice; wherein the third slice includes part or all of the second slice.

[0129] For example, after the terminal sends the first uplink signaling carrying the identification of the second slice for which slice authentication and authorization is requested to the network device, the network device performs slice authentication and authorization related processing according to the first uplink signaling, and sends the first downlink signaling (which can be referred to as a result signaling used to indicate the slice authentication and authorization result) to the network device to indicate the slice authentication and authorization result of the third slice. Since the third slice includes part or all of the second slice, i.e., the third slice can include part or all of the first slice, the third slice can also include other slices in addition to the second slice, and the embodiments of the present application are not limited in this regard.

[0130] Optionally, the performing of the slice authentication and authorization related processing according to the request information further comprises:

[0131] sending the second downlink signaling to the terminal before sending the first downlink signaling to the terminal; wherein the second downlink signaling carries the identification of the third slice; and the identification of the third slice includes part or all of the identification of the second slice.

[0132] receiving the first response message sent by the terminal according to the second downlink signaling; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries the related information of the updated first slice user identity.

[0133] The second downlink signaling may be a slice authentication and authorization request signaling; the slice authentication and authorization request signaling may carry the identifier of a third slice (the third slice may be a slice to be authenticated and authorized), and may also carry information related to slice authentication and authorization, etc., but the embodiments of the present invention are not limited thereto.

[0134] Specifically, after the terminal actively requests slice authentication and authorization, the network device sends a second downlink signaling (such as slice authentication and authorization request signaling) to the terminal according to the request. The second downlink signaling carries the identifier of the third slice to be authenticated and authorized (or may also carry information related to slice authentication and authorization on the network device side), and the identifier of the three slices should include one or more identifiers of the second slice requesting slice authentication and authorization in the first uplink signaling.

[0135] Based on the updated user identity verification, the terminal generates a new authentication and authorization response message (or reply information), i.e., the first response message. Based on the slice authentication and authorization request signaling sent by the network device, the terminal sends the newly generated authentication and authorization response message back to the network device (e.g., via uplink signaling). This uplink signaling may carry relevant information about the updated first slice's user identity verification (e.g., the identifier of the slice to be authenticated and authorized, the updated user identity verification of the first slice, etc.), as well as the aforementioned new authentication and authorization response message corresponding to the slice identifier. The identifier of the slice to be authenticated and authorized carried in this uplink signaling should be consistent with the identifier of the third slice carried in the downlink signaling sent by the network device.

[0136] The network device determines the result of slice authentication and authorization based on the EAP-response message replied by the terminal, and replies with the first downlink signaling (such as slice authentication and authorization result signaling for successful or failed authentication) according to the determination result. Thus, the terminal can determine the result of re-authenticating and authorizing the slice for the updated slice based on the first downlink signaling.

[0137] The above embodiments illustrate the slice authentication and authorization method of the present invention. The corresponding apparatus and network devices will be described below with reference to the accompanying drawings.

[0138] like Figure 6 As shown, this embodiment of the invention provides a slice authentication and authorization device 600, applied to network devices. The device 600 includes:

[0139] The receiving module 610 is configured to receive request information for slice authentication and authorization of a first slice sent by a terminal; wherein the request information is sent by the terminal when detecting that user identity information of the first slice is updated, and the first slice is a slice that has obtained a slice authentication and authorization result.

[0140] The processing module 620 is configured to perform related processing of slice authentication and authorization according to the request information.

[0141] Optionally, the receiving module 610 includes:

[0142] A first receiving unit is configured to receive first uplink signaling sent by the terminal; wherein the first uplink signaling carries an identity of a second slice for which slice authentication and authorization is requested, and the identity of the second slice contains part or all of an identity of the first slice.

[0143] Optionally, the processing module 620 includes:

[0144] A first sending unit is configured to send first downlink signaling to the terminal; wherein the first downlink signaling is used to indicate a slice authentication and authorization result of a third slice; wherein the third slice includes part or all of the second slice.

[0145] Optionally, the processing module 620 includes:

[0146] A second sending unit is configured to send second downlink signaling to the terminal before sending the first downlink signaling to the terminal; wherein the second downlink signaling carries an identity of the third slice; and the identity of the third slice contains part or all of an identity of the second slice.

