Slice authentication method and device
By carrying the identification information of the first network in the slice authentication method and distinguishing the slice authentication initiated by different PLMNs, the problem that terminal devices are difficult to distinguish and process during the slice authentication process is solved, and authentication efficiency and the accuracy of key management are improved.
Patent Information
- Application Number
- CN202310200612.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-30
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-04-30
AI Technical Summary
During the slicing authentication process, it is difficult for terminal devices to effectively distinguish and process slice authentication initiated by different PLMNs, resulting in confusion between authentication servers and affecting authentication efficiency and key management.
By carrying the identification information of the first network in the slice authentication method, distinguishing the slice authentication initiated by different PLMNs, ensuring that the authentication server can correctly distinguish and process, thereby improving the efficiency and accuracy of slice authentication.
It improves the efficiency of slice authentication, avoids confusion in authentication servers, ensures the accuracy of key management of different PLMNs, and enhances the reliability of the system.
Smart Images

Figure CN116193431B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a slice authentication method and device. Background Art
[0002] Before the terminal device is allowed to access the slice, it needs to perform two-way authentication with the slice. Generally, the network needs to authenticate the terminal device once or twice before it can access the slice. First, the public land mobile network (PLMN) must authenticate based on the subscriber permanent identifier (SUPI) used by the terminal device to sign a contract with the PLMN. This authentication is called primary authentication. Secondly, the PLMN must authenticate based on the contract identifier used by the terminal device with the data network (DN), that is, slice authentication or secondary authentication.
[0003] When performing slice authentication, the terminal device can initiate slice authentication with the authentication server through the network function (NF) in the network. When the terminal device accesses the same slice through different access methods in the same network, the NF that initiates the slice authentication is generally the same NF. For example, after the terminal device accesses the slice through one access method, the terminal device needs to access the slice through another access method. At this time, the terminal device can no longer perform slice authentication on the slice and can access the slice through the other access method.
[0004] Therefore, how terminal devices initiate slice authentication through different networks or NFs in different networks is a problem that technicians in this field are studying. Summary of the invention
[0005] The present application provides a slice authentication method and device, which can effectively improve the efficiency of slice authentication.
[0006] In a first aspect, the present application provides a slice authentication method, the method comprising:
[0007] A first network function (NF) initiates slice authentication regarding a slice between a terminal device and an authentication server; the first NF sends identification information of a first network, identification information of the slice, and identification information of the terminal device to the authentication server, and the first NF is a NF in the first network; the first NF receives a slice authentication result of the slice, identification information of the slice, and identification information of the terminal device from the authentication server.
[0008] In an embodiment of the present application, during the slice authentication process, by carrying the identification information of the first network, on the one hand, the authentication server can distinguish the slice authentications for the same S-NSSAI initiated by different PLMNs; on the other hand, it avoids the authentication server from confusing the slice authentications for the same S-NSSAI initiated by different PLMNs. By determining the slice authentications for the same S-NSSAI initiated by different PLMNs, the relevant NF (such as the first NF) can determine whether to re-initiate slice authentication for the S-NSSAI, etc., thereby improving the efficiency of slice authentication. At the same time, by distinguishing the slice authentications for the same S-NSSAI initiated by different PLMNs, it is also possible to distinguish the keys generated by different PLMNs (or AMFs), thereby avoiding the situation where the authentication server incorrectly updates the keys.
[0009] In a possible implementation, the first network function NF sends the identification information of the first network, the identification information of the slice, and the identification information of the terminal device to the authentication server, including: the first NF sends the identification information of the first network, the identification information of the slice, and the identification information of the terminal device to the authentication server through the second NF; the first NF receives the slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device from the authentication server, including: the first NF receives the slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device sent by the authentication server through the second NF.
[0010] In a possible implementation, the method also includes: the second NF stores authentication status information of the terminal device for the slice initiated by the first network, and the authentication status information of the terminal device for the slice initiated by the first network includes: slice authentication result of the slice, identification information of the first network, identification information of the slice and identification information of the terminal device.
[0011] In a possible implementation, the method also includes: the second NF sends the authentication status information of the terminal device for the slice initiated by the first network to the third NF; the third NF receives the authentication status information of the terminal device for the slice initiated by the first network, and stores the authentication status information of the terminal device for the slice initiated by the first network.
[0012] In a possible implementation, the method also includes: the fourth NF sends a request message to the second NF or the third NF, the request message is used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice includes the authentication status information of the terminal device for the slice initiated by the first network, and the fourth NF is a NF in the second network; in response to the request message, the second NF or the third NF sends a response message to the fourth NF.
[0013] In a possible implementation, the method also includes: the first NF sends a request message to the second NF or the third NF, the request message is used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice includes the authentication status information of the terminal device for the slice initiated by the first network; in response to the request message, the second NF or the third NF sends a response message to the first NF.
[0014] In a possible implementation, the response message includes any one or more of the following: indication information, the indication information being used to indicate whether the fourth NF initiates slice authentication for the terminal device; or, the indication information being used to indicate whether the terminal device has completed slice authentication for the slice; the slice authentication result of the terminal device for the slice; and the authentication status information of the terminal device for the slice initiated by the first network.
[0015] In a second aspect, the present application provides a slice authentication method, the method comprising: an authentication server receiving identification information of a first network, identification information of a slice, and identification information of a terminal device from a first network function NF, wherein the first NF is a NF in the first network; the authentication server performs slice authentication on the slice according to the identification information of the slice and the identification information of the terminal device; the authentication server sends a slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device to the first NF.
[0016] In a possible implementation, the method also includes: the authentication server stores authentication status information of the terminal device initiated by the first network for the slice, and the authentication status information of the terminal device initiated by the first network for the slice includes: slice authentication result of the slice, identification information of the first network, identification information of the slice and identification information of the terminal device.
[0017] In a possible implementation, the method further includes: the authentication server determines whether to initiate slice authentication for the slice for the terminal device based on the authentication status information of the terminal device initiated by the first network for the slice.
[0018] In a possible implementation, the method also includes: the authentication server receives a request message from the first NF or the fourth NF, the request message being used to request the authentication status information of the terminal device for the slice; in response to the request message, the authentication server sends a response message to the first NF or the fourth NF.
[0019] In a possible implementation, the response message includes any one or more of the following: indication information, the indication information being used to indicate whether the fourth NF initiates slice authentication for the terminal device; or, the indication information being used to indicate whether the terminal device has completed slice authentication for the slice; the slice authentication result of the terminal device for the slice; and the authentication status information of the terminal device for the slice initiated by the first network.
[0020] In a third aspect, the present application provides a communication device, comprising a processing unit and a transceiver unit, wherein the processing unit is used to initiate slice authentication regarding a slice between a terminal device and an authentication server; the transceiver unit is used to send identification information of a first network, identification information of the slice, and identification information of the terminal device to the authentication server, and the communication device is an NF in the first network; the transceiver unit is also used to receive a slice authentication result of the slice, identification information of the slice, and identification information of the terminal device from the authentication server.
[0021] In a possible implementation, the transceiver unit is specifically used to send the identification information of the first network, the identification information of the slice, and the identification information of the terminal device to the authentication server through the second NF; and receive the slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device sent by the authentication server through the second NF.
[0022] In a possible implementation, the transceiver unit is also used to send a request message to the second NF or the third NF, the request message is used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice includes: the authentication status information of the terminal device for the slice initiated by the first network; and receiving a response message from the second NF or the third NF.
[0023] Exemplarily, the first NF may determine, based on the above response message, not to initiate slice authentication for the slice by the terminal device, etc. This is not limited to the embodiments of the present application.
[0024] Optionally, the above communication device may include a first NF.
[0025] In a fourth aspect, the present application provides a communication device, comprising a processing unit and a transceiver unit, wherein the transceiver unit is used to receive authentication status information for the slice initiated by the first network from the terminal device of the first NF; the processing unit is used to store the authentication status information for the slice initiated by the first network of the terminal device. Alternatively, the processing unit is used to control a storage unit (such as a memory, etc.) to store the authentication status information for the slice initiated by the first network of the terminal device.
[0026] In a possible implementation, the transceiver unit is also used to receive a request message from a fourth NF (or the first NF), the request message being used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice comprising: the authentication status information of the terminal device for the slice initiated by the first network, the fourth NF being the NF in the second network; and sending a response message to the fourth NF (or the first NF).
[0027] In a possible implementation, when the above-mentioned communication device is a second NF, the transceiver unit is also used to send the authentication status information of the terminal device for the slice initiated by the first network to the third NF.
[0028] Optionally, the above communication device may include a second NF or a third NF.
[0029] In a fifth aspect, the present application provides a communication device, comprising a transceiver unit and a processing unit, wherein the transceiver unit is used to send and receive signals; the processing unit is used to execute through the transceiver unit: sending a request message to the second NF or the third NF, the request message is used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice includes the authentication status information of the terminal device for the slice initiated by the first network, and the communication device is a NF in the second network; and receiving a response message from the second NF or the third NF.
[0030] In a possible implementation, the response message includes any one or more of the following: indication information, the indication information being used to indicate whether the fourth NF initiates slice authentication for the terminal device; or, the indication information being used to indicate whether the terminal device has completed slice authentication for the slice; the slice authentication result of the terminal device for the slice; and the authentication status information of the terminal device for the slice initiated by the first network.
[0031] Optionally, the above communication device may include a fourth NF.
[0032] In a sixth aspect, the present application provides a communication device, comprising a transceiver unit and a processing unit, wherein the transceiver unit is used to receive identification information of a first network, identification information of a slice, and identification information of a terminal device from a first network function NF; the processing unit is used to perform slice authentication on the slice according to the identification information of the slice and the identification information of the terminal device; the transceiver unit is also used to send a slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device to the first NF.
[0033] In a possible implementation, the processing unit is used to store the authentication status information of the terminal device initiated by the first network for the slice. Alternatively, the processing unit controls the storage unit to store the authentication status information of the terminal device initiated by the first network for the slice. The authentication status information of the terminal device initiated by the first network for the slice includes: the slice authentication result of the slice, the identification information of the first network, the identification information of the slice, and the identification information of the terminal device.
[0034] In a possible implementation, the processing unit is further used to determine whether to initiate slice authentication for the slice for the terminal device based on authentication status information of the terminal device initiated by the first network for the slice.
[0035] Optionally, the above-mentioned communication device includes an authentication server.
[0036] In a seventh aspect, the present application provides a communication device, the communication device comprising a processor, configured to execute a program stored in a memory, and when the program is executed, the communication device executes the method shown by the first NF in the first aspect or any possible implementation of the first aspect. Alternatively, when the program is executed, the communication device executes the steps or functions shown in the third aspect or any possible implementation of the third aspect.
[0037] In a possible implementation manner, the memory is located outside the above communication device.
[0038] In a possible implementation manner, the memory is located within the above-mentioned communication device.
[0039] In a possible implementation manner, the communication device further includes a transceiver, where the transceiver is used to receive a signal or send a signal.
[0040] In an eighth aspect, the present application provides a communication device, the communication device comprising a processor, configured to execute a program stored in a memory, and when the program is executed, the communication device executes the method shown by the second NF or the third NF in the first aspect or any possible implementation of the first aspect. Alternatively, when the program is executed, the communication device executes the steps or functions shown in the fourth aspect or any possible implementation of the fourth aspect.
[0041] In a possible implementation manner, the memory is located outside the above communication device.
[0042] In a possible implementation manner, the memory is located within the above-mentioned communication device.
[0043] In a possible implementation manner, the communication device further includes a transceiver, where the transceiver is used to receive a signal or send a signal.
[0044] In the embodiment of the present application, the communication device may include a second NF or a third NF.
[0045] In a ninth aspect, the present application provides a communication device, the communication device comprising a processor, configured to execute a program stored in a memory, and when the program is executed, the communication device executes the method shown by the fourth NF in the first aspect or any possible implementation of the first aspect. Alternatively, when the program is executed, the communication device executes the steps or functions shown in the fifth aspect or any possible implementation of the fifth aspect.
[0046] In a possible implementation manner, the memory is located outside the above communication device.
[0047] In a possible implementation manner, the memory is located within the above-mentioned communication device.
[0048] In a possible implementation manner, the communication device further includes a transceiver, where the transceiver is used to receive a signal or send a signal.
[0049] In a tenth aspect, the present application provides a communication device, the communication device comprising a processor, configured to execute a program stored in a memory, and when the program is executed, the communication device executes the method as shown in the second aspect or any possible implementation of the second aspect. Alternatively, when the program is executed, the communication device executes the steps or functions as shown in the sixth aspect or any possible implementation of the sixth aspect.
[0050] In a possible implementation manner, the memory is located outside the above communication device.
[0051] In a possible implementation manner, the memory is located within the above-mentioned communication device.
[0052] In a possible implementation manner, the communication device further includes a transceiver, where the transceiver is used to receive a signal or send a signal.
[0053] In an eleventh aspect, the present application provides a communication device, which includes a processor and an interface circuit, the interface circuit being used to receive a computer code and transmit it to the processor; the processor runs the computer code to execute the corresponding method as shown in the first aspect or any possible implementation of the first aspect. Exemplarily, the processor runs the computer code to execute the steps or functions shown in the first NF above. Exemplarily, the processor runs the computer code to execute the steps or functions shown in the second NF above. Exemplarily, the processor runs the computer code to execute the steps or functions shown in the third NF above. Exemplarily, the processor runs the computer code to execute the steps or functions shown in the fourth NF above.
[0054] In a twelfth aspect, the present application provides a communication device, which includes a processor and an interface circuit, the interface circuit being used to receive computer code and transmit it to the processor; the processor runs the computer code to execute the corresponding method as shown in the above-mentioned second aspect or any possible implementation of the second aspect.
[0055] In a thirteenth aspect, the present application provides a computer-readable storage medium, which is used to store a computer program, and when it is run on a computer, the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the first NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the second NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the third NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the fourth NF in the method shown in the first aspect or any possible implementation of the first aspect is executed.
[0056] In a fourteenth aspect, the present application provides a computer-readable storage medium for storing a computer program, which, when executed on a computer, enables the method shown in the above-mentioned second aspect or any possible implementation of the second aspect to be executed.
[0057] In a fifteenth aspect, the present application provides a computer program product, which includes a computer program or a computer code, and when it is run on a computer, the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the first NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the second NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the third NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when it is run on a computer, the method shown by the fourth NF in the method shown in the first aspect or any possible implementation of the first aspect is executed.
[0058] In a sixteenth aspect, the present application provides a computer program product, which includes a computer program or a computer code, and when the computer program product runs on a computer, the method shown in the above-mentioned second aspect or any possible implementation of the second aspect is executed.
[0059] In a seventeenth aspect, the present application provides a computer program, and when the computer program is run on a computer, the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when the computer program is run on a computer, the method shown by the first NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when the computer program is run on a computer, the method shown by the second NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when the computer program is run on a computer, the method shown by the third NF in the method shown in the first aspect or any possible implementation of the first aspect is executed. Exemplarily, when the computer program is run on a computer, the method shown by the fourth NF in the method shown in the first aspect or any possible implementation of the first aspect is executed.
[0060] In an eighteenth aspect, the present application provides a computer program. When the computer program runs on a computer, the method shown in the above-mentioned second aspect or any possible implementation of the second aspect is executed.
[0061] In a nineteenth aspect, the present application provides a wireless communication system, the wireless communication system comprising a first NF and an authentication server. Optionally, the wireless communication system further comprises a second NF. Optionally, the wireless communication system may further comprise a third NF. Optionally, the wireless communication system may further comprise a fourth NF. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 It is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;
[0063] Figure 2 It is a flowchart of a slice authentication method provided in an embodiment of the present application;
[0064] Figure 3a This is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0065] Figure 3b This is a schematic diagram of a network architecture provided by an embodiment of the present application;
[0066] Figure 4 It is a flowchart of a slice authentication method provided in an embodiment of the present application;
[0067] Figure 5 It is a flowchart of a slice authentication method provided in an embodiment of the present application;
[0068] Figure 6 It is a flowchart of a slice authentication method provided in an embodiment of the present application;
[0069] Figure 7 It is a flowchart of a slice authentication method provided in an embodiment of the present application;
[0070] Figure 8 It is a flowchart of a slice authentication method provided in an embodiment of the present application;
[0071] Fig. 9 is a structural diagram of a communication device provided in an embodiment of the present application;
[0072] Fig.10 is a structural diagram of a communication device provided in an embodiment of the present application;
[0073] Fig.11 is a structural diagram of a communication device provided in an embodiment of the present application;
[0074] Fig.12 It is a schematic diagram of a wireless communication system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0075] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described below in conjunction with the accompanying drawings.
[0076] The terms "first" and "second" in the specification, claims and drawings of this application are only used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or devices.
[0077] The "embodiment" mentioned in this article means that the specific features, structures or characteristics described in conjunction with the embodiment can be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It can be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0078] In the present application, "at least one (item)" means one or more, "more than one" means two or more, "at least two (items)" means two or three and more than three, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0079] The following is an introduction to the communication system used in this application:
[0080] The technical solution provided in this application can be applied to various communication systems. In a communication system, the part operated by the operator can be called a public land mobile network (PLMN) (also referred to as an operator network, etc.). PLMN is a network established and operated by the government or an operator approved by it for the purpose of providing land mobile communication services to the public. It is mainly a public network in which mobile network operators (MNOs) provide mobile broadband access services to users. The PLMN described in this application may specifically be a network that meets the requirements of the third generation partnership project (3GPP) standards, referred to as a 3GPP network. 3GPP networks generally include but are not limited to fifth-generation mobile communication (5th-generation, 5G) networks (referred to as 5G networks), fourth-generation mobile communication (4th-generation, 4G) networks (referred to as 4G networks), etc. For the convenience of description, PLMN will be used as an example in the embodiments of this application. Alternatively, the technical solution provided in the present application can also be applied to long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), universal mobile telecommunication system (UMTS), worldwide interoperability for microwave access (WiMAX) communication system, fifth generation (5G) communication system or new radio (NR) and other future communication systems such as 6G.
[0081] As mobile broadband access services expand, mobile networks will also develop to better support diverse business models, meet more diverse application services and the needs of more industries. For example, in order to provide better and more complete services to more industries, 5G networks have made adjustments to the network architecture compared to 4G networks. For example, the 5G network splits the mobility management entity (MME) in the 4G network into multiple network functions including access and mobility management function (AMF) and session management function (SMF).
[0082] Figure 1 This is a schematic diagram of a network architecture of an embodiment of the present application, which takes the 5G network architecture based on the service-oriented architecture in the non-roaming scenario defined in the 3GPP standardization process as an example. The network architecture may include three parts, namely, the terminal device part, the PLMN and the data network (DN).
[0083] The terminal equipment part may include a terminal device 110, which may also be referred to as a user equipment (UE). The terminal device 110 in the present application is a device with wireless transceiver functions, which may communicate with one or more core network (CN) devices (or may also be referred to as core devices) via an access network device (or may also be referred to as an access device) in a radio access network (RAN) 140. The terminal device 110 may also be referred to as an access terminal, a terminal, a user unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a user agent or a user device, etc. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on the water (such as a ship, etc.); it may also be deployed in the air (such as an airplane, a balloon, and a satellite, etc.). The terminal device 110 may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the terminal device 110 may also be a handheld device with wireless communication function, a computing device or other device connected to a wireless modem, a vehicle-mounted device, a wearable device, a drone device, or a terminal in the Internet of Things or the Internet of Vehicles, a terminal of any form in a 5G network and future networks, a relay user device, or a terminal in a future evolved PLMN, etc. Among them, the relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The embodiments of the present application do not limit the type or category of the terminal device.
[0084] The PLMN may include: a network exposure function (NEF) 131, a network function repository function (NRF) 132, a policy control function (PCF) 133, a unified data management (UDM) 134, an application function (AF) 135, an authentication server function (AUSF) 136, an access and mobility management function (AMF) 137, a session management function (SMF) 138, a user plane function (UPF) 139, and a (radio) access network ((R)AN) 140. In the above PLMN, the part other than the (radio) access network 140 part may be referred to as a core network (CN) part or a core network part.
[0085] Data network DN 120, also known as packet data network (PDN), is usually a network located outside of PLMN, such as a third-party network. Exemplarily, PLMN can access multiple data network DNs 120, and multiple services can be deployed on data network DN 120 to provide data and / or voice services to terminal device 110. For example, data network DN 120 can be a private network of a smart factory, and sensors installed in the workshop of the smart factory can be terminal devices 110. A control server for the sensors is deployed in data network DN 120, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions. For another example, data network DN 120 can be an internal office network of a company, and the mobile phones or computers of the company's employees can be terminal devices 110, and the employees' mobile phones or computers can access information, data resources, etc. on the company's internal office network. The terminal device 110 can access the company's internal office network through the interface provided by the PLMN (for example Figure 1The terminal device 110 can establish a connection with the PLMN through the N1 interface in the data network DN 120, and use the data and / or voice services provided by the PLMN. The terminal device 110 can also access the data network DN 120 through the PLMN, and use the operator services deployed on the data network DN 120, and / or the services provided by a third party. Among them, the third party can be a service provider other than the PLMN and the terminal device 110, and can provide other data and / or voice services for the terminal device 110. Among them, the specific form of the third party can be determined according to the actual application scenario, and is not limited here.
[0086] Exemplarily, the network functions in PLMN are briefly introduced below.
[0087] (R)AN 140 is a subnetwork of PLMN, and is an implementation system between a service node (or network function) in PLMN and terminal device 110. To access PLMN, terminal device 110 first passes through (R)AN 140, and then connects to a service node in PLMN through (R)AN 140. The access network device in the embodiment of the present application is a device that provides wireless communication function for terminal device 110, and may also be referred to as access device, (R)AN device or network device, etc. For example, the access device includes but is not limited to: the next generation node basestation (gNB) in the 5G system, the evolved node B (eNB) in the LTE system, the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home evolved node B (or home node B, HNB), the base band unit (BBU), the transmission and receiving point (TRP), the transmitting point (TP), the small base station equipment (pico), the mobile switching center, or the network equipment in the future network, etc. It is understandable that the present application does not limit the specific type of access network equipment. In systems using different wireless access technologies, the names of devices with access network equipment functions may be different.
[0088] Optionally, in some deployments of access devices, the access device may include a centralized unit (CU) and a distributed unit (DU). In other deployments of access devices, the CU may also be divided into a CU-control plane (CP) and a CU-user plane (UP). In still other deployments of access devices, the access device may also be an open radio access network (ORAN) architecture, etc. This application does not limit the specific deployment method of the access device.
[0089] The network opening function NEF (also referred to as NEF network function or NEF network function entity) 131 is a control plane function provided by the operator. The NEF network function 131 opens the external interface of the PLMN to a third party in a secure manner. When the SMF network function 138 needs to communicate with the network function of a third party, the NEF network function 131 can serve as a relay for the communication between the SMF network function 138 and the network entity of the third party. When the NEF network function 131 acts as a relay, it can translate the identification information of the contracted user and the identification information of the network function of the third party. For example, when the NEF network function 131 sends the subscriber permanent identifier (SUPI) of the contracted user from the PLMN to a third party, the SUPI can be translated into its corresponding external identity (ID). Conversely, when the NEF network function 131 sends the external ID (network entity ID of a third party) to the PLMN, it can translate it into SUPI.
[0090] The network storage function NRF 132 can be used to maintain real-time information of all network function services in the network.
[0091] The policy control function PCF 133 is a control plane function provided by the operator, and is used to provide the protocol data unit (PDU) session policy to the session management function SMF 138. The policy may include charging-related policy, QoS-related policy, authorization-related policy, and the like.
[0092] Unified data management UDM 134 is a control plane function provided by the operator, which is responsible for storing information such as the subscriber permanent identifier (SUPI), security context, and subscription data of the subscribers in the PLMN. The subscribers of the above-mentioned PLMN may specifically be users who use the services provided by the PLMN, such as users who use the terminal device chip card of China Telecom, or users who use the terminal device chip card of China Mobile, etc. Exemplarily, the SUPI of the subscriber may be the number of the terminal device chip card, etc. The above-mentioned security context may be data (cookie) or token stored on the local terminal device (such as a mobile phone). The subscription data of the above-mentioned subscriber may be the supporting services of the terminal device chip card, such as the traffic package of the mobile phone chip card, etc.
[0093] The application function AF 135 is used to perform data routing affected by the application, access network open functions, interact with the policy framework to perform policy control, etc.
[0094] The authentication server function AUSF 136 is a control plane function provided by the operator, and is usually used for primary authentication, ie, authentication between the terminal device 110 (subscriber) and the PLMN.
[0095] The access and mobility management function AMF 137 is a control plane network function provided by the PLMN, responsible for the access control and mobility management of the terminal device 110 accessing the PLMN, including, for example, mobile state management, allocation of user temporary identity, authentication and authorization of users, and other functions.
[0096] The session management function SMF 138 is a control plane network function provided by the PLMN, responsible for managing the protocol data unit (PDU) session of the terminal device 110. The PDU session is a channel for transmitting PDUs, and the terminal device needs to transmit PDUs to and from the DN 120 through the PDU session. The PDU session can be established, maintained, and deleted by the SMF 138. SMF 138 includes session management (such as session establishment, modification, and release, including tunnel maintenance between UPF 139 and (R)AN140, etc.), selection and control of UPF 139, service and session continuity (SSC) mode selection, roaming and other session-related functions.
[0097] The user plane function UPF 139 is a gateway provided by the operator and is the gateway for the PLMN to communicate with the DN 120. UPF 139 includes user plane related functions such as data packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, legal monitoring, uplink packet detection, downlink packet storage, etc.
[0098] Figure 1 The network functions in the PLMN shown may also include a network slice selection function (NSSF) ( Figure 1 (not shown) is responsible for determining the network slice instance, selecting the AMF network function 137, etc. Figure 1 The network functions in the PLMN shown may also include a unified data repository (UDR) and the like. The embodiment of the present application does not limit other network functions included in the PLMN.
[0099] Figure 1 Where Nnef, Nausf, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. For example, the meaning of the above interface serial numbers can refer to the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface serial numbers. It should be noted that, Figure 1 In the example, only the terminal device 110 is used as the UE. Figure 1 The interface name between the various network functions is just an example. In a specific implementation, the interface name of the system architecture may also be other names, and this application does not limit this.
[0100] The mobility management network function in this application can be Figure 1 The AMF 137 shown may also be other network functions in future communication systems having the above-mentioned access and mobility management function AMF 137. Alternatively, the mobility management network function in the present application may also be a mobility management entity (mobility management entity, MME) in an LTE system, etc.
[0101] For the convenience of explanation, in the embodiment of the present application, the access and mobility management function AMF 137 is referred to as AMF, the unified data management UDM 134 is referred to as UDM, and the terminal device 110 is referred to as UE, that is, the AMF described later in the embodiment of the present application can be replaced by a mobility management network function, the UDM can be replaced by a unified data management, and the UE can be replaced by a terminal device. It can be understood that other network functions not shown are also applicable to the replacement method.
[0102] Figure 1 The network architecture shown in the figure (such as the 5G network architecture) adopts a service-based architecture and a universal interface. The traditional network element functions are split into several self-contained, self-managed, and reusable network function service modules based on network function virtualization (NFV) technology. Figure 1 The network architecture diagram shown in the figure can be understood as a service-based 5G network architecture diagram in a non-roaming scenario. In this architecture, different network functions are combined in an orderly manner according to the needs of specific scenarios, which can realize the customization of network capabilities and services, thereby avoiding the deployment of dedicated physical networks for different services. Network slicing technology can enable operators to respond to customer needs more flexibly and quickly, and support flexible allocation of network resources.
[0103] The following is an introduction to the slices and slice authentication involved in this application.
[0104] Slicing can be simply understood as cutting the operator's physical network into multiple virtual end-to-end networks. Each virtual network (including the equipment, access network, transmission network and core network within the network) is logically independent, and a failure in any virtual network will not affect other virtual networks. In order to meet diverse needs and isolation between slices, relatively independent management and operation and maintenance of services are required, and tailored business functions and analysis capabilities must be provided. Instances of different business types can be deployed on different network slices, and different instances of the same business type can also be deployed on different network slices. A slice can be composed of a set of network functions (NF) and / or sub-networks. For example, Figure 1 The subnetwork (R)AN140, AMF 137, SMF 138, and UPF 139 in the CAN bus can form a slice. It can be understood that Figure 1 Only one of each network function is schematically drawn, but in actual network deployment, there can be multiple, dozens or hundreds of each network function or subnetwork. Many slices can be deployed in the PLMN, and each slice can have different performance to meet the needs of different applications and different vertical industries. Operators can "tailor-make" a slice according to the needs of customers in different vertical industries. Operators can also allow some industry customers to enjoy greater autonomy and participate in some management and control functions of the slice. Among them, slice-level authentication is a network control function with limited participation of industry customers, that is, to authenticate and authorize terminal devices to access slices, that is, "slice-level authentication", also known as "secondary authentication", "secondary authentication", etc., and is referred to as "slice authentication" in this application.
[0105] Before the terminal device is allowed to access the network or slice, it needs to perform two-way authentication with the network and / or slice and obtain authorization from the network and / or slice. Generally, the network needs to authenticate and authorize the terminal device once or twice before it can access the network or slice. First, the PLMN must authenticate based on the SUPI used by the terminal device and the PLMN. This authentication is called primary authentication. Secondly, the PLMN must authenticate based on the contract identifier used by the terminal device with the DN, that is, slice authentication or secondary authentication.
[0106] If Figure 1 For example, when slices are deployed in the core network and UE 110 needs to access a certain slice, UE 110 can provide the requested slice to the core network. Among them, the slice requested by UE 110 may include a requested network slice selection assistance information set (requested network slice selection assistance information, requested NSSAI). The NSSAI may include one or more single network slice selection assistance information (single network slice selection assistance information, S-NSSAI), an S-NSSAI is used to identify a network slice type, it can also be understood that S-NSSAI is used to identify a slice, or it can be understood that S-NSSAI is the identification information of the slice. It can be understood that the slice in this application can also be referred to as a network slice, a network slice instance or S-NSSAI, etc., and this application does not limit the name of the slice. For ease of understanding, in the following description, this application does not make a strict distinction between slices or S-NSSAI, etc., and the two can be equally applicable.
[0107] Further, after UE 110 sends a registration request to the network, the core network network function (such as AMF network function 137 or NSSF network function) selects a set of network slices allowed to be accessed for UE 110 according to the subscription data of UE 110, the network slice requested by UE 110, the roaming agreement, and local configuration information. Among them, the set of network slices allowed to be accessed can be represented by an allowed NSSAI, and the S-NSSAI included in the allowed NSSAI can be the S-NSSAI that the current PLMN allows the UE 110 to access.
[0108] Take the first-level authentication and the second-level authentication as an example. For example, with the development of vertical industries and the Internet of Things, the data network DN 120 outside the PLMN (such as the DN serving the vertical industry) also has the need for authentication and authorization for the UE 110 accessing the DN 120. For example, a commercial company provides a game platform and provides game services to game players through the PLMN. On the one hand, since the UE 110 used by the player accesses the game platform through the PLMN, the PLMN needs to authenticate or authorize the identity (SUPI) of the UE 110, that is, the first-level authentication. The game player is a customer of the commercial company, and the commercial company also needs to authenticate or authorize the identity of the game player. For example, if the identity of the game player is authenticated or authorized, this authentication can be based on slices, or the authentication is based on slices. In this case, this authentication can be called slice authentication, or network slice-specific authentication and authorization (NSSAA).
[0109] It should be noted that the actual meaning of slice authentication may be: authentication performed between a terminal device and a third-party network (such as a DN or its authentication server). The slice authentication result will determine whether the PLMN authorizes the terminal device to access the slice provided by the PLMN. It should also be understood that the method applied to slice authentication in this application is also applicable to scenarios such as session-based secondary authentication or slice-based secondary authentication, which will not be described in detail here.
[0110] The following is a detailed introduction to the slice authentication method provided by this application.
[0111] Figure 2 This is a flow chart of a slice authentication method provided in an embodiment of the present application, which can be applied to Figure 1 The network shown. It can be understood that Figure 2 What is shown is a slice authentication method. The embodiment of the present application does not limit the first-level authentication method between the UE and the PLMN network. Figure 2The server responsible for slice authentication is the authentication, authorization, and accounting server (AAA-S), which can be deployed within the PLMN network; or, the AAA-S can also be deployed outside the PLMN network. When the AAA-S is deployed outside the network, the UE can transfer the AAA-S through the proxy service provided by the AAA proxy (AAA-proxy, AAA-P) deployed within the PLMN network to realize the authentication message interaction between the UE and the AAA-S. Figure 2 The network slice-specific authentication and authorization function (NSSAAF) is a network function that assists in completing slice authentication. In another implementation, AUSF or other NFs can replace NSSAAF to assist in completing slice authentication. Therefore, the embodiments of the present application do not limit the network functions (such as NSSAAF, AUSF or other NFs) that assist in completing slice authentication. Furthermore, in some deployment methods, AAA-P can be deployed separately from NSSAAF; in other deployment methods, AAA-P can be deployed together with NSSAAF (or AUSF). Therefore, the embodiments of the present application do not limit the deployment methods of AAA-P and NSSAAF (or AUSF).
[0112] Figure 2 It is shown that AAA-S is deployed outside the PLMN network, that is, the UE provides proxy services through the AAA-P inside the PLMN network, and transfers to AAA-S to implement slice authentication. At the same time, the AAA-P and NSSAAF (or AUSF) are deployed separately. However, for other deployment situations, the embodiments of the present application are also applicable.
[0113] like Figure 2 As shown, the slice authentication method includes:
[0114] 201. The UE sends a registration request message to the AMF, which carries the identification information of the slice and the identification information of the UE; accordingly, the AMF receives the registration request message.
[0115] For example, the identification information of the slice may include the S-NSSAI of the slice. The identification information of the UE may include the encrypted subscription concealed identifier (SUCI) of the UE or the globally unique temporary UE identity (GUTI), etc. The embodiment of the present application does not limit the identification information of the slice or the identification information of the UE.
[0116] 202. AMF determines whether it is necessary to perform slice authentication on the UE for the slice based on the identification information of the slice and the subscription information of the UE regarding the slice.
[0117] In an embodiment of the present application, the subscription information of the UE regarding the slice identified as S-NSSAI can be obtained by the AMF from the UDM. The subscription information of the UE regarding the slice (identified as S-NSSAI) can be used to indicate whether the network needs to perform slice authentication on the UE for the slice.
[0118] That is to say, the AMF can determine whether it is necessary to perform or initiate slice authentication for the slice of the UE based on the identification information of the slice to be accessed by the UE and the subscription information of the UE regarding the slice. In addition, if the AMF records (or stores) that the UE has completed (such as through other access methods, authentication is successful or rejected) slice authentication for the slice, the UE does not need to perform slice authentication for the slice again.
[0119] If slice authentication is required, the following process is executed; if not required, the AMF can directly send a message to the UE allowing access (or denying access) to the slice, etc., which is not limited to the embodiments of the present application.
[0120] In one possible implementation, Figure 2 The method shown may include step 203 and step 204 .
[0121] 203. AMF sends an extensible authentication protocol (EAP) ID request for slice authentication to the UE; accordingly, the UE receives the EAP ID request for slice authentication.
[0122] Among them, EAP is formulated by the International Standards Organization - Internet Engineering Task Force (IETF). The EAP ID request can be carried in the non-access stratum (NAS) message in the 3GPP network. The NAS message can also carry slice identification information such as S-NSSAI. The S-NSSAI can be used to indicate that the EAP ID request is a slice authentication request for the S-NSSAI. EAP ID request and S-NSSAI can also be carried in other types of (non-NAS) messages, and this application does not limit the carrying message.
[0123] 204. The UE sends an EAP ID response to the AMF. The EAP ID response may still be carried in a NAS message, and the NAS message may also carry S-NSSAI.
[0124] It can be understood that for ease of description, when the slice identification information is involved below, the slice identification information is represented by S-NSSAI. The UE identification information can be represented by a publicly available subscription identifier (generic public subscription identifier, GPSI) or SUPI, but it should not be understood as a limitation on the embodiments of the present application. EAP IDresponse and S-NSSAI can also be carried in other types of (non-NAS) messages, and this application does not limit the carrying messages.
[0125] 205. AMF sends a first request message to AAA-S, where the first request message carries EAP ID response, S-NSSAI and GPSI or SUPI. Correspondingly, the AAA-S receives the first request message.
[0126] In an embodiment of the present application, since the AUSF or NSSAAF is not deployed together with the AAA-S, the AMF needs to first send the first request message to the AUSF or NSSAAF. At the same time, if the AAA-S is deployed outside the PLMN network, the AUSF or NSSAAF needs to send the first request message to the AAA-P, and then the AAA-P sends the first request message to the AAA-S. Exemplarily, the AMF can send the first request message to the AUSF or NSSAAF, and the AUSF or NSSAAF receives the first request message. The AUSF or NSSAAF sends the first request message to the AAA-P; accordingly, the AAA-P receives the first request message. And the AAA-P sends the first request message to the AAA-S; accordingly, the AAA-S receives the first request message. If the AUSF or NSSAAF and the AAA-P are deployed together, the AMF can send the first request message to the AUSF or NSSAAF, and the AUSF or NSSAAF receives the first request message. The AUSF or NSSAAF sends the first request message to the AAA-S; accordingly, the AAA-S receives the first request message. It is to be understood that for this description, the following also applies.
[0127] It is understandable that the first request message in the above steps can also be other names, or carried in messages of other protocols, which is not limited in the embodiments of the present application. When different NFs forward the first request message, the first request message can also be other names or carried in messages of other protocols when passing through different NFs, which is not limited in the present application. For example, when AAA-P sends the first request message to AAA-S, the first request message may also be carried in an AAA protocol message.
[0128] 206. AAA-S sends a first response message to AMF, where the first response message carries the EAP message, S-NSSAI and GPSI (or SUPI). Correspondingly, the AMF receives the first response message.
[0129] It is understandable that when AAA-S sends the first response message to AAA-P, the first response message may also be carried in an AAA protocol message, which is not limited in the embodiments of the present application. The present application does not limit the specific type of the EAP message. For example, for different EAP authentication methods, the EAP message may have different names or types.
[0130] 207. AMF sends a NAS message to the UE, and the NAS message carries the EAP message and the S-NSSAI; accordingly, the UE receives the NAS message. The EAP message and the S-NSSAI may also be carried in other types of (non-NAS) messages, and this application does not limit the carrying messages.
[0131] 208. The UE sends a NAS message to the AMF, and the NAS message carries the EAP message and the S-NSSAI. Correspondingly, the AMF receives the NAS message. The EAP message and the S-NSSAI can also be carried in other types of (non-NAS) messages, and this application does not limit the carrying message.
[0132] 209. AMF sends a second request message to AAA-S, where the second request message carries the EAP message, S-NSSAI and GPSI (or SUPI). Correspondingly, the AAA-S receives the second request message.
[0133] Understandable, Figure 2 Steps 206 to 209 in the above example can be executed multiple times. For example, for different EAP methods, the number of times that steps 206 to 209 are executed can be different. After steps 206 to 209, the EAP authentication process is completed between AAA-S and UE. Therefore, when the second request message of UE in step 208 reaches AAA-S, the AAA-S can send the EAP authentication result to the UE.
[0134] It is understandable that in an embodiment of the present application, the EAP authentication result may also be used to indicate a slice authentication result. For example, the EAP authentication result may include a result of successful EAP authentication or a result of failed EAP authentication. Accordingly, the slice authentication result may include a result of successful slice authentication or a result of failed slice authentication.
[0135] For ease of description, the embodiments of the present application do not distinguish between EAP authentication results and slice authentication results. That is, the EAP authentication results in the embodiments of the present application can also be replaced by slice authentication results, and similarly, the slice authentication results can also be replaced by EAP authentication results, etc. The embodiments of the present application do not distinguish between EAP authentication and slice authentication. For example, the EAP authentication in the embodiments of the present application can also be replaced by slice authentication, and the slice authentication can also be replaced by EAP authentication, etc. For this description, the other embodiments in the present application are also applicable.
[0136] 210. AAA-S sends a second response message to AMF, where the second response message carries the EAP authentication result, S-NSSAI and GPSI (or SUPI); accordingly, the AMF receives the second response message.
[0137] The S-NSSAI and the GPSI (or SUPI) may be used to indicate that the EAP authentication result is an authentication result for the UE and the S-NSSAI.
[0138] 211. AMF sends a NAS message to the UE, and the NAS message carries the EAP authentication result; accordingly, the UE receives the NAS message. The EAP authentication result can also be carried in other types of (non-NAS) messages, and this application does not limit the carrying message.
[0139] The above is a slice authentication method provided in an embodiment of the present application. At the same time, in a 5G communication system, a UE can access the network through different types of access methods. Exemplarily, different types of access methods may include 3GPP access (3GPP access, such as access through the 5G new air interface) and non-3GPP access (non-3GPP access, N3GPP) (such as Wi-Fi, fixed network, etc.). Non-3GPP access can also be subdivided into trusted N3GPP access and untrusted N3GPP access. In a 5G communication system that complies with Release 16 defined by the 3GPP standard, when a UE accesses the same network slice through different access methods in the same PLMN network, the AMF used by the UE is the same. For example Figure 3a As shown, the UE uses the same AMF when accessing via 3GPP and non-3GPP. Figure 3a The N3IWF may be a non-3GPP inter working function.
[0140] Generally, if the UE needs to perform slice authentication, the UE only needs to perform slice authentication through any access method. After successful authentication, if the UE accesses through other access methods again, the UE does not need to repeat the slice authentication of the same slice (S-NSSAI), that is, the slice authentication results of different access methods can be shared and stored in the AMF.
[0141] However, in a roaming scenario, when the UE leaves its home PLMN (HPLMN) and comes to a visiting PLMN (VPLMN), the network function that processes the UE's access slice request or initiates slice authentication is the AMF in the VPLMN, while the AAA-S that actually authenticates the UE is still in the HPLMN; or the UE needs to initiate slice authentication with the AAA-S through the HPLMN.
[0142] Furthermore, when the roaming UE performs slice authentication with the AAA-S in the HPLMN through different access modes, since the networks with different access modes may belong to different VPLMNs, the AMF that initiates the slice authentication is also different. Figure 3bAs shown, for example, when the UE roams to PLMN1 (3GPP access) and attempts to access slice 1 (such as S-NSSAI 1), the UE can initiate slice authentication for the UE for S-NSSAI 1 through AMF1 in PLMN1, that is, the UE can perform slice authentication with AAA-S through AMF1. At the same time, when the UE needs to access the slice in another access mode (such as Wi-Fi network), the AMF2 in PLMN2 (non-3GPP access) to which the Wi-Fi network belongs will also try to initiate slice authentication between the UE and AAA-S. In other words, Figure 3b In the scenario shown, AMFs (AMF1, AMF2) belonging to two different PLMNs (PLMN1, PLMN2) attempt to initiate or perform slice authentication for the UE.
[0143] That is to say, Figure 3b In the scenario shown, AAA-S does not distinguish between slice authentication initiated by different PLMNs, and by default there is only one PLMN. Figure 2 It can be seen that the messages received by AAA-S, such as GPSI (or SUPI), S-NSSAI, etc., are the same information for different PLMNs. Therefore, the AAA-S cannot distinguish whether the slice authentication request received by the AAA-S is a slice authentication request (or re-authentication) initiated by PLMN2 or a slice authentication request (or re-authentication) initiated by PLMN1.
[0144] For example, if the slice authentication results of PLMN1 and PLMN2 are different (for example, the slice authentication initiated by PLMN1 is successful, while the authentication of PLMN2 fails due to link congestion), AAA-S will confuse the slice authentication results and cannot determine whether the slice authentication of the UE is successful or failed (because the links of PLMN1 and PLMN2 are independent and the initiation time is independent, the order in which the slice authentication results come out is not fixed, so it is not possible to simply use rigid rules based on the order to determine whether the authentication is successful or not).
[0145] For example, if the slice authentication initiated by UE from PLMN1 is successful, and the slice authentication initiated by PLMN2 is also successful, AAA-S may mistakenly believe that the initiator of the slice authentication is still PLMN1 (i.e., the second authentication is a re-authentication of PLMN1). Therefore, the authentication success record will be refreshed, that is, the validity period of the slice authentication of PLMN1 may be updated or extended (such as the counter restarts, etc.).
[0146] For example, for EAP authentication methods that require key generation, failure to distinguish between PLMNs will also cause the key of the previous authentication to become invalid. For example, PLMN1 successfully initiates slice authentication and generates a key, which is sent to AMF1 in PLMN1. When PLMN2 also initiates slice authentication and successfully generates a key, the key will be sent to AMF2 in PLMN2. As a result, AAA-S and UE will also update the key, that is, AMF2 stores the new key, while AMF1 stores the old key. AMF1 cannot interact with UE and AAA-S using the old key.
[0147] In view of this, the present application provides a slice authentication method, which can be applied not only to roaming scenarios, but also to situations where the UE initiates slice authentication through different PLMNs.
[0148] Figure 4 It is a flow chart of a slice authentication method provided in an embodiment of the present application, and the slice authentication method can be applied to a first NF, a second NF and an authentication server. Exemplarily, the first NF may include an AMF in a VPLMN; the second NF may include an NSSAAF or an AUSF in an HPLMN, or the second NF may also include an NSSAAF and an AAA-P or an AUSF and an AAA-P in an HPLMN. In other words, the second NF may be an NF when NSSAAF (or AUSF) and AAA-P are deployed together, and the second NF may also be an NSSAAF or an AAA-P when NSSAAF (or AUSF) and AAA-P are deployed separately. The authentication server may include an AAA-S, and the AAA-S may be deployed within or outside the HPLMN. Optionally, the slice authentication method may also be applied to a third NF, and the third NF may be an NF with a network storage function, such as the third NF may include a UDM or a UDR. Optionally, the slice authentication method may also be applied to a fourth NF, and the fourth NF may include an AMF in a VPLMN. However, the fourth NF and the first NF may be located in different VPLMNs, that is, the fourth NF and the first NF may have the same function but belong to different VPLMNs.
[0149] like Figure 4 As shown, the slice authentication method includes:
[0150] 401. The first NF initiates slice authentication between the terminal device and the authentication server regarding (or for) the slice (i.e., the slice corresponding to the S-NSSAI).
[0151] For how the first NF initiates slice authentication between the terminal device and the authentication server, please refer to other embodiments in this application, which will not be described in detail here. Figure 2 As shown, or as Figures 5 to 8 Any of the methods shown.
[0152] 402. The first NF sends identification information of the first network, identification information of the slice, and identification information of the terminal device to the authentication server, where the first NF is the NF in the first network; correspondingly, the authentication server receives the identification information of the first network, identification information of the slice, and identification information of the terminal device.
[0153] In an embodiment of the present application, the identification information of the first network sent by the first NF can also be replaced by the identification information of the network function in the first network. Exemplarily, the identification information of the first network may include the identification of the PLMN and / or the identification of the serving network. The identification of the PLMN may include the ID of the PLMN, and the identification of the serving network may include the ID (SN-ID) of the serving network, the name of the serving network (serving network name, SNN), or the network identifier (network identifier, NID), etc. The identification information of the network function in the first network may include the identification of the first NF. The identification of the first NF may include the ID of the AMF, the name of the AMF, or the globally unique AMF identifier (globally unique AMF identifier, GUAMI), etc. Alternatively, the above-mentioned first NF may also send both the identification information of the first network and the identification information of the NF in the first network to the authentication server.
[0154] For the convenience of description, this application does not distinguish between "identification information of the first network" and "identification information of the NF in the first network", and they are collectively referred to as "identification information of the first network".
[0155] Exemplarily, the identification information of the slice may include the S-NSSAI or slice instance ID of the slice, etc. The identification information of the UE may include the GPSI or SUPI of the UE, etc. The embodiment of the present application does not limit the identification information of the slice or the identification information of the UE.
[0156] Optionally, the first NF may send identification information of the first network, identification information of the slice, and identification information of the terminal device to the authentication server through the second NF.
[0157] It is understandable that the identification information of the first network, the identification information of the slice, and the identification information of the terminal device can be carried in a request message, such as the third request message or the fourth request message in other embodiments of the present application. Alternatively, the identification information of the first network, the identification information of the slice, and the identification information of the terminal device can also be carried in messages of other protocols, etc., which is not limited in the embodiments of the present application.
[0158] 403. The authentication server sends the slice authentication result for the slice, the identification information of the slice, and the identification information of the terminal device to the first NF.
[0159] Optionally, the first NF may also receive the slice authentication result, slice identification information, and terminal device identification information sent by the authentication server through the second NF.
[0160] In the embodiment of the present application, during the process of the authentication server performing slice authentication on the slice, by carrying the identification information of the first network, on the one hand, the authentication server can distinguish the slice authentications for the same S-NSSAI initiated by different PLMNs; on the other hand, it avoids the authentication server from confusing the slice authentications for the same S-NSSAI initiated by different PLMNs. At the same time, by distinguishing the slice authentications for the same S-NSSAI initiated by different PLMNs, the authentication server can also distinguish the keys generated by different PLMNs (or AMFs), avoiding the situation where the authentication server incorrectly updates the keys.
[0161] In one possible implementation, Figure 4 The illustrated method may further include step 404 .
[0162] 404. The second NF stores the authentication status information of the terminal device for the slice initiated by the first network.
[0163] Among them, the authentication status information of the terminal device for the slice initiated by the first network includes the slice authentication result of the slice, the identification information of the first network, the identification information of the slice, and the identification information of the terminal device. In other words, the second NF can store the slice authentication result of the slice, the identification information of the first network, the identification information of the slice, and the identification information of the terminal device. It can be understood that the description of the authentication status information of the slice initiated by the first network for the terminal device is also applicable elsewhere in the embodiments of the present application.
[0164] In the embodiment of the present application, the second NF can provide useful information for subsequent slice authentication by storing the authentication status information of the terminal device for the slice initiated by the first network. For this method, refer to step 407 and step 408; or, refer to Figure 6 or refer to the related methods shown in Figure 5 , Figure 7 and Figure 8 The methods shown, etc., will not be described in detail here.
[0165] In one possible implementation, Figure 4 The method shown may further include step 405 and step 406 .
[0166] 405. The second NF sends the authentication status information of the terminal device for the slice initiated by the first network to the third NF; correspondingly, the third NF receives the authentication status information of the terminal device for the slice initiated by the first network.
[0167] 406. The third NF stores the authentication status information of the terminal device for the slice initiated by the first network.
[0168] It is understandable that if there is no interface between the second NF and the third NF, the authentication status information of the slice of the terminal device initiated by the first network can also be sent to the third NF through the first NF.
[0169] In the embodiment of the present application, the third NF can provide useful information for subsequent slice authentication by storing the authentication status information of the terminal device for the slice initiated by the first network. For this method, refer to step 407 and step 408; or, refer to Figure 8 The related methods shown will not be described in detail here.
[0170] 407. The fourth NF sends a request message to the second NF or the third NF, where the request message is used to request authentication status information of the terminal device for the slice, and the fourth NF is an NF in the second network; accordingly, the second NF or the third NF receives the request message.
[0171] 408. The second NF or the third NF sends a response message to the first NF; correspondingly, the first NF receives the first response message.
[0172] It is understandable that if the authentication status information of the slice initiated by the first network of the above-mentioned terminal device is stored in the second NF, when the fourth NF sends a request message to the second NF, it can obtain the indication information of the slice authentication initiated by the first network from the response message. The request message may include the identification information of the terminal device, the identification information of the slice, and the identification information of the second network. For the above-mentioned identification information, please refer to the introduction of step 401, which will not be described in detail here. Exemplarily, the request message may be the sixth request message shown below, etc.
[0173] If the authentication status information of the slice initiated by the first network of the terminal device is stored in the third NF, the fourth NF can send a request message to the third NF. Exemplarily, the request message can be Figure 8 The fifth request message shown, etc.
[0174] Optionally, the response message includes any one or more of the following:
[0175] Indication information, where the indication information is used to indicate whether the fourth NF needs to initiate slice authentication for the slice for the terminal device; or, the indication information is used to indicate whether the terminal device has completed slice authentication for the slice;
[0176] The slice authentication result of the terminal device for the slice;
[0177] Authentication status information of the terminal device for the slice initiated by the first network.
[0178] In some implementations, the indication information can be used to indicate whether it is necessary to initiate slice authentication for the terminal device. For example, the indication information can be used to instruct the fourth NF to continue or initiate slice authentication. In other implementations, the above response message may carry the authentication status information of the terminal device for the slice initiated by the first network (and / or other networks). For example, the response message may carry S-NSSAI, GPSI (or SUPI), PLMN-ID (or AMF-ID) (such as the ID of the first network) and slice authentication results. For another example, the response message may also carry information such as the reason for the failure of the slice authentication result of the S-NSSAI. Optionally, the above response message may carry the slice authentication result for S-NSSAI initiated by the first network for the UE, which is most recently (or most recently) stored in the second NF or the third NF (such as carrying S-NSSAI, PLMN-ID (or AMF-ID), GPSI (or SUPI) and slice authentication result); or, it may also carry authentication status information for S-NSSAI initiated by all PLMN networks about the terminal device, which is stored in the second NF or the third NF.
[0179] For a detailed description of the above request message and / or response message, please refer to the following text and will not be described in detail here.
[0180] In one possible implementation, Figure 4 The illustrated method may further include step 409 .
[0181] 409. The authentication server stores the authentication status information of the terminal device for the slice initiated by the first network.
[0182] For a detailed description of the authentication status information of the authentication server storing the terminal device initiated by the first network for the slice, please refer to Figures 5 to 8 For example, please refer to Figure 5 Step 515 shown, Figure 6 Step 615 etc. shown.
[0183] Optionally, the authentication server may also determine whether to initiate slice authentication for the slice for the terminal device based on the authentication status information for the slice initiated by the first network of the terminal device. Optionally, when the fourth NF sends a request message to the authentication server, the authentication server may determine whether to initiate slice authentication for the slice for the terminal device through the second network (i.e., the network where the fourth NF is located) based on the authentication status information for the slice initiated by the first network of the terminal device. The request message carries the identification information of the terminal device, the identification information of the slice, and the identification information of the second network.
[0184] In other words, when the authentication status information of the terminal device initiated by the first network for the slice is likely to be stored in the authentication server, the fourth NF may also send a request message to the authentication server. For example, the specific description of the request message may refer to Figure 6 The method shown will not be described in detail here.
[0185] Understandably, for Figure 4 For the specific method shown, reference may be made to the various embodiments shown below.
[0186] For a more vivid understanding Figure 4 The present application also provides a slice authentication method, such as Figures 5 to 8 shown.
[0187] It is understood that in each of the embodiments shown below, AAA-P and NSSAAF (or AUSF) are deployed together, but the present application is not limited thereto. The present application also does not limit whether AAA-S is deployed inside or outside the PLMN network.
[0188] Figure 5 is a flow chart of a slice authentication method provided in an embodiment of the present application, such as Figure 5 As shown, the method includes:
[0189] 501. The UE sends a registration request message to the AMF, which carries the identification information of the slice and the identification information of the UE; accordingly, the AMF receives the registration request message.
[0190] 502. AMF determines to perform slice authentication on the slice based on the identification information of the slice and the contract information of the slice.
[0191] The following will be explained as the slice that needs to be authenticated, but for other situations (see Figure 2 ), the present application is also applicable.
[0192] 503. AMF sends an EAP ID request for slice authentication to the UE; accordingly, the UE receives the EAP ID request for slice authentication.
[0193] 504. The UE sends an EAP ID response to the AMF. The EAP ID response may still be carried in a NAS message, and the NAS message may also carry an S-NSSAI.
[0194] It is understood that for the detailed description of steps 501 to 504, reference can be made to Figure 2 The introduction of steps 201 to 204 will not be described in detail here.
[0195] 505. AMF sends a third request message to NSSAAF (or AUSF), where the third request message carries an EAP ID response, slice identification information, UE identification information, and network identification information or network function identification information; accordingly, the NSSAAF receives the third request message.
[0196] In the embodiment of the present application, the identification information of the slice may refer to the above description, such as the identification information of the slice may include S-NSSAI, and the identification information of the UE may include GPSI or SUPI, etc. The identification information of the network may include the ID of the PLMN (referred to as PLMN-ID), the ID of the serving network (SN-ID), the name of the serving network (serving network name, SNN), or the network identifier (network identifier, NID), etc. The identification information of the network function may include the ID of the AMF (referred to as AMF-ID), the name of the AMF (AMF name), or the globally unique AMF identifier (globally unique AMF identifier, GUAMI), etc. In the present application, the identification information of the network is only taken as PLMN-ID as an example, and the identification information of the network function is only illustrated by taking AMF-ID as an example, but it should not be understood as a limitation on the embodiments of the present application.
[0197] For the convenience of description, this application does not distinguish between "network identification information" (such as PLMN-ID) and "network function identification information" (such as AMF-ID), and collectively refers to them as "network identification information".
[0198] Exemplarily, the PLMN-ID can be understood as Figure 3b The ID of PLMN1 in the AMF-ID can be understood as Figure 3b The ID of AMF1 in .
[0199] It is understandable that when using AMF-ID as the identification information of the network, additional operations may be introduced. For example, there may be many AMFs in a PLMN, and the AMF providing services to the UE may change (the PLMN does not change). In this way, every time the AMF changes, all related NFs or network elements (such as AAA-S, NSSAAF / AUSF, etc.) need to be notified to maintain synchronization.
[0200] Optionally, the third request message may not carry the network identification information. In this case, Figure 5 The illustrated method may also include step 506 .
[0201] 506. The NSSAAF (or AUSF) determines the identification information of the network (such as PLMN-ID or AMF-ID) according to the received third request message.
[0202] Generally, in order to ensure the authenticity of the message sent from the AMF, the message will include a token for verifying the AMF. The token can be used to indicate the source of the message, that is, the token can indicate the ID of the AMF that sent the message, and further obtain the ID of the PLMN. That is to say, after receiving the third request message, the NSSAAF (or AUSF) can determine the identification information of the network according to the token included in the third request message.
[0203] It can be understood that the description of step 505 and step 506 is also applicable to the following embodiments.
[0204] 507. NSSAAF (or AUSF) sends a third request message to AAA-S, where the third request message carries EAP ID response, S-NSSAI, GPSI (or SUPI) and PLMN-ID (or AMF-ID); accordingly, the AAA-S receives the third request message.
[0205] 508. AAA-S sends a third response message to the NSSAAF (or AUSF), where the third response message carries the EAP message, S-NSSAI, GPSI (or SUPI) and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the third response message.
[0206] 509. NSSAAF (or AUSF) sends a third response message to AMF, where the third response message carries EAP message, S-NSSAI, and GPSI (or SUPI); accordingly, the AMF receives the third response message.
[0207] 510. AMF sends a NAS message to the UE, where the NAS message carries the EAP message and the S-NSSAI. Correspondingly, the UE receives the NAS message.
[0208] 511. The UE sends a NAS message to the AMF, where the NAS message carries the EAP message and the S-NSSAI. Correspondingly, the AMF receives the NAS message.
[0209] 512. AMF sends a fourth request message to NSSAAF (or AUSF), where the fourth request message carries EAP message, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the fourth request message.
[0210] Optionally, the fourth request message may not carry PLMN-ID (or AMF-ID). Figure 5 The illustrated method may further include step 513 .
[0211] 513. NSSAAF (or AUSF) determines the PLMN-ID (or AMF-ID) according to the received fourth request message.
[0212] It is understandable that the specific description of step 512 and step 513 can also refer to the introduction of step 505 and step 506, and the description of step 512 and step 513, which are also applicable in the following embodiments.
[0213] 514. NSSAAF (or AUSF) sends a fourth request message to AAA-S, where the fourth request message carries an EAP message, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the fourth request message.
[0214] Understandable, Figure 5 Steps 508 to 514 in the above may also be performed multiple times. For this implementation, please refer to Figure 2 The introduction will not be described in detail here.
[0215] 515. AAA-S stores the EAP authentication result, EAP-ID, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI).
[0216] In the embodiment of the present application, the AAA-S stores the slice authentication result of the S-NSSAI initiated by the UE (GPSI / SUPI and EAP-ID) through the PLMN (or the AMF). By storing the authentication status information of the S-NSSAI, AAA-S can determine which PLMN (or AMF) the slice authentication for the S-NSSAI is initiated by when other PLMNs (or AMFs) subsequently initiate slice authentication for the S-NSSAI, whether it is a slice authentication initiated again after the PLMN (or AMF) has performed slice authentication, or a slice authentication initiated for the first time by other PLMNs (or AMFs). AAA-S can know whether the slice authentication initiated by the PLMN (or AMF) is the first slice authentication or the second slice authentication performed by the PLMN (or AMF) for S-NSSAI based on the authentication status information for S-NSSAI stored by the AAA-S.
[0217] Exemplarily, the above-mentioned AMF ( Figure 5 The AMF shown in Figure 3b The other AMFs mentioned above can be understood as AMF1 Figure 3b Alternatively, the AMF can also be understood as Figure 3b AMF2 in , while other AMFs can be understood as Figure 3b AMF1 in. Exemplarily, the above PLMN can be understood as Figure 3b PLMN1 in the , and other PLMNs can be understood as Figure 3b PLMN2 in the hereinafter. For the convenience of description, the AMF will be understood as Figure 3b AMF1 in, other AMFs are understood as Figure 3b The AMF2 in FIG. 2 is used as an example to illustrate. And the PLMN is understood as Figure 3b PLMN1 in the table, other PLMNs can be understood as Figure 3b It can be understood that the PLMN1 and PLMN2 shown above both belong to VPLMN.
[0218] In other words, by storing the slice authentication status information in AAA-S, the AAA-S can distinguish whether the slice authentication request (such as the third request message or the fourth request message, etc.) it receives is initiated by PLMN1 or PLMN2. At the same time, it avoids the AAA-S from mistakenly refreshing the validity period of slice authentication of other PLMNs, and avoids the situation where the key is invalid due to failure to distinguish PLMNs.
[0219] It is understandable that the authentication status information involved in this application may also be referred to as authentication related information, etc., and this application does not limit its name. The slice authentication status information may include the slice authentication result, EAP-ID, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI) corresponding relationship (or may also be referred to as association relationship, etc.). In other words, the authentication status information may include the authentication status information of the terminal device initiated by the first network for the slice and / or the authentication status information of the slice in the second network, etc.
[0220] 516. AAA-S sends a fourth response message to the NSSAAF (or AUSF), where the fourth response message carries the EAP authentication result, GPSI (or SUPI), S-NSSAI and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the fourth response message.
[0221] 517. NSSAAF (or AUSF) sends a fourth response message to AMF, where the fourth response message carries the EAP authentication result, GPSI (or SUPI) and S-NSSAI; accordingly, the AMF receives the fourth response message.
[0222] 518. AMF sends a NAS message to the UE, where the NAS message carries the EAP authentication result. Correspondingly, the UE receives the NAS message.
[0223] Optionally, the AMF may also send a registration update message (or configuration update message) to the UE, where the registration update message carries S-NSSAI, etc. It is understandable that the embodiment of the present application does not limit the response message to the registration request message, and the response message to the registration request message may refer to relevant protocols or standards, etc.
[0224] Optional, Figure 5 In the method shown, one of the messages sent to AAA-S may carry PLMN-ID or AMF-ID (such as the fourth request message in step 514), while other messages (such as the third request message in step 507) may not carry the PLMN-ID or AMF-ID. This is because the message sent to the AAA-S (whether it is an EAP message or an AAA protocol message) will carry the same session identifier (session ID). Therefore, AAA-S can associate the session identifier carried in the fourth request message in step 514 with the third request message in step 507, thereby obtaining the PLMN-ID or AMF-ID in the third request message. Alternatively, the third request message carries the PLMN-ID or AMF-ID, while the fourth request message does not carry the PLMN-ID or AMF-ID.
[0225] Optional, Figure 5 In the method shown, the message sent by AAA-S to NSSAAF (or AUSF) (such as the third response message in step 508 and the fourth response message in step 516) may not carry PLMN-ID (or AMF-ID). That is, the network function in the HPLMN (such as NSSAAF or AUSF, UDM, etc.) may not store the authentication status information of the slice. And when the network function in the HPLMN (such as NSSAAF or AUSF, UDM, etc.) needs to store the authentication status information of the slice, the message sent by the above AAA-S to NSSAAF (or AUSF) may carry PLMN-ID (or AMF-ID).
[0226] It is understood that for the incomplete description of the third request message and / or the fourth request message, please refer to Figure 2 The introduction of the first request message and / or the second request message in will not be described in detail here.
[0227] In the embodiment of the present application, by carrying the identification information of the network in the third request message and / or the fourth request message, on the one hand, AAA-S can distinguish the slice authentications for the same S-NSSAI initiated by different PLMNs; on the other hand, it avoids AAA-S from confusing the slice authentications for the same S-NSSAI initiated by different PLMNs. At the same time, by distinguishing the slice authentications for the same S-NSSAI initiated by different PLMNs, AAA-S can distinguish the keys used by different PLMNs (or AMFs), avoiding the situation where some AMFs cannot use the keys.
[0228] Furthermore, by storing the authentication status information of slice authentication performed by the same S-NSSAI through different networks, the AAA-S can provide useful information for subsequent slice authentication. For the specific steps of this method, refer to Figure 6 As shown in the method. Figure 6 As shown, the present application also provides a flow chart of a slice authentication method. It can be understood that in some implementations, Figure 5 and Figure 6 The methods shown can be combined; in other implementations, Figure 5 and Figure 6 They can also be executed separately, etc., which is not limited in this application. Figure 6 As shown, the slice authentication method includes:
[0229] 601. The UE sends a registration request message to the AMF, which carries the identification information of the slice and the identification information of the UE; accordingly, the AMF receives the registration request message.
[0230] 602. The AMF determines to perform slice authentication on the slice based on the identification information of the slice and the subscription information of the UE for the slice. In addition, if the AMF stores that the UE has successfully completed the slice authentication for the slice (such as through other access methods), the UE does not need to perform slice authentication for the slice again.
[0231] 603. AMF sends an EAP ID request for slice authentication to the UE; accordingly, the UE receives the EAP ID request for slice authentication.
[0232] 604. The UE sends an EAP ID response to the AMF. The EAP ID response may still be carried in a NAS message, and the NAS message may also carry an S-NSSAI.
[0233] 605. AMF sends the seventh request message to NSSAAF (or AUSF), where the seventh request message carries the EAP ID response, slice identification information, UE identification information and network identification information; accordingly, the NSSAAF receives the seventh request message.
[0234] Optionally, the seventh request message may not carry the network identification information. In this case, Figure 6 The illustrated method may also include step 606 .
[0235] 606. The NSSAAF (or AUSF) determines the network identification information (such as PLMN-ID or AMF-ID) according to the received seventh request message. The method for the NSSAAF (or AUSF) to determine the network identification information can refer to the description of step 506, which will not be repeated here.
[0236] 607. NSSAAF (or AUSF) sends a seventh request message to AAA-S, where the seventh request message carries EAP ID response, S-NSSAI, GPSI (or SUPI) and PLMN-ID (or AMF-ID); accordingly, the AAA-S receives the seventh request message.
[0237] 631. AAA-S determines whether to continue with slice authentication. If AAA-S determines to continue with slice authentication, Figure 6 The method shown may also include steps 608 to 618; if the AAA-S determines not to proceed with slice authentication, then Figure 6 The method shown may also include steps 632 to 634 .
[0238] In some implementations, if Figure 5 The VPLMN (or AMF) and Figure 6The VPLMN (or AMF) shown is not the same VPLMN (or AMF). Figure 5 The VPLMN (or AMF) shown is Figure 3b PLMN1 (or AMF1) in Figure 6 The VPLMN (or AMF) shown is Figure 3b AAA-S is based on the PLMN2 (or AMF2) in Figure 5 The step 515 shown stores the authentication status information of the S-NSSAI initiated by the UE through AMF1 (or PLMN1) (i.e., AAA-S stores the authentication status information of the S-NSSAI). In this case, when AMF2 initiates slice authentication of the S-NSSAI, the AAA-S can learn, by receiving the seventh request message, that the UE requested (or initiated) the slice authentication for the S-NSSAI through PLMN2 or AMF2, so that the AAA-S can determine whether the AMF2 needs to continue to perform slice authentication on the S-NSSAI based on its stored EAP authentication result (e.g., successful authentication), PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI), and its policy (or local policy). In one implementation method, AAA-S allows different PLMNs to share slice authentication results, then AAA-S can determine not to continue the authentication process (i.e., not to perform slice authentication), and execute steps 632 to 634. In another implementation method, AAA-S does not allow PLMN2 to share slice authentication results with other PLMNs. In this case, AAA-S can determine that the slice authentication process initiated by PLMN2 needs to continue (i.e., perform slice authentication), that is, execute steps 608 to 618.
[0239] The two implementations shown above are combined Figure 5 and Figure 6 In other words, AAA-S can determine whether to continue slice authentication based on the stored slice (S-NSSAI) authentication results of the same UE (GPSI, EAP ID) and the AAA-S policy. For example, if the UE has successfully completed authentication through other PLMNs, AAA-S can exempt re-authentication and directly approve the authentication request initiated by the PLMN and record it. However, when Figure 5 and Figure 6 When the method shown is executed alone, that is, when the AAA-S has not yet stored the slice authentication result of the UE initiating the S-NSSAI through the AMF, the AAA-S can also determine that the AMF can continue to perform slice authentication.
[0240] 632. AAA-S sends a seventh response message to the NSSAAF (or AUSF), where the seventh response message carries the EAP authentication result, S-NSSAI and GPSI (or SUPI); accordingly, the NSSAAF (or AUSF) receives the seventh response message.
[0241] 633. NSSAAF (or AUSF) sends a seventh response message to AMF, where the seventh response message carries the EAP authentication result, S-NSSAI and GPSI (or SUPI); accordingly, the AMF receives the seventh response message.
[0242] 634. AMF sends a NAS message to the UE, where the NAS message carries the EAP authentication result; correspondingly, the UE receives the NAS message.
[0243] It is understandable that for the specific description of steps 632 to 634, reference may be made to steps 616 to 618, which will not be described in detail here.
[0244] 608. AAA-S sends a seventh response message to the NSSAAF (or AUSF), where the seventh response message carries the EAP message, S-NSSAI, GPSI (or SUPI) and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the seventh response message.
[0245] 609. The NSSAAF (or AUSF) sends a seventh response message to the AMF, where the seventh response message carries the EAP message, S-NSSAI and GPSI (or SUPI); accordingly, the AMF receives the seventh response message.
[0246] 610. AMF sends a NAS message to the UE, where the NAS message carries the EAP message and the S-NSSAI. Correspondingly, the UE receives the NAS message.
[0247] 611. The UE sends a NAS message to the AMF, where the NAS message carries the EAP message and the S-NSSAI. Correspondingly, the AMF receives the NAS message.
[0248] 612. AMF sends an eighth request message to NSSAAF (or AUSF), where the eighth request message carries EAP message, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the eighth request message.
[0249] Optionally, the eighth request message may not carry the network identification information PLMN-ID (or AMF-ID). Figure 6The illustrated method may further include step 613 .
[0250] 613. NSSAAF (or AUSF) determines the PLMN-ID (or AMF-ID) according to the received eighth request message.
[0251] 614. The NSSAAF (or AUSF) sends an eighth request message to the AAA-S, where the eighth request message carries an EAP message, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the eighth request message.
[0252] 615. AAA-S stores the EAP authentication result, EAP-ID, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI).
[0253] 616. AAA-S sends an eighth response message to the NSSAAF (or AUSF), where the eighth response message carries the EAP authentication result, GPSI (or SUPI), S-NSSAI and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the eighth response message.
[0254] 617. NSSAAF (or AUSF) sends an eighth response message to AMF, where the eighth response message carries the EAP authentication result, GPSI (or SUPI) and S-NSSAI; accordingly, the AMF receives the eighth response message.
[0255] 618. AMF sends a NAS message to the UE, where the NAS message carries the EAP authentication result. Correspondingly, the UE receives the NAS message.
[0256] It is understood that steps 601 to 618 in the embodiment of the present application can refer to Figure 5 The method shown is not described in detail here. Exemplarily, the seventh request message can refer to the third request message, the seventh response message can refer to the third response message, the eighth request message can refer to the fourth request message, the eighth response message can refer to the fourth response message, and so on.
[0257] Figure 5 and Figure 6 It is shown that AAA-S stores EAP authentication result, EAP-ID, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI).
[0258] In some implementations, Figure 5In the method shown, any one or more of the third request message, the third response message, the fourth request message or the fourth response message may not carry the identification information of the network (such as PLMN-ID or AMF-ID). In this case, the NSSAAF (or AUSF) can obtain the identification information of the network through step 506 and / or step 513. At the same time, in step 506 and / or step 513, the NSSAAF (or AUSF) can extract the session ID from the EAP message or AAA protocol message in the third request message or the fourth request message, and store the UE's identity information GPSI, S-NSSAI and the network's identification information (such as AMF-ID) corresponding to the session ID.
[0259] Further, in step 516, the NSSAAF (or AUSF) searches for a message with the same session ID from the received message, and the EAP authentication result contained in the message is the slice authentication result for the S-NSSAI initiated by the UE (GPSI / EAP-ID) from the PLMN / AMF. That is, the NSSAAF (or AUSF) associates the authentication result in the fourth response message of step 516 according to the session ID, so that the NSSAAF (or AUSF) can store the EAP authentication result, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI).
[0260] Optionally, before executing step 502, the AMF may send a sixth request message to the NSSAAF (or AUSF), where the sixth request message may be used to request the UE for the slice authentication result of the S-NSSAI, etc. For the sixth request message, please refer to Figure 8 The fifth request message shown is not described in detail here. At the same time, the NSSAAF (or AUSF) can also send a sixth response message to the AMF. The sixth response message can refer to Figure 8 The fifth response message shown is not described in detail here.
[0261] Furthermore, the NSSAAF (or AUSF) may also send the EAP authentication result, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI) to the UDM, such as Figure 7 Steps 531 to 533 in .
[0262] In some other implementations, the present application also provides a slice authentication method, in which the EAP authentication result, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI) can be stored in the UDM. Figure 5As an example, the slice authentication method provided in the embodiment of the present application is as follows Figure 7 As shown, Figure 7 For detailed description of steps 501 to 518, please refer to Figure 5 , which will not be elaborated here.
[0263] Understandable, Figure 7 The AAA-S may store the EAP authentication result, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI); alternatively, the AAA-S may not store the EAP authentication result, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI), which is not limited in this embodiment of the present application.
[0264] like Figure 7 As shown, after step 516, Figure 7 The method shown also includes:
[0265] 531. NSSAAF (or AUSF) stores slice authentication results, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID).
[0266] In other words, the NSSAAF (or AUSF) can store the authentication result of the slice (S-NSSAI) initiated by the UE (GPSI or SUPI) through the AMF (AMF-ID). Alternatively, the NSSAAF (or AUSF) can store the association between the UE's identification information (such as GPSI or SUPI), the network's identification information (such as AMF-ID), and the authentication result (such as EAP authentication result) of the slice (such as S-NSSAI). Regarding the description of storing the association relationship, other embodiments of the present application are also applicable.
[0267] It is understandable that the NSSAAF (or AUSF) may store the above information; or, it may not store the above information, and this embodiment of the present application is not limited to this.
[0268] 532. NSSAAF (or AUSF) sends slice authentication results, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID) to UDM.
[0269] 533. UDM stores slice authentication results, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID).
[0270] It is understandable that the embodiment of the present application does not limit the order of step 517 and step 531.
[0271] In the embodiment of the present application, UDM can assist AAA-S in initiating re-authentication or revocation operations by storing the above information. When AAA-S initiates a request for re-authentication or revocation operation, NSSAAF (or AUSF) or UDM can index all relevant AMFs and forward the corresponding EAP request message of the re-authentication / revocation operation to AMF.
[0272] The re-authentication and revocation process is illustrated by way of example, but should not be construed as a limitation on the embodiments of the present application.
[0273] Exemplarily, the re-authentication process initiated by AAA-S is as follows:
[0274] 1) AAA-S sends a re-authentication request message to NSSAAF or AUSF, which carries S-NSSAI and GPSI (or SUPI). Optionally, the re-authentication request message may also carry PLMN-ID (or AMF-ID) to indicate which PLMN initiated the re-authentication of the original slice authentication.
[0275] 2) NSSAAF determines the corresponding AMF (such as the above Figure 7 The AMF shown in the figure is used to process the re-authentication of the UE for the S-NSSAI. For example, the NSSAAF may send a request message to the UDM, requesting the UDM to determine the required AMF. The request message carries the GPSI (or SUPI) of the UE. Optionally, the re-authentication request message may also carry the PLMN-ID stored by the NSSAAF or received from the AAA-S. The UDM determines the corresponding PLMN and AMF based on the stored AMF-ID corresponding to the slice authentication of the UE for the S-NSSAI and the received PLMN-ID. Optionally, if the determined AMF-ID cannot serve the UE, the UDM may replace it with other AMFs, such as other AMFs in the same AMF group (AMF set) in the same PLMN or the default AMF in the PLMN, to process the re-authentication of the UE.
[0276] 3) NSSAAF sends a re-authentication request message to the determined AMF, which carries the UE's GPSI (or SUPI) and the S-NSSAI.
[0277] 4) After receiving the re-authentication request message, AMF initiates re-authentication between UE and AAA-S.
[0278] Exemplarily, the revocation process initiated by AAA-S is as follows:
[0279] 1) AAA-S initiates a revocation request message to NSSAAF or AUSF for the UE, and the revocation request message carries S-NSSAI and GPSI (or SUPI). Optionally, the revocation request message may also carry PLMN-ID.
[0280] 2) NSSAAF determines the corresponding AMF (such as the above Figure 7 The AMF shown in the figure is used to process the revocation of the S-NSSAI by the UE. For example, the NSSAAF may send a request message to the UDM, requesting the UDM to determine the required AMF. The request message carries the GPSI (or SUPI) of the UE. Optionally, if only the slice authentication result initiated by a certain PLMN is to be revoked, the request message may also carry the PLMN-ID stored by the NSSAAF or received from the AAA-S. The UDM determines the corresponding AMF based on the stored AMF-ID corresponding to the slice authentication for the S-NSSAI initiated by the UE through the PLMN. Optionally, if the determined AMF-ID cannot serve the UE, the UDM may replace other AMFs in the same AMF group (AMF set) or the default AMF in the same PLMN to process the revocation process of the UE.
[0281] 3) NSSAAF sends a revocation request message to the determined AMF, where the revocation request message carries the UE's GPSI and the S-NSSAI.
[0282] 4) After receiving the revocation request message, the AMF initiates the revocation process for the S-NSSAI to the UE.
[0283] It is understandable that the above is merely an example and should not be construed as a limitation on the embodiments of the present application.
[0284] It should be further explained that in step 532, NSSAAF (or AUSF) obtains information such as slice authentication results and forwards it to UDM. If there is no interface between NSSAAF (or AUSF) and UDM, the slice authentication results and other information can be sent to UDM through AMF. For example, after AMF receives the fourth response message in step 517, the AMF can directly send information such as slice authentication results to UDM through the interface between AMF and UDM. It can be understood that the description of the case where there is no interface between UDM and NSSAAF (or AUSF) is also applicable to other embodiments of the present application.
[0285] UDM can provide useful information for other AMFs to initiate slice authentication by storing EAP authentication results, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID). Figure 8 .
[0286] 801. The UE sends a registration request message to the AMF, which carries the identification information of the slice and the identification information of the UE; accordingly, the AMF receives the registration request message.
[0287] according to Figure 7 The method shown in the figure can store the authentication status information of the slice in the UDM, so Figure 8 The method shown also includes steps 841 to 843 .
[0288] 841. AMF sends a fifth request message to UDM, where the fifth request message carries S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID). Accordingly, the UDM receives the fifth request message.
[0289] Among them, the fifth request message can be used to request to obtain the slice authentication result of S-NSSAI initiated by the UE through other PLMN (or AMF).
[0290] Optionally, the fifth request message may not carry the AMF-ID, and the UDM determines or obtains the AMF-ID of the AMF based on the token in the fifth request message.
[0291] Generally, when the AMF sends a request message related to a slice to the UDM, the AMF is limited to obtaining the UE's subscription information about the slice, that is, the UDM does not store which AMF the UE uses to initiate the slice authentication for the S-NSSAI. However, in an embodiment of the present application, the UDM can store the UE's authentication status information about the slice, so the AMF can request the UDM to obtain the UE's authentication status information about the slice. At the same time, the UDM can store the UE's slice authentication results, S-NSSAI, GPSI (or SUPI), PLMN-ID (or AMF-ID), etc., and the above information can be updated after each slice authentication is completed.
[0292] It is understandable that AMF can also request slice authentication results of multiple S-NSSAIs in the fifth request message, etc., which is not limited to this embodiment of the present application.
[0293] 842. The UDM determines whether to perform slice authentication for the S-NSSAI based on the stored UE information, including the UE's GPSI (or SUPI), the S-NSSAI of the slice to which the UE subscribes, the UE's slice authentication result for the S-NSSAI, and the PLMN-ID (or AMF-ID) of the initiating network corresponding to the slice authentication result. Figure 8The UDM shown in can determine whether to perform slice authentication for the S-NSSAI based on the S-NSSAI stored therein, the slice authentication result of the S-NSSAI, the GPSI (or SUPI), and the PLMN-ID (or AMF-ID).
[0294] In other words, the UDM can determine that the UE needs to initiate slice authentication through the current AMF (i.e., the AMF-ID in the above fifth request message) based on the slice authentication result of the UE (initiated through other PLMNs, other AMFs) regarding the S-NSSAI. Alternatively, the UDM can determine that the UE does not need to initiate slice authentication through the current AMF (i.e., the AMF-ID in the above fifth request message) based on the stored slice authentication result of the UE regarding the S-NSSAI.
[0295] Optionally, the method shown in step 842 can also only query and obtain the authentication status of the UE for the slice S-NSSAI, without having to determine whether the current AMF (i.e., the AMF-ID in the fifth request message) needs to perform slice authentication on the S-NSSAI. Determine whether slice authentication is required, and the current AMF determines it by itself after receiving the response (step 843). The specific judgment method can also refer to the UDM judgment method in step 842 of this embodiment.
[0296] In some implementations, if Figure 7 The AMF and Figure 8 The AMF shown is not the same AMF. Figure 7 The AMF shown is Figure 3b AMF1 in Figure 8 The AMF shown is Figure 3b AMF2 in. That is, the UDM has stored the authentication status information for S-NSSAI initiated by the UE through AMF1. In this case, since the slice authentication is initiated by AMF2 in step 841, the UDM can determine to perform slice authentication on the S-NSSAI according to its policy (or local policy, etc.). Alternatively, since the slice authentication for S-NSSAI initiated by AMF2 has been executed by AMF1, the UDM can also determine that it is not necessary to perform slice authentication on the S-NSSAI (that is, it is equivalent to directly allowing or rejecting the UE
[0297] access slice request).
[0298] Exemplarily, for example, the UE has completed the slice authentication of the S-NSSAI through AMF1, and the slice authentication result of the S-NSSAI (such as the slice authentication completed by AMF1 or PLMN1) is stored in the UDM. When AMF2 requests the slice authentication result of the S-NSSAI, the UDM can determine that the UE does not need to authenticate again based on the fact that the UE has successfully completed the slice authentication of the S-NSSAI through AMF1 / PLMN1.
[0299] For another example, the UE has completed the slice authentication of S-NSSAI through AMF1, and the slice authentication result of the S-NSSAI stored in UDM is that the authentication is unsuccessful (access is denied). When AMF2 requests the slice authentication status of the S-NSSAI, UDM can determine that the UE does not need to initiate authentication again (even if it is initiated, it will still fail or be rejected) based on the slice authentication result of the S-NSSAI. In another possible implementation, UDM determines that the UE can still try to re-initiate the slice authentication of the S-NSSAI.
[0300] For another example, the UE has not performed S-NSSAI slice authentication through any network. When AMF2 requests the slice authentication status of the S-NSSAI, UDM can determine that the UE needs to initiate authentication.
[0301] It should be noted that Figure 7 and Figure 8 The methods shown can be combined with, or Figure 7 and Figure 8 The method shown can also be executed separately, etc., which is not limited in the embodiments of the present application.
[0302] 843. UDM sends a fifth response message to AMF, and the AMF receives the fifth response message.
[0303] Optionally, in some implementations, the fifth response message may carry indication information, and the indication information may be used to indicate whether slice authentication is initiated through AMF (i.e., the AMF-ID in the fifth request message mentioned above, or AMF2 as shown above). For example, the indication information may be used to instruct the AMF to perform slice authentication on the slice. Optionally, in other implementations, the fifth response message may also carry the slice authentication result of the slice through other networks. For example, the fifth response message may carry the slice authentication result initiated by S-NSSAI, GPSI (or SUPI), PLMN-ID (or AMF-ID) (such as AMF1 or PLMN1) and the PLMN-ID (or AMF-ID). For another example, the fifth response message may also carry information such as the reason for the failure of the slice authentication result of the S-NSSAI. Optionally, UDM can send the most recent (or latest) stored slice authentication result for S-NSSAI initiated by the UE through the PLMN (or AMF); or, it can also send the valid slice authentication result for S-NSSAI initiated by the UE through all PLMNs (or AMFs).
[0304] It should be noted that in step 842, UDM can also determine whether to perform slice authentication on S-NSSAI based on other information. For example, UDM can make auxiliary judgments based on the agreement between PLMNs, the trust relationship, the credibility of PLMNs, the stored black / white list of PLMNs, and the information obtained from the big data network element of the network. For example, UDM (belonging to HPLMN) stores the trust relationship between PLMN1 and PLMN2 (there is an agreement between them, or they can share the slice authentication results initiated by each other). When PLMN2 requests the slice authentication result, UDM stores that the UE has completed the slice authentication (successfully) in PLMN1, so UDM instructs PLMN2 not to initiate slice authentication again based on the trust relationship between PLMN2 and PLMN1.
[0305] For another example, if there is no agreement between PLMN1 and PLMN2 in the above example, and UDM knows that the security / trustworthiness of PLMN1 is relatively high (or low), then UDM can notify PLMN2 that it is not necessary (or necessary) to initiate slice authentication.
[0306] For another example, if PLMN1 and PLMN2 in the above example are in the whitelist of slice authentication results that can be shared / in the blacklist of slice authentication results that cannot be shared, the UDM can notify PLMN2 whether to initiate slice authentication according to the instructions of the blacklist / whitelist. For example, if PLMN1 and PLMN2 are in the whitelist of shared authentication, the UDM can instruct PLMN2 to initiate slice authentication. For another example, if PLMN1 and PLMN2 are in the blacklist of slice authentication results that cannot be shared, the UDM can instruct PLMN2 not to initiate slice authentication.
[0307] Optionally, in another implementation, the AMF may obtain the authentication status information of other PLMNs after step 802. Figure 8 The method shown may also not include steps 841 to 843, but after step 805, Figure 8 The method shown may also include the NSSAAF (or AUSF) determining whether to perform slice authentication on the S-NSSAI based on the S-NSSAI stored therein, the slice authentication result for the S-NSSAI, the GPSI (or SUPI), and the PLMN-ID (or AMF-ID). If the NSSAAF (or AUSF) determines to perform slice authentication, step 807 is executed. If it is determined not to perform slice authentication, a message indicating not to perform slice authentication is sent to the AMF.
[0308] It can be understood that the method for the NSSAAF (or AUSF) to determine whether to perform slice authentication can refer to the above-mentioned UDM method, which will not be described in detail here.
[0309] For the method by which UDM determines slice authentication for the S-NSSAI based on the stored S-NSSAI, the slice authentication result of the S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID), please refer to the following introduction.
