Optimized method, system, and storage medium for application to retrieve ue identifier

The method of synchronously receiving and verifying IP addresses by UDM, converting subscription identifiers and generating external UE identifiers solves the problem of low efficiency in DCAF UE identifier retrieval, improves response speed and reduces latency.

CN116634414BActive Publication Date: 2026-04-07NANJING AIPULU SATELLITE COMMUNICATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-27
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In existing technologies, DCAF is not efficient in retrieving UE identifiers, resulting in slow intelligent analysis speed and increased latency. Asynchronous signaling interaction also increases latency.

Method used

The UDM synchronously receives authentication requests from NEF and AMF, verifies the IP address consistency, converts the subscription hidden identifier into a subscription permanent identifier, generates an external UE identifier in a preset format, and synchronously sends analysis requests to improve efficiency.

Benefits of technology

It improves the response speed of DCAF in obtaining UE identifiers and reduces the latency of network data collection and analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116634414B_ABST
    Figure CN116634414B_ABST
Patent Text Reader

Abstract

This invention discloses an optimized method, system, and storage medium for retrieving UE identifiers by an application. When the DCAF needs to obtain a UE identifier, the UDM simultaneously receives a first authentication request from the NEF (including an analysis ID and a first IP address) and a second authentication request from the AMF (including a subscription hidden identifier and a second IP address). Upon verifying that the first IP address and the second IP address are identical, the UDM converts the subscription hidden identifier into a subscription permanent identifier. After confirming successful UE authentication based on the subscription permanent identifier, the UDM returns authentication response information including the subscription permanent identifier and the analysis ID to the NEF. This allows the NEF to generate an external UE identifier in a preset format based on the subscription permanent identifier and send the external UE identifier to the DCAF. This invention improves response speed and reduces latency by sending requests to different network elements of the 5G core network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of 5G communication network technology, and in particular to an optimized method, system, and storage medium for application retrieval of UE identifiers. Background Technology

[0002] In related technologies, the efficiency of retrieving UE identifiers via DCAF is not high. