Data acquisition method, system, related network element, edge node and storage medium

By integrating UDM and AUSF functions into the core network element for hot backup in the private network, the problem of communication interruption in the private network caused by 5G public network failures was solved, realizing independent operation of the private network and authentication of terminal devices, and improving communication reliability and fault diagnosis efficiency.

CN116456451BActive Publication Date: 2026-04-28CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD
Filing Date
2022-01-06
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

When the 5G public network fails, communication between the 5G private network and the public network is interrupted, causing terminal devices to be unable to use 5G network communication. Existing technologies cannot effectively solve this problem.

Method used

When communication between the private network and the public network is interrupted, the authentication parameters are obtained from the designated core network element through the AMF network element of the private network to authenticate the terminal device. The designated core network element, which integrates the functions of UDM and ASF network elements, performs hot backup to ensure the independent operation of the private network.

Benefits of technology

Even if communication between the public network and the private network is interrupted, the terminal device can still register in the private network and use the 5G network to communicate, which improves communication reliability and fault diagnosis capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116456451B_ABST
    Figure CN116456451B_ABST
Patent Text Reader

Abstract

The application discloses a data acquisition method, a system, related network elements and a storage medium. The data acquisition method of an AMF network element of a private network comprises the following steps: acquiring authentication parameters from a set core network element of the private network in the case that communication between the private network and a public network is interrupted; wherein the set core network element is used for hot backup of authentication-related information in a unified data management (UDM) network element of the public network and has the capability of authenticating terminal equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a data acquisition method, system, related network element and storage medium. Background Technology

[0002] In related technologies, within a carrier's 5G public network (macro network), primary and backup core network elements are configured to back up data stored in the primary core network element. However, when a failure occurs in the carrier's 5G public network, both the primary and backup core network elements become unavailable, disrupting communication between the local 5G private network and the 5G public network. This prevents terminal devices in the 5G private network from using the 5G network for communication. Summary of the Invention

[0003] To address the related technical issues, embodiments of this application provide a data acquisition method, system, related network elements, edge nodes, and storage media.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] This application provides a data acquisition method applied to the AMF network element of a private network, the method comprising:

[0006] In the event of a communication interruption between the private network and the public network, authentication parameters are obtained from designated core network elements of the private network; wherein,

[0007] The core network element is used to perform hot backup of authentication-related information in the public network's UDM network element, and has the ability to authenticate terminal devices.

[0008] The method in the above scheme further includes:

[0009] In the event of a communication interruption between the private network and the public network, the ability of the designated core network element of the private network to authenticate terminal devices is enabled.

[0010] In the above scheme, the authentication parameters include a 5G authentication vector; obtaining the authentication parameters from the designated core network element of the private network includes:

[0011] Receive registration requests sent by terminal devices;

[0012] Based on the registration request, a first authentication request is sent to the designated core network element of the private network;

[0013] Receive the 5G authentication vector sent by the designated core network element of the private network regarding the first authentication request.

[0014] In the above scheme, the authentication parameter further includes SUPI; the method further includes:

[0015] In the event of a communication interruption between the private network and the public network, the terminal device receives the SUPI sent by a designated core network element of the private network.

[0016] In the above scheme, after receiving the 5G authentication vector regarding the first authentication request sent by the designated core network element of the private network, the method further includes:

[0017] Generate a security context identifier corresponding to the terminal device;

[0018] The second authentication request is sent to the terminal device based on the received 5G authentication vector; wherein,

[0019] The second authentication request carries the security context identifier; the security context identifier is used to indicate that the AMF network element of the private network and the terminal device do not need to re-authenticate when performing data interaction.

[0020] The method in the above scheme further includes:

[0021] Without interruption of communication between the private network and the public network, authentication parameters are obtained from the UDM network element of the public network through the AUSF network element of the public network.

[0022] This application also provides a data acquisition method, applied to a designated core network element in a private network, the method comprising:

[0023] Under the condition that the communication between the private network and the public network is not interrupted, the authentication-related information in the UDM network element of the public network is hot-backed up;

[0024] In the event of a communication interruption between the private network and the public network, authentication parameters are fed back to the AMF network element of the private network.

[0025] In the above scheme, the authentication parameters include a 5G authentication vector; the step of feeding back the authentication parameters to the AMF network element of the private network includes:

[0026] Based on the first authentication request sent by the AMF network element of the private network, a 5G authentication vector regarding the first authentication request is sent to the AMF network element of the private network; wherein,

[0027] The first authentication request is sent upon receiving a registration request from the terminal device.

[0028] In the above scheme, the core network elements of the private network include an authentication server function (AUSF) network element and a UDM network element; the first authentication request sent based on the AMF network element of the private network, sending a 5G authentication vector about the first authentication request to the AMF network element of the private network, includes:

[0029] The AUSF network element of the private network receives the first authentication request sent by the AMF network element of the private network, and sends an authentication parameter acquisition request to the UDM network element of the private network based on the first authentication request.

[0030] The UDM network element of the private network constructs a 5G home environment authentication vector based on the authentication parameter acquisition request, and sends a response message to the AUSF network element of the private network. The response message carries the 5G home environment authentication vector.

[0031] The AUSF network element of the private network constructs a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, and sends the 5G authentication vector regarding the first authentication request to the AMF network element of the private network.

[0032] In the above scheme, the 5G home environment authentication vector includes a random number, an authentication token, expected response parameters, and an intermediate key; the AUSF network element of the private network constructs a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, including:

[0033] The AUSF network element of the private network calculates the first hash value based on the expected response parameter in the 5G home environment authentication vector, and calculates the anchor key based on the intermediate key in the 5G home environment authentication vector.

[0034] The AUSF network element of the private network replaces the expected response parameter in the 5G home environment authentication vector with the calculated first hash value, and replaces the intermediate key in the 5G home environment authentication vector with the calculated anchor key, to obtain the 5G authentication vector.

[0035] In the above scheme, the authentication parameter acquisition request carries the user hidden identifier (SUCI) of the terminal device, and the response message also carries the SUPI of the terminal device.

[0036] In the above scheme, the authentication parameters include SUPI; the method further includes:

[0037] If communication between the private network and the public network is interrupted, and the authentication of the home location of the terminal device is successful, the AUSF network element of the private network sends the SUPI of the terminal device to the AMF network element of the private network.

[0038] The method in the above scheme further includes:

[0039] The AUSF network element of the private network stores the expected response parameter in the 5G home environment authentication vector in association with at least one of the following:

[0040] The authentication parameters are obtained by acquiring the SUCI carried in the request.

[0041] The response message carries the SUPI;

[0042] The intermediate key in the 5G home environment authentication vector.

[0043] This application also provides a data acquisition system, including:

[0044] The AMF network element of the private network is used to request authentication parameters from the UDM network element of the private network in the event of a communication interruption between the private network and the public network.

[0045] The private network is configured with core network elements for hot backup of authentication-related information in the public network's UDM network elements, and for providing authentication parameters to the private network's AMF network elements in the event of a communication interruption between the private network and the public network.

[0046] In the above scheme, the AMF network element of the private network is also used to enable the UDM network element of the private network to authenticate terminal devices in the event of a communication interruption between the private network and the public network.

[0047] In the above scheme, the AMF network element of the private network is specifically used to send a first authentication request to the designated core network element of the private network based on the registration request sent by the terminal device, and to receive the 5G authentication vector sent by the designated core network element of the private network regarding the first authentication request.

[0048] The core network element of the private network is specifically used to send the 5G authentication vector regarding the first authentication request to the AMF network element of the private network.

[0049] In the above scheme, the core network elements of the private network include:

[0050] The AUSF network element is configured to receive a first authentication request sent by the AMF network element of the private network, and send an authentication parameter acquisition request to the UDM network element of the private network based on the first authentication request; and to construct a 5G authentication vector based on the 5G home environment authentication vector carried in the response message when a response message is received from the UDM network element of the private network, and to send the 5G authentication vector related to the first authentication request to the AMF network element of the private network.

[0051] The UDM network element is used to construct a 5G home environment authentication vector based on the authentication parameter acquisition request, and send a response message to the AUSF network element of the private network. The response message carries the 5G home environment authentication vector.

[0052] In the above scheme, the AMF network element of the private network is also used for:

[0053] Generate a security context identifier corresponding to the terminal device;

[0054] A second authentication request is sent to the terminal device based on the received 5G authentication vector; wherein,

[0055] The second authentication request carries the security context identifier; the security context identifier is used to indicate that the AMF network element of the private network and the terminal device do not need to re-authenticate when performing data interaction.

[0056] In the above scheme, the authentication parameter acquisition request carries the SUCI of the terminal device, and the response message also carries the SUPI of the terminal device;

[0057] The AUSF network element of the private network is also used to: send the SUPI of the terminal device to the AMF network element of the private network when the home location authentication of the terminal device is successful;

[0058] The AMF network element of the private network is also used to: receive the SUPI of the terminal device sent by the designated core network element of the private network.

[0059] In the above scheme, the system is deployed on edge nodes and / or in the central cloud.

[0060] In the above scheme, the system also includes an SFM network element.

[0061] This application also provides an AMF network element for a private network, including:

[0062] The acquisition unit is used to acquire authentication parameters from a designated core network element of the private network when communication between the private network and the public network is interrupted; wherein, the UDM network element of the private network is used to perform hot backup of authentication-related information in the UDM network element of the public network and has the ability to authenticate terminal devices.

[0063] This application embodiment also provides a setting of core network elements for a private network, including:

[0064] The backup unit is used to perform hot backup of the authentication-related information in the UDM network element of the public network when the communication between the private network and the public network is uninterrupted.

[0065] The feedback unit is used to feed back authentication parameters to the AMF network element of the private network when the communication between the private network and the public network is interrupted.

[0066] This application embodiment also provides an edge node, including a processor and a communication interface, wherein,

[0067] The processor is configured to perform at least one of the following:

[0068] In the event of a communication interruption between the private network and the public network, authentication parameters are obtained from a designated core network element of the private network; wherein, the UDM network element of the private network is used to perform hot backup of authentication-related information in the UDM network element of the public network, and has the ability to authenticate terminal devices.

[0069] In the absence of interruption in communication between the private network and the public network, the authentication-related information in the UDM network element of the public network is hot-backed up; and in the absence of interruption in communication between the private network and the public network, the authentication parameters are fed back to the AMF network element of the private network.

[0070] In the event of a communication interruption between the private network and the public network, authentication-related data obtained from the UDM network element of the private network will be fed back to the AMF network element of the private network.

[0071] This application also provides an edge node, including a processor and a memory for storing computer programs that can run on the processor.

[0072] When the processor runs the computer program, it performs at least one of the following:

[0073] The steps of the above-mentioned data acquisition method on the AMF network element side of the private network;

[0074] The steps for setting up the data acquisition method on the core network element side of the aforementioned private network.

[0075] This application embodiment also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements at least one of the following:

[0076] The steps of the data acquisition method on the AMF network element side of the private network are described;

[0077] The steps for setting up the data acquisition method on the core network element side of the aforementioned private network.

[0078] In this embodiment, when communication between the private network and the public network is interrupted, the AMF (Authentication, Authorization, and Function) network element of the private network obtains authentication parameters from the designated core network element of the private network. Therefore, even when communication between the private network and the public network is interrupted, the private network can still achieve full-process management of the user control plane and user plane. Even if communication between the local 5G private network and the 5G public network is interrupted, when a terminal device needs to register with the core network, it can register in the private network's 5GC (5G Core Network) through the AMF network element, thereby using the 5G network for communication, which improves communication reliability. Attached Figure Description

[0079] Figure 1 A schematic diagram of the communication system provided in the embodiments of this application;

[0080] Figure 2 This is a schematic diagram of the network architecture of the communication system provided in the embodiments of this application;

[0081] Figure 3 An interaction diagram illustrating the data acquisition method provided in the embodiments of this application;

[0082] Figure 4 An interaction diagram illustrating a data acquisition method provided in another embodiment of this application;

[0083] Figure 5 An interaction diagram illustrating a data acquisition method provided in yet another embodiment of this application;

[0084] Figure 6 An interaction diagram illustrating a data acquisition method provided in another embodiment of this application;

[0085] Figure 7 An interaction diagram of a data acquisition method provided in another embodiment of this application;

[0086] Figure 8 This is a schematic diagram of the network architecture provided in the embodiments of this application;

[0087] Figure 9 This is a schematic diagram illustrating the implementation process of preprocessing user contract information provided in an embodiment of this application;

[0088] Figure 10 A schematic diagram illustrating the implementation process of the method for controlling the number of users accessing the core network provided in this application embodiment;

[0089] Figure 11 A schematic diagram of the structure of the AMF network element of the private network provided in the embodiments of this application;

[0090] Figure 12 A schematic diagram illustrating the structure of the core network elements of the private network provided in this embodiment of the application;

[0091] Figure 13This is a schematic diagram of the hardware structure of an edge node provided in an embodiment of this application. Detailed Implementation

[0092] Currently, my country has 1,800 government emergency management departments at the county level and above (including those for government affairs, earthquake, water resources, and transportation). Assuming each department is equipped with 5-10 satellite mobile communication terminals and 2 satellite mobile data terminals, a total of approximately 14,000 satellite mobile communication terminals and 3,600 satellite mobile data terminals are needed. In addition, there are over 2,800 county-level administrative units and over 40,000 township-level administrative units nationwide. In total, there are approximately 45,000 user departments in the emergency response field nationwide, requiring nearly 100,000 satellite mobile communication terminals and 90,000 satellite mobile data terminals. Beyond the terminal demand, the entire emergency communication market will likely multiply in size due to system networking, emergency communication vehicles and other equipment, and the commercial market.

[0093] Given such a massive demand for emergency management, relying solely on traditional emergency response methods and equipment presents the following bottlenecks and shortcomings:

[0094] 1. In the process of emergency support, traditional operators first need to restore transmission resources and lay optical cables, which requires a lot of professional personnel and resources, takes a long time and is highly dangerous.

[0095] 2. Emergency communication vehicles need to be driven into the disaster area, and professional engineers must risk their lives to restore communication and restore the lifeline from the base station to the transmission line. This is a highly dangerous situation.

[0096] 3. Using satellite communication has limited bandwidth and it is not possible for everyone to have one.

[0097] Based on this, this application provides a data acquisition method in which, when communication between the private network and the public network is interrupted, the AMF network element of the private network obtains authentication parameters from a designated core network element of the private network. Thus, even after the private network loses connection with the operator's network, the core network of the private network can still operate independently, authenticating terminal devices and ensuring uninterrupted communication within the area covered by the private network without requiring changes to SIM cards or phone numbers.

[0098] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0099] Figure 1 This is a schematic diagram of a communication system provided in an embodiment of this application. Figure 1 The communication system shown includes a carrier's public 5G network and a local 5G private network. The carrier's public 5G network includes the public 5G core network (5GC), and the local 5G private network includes the private 5GC network.

[0100] A private network refers to a dedicated network established on the public network of an operator.

[0101] The public network 5GC includes at least a Unified Data Management (UDM) network element and an Authentication Server Function (AUSF) network element, and may also include at least one of the following: an Access and Mobility Management (AMF) network element, a Session Management (SMF) network element, a Packet Control (PCF) network element, a Network Exposure (NEF) network element, and a User Plane (UPF) network element.

[0102] The private network 5GC includes at least a core network element and an AMF network element, and may also include at least one of the SMF network element, PCF network element and UPF network element.

[0103] A schematic diagram of the network architecture of a communication system consisting of user equipment (UE), public network 5GC, private network 5GC, and data network (DN) is shown below. Figure 2 As shown. Figure 2 As shown, the AMF and SMF network elements of the private network are interconnected with the public network; the UPF network element is connected to the local private network at the next layer, thereby reducing data transmission latency.

[0104] It should be noted that, compared to the private network 5GC in the prior art, the private network 5GC in this application embodiment adds a core network element. This core network element integrates at least the functions of a public network UDM network element and a public network AUSF network element. The core network element is used to perform hot backup of authentication-related information in the public network UDM network element and has the ability to authenticate terminal devices.

[0105] When communication between the private network and the public network is uninterrupted, the ability of the core network element to authenticate terminal devices is disabled, and the core network element is not displayed externally. When communication between the private network and the public network is interrupted, the ability of the core network element to authenticate terminal devices becomes effective, and the core network element is displayed externally. In other words, the core network element settings for the private network are dynamically activated. The existence of the core network element settings does not interfere with the normal functions of the private network 5GC and the public network 5GC. Terminal devices are unaware of the core network element settings and do not require SIM card or phone number changes.

[0106] It should be noted that in the private network 5GC, regardless of whether the communication between the private network and the public network is interrupted, the AMF network element of the private network is always displayed to the outside world.

[0107] like Figure 3 As shown, when communication between the private network and the public network is uninterrupted, and a terminal device needs to register with the core network, the terminal device registers in the public network 5GC through the AMF network element of the private network. The AMF network element of the private network obtains authentication parameters from the UDM network element of the public network through the AUSF network element of the public network.

[0108] In the event of a communication interruption between the private network and the public network (i.e., a disconnection between the private network and the operator's network), the AMF (Automatic Authentication Function) network elements of the private network cannot communicate with the AUSF (Automatic Access Authentication Function) network elements and the UDM (User Authentication Function) network elements of the public network, resulting in the failure of the control plane link between the private network and the public network. When a terminal device needs to register with the core network, it registers within the private network's 5GC (User Core Domain Controller) through the AMF network elements of the private network. The AMF network elements of the private network obtain authentication parameters from the designated core network elements of the private network. Therefore, even with a communication interruption between the private network and the public network, the private network can still achieve full-process management of the user control plane and user plane, retaining complete control plane capabilities. Even if communication between the local 5G private network and the 5G public network is interrupted, the terminal device can still register on the 5G private network and use the 5G network for communication, thus improving communication reliability.

[0109] In addition, even if communication between the private network and the public network is interrupted, the private network still retains its complete control plane capabilities. The private network can completely preserve its control plane data, which is beneficial for subsequent network fault diagnosis.

[0110] It should be noted that the process of obtaining authentication parameters mainly involves configuring the core network elements of the private network, the AMF network elements of the private network, the AUSF network elements of the public network, and the UDM network elements of the public network. The implementation process of obtaining authentication parameters is described in detail below with reference to the attached diagram.

[0111] Figure 4 An interaction diagram illustrating a data acquisition method provided in another embodiment of this application. For example... Figure 4 The data acquisition methods shown include:

[0112] Step 401: The core network element of the private network performs a hot backup of the authentication-related information in the UDM network element of the public network, provided that the communication between the private network and the public network is not interrupted.

[0113] Here, without interruption of communication between the private network and the public network, the core network element of the private network performs a mirrored hot backup of authentication-related information in the public network's UDM network element through a designated communication interface. Authentication-related information refers to information related to authentication, which may include user identifiers, user subscription information, and authentication data. This authentication-related information is used to authenticate terminal devices.

[0114] In some embodiments, the core network element of the private network performs mirrored hot backup of authentication-related information in the UDM network element of the public network through the AMF network element of the private network and the AUSF network element of the public network. Different network elements communicate with each other through standard communication interfaces.

[0115] Step 402: When communication between the private network and the public network is interrupted, the AMF network element of the private network obtains authentication parameters from the designated core network element of the private network.

[0116] Here, when communication between the private network and the public network is interrupted, and a registration request is received from a terminal device, the AMF network element of the private network requests authentication parameters from the designated core network element of the private network.

[0117] In practical applications, the AMF network element of a private network can send an authentication request to the designated core network element of the private network in order to request the authentication parameters.

[0118] It should be noted that, provided that communication between the private network and the public network is not interrupted, the core network elements configured for the private network can be displayed externally, or they can be left undisclosed.

[0119] To save power consumption in setting up core network elements, in some embodiments, the method further includes:

[0120] In the event of a communication interruption between the private network and the public network, the AMF network element of the private network enables the designated core network element of the private network to authenticate terminal devices.

[0121] Here, in the event of a communication interruption between the private network and the public network, the ability of the designated core network element of the private network to authenticate terminal devices is enabled, and the designated core network element is displayed externally. That is, when communication between the private network and the public network is interrupted, the ability of the designated core network element of the private network to authenticate terminal devices is activated, and this authentication capability becomes effective. When communication between the private network and the public network is not interrupted, the ability of the designated core network element of the private network to authenticate terminal devices is deactivated, and in this case, the authentication capability becomes ineffective.

[0122] Step 403: When communication between the private network and the public network is interrupted, the core network element of the private network sets up to send authentication parameters back to the AMF network element of the private network.

[0123] Here, in the event of a communication interruption between the private network and the public network, when the core network element of the private network receives an authentication request sent by the AMF network element of the private network, it feeds back authentication parameters to the AMF network element of the private network based on the backup authentication-related information.

[0124] In this embodiment, when communication between the private network and the public network is uninterrupted, the designated core network element of the private network performs hot backup of authentication-related information in the UDM network element of the public network. When communication between the private network and the public network is interrupted, the AMF network element of the private network obtains authentication parameters from the designated core network element of the private network. Therefore, even when communication between the private network and the public network is interrupted, the private network can achieve full-process management of the user control plane and user plane. Even if communication between the local 5G private network and the 5G public network is interrupted, when a terminal device needs to register with the core network, the terminal device can register in the private network 5GC through the AMF network element of the private network, thereby using the 5G network for communication, which can improve communication reliability.

[0125] When communication between the private network and the public network remains uninterrupted, and a terminal device needs to register with the core network, it registers in the public 5GC via the AMF network element of the private network. This reduces the resource consumption of the private network 5GC and improves its data processing efficiency. In some embodiments, the method further includes:

[0126] When the communication between the private network and the public network is uninterrupted, the AMF network element of the private network obtains authentication parameters from the UDM network element of the public network through the ASF network element of the public network.

[0127] Here, assuming uninterrupted communication between the private network and the public network, when a terminal device needs to register with the core network, it registers in the operator's public 5GC network via the AMF network element of the private network. The terminal device sends a registration request to the AMF network element of the private network through the base station. Upon receiving the registration request from the terminal device, the AMF network element of the private network obtains authentication parameters from the UDM network element of the public network via the AUSF network element of the public network.

[0128] In some embodiments, the authentication parameters include at least a 5G authentication vector and may also include a Subscription Permanent Identifier (SUPI).

[0129] like Figure 5 As shown, the process by which the AMF network element of the private network obtains authentication parameters from the UDM network element of the public network through the ASF network element of the public network is as follows:

[0130] 1. The UE sends a registration request to the AMF network element of the private network.

[0131] In this process, the UE sends a registration request to the AMF network element of the private network through the base station.

[0132] 2. When the private network AMF element receives the registration request sent by the UE, it sends a Nausf_UEAuthentication_Authenticate Request message to the public network AUSF element.

[0133] Among them, the AMF network element of the private network sends the Nausf_UEAuthentication_AuthenticateRequest message to the AUSF network element of the public network based on the PUT method of Hypertext Transfer Protocol (HTTP).

[0134] 3. When a public AUSF network element receives a Nausf_UEAuthentication_Authenticate Request message from a public UDM network element, it sends a Nudm_UEAuthentication_GetRequest message to the public UDM network element.

[0135] Among them, the AUSF network element on the public network sends the Nudm_UEAuthentication_Get Request message to the UDM network element on the public network based on the HTTP POST method.

[0136] 4. When a public network UDM element receives a Nudm_UEAuthentication_GetRequest message sent by a public network AUSF element, it constructs a 5G Home Environment Authentication Vector (5G HE AV).

[0137] Among them, 5G HE AV includes: RAND, AUTN, XRES* and K_AUSF; RAND represents a 128-bit random number, AUTN represents an authentication token, XRES* represents the expected response parameters, and K_AUSF represents the intermediate key used to store in the AUSF network element on the public network.

[0138] 5G HE AV can be represented as (RAND, AUTN, XRES*, K_AUSF).

[0139] 5. The public network UDM element sends a Nudm_UEAuthentication_Get Response message to the public network AUSF element. This message carries at least 5G HE AV. If the Nudm_UEAuthentication_Get Request message carries the UE's Subscription Concealed Identifier (SUCI), the Nudm_UEAuthentication_Get Response message also carries the UE's SUPI.

[0140] 6. When the AUSF network element of the public network receives the Nudm_UEAuthentication_GetResponse message sent by the UDM network element of the public network, it constructs a 5G authentication vector (5G AV, 5G AuthenticationVector) based on 5G HE AV.

[0141] Among them, 5G AV includes RAND, AUTN, HXRES*, and K_SEAF.

[0142] According to TS33.501 Annex A.5, the HXRES* of the public network AUSF network element is calculated based on XRES* in 5G HE AV; according to TS33.501 Annex A.6, K_SEAF is calculated based on K_AUSF in 5G HE AV; the calculated HXRES* is used to replace XRES* in 5G HE AV; the calculated K_SEAF is used to replace K_AUSF in 5G HE AV, resulting in 5GAV(RAND, AUTN, HXRES*, K_SEAF).

[0143] 7. When a public AUSF network element constructs a 5G AV, it sends a Nausf_UEAuthentication_Authenticate Response message to a private AMF network element based on the constructed 5G AV. This message carries the 5G AV.

[0144] The AUSF network element in the public network can also be associated with and stored as XRES* and K_AUSF in 5G HE AV.

[0145] In practical applications, the public network AFS network element can send the Nausf_UEAuthentication_Authenticate Response message to the private network AMF network element carrying only RAND, AUTN, and HXRES*; RAND, AUTN, and HXRES* are used for visited location authentication. If the visited location authentication of the UE is successful in step 12, then K_SEAF from 5G AV is sent to the UE.

[0146] 8. The AMF network element of the private network sends an Authentication Request message to the UE, which carries the RAND and AUTN in 5G AV.

[0147] 9. When the UE receives an Authentication Request sent by the AMF network element of the private network, it calculates RES* and sends an Authentication Response message to the AMF network element of the private network. This message carries the calculated RES*, and RES* represents the authentication response parameters.

[0148] 10. When the AMF network element of the private network receives the Authentication Response sent by the UE, it shall calculate the HRES* based on the RES* carried in the Authentication Response in accordance with TS33.501 Annex A.5.

[0149] The AMF network element of the private network compares the calculated HRES* with the HXRES* in the constructed 5G AV. If the comparison result indicates that the two are the same, it means that the authentication of the UE's visited location is successful; if the comparison result indicates that the two are different, it means that the authentication of the UE's visited location fails, and this authentication fails. Among them, this authentication failure indicates that the UE registration fails.

[0150] 11. The AMF network element of the private network sends a Nausf_UEAuthentication_Authenticate Request message to the AUSF network element of the public network.

[0151] If the UE successfully authenticates the visited location, the message carries the RES* sent by the UE; if the UE fails to authenticate the visited location, the message does not carry the RES* sent by the UE.

[0152] 12. When the AMF network element of the public network receives the Nausf_UEAuthentication_Authenticate Request message sent by the AMF network element of the private network, it performs home location authentication on the UE and sends the Nausf_UEAuthentication_Authenticate Response message to the AMF network element of the private network. This message carries the home location authentication result.

[0153] In this process, the AUSF network element in the public network determines whether the 5G AV and / or 5G HE AV has expired. If the 5G AV or 5G HE AV has expired, it indicates that the home authentication has failed. In this authentication failure, a Nausf_UEAuthentication_Authenticate Response message without carrying the UE's SUPI is sent to the AMF network element in the private network.

[0154] If 5G AV and 5G HE AV have not expired, compare RES* with XRES* in 5G HE AV. If RES* is the same as XRES* in 5G HE AV, it indicates that the home authentication is successful. Then, send a Nausf_UEAuthentication_Authenticate Response message carrying the UE's SUPI to the AMF network element of the private network. It can also carry K_SEAF from 5G AV.

[0155] 13. When the private network's AMF element receives a Nausf_UEAuthentication_Authenticate Response message from the public network's AUSF element, and this message carries the UE's SUPI, the private network's AMF element assigns a globally unique temporary UE identity (GUTI) to the UE, associates and stores the GUTI with the SUPI, and sends a Registration Accept message to the UE, which also carries the GUTI. At this point, the UE successfully registers with the operator's network.

[0156] It should be noted that if UE authentication fails, the private network's AMF network element sends a registration refusal message to the UE.

[0157] The above combination Figure 4 and Figure 5 This document details the process by which the AMF (Authentication, Authentication, and Authentication) network element in the private network obtains authentication parameters from the UDM (Universal Authentication, Authentication, and Delegation) network element in the public network, without interrupting communication between the private network and the public network. The following section combines this with... Figures 6 to 7This section details the process by which the AMF network element of the private network obtains authentication parameters from the designated core network element of the private network when communication between the private network and the public network is interrupted.

[0158] Figure 6 An interaction diagram of a data acquisition method provided in another embodiment of this application, such as... Figure 6 As shown, in the event of a communication interruption between the private network and the public network, the data acquisition method includes:

[0159] Step 601: In the event of a communication interruption between the private network and the public network, the terminal device sends a registration request to the AMF network element of the private network.

[0160] Here, when communication between the private network and the public network is interrupted, and the terminal device needs to register with the core network, the terminal device generates a registration request and sends the registration request to the AMF network element of the private network through the base station.

[0161] When a terminal device is registering for the first time, the registration request carries the terminal device's SUCI; when it is not registering for the first time, the registration request carries the terminal device's GUTI.

[0162] Step 602: The AMF network element of the private network receives the registration request sent by the terminal device.

[0163] Step 603: Based on the registration request, the AMF network element of the private network sends a first authentication request to the designated core network element of the private network.

[0164] Here, when the registration request carries SUCI, the AMF network element of the private network decrypts the SUCI to obtain the corresponding SUPI, and sends the first authentication request to the designated core network element of the private network.

[0165] When the registration request carries a GUTI, the AMF network element of the private network determines the SUPI corresponding to the GUTI carried in the registration request based on the pre-saved correspondence between GUTI and SUPI, and sends a first authentication request to the core network element of the private network. The first authentication request is used to request authentication parameters.

[0166] In practical applications, the first authentication request carries the service network identifier and resynchronization information, and may also carry SUCI or the determined SUPI.

[0167] Step 604: The core network element of the private network sends a 5G authentication vector to the AMF network element of the private network based on the first authentication request sent by the AMF network element of the private network.

[0168] Here, when the core network element of the private network receives the first authentication request sent by the AMF network element of the private network, it creates a 5G authentication vector for the first authentication request based on the backed-up authentication-related information, and sends the 5G authentication vector for the first authentication request to the AMF network element of the private network.

[0169] In practical applications, the core network element of the private network can send a response message about the registration request to the AMF network element of the private network. This response message includes at least the 5G authentication vector for the first authentication request.

[0170] Step 605: The AMF network element of the private network receives the 5G authentication vector regarding the first authentication request sent by the designated core network element of the private network.

[0171] In some embodiments, in addition to the authentication parameter including SUPI, after step 605, the method further includes: the AMF network element of the private network receiving the SUPI of the terminal device sent by the designated core network element of the private network when the communication between the private network and the public network is interrupted.

[0172] Here, when the core network element of the private network receives the first authentication request sent by the AMF network element of the private network, it sends the SUPI of the terminal device to the AMF network element of the private network based on the first authentication request.

[0173] In practical applications, when the core network element of the private network sends a response message about the registration request to the AMF network element of the private network, the response message can also carry the SUPI of the terminal device.

[0174] In this embodiment, when communication between the private network and the public network is interrupted, the AMF network element of the private network obtains the 5G authentication vector and SUPI from the designated core network element of the private network. Therefore, even when communication between the private network and the public network is interrupted, the private network 5GC can still authenticate the terminal device, and determine whether to allow the terminal device to register with the private network 5GC based on the authentication result. If the terminal device successfully registers with the private network 5GC, it can use the 5G network for communication, thus improving communication reliability.

[0175] In some embodiments, the core network elements of the private network include AUSF network elements and UDM network elements; such as Figure 7 As shown, in the event of a communication interruption between the private network and the public network, the data acquisition method includes:

[0176] Step 701: In the event of a communication interruption between the private network and the public network, the terminal device sends a registration request to the AMF network element of the private network.

[0177] Steps 701 to 702 are the same as steps 601 to 602, and will not be described again here.

[0178] Step 702: The AMF network element of the private network receives the registration request sent by the terminal device.

[0179] Step 703: The AMF network element of the private network sends a first authentication request to the AUSF network element of the private network based on the registration request.

[0180] Step 703 is similar to step 603. For the specific implementation process, please refer to the relevant description of step 603, which will not be repeated here.

[0181] In practical applications, the first authentication request can be Nausf_UEAuthentication_AuthenticateRequest.

[0182] In practical applications, the AMF network element of the private network sends the first authentication request to the AUSF network element of the private network based on the HTTP POST method.

[0183] Step 704: The AUSF network element of the private network receives the first authentication request sent by the AMF network element of the private network, and sends an authentication parameter acquisition request to the UDM network element of the private network based on the first authentication request.

[0184] Here, the authentication parameter retrieval request can be a Nudm_UEAuthentication_Get Request. The AUSF network element of the private network sends the authentication parameter retrieval request to the UDM network element of the private network based on the HTTP POST method. The authentication parameter retrieval request carries at least the service network identifier and resynchronization information, and may also carry the SUCI of the terminal device.

[0185] Step 705: The UDM network element of the private network constructs a 5G home environment authentication vector based on the authentication parameter acquisition request, and sends a response message to the AUSF network element of the private network. The response message carries the 5G home environment authentication vector.

[0186] Here, each time a UDM network element in the private network receives an authentication parameter acquisition request, it constructs the corresponding 5G Home Environment Authentication Vector (5G HE AV) and sends a response message carrying the 5G HE AV to the AUSF network element in the private network.

[0187] When constructing 5G HE AV, the UDM network element of the private network calculates K_AUSF according to TS33.501 Annex A.2 and XRES* according to TS33.501 Annex A.4, and constructs 5G HE AV (RAND, AUTN, XRES*, K_AUSF) based on K_AUSF and XRES*.

[0188] In practical applications, this response message can be a Nudm_UEAuthentication_Get Response. This response message can also carry the authentication type authType.

[0189] In some embodiments, the authentication parameter acquisition request carries the SUCI of the terminal device, and the response message also carries the SUPI of the terminal device.

[0190] Here, when the authentication parameter retrieval request carries the terminal device's SUCI, the response message to the authentication parameter retrieval request also carries the terminal device's SUPI.

[0191] In practical applications, when the Nudm_UEAuthentication_Get Request carries the SUCI of the terminal device, the Nudm_UEAuthentication_Get Response also carries the SUPI of the terminal device.

[0192] Step 706: The AUSF network element of the private network constructs a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, and sends the 5G authentication vector regarding the first authentication request to the AMF network element of the private network.

[0193] Here, when the AUSF network element of the private network receives a response message from the UDM network element of the private network, it constructs a 5G AV (RAND, AUTN, HXRES*, K_SEAF) based on the 5G HE AV carried in the response message, and sends a response message regarding the first authentication request to the AMF network element of the private network. This response message carries the 5G AV. In practical applications, the response message regarding the first authentication request can be Nausf_UEAuthentication_Authenticate Response.

[0194] In some embodiments, the 5G home environment authentication vector includes a random number, an authentication token, expected response parameters, and an intermediate key; the AUSF network element of the private network constructs a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, including:

[0195] The AUSF network element of the private network calculates the first hash value based on the expected response parameter in the 5G home environment authentication vector, and calculates the anchor key based on the intermediate key in the 5G home environment authentication vector.

[0196] The AUSF network element of the private network replaces the expected response parameter in the 5G home environment authentication vector with the calculated first hash value, and replaces the intermediate key in the 5G home environment authentication vector with the calculated anchor key, to obtain the 5G authentication vector.

[0197] Here, the method for constructing 5G AV based on 5G HE AV (RAND, AUTN, XRES*, K_AUSF) for private network AUSF elements is as follows:

[0198] According to TS33.501 Annex A.5, HXRES* is calculated based on XRES* in 5G HE AV, and K_SEAF is calculated based on K_AUSF in 5G HE AV according to TS33.501 Annex A.6. The calculated HXRES* replaces XRES* in 5G HE AV, and the calculated K_SEAF replaces K_AUSF in 5G HE AV, to obtain 5GAV(RAND, AUTN, HXRES*, K_SEAF).

[0199] Among them, RAND represents a random number, AUTN represents an authentication token, XRES* represents the expected response parameter, and K_AUSF represents the intermediate key used to store in the KUSF network element of the private network.

[0200] To improve data query efficiency, in some embodiments, the method further includes:

[0201] The AUSF network element of the private network stores the expected response parameter in the 5G home environment authentication vector in association with at least one of the following:

[0202] The authentication parameters are obtained by acquiring the SUCI carried in the request.

[0203] The response message carries the SUPI;

[0204] The intermediate key in the 5G home environment authentication vector.

[0205] Here, when the AUSF network element of the private network receives the 5G HE AV sent by the private network, it associates and stores the XRES* in the 5G HE AV with SUCI or SUPI, and can also associate and store the K_AUSF in the 5G HE AV.

[0206] Step 707: The AMF network element of the private network receives the 5G authentication vector regarding the first authentication request sent by the AUSF network element of the private network.

[0207] To improve communication efficiency, in some embodiments, after step 707, the method further includes steps 708 to 709:

[0208] Step 708: The AMF network element of the private network generates the security context identifier corresponding to the terminal device;

[0209] Step 709: The AMF network element of the private network sends the second authentication request to the terminal device based on the received 5G authentication vector; wherein,

[0210] The second authentication request carries the security context identifier; the security context identifier is used to indicate that the AMF network element of the private network and the terminal device do not need to re-authenticate when performing data interaction.

[0211] Here, the AMF network element of the private network generates the security context identifier corresponding to the terminal device. The security context identifier is used to identify security context information. In practical applications, the security context identifier can be the ngKSI (NAS key set identifier) ​​of the non-access stratum NAS.

[0212] After receiving the 5G authentication vector for the first authentication request from the designated core network element of the private network, the AMF network element of the private network sends a second authentication request to the terminal device based on the received 5G AV, thereby initiating the authentication process for the terminal device. The second authentication request carries RAND, AUTN, and ngKSI from the received 5G AV.

[0213] In practical applications, the second authentication request is called an Authentication Request.

[0214] In some embodiments, the authentication parameters include SUPI; the method further includes:

[0215] If communication between the private network and the public network is interrupted, and the authentication of the home location of the terminal device is successful, the AUSF network element of the private network sends the SUPI of the terminal device to the AMF network element of the private network.

[0216] The following is combined Figure 7 Steps 710 to 714 illustrate the process by which the AUSF network element of the private network sends the SUPI of the terminal device to the AMF network element of the private network:

[0217] Step 710: Upon receiving the second authentication request sent by the AMF network element of the private network, the terminal device calculates RES* and sends an authentication response message regarding the second authentication request to the AMF network element of the private network. The authentication response message carries the calculated RES*.

[0218] The authentication response message can be an Authentication Response.

[0219] Step 711: The AMF network element of the private network calculates HRES* based on the RES* sent by the terminal device.

[0220] Here, when the AMF network element of the private network receives the authentication response message sent by the terminal device, it calculates HRES* based on the RES* carried in the authentication response message in accordance with TS33.501 Annex A.5.

[0221] The AMF network element of the private network compares the calculated HRES* with the HXRES* in the constructed 5G AV. If the comparison result indicates that the two are the same, it means that the authentication of the visited location of the terminal device is successful; if the comparison result indicates that the two are different, it means that the authentication of the visited location of the terminal device fails, and this authentication fails. Among them, this authentication failure indicates that the terminal device registration fails.

[0222] Step 712: If the calculated HRES* is the same as the HXRES* in the constructed 5G authentication vector, the AMF network element of the private network sends a third authentication request to the AUSF network element of the private network. The third authentication request carries RES*.

[0223] The third authentication request can be a Nausf_UEAuthentication_Authenticate Request.

[0224] It should be noted that in the event that the authentication of the visited location by the terminal device fails, the third authentication request does not carry the RES* sent by the terminal device.

[0225] Step 713: If the received RES* is the same as XRES* in the 5G home environment authentication vector, the AMF network element of the private network sends an authentication response message to the AMF network element of the private network; the authentication response message carries SUPI.

[0226] Here, when the AUSF network element of the private network receives a third authentication request from the AMF network element of the private network, the AUSF network element determines whether the 5G AV and / or 5G HE AV has expired. If neither the 5G AV nor the 5G HE AV has expired, it compares the received RES* with the XRES* in the 5G HE AV. If the RES* is the same as the XRES* in the 5G HE AV, it indicates that the home authentication is successful, and sends an authentication response message regarding the third authentication request to the AMF network element of the private network. This authentication response message carries at least the SUPI of the terminal device. The authentication response message can be a Nausf_UEAuthentication_Authenticate Response.

[0227] It should be noted that in some embodiments, in step 706, the AUSF network element of the private network can send RAND, AUTN, and HXRES* from 5G AV to the AMF network element of the private network. In step 713, if the home location authentication of the terminal device is successful, K_SEAF from 5G AV is then sent to the AMF network element of the private network. That is to say, the AUSF network element of the private network can also carry K_SEAF from 5G AV when sending the authentication response message from the AUSF network element of the private network to the AMF network element of the private network.

[0228] It should be noted that if 5G AV or 5G HE AV has expired, indicating that the home authentication has failed, the AUSF network element of the private network will also send an authentication response message regarding the third authentication request to the AMF network element of the private network. This authentication response message does not carry SUPI.

[0229] Step 714: The AMF network element of the private network sends an acceptance registration message to the terminal device; the acceptance registration message carries the GUTI.

[0230] Here, when the AMF network element of the private network receives an authentication response message regarding a third authentication request from the AUSF network element of the private network, and this authentication response message carries a SUPI, it allocates a GUTI to the terminal device, associates and stores the GUTI with the SUPI, and sends an acceptance registration message to the UE, which carries the GUTI. At this point, the UE successfully registers in the private network 5GC.

[0231] It should be noted that if the authentication response message for the third authentication request indicates that the authentication has failed, the AMF network element of the private network sends a registration refusal message to the terminal device.

[0232] In this embodiment, when communication between the private network and the public network is interrupted, the AMF network element of the private network obtains authentication parameters from the UDM network element of the private network through the AUSF network element of the private network. Therefore, even when communication between the private network and the public network is interrupted, the private network 5GC can still authenticate the terminal device, and determine whether to allow the terminal device to register with the private network 5GC based on the authentication result. If the terminal device successfully registers with the private network 5GC, it can use the 5G network for communication, thus improving communication reliability.

[0233] This application also provides a data acquisition system, which includes at least the AMF network element and the designated core network element of the private network, and may also include the SMF network element of the private network.

[0234] The AMF network element of the private network is used to perform the above. Figures 4 to 7 In this context, the steps on the AMF network element side of the private network are as follows. The core network element of the private network is configured to perform... Figures 4 to 7In this context, the steps for setting up the core network element side of the private network can be implemented by the AUSF network element and the UDM network element of the private network.

[0235] The SMF network element in the private network is mainly responsible for interacting with the separate data plane, creating, updating and deleting PDU sessions, and managing the session context with the UPF.

[0236] In some embodiments, the data acquisition system is deployed at edge nodes and / or in the central cloud.

[0237] Here, when the data acquisition system is deployed at edge nodes, these edge nodes can be deployed near a private network data center or in a carrier's local data center. Edge nodes can interconnect with the public 5GC network via the carrier's bearer network.

[0238] When the data acquisition system is deployed in the central cloud, it can be backed up to the central cloud in real time, and supports one-click download and installation of the data acquisition system, so that customers can download and install the data acquisition system according to their actual needs, thereby improving the efficiency of data acquisition system deployment.

[0239] Considering that natural disasters or large-scale performances may cause a surge in the number of users in a certain area, existing cellular network systems could become overloaded due to the influx of registration requests, potentially leading to service disruptions. To prioritize the registration needs of resident users on the core network side of the private network, in some embodiments, the data acquisition system can connect to the private network management platform via a designated interface. This platform has the ability to identify resident users. The private network management platform can be a server or an electronic device such as a computer. Alternatively, the private network management platform can be deployed within the data acquisition system.

[0240] Based on the authentication-related information, including user subscription information, backed up in the core network elements of the private network, the backed-up user subscription information is stored in the UDM network elements included in the core network elements of the private network.

[0241] Figure 8 This is a schematic diagram of the network architecture provided in the embodiments of this application, such as... Figure 8 As shown, the private network management platform reads user subscription information stored in the designated core network elements of the private network from the data acquisition system through a set interface. Based on the read user subscription information, it identifies resident users, thereby enabling the core network side of the private network to prioritize the registration needs of resident users.

[0242] The process by which the private network management platform identifies resident users and controls the number of users accessing the core network is as follows:

[0243] 1. The private network management platform preprocesses the retrieved user contract information to obtain preprocessed user contract information. Preprocessing the retrieved user contract information includes:

[0244] Based on the read user subscription information, the UE's home domain, resident area, movement range, and movement frequency are determined, and a corresponding first identifier is assigned to the UE's home domain, resident area, movement range, and movement frequency respectively. Based on the first identifier, home domain users, resident users, and low-mobility users are identified. A second identifier is assigned to each UE according to the principle of prioritizing home domain users, resident users, and low-mobility users. The second identifier is used to indicate the access priority.

[0245] In practical applications, according to Figure 9 User subscription information is preprocessed. It should be noted that the private network management platform associates and stores the UE's identity identifier with its corresponding first and second identifiers.

[0246] 2. In the event of a surge in mobile phone users and a flood of registration requests within a certain area, the 5GC side of the private network, with the assistance of the private network management platform, prioritizes registration requests from resident users by granting access in a tiered manner, based on access priority. Specifically, if a user's access priority is greater than or equal to the access priority allowed to access the private network, the private network's AMF will allow that user to register.

[0247] 3. When the number of network access requests is greater than or equal to the set load threshold, reject the remaining user access requests.

[0248] This prevents the cellular network communication system from becoming overwhelmed by a surge of registration requests when a large number of users join.

[0249] In practical applications, according to Figure 10 The flowchart shown controls the number of users accessing the core network. Figure 10 As shown:

[0250] In the event of a surge in registration requests, determine whether it is necessary to modify the access priority that allows access to the core network.

[0251] For example, if the number of registration requests received within a set time period is greater than or equal to a first set threshold, the private network management platform increases the access priority allowed to access the core network; if the number of registration requests received within a set time period is less than or equal to a second set threshold, the private network management platform decreases the access priority allowed to access the core network. The first set threshold is greater than the second set threshold.

[0252] The AMF network element of the private network forwards the received registration request to the private network management platform.

[0253] The private network management platform receives a registration request forwarded by the AMF network element of the private network. Based on the UE's identity identifier carried in the registration request, it determines the second identifier corresponding to the UE; it compares the access priority indicated by the second identifier with the access priority allowed to access the core network, and obtains a comparison result; based on the comparison result, it determines whether to allow the UE to access the core network, and obtains a judgment result. The private network management platform sends the judgment result to the AMF network element of the private network.

[0254] In cases where the access priority indicated by the second identifier is lower than the access priority allowed to access the core network, the corresponding UE is not allowed to access the core network, and the AMF network element of the private network rejects the UE's registration.

[0255] If the access priority indicated by the second identifier is greater than or equal to the access priority allowed to access the core network, the corresponding UE is allowed to access the core network. The AMF network element of the private network allows the UE to register, registers the UE according to the registration process, and notifies the private network management platform when the UE registration is successful, so that the private network management platform can update the total number of accesses to the core network.

[0256] The private network management platform calculates the network load margin of the core network based on the total number of accesses and the corresponding set load threshold. Specifically, network load margin = set load threshold - total number of accesses to the core network.

[0257] If the network load margin of the core network is less than or equal to zero, the private network management platform will reject the remaining registration requests.

[0258] It should be noted that, in some embodiments, the functions implemented by the private network management platform can be integrated into the private network AMF network element or set core network element.

[0259] To implement the data acquisition method for AMF network elements applied to private networks in the embodiments of this application, the embodiments of this application also provide an AMF network element for private networks, such as... Figure 11 As shown, the AMF network elements of this private network include:

[0260] The acquisition unit 111 is used to acquire authentication parameters from a designated core network element of the private network when communication between the private network and the public network is interrupted; wherein, the UDM network element of the private network is used to perform hot backup of authentication-related information in the UDM network element of the public network and has the ability to authenticate terminal devices.

[0261] In some embodiments, the AMF network element of the private network also includes:

[0262] The enabling unit is used to enable the ability of a designated core network element of the private network to authenticate terminal devices in the event of a communication interruption between the private network and the public network.

[0263] In some embodiments, the authentication parameters include a 5G authentication vector; the acquisition unit 111 is specifically used for:

[0264] Receive registration requests sent by terminal devices;

[0265] Based on the registration request, a first authentication request is sent to the designated core network element of the private network;

[0266] Receive the 5G authentication vector sent by the designated core network element of the private network regarding the first authentication request.

[0267] In some embodiments, the authentication parameters further include SUPI; the acquisition unit 111 is further configured to: receive the SUPI of the terminal device sent by a designated core network element of the private network when the communication between the private network and the public network is interrupted.

[0268] In some embodiments, the AMF network element of the private network also includes:

[0269] A generation unit is used to generate a security context identifier corresponding to the terminal device;

[0270] The sending unit is configured to send the second authentication request to the terminal device based on the received 5G authentication vector; wherein,

[0271] The second authentication request carries the security context identifier; the security context identifier is used to indicate that the AMF network element of the private network and the terminal device do not need to re-authenticate when performing data interaction.

[0272] In some embodiments, the obtaining unit 111 is further configured to:

[0273] Without interruption of communication between the private network and the public network, authentication parameters are obtained from the UDM network element of the public network through the AUSF network element of the public network.

[0274] In practical applications, the acquisition unit 111 and the generation unit can be implemented using processors in the AMF network elements of the private network, such as central processing units (CPUs), digital signal processors (DSPs), microcontroller units (MCUs), or field-programmable gate arrays (FPGAs), or can be implemented using both processors and communication interfaces. The transmission unit is implemented using the communication interface in the AMF network elements of the private network.

[0275] It should be noted that the AMF network element of the private network provided in the above embodiments is only illustrated by the division of the above program modules when acquiring authentication parameters. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the AMF network element of the private network provided in the above embodiments and the data acquisition method embodiments belong to the same concept, and its specific implementation process is detailed in the method embodiments, which will not be repeated here.