[0310] 802. AMF determines whether to perform slice authentication on S-NSSAI based on the fifth response message. If it is determined that slice authentication is required, proceed to step 803.
[0311] If it is determined that slice authentication is not required, a message can be sent to the UE to notify whether access to the slice is allowed, which is equivalent to directly jumping to step 818. The embodiment of the present application does not limit the method shown after step 818.
[0312] 803. AMF sends an EAP ID request for slice authentication to the UE; accordingly, the UE receives the EAP ID request for slice authentication.
[0313] 804. The UE sends an EAP ID response to the AMF. The EAP ID response may still be carried in a NAS message, and the NAS message may also carry an S-NSSAI.
[0314] 805. AMF sends a ninth request message to NSSAAF (or AUSF), where the ninth request message carries an EAP ID response, slice identification information, UE identification information and network identification information; accordingly, the NSSAAF receives the ninth request message.
[0315] 806. The NSSAAF (or AUSF) determines the identification information of the network (such as PLMN-ID or AMF-ID) according to the received ninth request message.
[0316] 807. NSSAAF (or AUSF) sends a ninth request message to AAA-S, where the ninth request message carries EAP ID response, S-NSSAI, GPSI (or SUPI) and PLMN-ID (or AMF-ID); accordingly, the AAA-S receives the ninth request message.
[0317] 808. AAA-S sends a ninth response message to the NSSAAF (or AUSF), where the ninth response message carries the EAP message, S-NSSAI, GPSI (or SUPI) and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the ninth response message.
[0318] 809. NSSAAF (or AUSF) sends a ninth response message to AMF, where the ninth response message carries the EAP message, S-NSSAI and GPSI (or SUPI); accordingly, the AMF receives the ninth response message.
[0319] 810. AMF sends a NAS message to the UE, where the NAS message carries an EAP message and S-NSSAI. Correspondingly, the UE receives the NAS message.
[0320] 811. The UE sends a NAS message to the AMF, where the NAS message carries an EAP message and S-NSSAI. Correspondingly, the AMF receives the NAS message.
[0321] 812. AMF sends the tenth request message to NSSAAF (or AUSF), where the tenth request message carries EAP message, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the tenth request message.
[0322] 813. NSSAAF (or AUSF) determines the PLMN-ID (or AMF-ID) based on the received tenth request message.
[0323] 814. The NSSAAF (or AUSF) sends a tenth request message to the AAA-S, where the tenth request message carries an EAP message, S-NSSAI, GPSI (or SUPI), and PLMN-ID (or AMF-ID). Accordingly, the NSSAAF (or AUSF) receives the tenth request message.
[0324] 815. AAA-S stores the EAP authentication result, EAP-ID, PLMN-ID (or AMF-ID), S-NSSAI and GPSI (or SUPI).
[0325] 816. AAA-S sends a tenth response message to the NSSAAF (or AUSF), where the tenth response message carries the EAP authentication result, GPSI (or SUPI), S-NSSAI and PLMN-ID (or AMF-ID); accordingly, the NSSAAF (or AUSF) receives the tenth response message.
[0326] 817. NSSAAF (or AUSF) sends a tenth response message to AMF, where the tenth response message carries the EAP authentication result, GPSI (or SUPI) and S-NSSAI; accordingly, the AMF receives the tenth response message.
[0327] 818. AMF sends a NAS message to the UE, where the NAS message carries the EAP authentication result. Correspondingly, the UE receives the NAS message.
[0328] Optional, Figure 8 The method shown may also include steps 831 to 833. For detailed descriptions of steps 831 to 833, please refer to Figure 7 Steps 531 to 533 in the above are not described in detail here.
[0329] It should be noted that the description of the accompanying drawings Figure 8 Steps 802 to 816 are not shown. For details of the process not shown, please refer to Figure 5 .
[0330] The technical solution provided by this application can improve the security of slice authentication: the authentication server and / or NSSAAF (or AUSF, etc.) can distinguish the slice authentication status initiated by different PLMNs, avoiding the incorrect update, termination, extension of authentication validity, etc. of slice authentication with the same EAP-ID due to different PLMN-IDs. At the same time, the efficiency of slice authentication can be improved, that is, unnecessary slice authentication can be avoided and network resources can be saved while ensuring security.
[0331] It can be understood that the embodiments shown above have various emphases, and the implementation method that is not exhaustively described in one embodiment can be referred to other embodiments and will not be described in detail here.
[0332] The communication device provided by the present application is described in detail below.
[0333] Fig. 9 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application, and the communication device can be used to perform the operation performed by the first NF in the above method embodiment. Exemplarily, the communication device can be used to perform Figure 4 The operations performed by the first NF in the method shown. Exemplarily, the communication device can also be used to perform Figures 5 to 8 The operations performed by the AMF in any one or more of the methods described.
[0334] like Fig. 9 As shown, the communication device includes a transceiver unit 901 and a processing unit 902 .
[0335] The processing unit 902 is used to initiate slice authentication about the slice between the terminal device and the authentication server;
[0336] The transceiver unit 901 is used to send the identification information of the first network, the identification information of the slice, and the identification information of the terminal device to the authentication server, where the above-mentioned communication device is the NF in the first network; or to output the identification information of the first network, the identification information of the slice, and the identification information of the terminal device;
[0337] The transceiver unit 901 is also used to receive slice authentication results of the slices, identification information of the slices and identification information of the terminal device from the authentication server.
[0338] In a possible implementation, the transceiver unit 901 is specifically used to send the identification information of the first network, the identification information of the slice, and the identification information of the terminal device to the authentication server through the second NF; and receive the slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device sent by the authentication server through the second NF. Alternatively, the transceiver unit 901 is specifically used to output the identification information of the first network, the identification information of the slice, and the identification information of the terminal device, and obtain the slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device.
[0339] In a possible implementation, the transceiver unit 901 is further used to send a request message to the second NF or the third NF, the request message is used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice includes the authentication status information of the terminal device for the slice initiated by the first network; and receive a response message from the second NF or the third NF. Alternatively, the transceiver unit 901 is also used to output the request message and obtain the response message.
[0340] It can be understood that for the authentication status information, request message and response message of the terminal device for the slice shown above, you can refer to Figures 5 to 8 The method shown is not described in detail here. Exemplarily, the response message may include indication information, which is used to indicate whether the fourth NF initiates slice authentication for the terminal device; or the indication information is used to indicate whether the terminal device has completed slice authentication for the slice; the slice authentication result of the terminal device for the slice; the authentication status information of the terminal device for the slice initiated by the first network.
[0341] For example, the transceiver unit 901 can also be used to receive Figures 5 to 8 For example, the transceiver unit 901 can also be used to send Figures 5 to 8 NAS message, third request message, fourth request message, fifth request message or seventh request message, eighth request message, etc. As another example, the transceiver unit 901 may also be used to receive Figures 5 to 8 The NAS message, the third response message, the fourth response message, the fifth response message, etc. shown in FIG. 10A and 10B are also provided. For example, the processing unit 902 can also be used to execute Figures 5 to 8 For the specific implementation of the transceiver unit and the processing unit, please refer to Figures 4 to 8 The first NF or AMF shown will not be described in detail here.
[0342] It should be understood that when the above-mentioned communication device is the first NF or a component in the first NF (such as a network function, a core device or a network element, etc.) that implements the above-mentioned functions, the processing unit 902 may be one or more processors, the transceiver unit 901 may be a transceiver, or the transceiver unit 901 may also be a sending unit and a receiving unit, the sending unit may be a transmitter, the receiving unit may be a receiver, and the sending unit and the receiving unit are integrated into one device, such as a transceiver.
[0343] When the above-mentioned communication device is a circuit system such as a chip, the processing unit 902 may be one or more processors, or the processing unit 902 may be a processing circuit, etc. The transceiver unit 901 may be an input-output interface, or may be called a communication interface, or an interface circuit, or an interface, etc. Alternatively, the transceiver unit 901 may also be a sending unit and a receiving unit, the sending unit may be an output interface, the receiving unit may be an input interface, and the sending unit and the receiving unit are integrated into one unit, such as an input-output interface. It can be understood that when the communication device is any one of the second NF, the third NF, the fourth NF or the authentication server, the description of the processing unit and the transceiver unit is applicable to all the communication devices shown below.
[0344] The communication device of the embodiment of the present application can execute any function performed by the first NF in the above method embodiment. The specific executable steps and / or functions can refer to the detailed description in the above method embodiment, which is only briefly summarized here and will not be repeated.
[0345] In some implementations, the communication device may be the first NF in each of the above method embodiments, and the first NF may be a core device. In this case, the transceiver unit 901 may be implemented by a transceiver, and the processing unit 902 may be implemented by a processor. Fig.10 As shown, the communication device 100 includes one or more processors 1020 and a transceiver 1010. The processor and the transceiver can be used to perform the functions or operations performed by the first NF.
[0346] Processor 1020, configured to initiate slice authentication about the slice between the terminal device and the authentication server;
[0347] The transceiver 1010 is used to send the identification information of the first network, the identification information of the slice, and the identification information of the terminal device to the authentication server, where the above-mentioned communication device is an NF in the first network;
[0348] Transceiver 1010 is also used to receive slice authentication results of the slices, identification information of the slices and identification information of the terminal device from the authentication server.
[0349] In one possible implementation, the transceiver 1010 is specifically used to send identification information of the first network, identification information of the slice, and identification information of the terminal device to the authentication server through the second NF; and receive the slice authentication result of the slice, identification information of the slice, and identification information of the terminal device sent by the authentication server through the second NF.
[0350] In one possible implementation, the transceiver 1010 is also used to send a request message to the second NF or the third NF, where the request message is used to request authentication status information of the terminal device for the slice, where the authentication status information of the terminal device for the slice includes the authentication status information of the terminal device for the slice initiated by the first network; and receive a response message from the second NF or the third NF.
[0351] For the specific implementation of the processor and transceiver, please refer to Figures 4 to 8 Alternatively, you can also refer to the method shown in Fig. 9 The steps and / or functions shown, etc.
[0352] exist Fig.10 In various implementations of the communication device shown, the transceiver may include a receiver and a transmitter, the receiver is used to perform a receiving function (or operation), and the transmitter is used to perform a transmitting function (or operation). And the transceiver is used to communicate with other devices / devices through a transmission medium. The processor 1020 sends and receives data and / or signaling through the transceiver 1010, and is used to implement the above method embodiment. Figures 4 to 8 The corresponding methods described above, etc.
[0353] Optionally, the communication device 100 may further include one or more memories 1030 for storing program instructions and / or data. The memory 1030 is coupled to the processor 1020. Exemplarily, the memory 1030 may be used to store a root key, an access layer key, or a non-access layer key.
[0354] The coupling in the embodiment of the present application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information exchange between devices, units or modules. The processor 1020 may operate in conjunction with the memory 1030. The processor 1020 may execute program instructions stored in the memory 1030. Optionally, at least one of the one or more memories may be included in the processor.
[0355] The specific connection medium between the transceiver 1010, the processor 1020 and the memory 1030 is not limited in the embodiment of the present application. Fig.10 In the embodiment, the memory 1030, the processor 1020 and the transceiver 1010 are connected via a bus 1040. Fig.10 The connections between the other components are shown in bold lines, which are only for illustration and are not intended to be limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.10 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0356] In the embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc., and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application may be directly embodied as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor, etc.
[0357] Understandably, Fig.10 When the communication device shown is a first NF, the first NF may also have Fig.10 More components and the like are not limited in the embodiments of the present application.
[0358] It can be understood that the method executed by the processor and transceiver shown above is only an example, and the specific steps executed by the processor and transceiver can refer to the method introduced above.
[0359] It can be understood that the above description of the connection relationship between the processor, the transceiver and the memory, as well as the description of the processor or the transceiver, etc., are applicable to the core devices shown below. For example, when the communication device is any one of the second NF, the third NF, the fourth NF or the authentication server, the description of the connection relationship between the processor, the transceiver and the memory, as well as the description of the processor or the transceiver, etc., are applicable to each communication device shown below.
[0360] In some other implementations, the communication device may be a circuit system in the first NF. In this case, the processing unit 902 may be implemented by a processing circuit, and the transceiver unit 901 may be implemented by an interface circuit. Fig.11 As shown, the communication device may include a processing circuit 1102 and an interface circuit 1101. The processing circuit 1102 may be a chip, a logic circuit, an integrated circuit, a processing circuit or a system on chip (SoC) chip, etc., and the interface circuit 1101 may be a communication interface, an input / output interface, etc.
[0361] The processing circuit 1102 is configured to initiate slice authentication about the slice between the terminal device and the authentication server;
[0362] The interface circuit 1101 is used to output identification information of the first network, identification information of the slice, and identification information of the terminal device;
[0363] The interface circuit 1101 is also used to obtain the slice authentication result of the slice, the identification information of the slice and the identification information of the terminal device.
[0364] In one possible implementation, the interface circuit 1101 is also used to output a request message, where the request message is used to request authentication status information of a terminal device for a slice, where the authentication status information of the terminal device for the slice includes authentication status information of the terminal device for the slice initiated by the first network; and to obtain a response message.
[0365] It can be understood that for the specific implementation of the processing circuit and the interface circuit, reference can be made to Figures 4 to 8 Alternatively, you can also refer to the method shown in Fig. 9 The steps and / or functions shown, etc.
[0366] In the embodiments of the present application, the processing circuit may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc., and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. It is understood that for the description of the processing circuit, the circuit systems shown below are all applicable.
[0367] It can be understood that the method executed by the interface circuit and the processing circuit shown above is only an example, and the specific steps executed by the interface circuit and the processing circuit can refer to the method introduced above.
[0368] Reuse Fig. 9 , the communication device can be used to perform the operations performed by the second NF in the above method embodiment. Alternatively, the communication device can be used to perform the operations performed by the second NF in the above method embodiment (such as Figures 5 to 8 Any one or more of the methods performed by AUSF or NSSAAF (AAAP-).
[0369] Reuse Fig. 9 , the communication device can be used to perform the operations performed by the third NF in the above method embodiment. Alternatively, the communication device can be used to perform the operations performed by the third NF in the above method embodiment (such as Figure 7 and / or Figure 8 )Methods executed by UDM.
[0370] Exemplarily, the transceiver unit 901 is configured to receive authentication status information for a slice initiated by the first network from a terminal device of the first NF;
[0371] Processing unit 902 is used to store authentication status information of the terminal device for the slice initiated by the first network.
[0372] Alternatively, the processing unit 902 is used to control a storage unit (such as a memory, etc.) to store authentication status information of the terminal device for the slice initiated by the first network.
[0373] In a possible implementation, the transceiver unit is also used to receive a request message from a fourth NF (or the first NF), where the request message is used to request authentication status information of the terminal device for the slice, where the authentication status information of the terminal device for the slice includes authentication status information of the terminal device for the slice initiated by the first network, and the fourth NF is a NF in the second network; and to send a response message to the fourth NF (or the first NF).