[0147] A second receiving unit is configured to receive a first response message sent by the terminal according to the second downlink signaling; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries related information of updated user identity information of the first slice.

[0148] Optionally, the slice authentication and authorization result includes: slice authentication and authorization success, or slice authentication and authorization failure.

[0149] In this embodiment of the invention, the apparatus 600, for a first slice that has obtained slice authentication and authorization results (such as slice authentication and authorization success or failure), when the terminal detects that a user identity certificate update has occurred, can proactively initiate a request to the network device to perform slice authentication or authorization for the first slice. This enables the network device to re-perform slice authentication and authorization for the first slice with updated user identity certificate, avoiding the problem that the network device cannot detect the update of the user identity certificate for a slice when the authentication of a slice fails during the slice authentication and authorization process, thus causing the slice service to be unavailable, thereby improving the slice service performance.

[0150] A network device according to an embodiment of the present invention, such as Figure 7 As shown, it includes a transceiver 710, a processor 700, a memory 720, and a program or instructions stored in the memory 720 and executable on the processor 700; when the processor 700 executes the program or instructions, it implements the steps in the above-described slice authentication and authorization method applied to the network device side.

[0151] The transceiver 710 is used to receive and send data under the control of the processor 700.

[0152] Among them, Figure 7 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 700) and memory (memory 720). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 710 may be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. The processor 700 is responsible for managing the bus architecture and general processing, and the memory 720 may store data used by the processor 700 during operation.

[0153] An embodiment of the present invention provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the steps in the slice authentication and authorization method described above and achieve the same technical effect. To avoid repetition, further details are omitted here.

[0154] The processor mentioned above is the processor in the terminal or network device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0155] It is further noted that the terminal described in this specification includes, but is not limited to, a smart phone, a tablet computer, and the like, and many of the functional components described are referred to as modules in order to more particularly emphasize their independent implementation.

[0156] In the embodiments of the present application, the modules can be implemented in software, to be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions that can, for instance, be organized as an object, procedure, or function. Nevertheless, the executable code of an identified module need not be physically located together, but can include disparate instructions stored in different locations which, as a combined whole, deliver the

[0157] Indeed, an executable code module can be a single instruction, or many instructions, and can even be distributed over several different code segments, among different programs, and across several memory devices. Also, operational data can be identified within an executable code module and can be

[0158] When the modules can be implemented in software, the present application contemplates that a corresponding hardware circuit can be built to implement the corresponding function, without considering the cost, by those skilled in the art, in view of the level of existing hardware technology, which includes conventional very large scale integration (VLSI) circuits or gate arrays, and existing semiconductors or other discrete components such as logic chips, transistors, and the like. The modules can also be implemented in programmable hardware devices, such as field programmable gate arrays, programmable array logic, programmable logic devices, or the like.

[0159] The foregoing exemplary embodiments are described with reference made to the drawings which are provided for the purpose of explanation and illustration. They are not intended to limit the scope of the invention. Rather, these exemplary embodiments are described in order to enable others skilled in the art to embody the application. As will be understood by those familiar with the art, the application can be embodied in many different forms and should not be limited to the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided so that this disclosure will be complete and fully convey the scope of the application to those skilled in the art. In the drawings, the size and relative sizes of components can be exaggerated for clarity. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, the singular articles "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. Unless otherwise indicated, a value range includes the upper and lower limits of the range and any sub-ranges therebetween.

[0160] The preferred embodiments of the application are described above in detail. It should be noted that the above-mentioned embodiments are only used to illustrate the technical solutions of the present application, and are not used to limit the scope of the present application. For those skilled in the art, the modifications and improvements can be made without departing from the principles of the present application, and these modifications and improvements should also be considered as falling within the protection scope of the present application.

Claims

1. A slice authentication and authorization method, applied to a terminal, characterized in that, The method includes: If an update to the user identity certificate of the first slice is detected, a request for slice authentication and authorization of the first slice is sent to the network device; The first slice is a slice that has obtained slice authentication and authorization results.

2. The method according to claim 1, characterized in that, Sending the request information to the network device for slice authentication and authorization of the first slice includes: Send a first uplink signaling to the network device; wherein the first uplink signaling carries an identifier of a second slice requesting slice authentication and authorization, and the identifier of the second slice contains part or all of the identifier of the first slice.