[0276] To implement the data acquisition method for a designated core network element in a private network as described in this application embodiment, this application embodiment also provides a designated core network element for a private network, such as... Figure 12 As shown, the core network elements configured for this private network include:

[0277] Backup unit 121 is used to perform hot backup of authentication-related information in the UDM network element of the public network when the communication between the private network and the public network is uninterrupted;

[0278] Feedback unit 122 is used to feed back authentication parameters to the AMF network element of the private network when the communication between the private network and the public network is interrupted.

[0279] In some embodiments, the authentication parameters include a 5G authentication vector; the feedback unit 122 is specifically used for:

[0280] Based on the first authentication request sent by the AMF network element of the private network, a 5G authentication vector regarding the first authentication request is sent to the AMF network element of the private network; wherein,

[0281] The first authentication request is sent upon receiving a registration request from the terminal device.

[0282] In some embodiments, the core network elements of the private network include AUSF network elements and UDM network elements; wherein,

[0283] The AUSF network element of the private network is used to receive the first authentication request sent by the AMF network element of the private network, and to send an authentication parameter acquisition request to the UDM network element of the private network based on the first authentication request.

[0284] The UDM network element of the private network is used to construct a 5G home environment authentication vector based on the authentication parameter acquisition request, and send a response message to the AUSF network element of the private network. The response message carries the 5G home environment authentication vector.

[0285] The AUSF network element of the private network is also used to construct a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, and send the 5G authentication vector about the first authentication request to the AMF network element of the private network.

[0286] In some embodiments, the 5G home environment authentication vector includes a random number, an authentication token, an expected response parameter, and an intermediate key;

[0287] The AUSF network element of the private network is specifically used to calculate the first hash value based on the expected response parameters in the 5G home environment authentication vector, and to calculate the anchor key based on the intermediate key in the 5G home environment authentication vector.

[0288] The AUSF network element of the private network is specifically used to replace the expected response parameter in the 5G home environment authentication vector with the calculated first hash value, and to replace the intermediate key in the 5G home environment authentication vector with the calculated anchor key, so as to obtain the 5G authentication vector.

[0289] In some embodiments, the authentication parameter acquisition request carries the user hidden identifier (SUCI) of the terminal device, and the response message also carries the SUPI of the terminal device.

[0290] In some embodiments, the authentication parameters include SUPI, and the AUSF network element of the private network is further used for:

[0291] If communication between the private network and the public network is interrupted, and the authentication of the home location of the terminal device is successful, the SUPI of the terminal device is sent to the AMF network element of the private network.

[0292] In some embodiments, the AUSF network element of the private network is also used for:

[0293] The expected response parameter in the 5G home environment authentication vector is associated with at least one of the following:

[0294] The authentication parameters are obtained by acquiring the SUCI carried in the request.

[0295] The response message carries the SUPI;

[0296] The intermediate key in the 5G home environment authentication vector.

[0297] In practical applications, the backup unit 121 and the feedback unit 122 can be implemented using processors in the core network elements of the dedicated network, such as central processing units (CPUs), digital signal processors (DSPs), microcontroller units (MCUs), or field-programmable gate arrays (FPGAs), or can be implemented using both a processor and a communication interface. The transmitting unit is implemented using the communication interface in the core network elements of the dedicated network.

[0298] It should be noted that the above embodiments of the private network's core network element configuration for acquiring authentication parameters are only illustrated using the division of the above-described program modules. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. Furthermore, the private network's core network element configuration and the data acquisition method embodiments provided above belong to the same concept, and their specific implementation process is detailed in the method embodiments, which will not be repeated here.

[0299] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide an edge node. Figure 13 This is a schematic diagram of the hardware composition structure of the edge node provided in the embodiments of this application, as shown below. Figure 13 As shown, edge node 13 includes:

[0300] Communication interface 131 enables information exchange with other devices, such as network devices;

[0301] The processor 132 is connected to the communication interface 131 to enable information interaction with other devices. When running a computer program, it executes methods provided by one or more technical solutions on the AMF side of the aforementioned private network, or executes methods provided by one or more technical solutions on the core network element side of the aforementioned private network. The computer program is stored in the memory 133.

[0302] Of course, in practical applications, the various components in edge node 13 are coupled together through bus system 134. It can be understood that bus system 134 is used to implement communication between these components. In addition to a data bus, bus system 134 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 13 The general labeled all buses as Bus System 134.

[0303] The memory 133 in this embodiment is used to store various types of data to support the operation of the edge node 13. Examples of such data include any computer program used to operate on the edge node 13.

[0304] It is understood that memory 133 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), Sync Link Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 133 described in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.

[0305] The methods disclosed in the embodiments of this application can be applied to or implemented by the processor 132. The processor 132 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 132 or by instructions in the form of software. The processor 132 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 132 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the memory 133. The processor 132 reads the program in the memory 133 and completes the steps of the aforementioned method in combination with its hardware.

[0306] Optionally, when the processor 132 executes the program, it implements the corresponding processes implemented by the terminal in the various methods of the embodiments of this application. For the sake of brevity, these will not be described in detail here.

[0307] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a first memory 133 storing a computer program, which can be executed by a terminal processor 132 to complete the steps described in the aforementioned method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0308] In the several embodiments provided in this application, it should be understood that the disclosed apparatus, terminal, and method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0309] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0310] In addition, each functional unit in the various embodiments of this application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0311] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0312] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0313] It should be noted that the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0314] It should be noted that the term "and / or" in the embodiments of this invention is merely a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more of a plurality of elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0315] In addition, in this application example, terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0316] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A data acquisition method, characterized in that, The method, applied to the Access and Mobility Management Function (AMF) network element in a private network, includes: In the event of a communication interruption between the private network and the public network, authentication parameters are obtained from a designated core network element of the private network. This designated core network element performs hot backup of authentication-related information in the Unified Data Management (UDM) network element of the public network and has the capability to authenticate terminal devices. The designated core network element of the private network includes AUSF network elements and UDM elements. The authentication-related information includes user subscription information and authentication data. The user subscription information is used to determine the first identifier corresponding to the home domain, resident area, movement range, and movement frequency of the terminal device. The first identifier is used to identify home domain users, resident users, and low-mobility users, and a second identifier for the terminal device is determined based on the principle of prioritizing home domain users, resident users, and low-mobility users. The second identifier is used to indicate access priority.

2. The method according to claim 1, characterized in that, The method further includes: In the event of a communication interruption between the private network and the public network, the ability of the designated core network element of the private network to authenticate terminal devices is enabled.

3. The method according to claim 1 or 2, characterized in that, The authentication parameters include a 5G authentication vector; obtaining the authentication parameters from the designated core network element of the private network includes: Receive registration requests sent by terminal devices; Based on the registration request, a first authentication request is sent to the designated core network element of the private network; Receive the 5G authentication vector sent by the designated core network element of the private network regarding the first authentication request.

4. The method according to claim 3, characterized in that, The authentication parameters also include a user permanent identifier (SUPI); the method further includes: In the event of a communication interruption between the private network and the public network, the terminal device receives the SUPI sent by a designated core network element of the private network.

5. The method according to claim 3, characterized in that, After receiving the 5G authentication vector regarding the first authentication request sent by a designated core network element of the private network, the method further includes: Generate a security context identifier corresponding to the terminal device; A second authentication request is sent to the terminal device based on the received 5G authentication vector; wherein, The second authentication request carries the security context identifier; the security context identifier is used to indicate that the AMF network element of the private network and the terminal device do not need to re-authenticate when performing data interaction.

6. The method according to claim 1, characterized in that, The method further includes: If the communication between the private network and the public network is uninterrupted, the authentication parameters are obtained from the UDM network element of the public network through the authentication server function (AUSF) of the public network.

7. A data acquisition method, characterized in that, The method for configuring core network elements in a private network, including AUSF network elements and UDM network elements, includes: Under the condition that the communication between the private network and the public network is not interrupted, the authentication-related information in the UDM network element of the public network is hot-backed up; the authentication-related information includes user subscription information and authentication data; the user subscription information is used to determine the first identifier corresponding to the home domain, resident area, movement range, and movement frequency of the terminal device; the first identifier is used to identify home domain users, resident users, and low-mobility users, and the second identifier of the terminal device is determined according to the principle of home domain users first, resident users first, and low-mobility users first; the second identifier is used to indicate the access priority; In the event of a communication interruption between the private network and the public network, authentication parameters are fed back to the AMF network element of the private network.