[0374] In a possible implementation, when the above-mentioned communication device is a second NF, the transceiver unit 901 is also used to send authentication status information of the terminal device for the slice initiated by the first network to the third NF.
[0375] It can be understood that for the specific implementation of the processing unit and the transceiver unit, reference can be made to Figures 4 to 8 The method shown will not be described in detail here.
[0376] In some implementations, the communication device may be the second NF in each of the above method embodiments, and the second NF may be a core device. In this case, the transceiver unit 901 may be implemented by a transceiver, and the processing unit 902 may be implemented by a processor. Fig.10 As shown, the communication device 100 includes one or more processors 1020 and a transceiver 1010 .
[0377] For example, the transceiver 1010 is used to receive authentication status information for a slice initiated by the first network from a terminal device of the first NF. The processor 1020 is used to store the authentication status information for the slice initiated by the first network of the terminal device. Alternatively, the processor 1020 is used to control the memory (such as the memory 1030, etc.) to store the authentication status information for the slice initiated by the first network of the terminal device.
[0378] For another example, the transceiver 1010 is also used to receive a request message from a fourth NF (or the first NF), where the request message is used to request authentication status information of the terminal device for the slice, where the authentication status information of the terminal device for the slice includes authentication status information of the terminal device for the slice initiated by the first network, and the fourth NF is a NF in the second network; and to send a response message to the fourth NF (or the first NF).
[0379] For another example, the transceiver 1010 is also used to send authentication status information of the slice of the terminal device initiated by the first network to the third NF.
[0380] It can be understood that the method executed by the processor and transceiver shown above is only an example, and the specific steps executed by the processor and transceiver can refer to the method introduced above.
[0381] In some other implementations, the communication device may be a circuit system in the second NF. In this case, the processing unit 902 may be implemented by a processing circuit, and the transceiver unit 901 may be implemented by an interface circuit. Fig.11 As shown, the communication device may include a processing circuit 1102 and an interface circuit 1101 .
[0382] For example, the interface circuit is used to obtain the authentication status information of the terminal device for the slice initiated by the first network; the processing circuit is used to store the authentication status information of the terminal device for the slice initiated by the first network. Alternatively, the processing circuit is used to control the memory outside the circuit system to store the authentication status information of the terminal device for the slice initiated by the first network.
[0383] For another example, the interface circuit is also used to obtain a request message, and output a response message, etc. For another example, the interface circuit is also used to output authentication status information of the terminal device for the slice initiated by the first network.
[0384] It can be understood that the methods executed by the processing circuit and the interface circuit shown above are only examples, and the specific steps executed by the processing circuit and the interface circuit can refer to the methods introduced above.
[0385] It can be understood that the communication device is Figure 4 The third NF in Figure 7 or Figure 8 For the specific implementation method of the UDM in the method, please refer to the second NF or the above method embodiment, etc., which will not be described in detail here.
[0386] Reuse Fig. 9 , the communication device can be used to perform the operation performed by the fourth NF in the above method embodiment. Alternatively, the communication device can be used to perform the above method embodiment (such as Figures 5 to 8 Any one or more of the methods performed by AMF.
[0387] Exemplarily, the transceiver unit 901 is used to send and receive signals; the processing unit 902 is used to execute through the transceiver unit: sending a request message to the second NF or the third NF, the request message is used to request the authentication status information of the terminal device for the slice, the authentication status information of the terminal device for the slice includes the authentication status information of the terminal device for the slice initiated by the first network, and the communication device is an NF in the second network; and receiving a response message from the second NF or the third NF.
[0388] In one possible implementation, the response message includes any one or more of the following: indication information, the indication information is used to indicate whether the fourth NF initiates slice authentication for the terminal device; or, the indication information is used to indicate whether the terminal device has completed slice authentication for the slice; the slice authentication result of the terminal device for the slice; the authentication status information of the terminal device for the slice initiated by the first network.
[0389] It can be understood that for the specific implementation method of the fourth NF, reference can be made to the introduction related to AMF in the method embodiment, which will not be described in detail here.
[0390] In some implementations, the communication device may be the fourth NF in each of the above method embodiments, and the fourth NF may be a core device. In this case, the transceiver unit 901 may be implemented by a transceiver, and the processing unit 902 may be implemented by a processor.
[0391] In some other implementations, the communication device may be a circuit system in the fourth NF. In this case, the processing unit 902 may be implemented by a processing circuit, and the transceiver unit 901 may be implemented by an interface circuit.
[0392] It can be understood that for the specific implementation of the transceiver and the processor, as well as the specific implementation of the processing circuit and the interface circuit, reference can be made to the above-mentioned method embodiment or the specific description of the above-mentioned communication device including the processing unit and the transceiver unit, and they will not be described in detail here.
[0393] Reuse Fig. 9 , the communication device can be used to perform the operations performed by the authentication server in the above method embodiment. Alternatively, the communication device can be used to perform the operations performed by the authentication server in the above method embodiment (such as Figures 5 to 8 Any one or more of the methods performed by AAA-S.
[0394] The transceiver unit 901 is configured to receive identification information of a first network, identification information of a slice, and identification information of a terminal device from a first network function NF;
[0395] A processing unit 902 is configured to perform slice authentication on the slice according to identification information of the slice and identification information of the terminal device;
[0396] The transceiver unit 901 is also used to send the slice authentication result of the slice, the identification information of the slice and the identification information of the terminal device to the first NF.
[0397] In a possible implementation, the processing unit 902 is used to store the authentication status information of the terminal device initiated by the first network for the slice. Alternatively, the processing unit 902 controls the storage unit to store the authentication status information of the terminal device initiated by the first network for the slice.
[0398] In one possible implementation, processing unit 902 is also used to determine whether to initiate slice authentication for the slice for the terminal device based on the authentication status information for the slice initiated by the first network of the terminal device.
[0399] In some implementations, the communication device may be the authentication server in each of the above method embodiments. In this case, the transceiver unit 901 may be implemented by a transceiver, and the processing unit 902 may be implemented by a processor.
[0400] In some other implementations, the communication device may be a circuit system in the authentication server. In this case, the processing unit 902 may be implemented by a processing circuit, and the transceiver unit 901 may be implemented by an interface circuit.
[0401] It is understandable that for the specific implementation of the transceiver and the processor, as well as the specific implementation of the processing circuit and the interface circuit, reference may be made to the specific description of the above method embodiment or the above communication device including the processing unit and the transceiver unit, and will not be described in detail here. Figure 4 The method performed by the authentication server shown in FIG. 10 ; for example, reference may be made to Figures 5 to 8 The method performed by AAA-S is shown.
[0402] Fig.12 is a schematic diagram of a wireless communication system provided in an embodiment of the present application, such as Fig.12 As shown, the wireless communication system may include a first NF and an authentication server. The first NF may execute Figure 4 The method performed by the first NF shown; and / or, performing Figures 5 to 8 Any one or more of the methods shown in the figure performed by the AMF. The authentication server may perform Figure 4 The method shown is performed by the authentication server; and / or, performing Figures 5 to 8 Any one or more of the methods described above performed by AAA-S.
[0403] Furthermore, the wireless communication system may further include a second NF. The second NF may execute Figure 4 The method shown is performed by the second NF, and / or, performing Figures 5 to 8Any one or more of the methods shown as performed by AUSF or NSSAAF (AAA-P).
[0404] Furthermore, the wireless communication system may further include a third NF. The third NF may execute Figure 4 The method shown is performed by the third NF, and / or, performs Figure 7 or Figure 8 Any one or more of the methods shown as being performed by the UDM.
[0405] Further, the wireless communication system may further include a fourth NF ( Fig.12 ), the fourth NF may also execute Figure 4 The method performed by the first NF shown; and / or, performing Figures 5 to 8 Any one or more of the methods shown in the figure are performed by the AMF. For the steps or functions performed by each NF, reference may be made to the aforementioned embodiments, which will not be described in detail here.
[0406] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or it can be an electrical, mechanical or other form of connection.
[0407] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the technical effects of the solutions provided in the embodiments of the present application.
[0408] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0409] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or partly contributed to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a readable storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned readable storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0410] In addition, the present application also provides a computer program, which is used to implement the secure communication method provided by the present application by the first NF and / or Figures 5 to 8 The operations and / or processing performed by the AMF shown.
[0411] The present application also provides a computer program, which is used to implement the secure communication method provided by the present application by the second NF and / or Figures 5 to 8 The operations and / or processing performed by the AUSF or NSSAAF (AAA-P) shown.
[0412] The present application also provides a computer program, which is used to implement the secure communication method provided by the present application by the third NF and / or Figures 5 to 8 The operations and / or processes performed by the UDM are shown.
[0413] The present application also provides a computer program, which is used to implement the secure communication method provided by the present application by the authentication server and / or Figures 5 to 8 The operations and / or processes performed by the AAA-S are shown.
[0414] The present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer code, and when the computer code is executed on a computer, the computer executes the secure communication method provided by the present application by the first NF and / or Figures 5 to 8 The operations and / or processing performed by the AMF shown.
[0415] The present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer code, and when the computer code is executed on a computer, the computer executes the secure communication method provided by the present application by the second NF and / or Figures 5 to 8The operations and / or processing performed by the AUSF or NSSAAF (AAA-P) shown.
[0416] The present application also provides a computer-readable storage medium, in which a computer code is stored. When the computer code is run on a computer, the computer executes the secure communication method provided by the present application by the third NF and / or Figures 5 to 8 The operations and / or processes performed by the UDM are shown.
[0417] The present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer code, and when the computer code is executed on a computer, the computer executes the secure communication method provided by the present application by the authentication server and / or Figures 5 to 8 The operations and / or processes performed by the AAA-S are shown.
[0418] The present application also provides a computer program product, which includes a computer code or a computer program. When the computer code or the computer program is run on a computer, the secure communication method provided by the present application is performed by the first NF and / or Figures 5 to 8 The operations and / or processing performed by the AMF shown are performed.
[0419] The present application also provides a computer program product, which includes a computer code or a computer program. When the computer code or the computer program is run on a computer, the secure communication method provided by the present application is performed by the second NF and / or Figures 5 to 8 The operations and / or processing performed by the AUSF or NSSAAF (AAA-P) shown are performed.
[0420] The present application also provides a computer program product, which includes a computer code or a computer program. When the computer code or the computer program is run on a computer, the secure communication method provided by the present application is performed by the third NF and / or Figures 5 to 8 The operations and / or processes performed by the UDM shown are executed.
[0421] The present application also provides a computer program product, which includes a computer code or a computer program. When the computer code or the computer program is run on a computer, the authentication server and / or the authentication server in the secure communication method provided by the present application are executed. Figures 5 to 8 The operations and / or processes performed by the AAA-S shown are executed.
[0422] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A slice authentication method, It is characterized in that The method comprises: In the case where it is determined that slice authentication regarding the slice needs to be initiated between the terminal device and the authentication server, the first network function NF in the first network sends identification information of the first network, identification information of the slice, and identification information of the terminal device to the authentication server through the second NF; The first NF receives a slice authentication result of the slice, identification information of the slice, and identification information of the terminal device sent from the authentication server through the second NF; The second NF stores authentication status information of the terminal device for the slice initiated by the first network, wherein the authentication status information includes: a slice authentication result of the slice, identification information of the first network, identification information of the slice, and identification information of the terminal device.
2. The method according to claim 1, It is characterized in that The method further comprises: The second NF sends the authentication status information to the third NF; The third NF receives the authentication status information, and stores the authentication status information.
3. The method according to claim 2, It is characterized in that The method further comprises: The fourth NF sends a request message to the second NF, where the request message is used to request the authentication status information, wherein the fourth NF is a network function in the second network; In response to the request message, the second NF sends a response message to the fourth NF.
4. The method according to claim 2, It is characterized in that The method further comprises: The fourth NF sends a request message to the third NF, where the request message is used to request the authentication status information, and the fourth NF is a network function in the second network; In response to the request message, the third NF sends a response message to the fourth NF.
5. The method according to claim 3 or 4, It is characterized in that The response message includes any one or more of the following: Indication information, the indication information is used to indicate whether the fourth NF needs to initiate slice authentication for the terminal device; or, the indication information is used to indicate whether the terminal device has completed slice authentication for the slice; a slice authentication result of the slice; The authentication status information.
6. The method according to any one of claims 1 to 4, It is characterized in that The first NF is the access and mobility management function AMF.
7. A slice authentication method, It is characterized in that The method comprises: The authentication server receives, through the second NF, identification information of the first network, identification information of the slice, and identification information of the terminal device from the first network function NF, where the first NF is a network function in the first network; The authentication server performs slice authentication on the slice according to the identification information of the slice and the identification information of the terminal device; The authentication server sends the slice authentication result of the slice, the identification information of the slice, and the identification information of the terminal device to the first NF through the second NF; The authentication server stores authentication status information of the terminal device for the slice initiated by the first network, and the authentication status information includes: a slice authentication result of the slice, identification information of the first network, identification information of the slice, and identification information of the terminal device.
8. The method according to claim 7, It is characterized in that The method further comprises: The authentication server determines whether to initiate slice authentication for the slice to the terminal device based on the authentication status information.
9. A communication device located in a first network, It is characterized in that include: The processor is configured to execute a program stored in the memory, and when the program is executed, the communication device: In the case where it is determined that slice authentication regarding the slice needs to be initiated between the terminal device and the authentication server, sending identification information of the first network, identification information of the slice, and identification information of the terminal device to the authentication server through the second NF; Receiving, through the second NF, a slice authentication result of the slice, identification information of the slice, and identification information of the terminal device from the authentication server; The authentication status information of the slice initiated by the first network for the terminal device is stored through the second NF, wherein the authentication status information includes: the slice authentication result of the slice, the identification information of the first network, the identification information of the slice and the identification information of the terminal device.
10. An authentication server, It is characterized in that include: The processor is configured to execute a program stored in the memory, and when the program is executed, the authentication server: Receiving, through the second NF, identification information of the first network, identification information of the slice, and identification information of the terminal device from the first network function NF, where the first NF is a network function in the first network; Performing slice authentication on the slice according to the identification information of the slice and the identification information of the terminal device; Sending, through the second NF, a slice authentication result of the slice, identification information of the slice, and identification information of the terminal device to the first NF; Store authentication status information of the slice initiated by the first network for the terminal device, the authentication status information including: slice authentication result of the slice, identification information of the first network, identification information of the slice and identification information of the terminal device.
11. The authentication server according to claim 10, It is characterized in that When the program is executed, it causes the authentication server to: Based on the authentication status information, determine whether to initiate slice authentication for the slice for the terminal device.
12. A computer-readable storage medium, wherein the computer-readable storage medium is used to store a computer program, and when the computer-readable storage medium is run on a computer, the method according to any one of claims 1 to 6 or 7 to 8 is executed.