3. The method according to claim 2, characterized in that, After sending the first uplink signaling to the network device, the method further includes: The network device receives a first downlink signaling message; wherein the first downlink signaling message is used to indicate the slice authentication and authorization result of the third slice; wherein the third slice includes part or all of the second slice.

4. The method according to claim 3, characterized in that, After sending the first uplink signaling to the network device and before receiving the first downlink signaling sent by the network device, the method further includes: The network device receives a second downlink signaling message; wherein the second downlink signaling message carries the identifier of the third slice; the identifier of the third slice includes part or all of the identifier of the second slice. According to the second downlink signaling, a first response message is sent to the network device; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries relevant information of the updated user identity certificate of the first slice.

5. The method according to claim 3, characterized in that, After receiving the first downlink signaling sent by the network device, the method further includes: If a first target slice identifier exists among the stored slice identifiers, then the slice authentication and authorization results corresponding to the stored first target slice identifier are updated; wherein, the first target slice identifier is the identifier of some or all of the third slices; If the second target slice identifier is not present in the stored slice identifiers, then the slice authentication and authorization results corresponding to the second target slice identifier are stored; wherein, the second target slice identifier is the identifier of some or all of the third slices.

6. The method according to claim 1, characterized in that, The slice authentication and authorization results include: slice authentication and authorization successful, or slice authentication and authorization failed.

7. The method according to claim 1, characterized in that, The user identity verification update for the first slice includes at least one of the following: software update of the terminal, hardware update connected to the terminal, information writing, information update, and user input indication.

8. A slice authentication and authorization method, applied to network devices, characterized in that, The method includes: The receiving terminal sends a request message for slice authentication and authorization of the first slice; wherein the request message is sent by the terminal when it detects an update to the user identity certificate of the first slice, and the first slice is a slice that has obtained slice authentication and authorization results; Based on the requested information, perform the relevant processing for slice authentication and authorization.

9. The method according to claim 8, characterized in that, The request information sent by the receiving terminal for slice authentication and authorization of the first slice includes: The terminal receives a first uplink signaling message; wherein the first uplink signaling message carries an identifier of a second slice requesting slice authentication and authorization, and the identifier of the second slice contains part or all of the identifier of the first slice.

10. The method according to claim 9, characterized in that, The step of performing slice authentication and authorization based on the request information includes: Send a first downlink signaling to the terminal; wherein the first downlink signaling is used to indicate the slice authentication and authorization result of the third slice; wherein the third slice includes part or all of the second slice.

11. The method according to claim 10, characterized in that, The step of performing slice authentication and authorization based on the request information further includes: Before sending the first downlink signaling to the terminal, a second downlink signaling is sent to the terminal; wherein the second downlink signaling carries the identifier of the third slice; the identifier of the third slice includes part or all of the identifier of the second slice; The network device receives a first response message sent by the terminal based on the second downlink signaling; wherein the first downlink signaling is sent by the network device based on the first response message, and the first response message carries information related to the updated user identity certificate of the first slice.

12. The method according to claim 8, characterized in that, The slice authentication and authorization results include: slice authentication and authorization successful, or slice authentication and authorization failed.

13. A slice authentication and authorization device, applied to a terminal, characterized in that, The device includes: The first sending module is used to send a request message for slice authentication and authorization of the first slice to the network device if the user identity certificate of the first slice is detected to be updated. The first slice is a slice that has obtained slice authentication and authorization results.

14. A terminal, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the steps of the slice authentication and authorization method as described in any one of claims 1 to 7.

15. A slice authentication and authorization device, applied to network equipment, characterized in that, The device includes: The receiving module is used to receive a request message sent by the terminal for slice authentication and authorization of the first slice; wherein the request message is sent by the terminal when it detects that the user identity certificate of the first slice has been updated, and the first slice is a slice that has obtained slice authentication and authorization results; The processing module is used to perform slice authentication and authorization related processing based on the request information.

16. A network device, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the steps of the slice authentication and authorization method as described in any one of claims 8 to 12.

17. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps of the slice authentication and authorization method as described in any one of claims 1 to 12.

Citation Information

Patent Citations

  • Network slice access method and device, storage medium and electronic device

    CN110351721A

  • Network access method and device and computer readable storage medium

    CN112969175A