8. The method according to claim 7, characterized in that, The authentication parameters include a 5G authentication vector; the step of feeding back the authentication parameters to the AMF network element of the private network includes: Based on the first authentication request sent by the AMF network element of the private network, a 5G authentication vector regarding the first authentication request is sent to the AMF network element of the private network; wherein, The first authentication request is sent upon receiving a registration request from the terminal device.

9. The method according to claim 8, characterized in that, The first authentication request sent by the AMF network element based on the private network sends a 5G authentication vector regarding the first authentication request to the AMF network element of the private network, including: The AUSF network element of the private network receives the first authentication request sent by the AMF network element of the private network, and sends an authentication parameter acquisition request to the UDM network element of the private network based on the first authentication request. The UDM network element of the private network constructs a 5G home environment authentication vector based on the authentication parameter acquisition request, and sends a response message to the AUSF network element of the private network. The response message carries the 5G home environment authentication vector. The AUSF network element of the private network constructs a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, and sends the 5G authentication vector regarding the first authentication request to the AMF network element of the private network.

10. The method according to claim 9, characterized in that, The 5G home environment authentication vector includes a random number, an authentication token, expected response parameters, and an intermediate key; the AUSF network element of the private network constructs a 5G authentication vector based on the 5G home environment authentication vector carried in the response message, including: The AUSF network element of the private network calculates the first hash value based on the expected response parameter in the 5G home environment authentication vector, and calculates the anchor key based on the intermediate key in the 5G home environment authentication vector. The AUSF network element of the private network replaces the expected response parameter in the 5G home environment authentication vector with the calculated first hash value, and replaces the intermediate key in the 5G home environment authentication vector with the calculated anchor key, to obtain the 5G authentication vector.

11. The method according to claim 9, characterized in that, The authentication parameter acquisition request carries the user hidden identifier (SUCI) of the terminal device, and the response message also carries the SUPI of the terminal device.

12. The method according to claim 11, characterized in that, The authentication parameters include SUPI; the method further includes: If communication between the private network and the public network is interrupted, and the authentication of the home location of the terminal device is successful, the AUSF network element of the private network sends the SUPI of the terminal device to the AMF network element of the private network.

13. The method according to claim 11, characterized in that, The method further includes: The AUSF network element of the private network stores the expected response parameter in the 5G home environment authentication vector in association with at least one of the following: The authentication parameters are obtained by acquiring the SUCI carried in the request. The response message carries the SUPI; The intermediate key in the 5G home environment authentication vector.

14. A data acquisition system, characterized in that, include: The AMF network element of the private network is used to request authentication parameters from the UDM network element of the private network in the event of a communication interruption between the private network and the public network. The private network is configured with core network elements for hot backup of authentication-related information in the public network's UDM network elements, and for providing authentication parameters to the private network's AMF network elements in the event of a communication interruption between the private network and the public network. The core network elements of the private network include AMF network elements and UDM network elements. The authentication-related information includes user subscription information and authentication data. The user subscription information is used to determine the first identifier corresponding to the terminal device's home domain, resident area, movement range, and movement frequency. The first identifier is used to identify home domain users, resident users, and low-mobility users, and determines the second identifier of the terminal device based on the principle of prioritizing home domain users, resident users, and low-mobility users. The second identifier is used to indicate the access priority.

15. The system according to claim 14, characterized in that, The AMF network element of the private network is also used to enable the UDM network element of the private network to authenticate terminal devices in the event of a communication interruption between the private network and the public network.

16. The system according to claim 14 or 15, characterized in that, The AMF network element of the private network is specifically used to send a first authentication request to a designated core network element of the private network based on the registration request sent by the terminal device, and to receive a 5G authentication vector sent by the designated core network element of the private network regarding the first authentication request. The core network element of the private network is specifically used to send the 5G authentication vector regarding the first authentication request to the AMF network element of the private network.

17. The system according to claim 16, characterized in that, The core network elements configured for the private network include: The AUSF network element is configured to receive a first authentication request sent by the AMF network element of the private network, and send an authentication parameter acquisition request to the UDM network element of the private network based on the first authentication request; and to construct a 5G authentication vector based on the 5G home environment authentication vector carried in the response message when a response message is received from the UDM network element of the private network, and to send the 5G authentication vector related to the first authentication request to the AMF network element of the private network. The UDM network element is used to construct a 5G home environment authentication vector based on the authentication parameter acquisition request, and send a response message to the AUSF network element of the private network. The response message carries the 5G home environment authentication vector.

18. The system according to claim 16, characterized in that, The AMF network element of the private network is also used for: Generate a security context identifier corresponding to the terminal device; A second authentication request is sent to the terminal device based on the received 5G authentication vector; wherein, The second authentication request carries the security context identifier; the security context identifier is used to indicate that the AMF network element of the private network and the terminal device do not need to re-authenticate when performing data interaction.

19. The system according to claim 17, characterized in that, The authentication parameter acquisition request carries the SUCI of the terminal device, and the response message also carries the SUPI of the terminal device. The AUSF network element of the private network is also used to: send the SUPI of the terminal device to the AMF network element of the private network when the home location authentication of the terminal device is successful; The AMF network element of the private network is also used to: receive the SUPI of the terminal device sent by the designated core network element of the private network.

20. The system according to any one of claims 14 to 19, characterized in that, The system is deployed at edge nodes and / or in the central cloud.

21. The system according to any one of claims 14 to 19, characterized in that, The system also includes a Session Management Function (SFM) network element.

22. An AMF network element for a private network, characterized in that, include: The acquisition unit is used to acquire authentication parameters from designated core network elements of the private network when communication between the private network and the public network is interrupted. The designated core network elements of the private network include AUSF network elements and UDM network elements. The UDM network elements of the private network are used to perform hot backup of authentication-related information in the UDM network elements of the public network and have the ability to authenticate terminal devices. The authentication-related information includes user subscription information and authentication data. The user subscription information is used to determine the first identifier corresponding to the home domain, resident area, movement range, and movement frequency of the terminal device. The first identifier is used to identify home domain users, resident users, and low-mobility users, and determines the second identifier of the terminal device based on the principle of priority for home domain users, priority for resident users, and priority for low-mobility users. The second identifier is used to indicate access priority.

23. A method for configuring core network elements in a private network, characterized in that: include: The backup unit is used to perform hot backup of authentication-related information in the UDM network element of the public network when the communication between the private network and the public network is uninterrupted; the authentication-related information includes user subscription information and authentication data; the user subscription information is used to determine the first identifier corresponding to the home domain, resident area, movement range, and movement frequency of the terminal device; the first identifier is used to identify home domain users, resident users, and low-mobility users, and to determine the second identifier of the terminal device based on the principle of home domain users first, resident users first, and low-mobility users first; The second identifier is used to indicate access priority; The feedback unit is used to feed back authentication parameters to the AMF network element of the private network when the communication between the private network and the public network is interrupted. The core network element of the private network integrates at least the functions of the public network UDM network element and the public network AUSF network element.

24. An edge node, characterized in that, Includes processor and communication interface, among which, The processor is configured to perform at least one of the following: In the event of a communication interruption between the private network and the public network, authentication parameters are obtained from designated core network elements of the private network. These designated core network elements include AUSF elements and UDM elements. The UDM elements of the private network are used to perform hot backup of authentication-related information in the public network's UDM elements and have the capability to authenticate terminal devices. The authentication-related information includes user subscription information and authentication data. The user subscription information is used to determine the first identifier corresponding to the terminal device's home domain, resident area, movement range, and movement frequency. The first identifier is used to identify home domain users, resident users, and low-mobility users, and a second identifier for the terminal device is determined based on the principle of prioritizing home domain users, resident users, and low-mobility users. The second identifier is used to indicate access priority. In the absence of interruption in communication between the private network and the public network, the authentication-related information in the UDM network element of the public network is hot-backed up; and in the absence of interruption in communication between the private network and the public network, the authentication parameters are fed back to the AMF network element of the private network. In the event of a communication interruption between the private network and the public network, authentication-related data obtained from the UDM network element of the private network will be fed back to the AMF network element of the private network.

25. An edge node, characterized in that, This includes a processor and memory for storing computer programs that can run on the processor. When the processor runs the computer program, it performs at least one of the following: The steps of the method according to any one of claims 1 to 6; The steps of the method according to any one of claims 7 to 13.

26. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it performs at least one of the following: The steps of the method according to any one of claims 1 to 6; The steps of the method according to any one of claims 7 to 13.

Citation Information

Patent Citations

  • Data processing method and device

    CN113573346A

  • Apparatus and method for registration on network in wireless communication system

    US20210329583A1

  • A method for authentication a secure element cooperating with a mobile equipment within a terminal in a telecommunication network

    WO2020148397A1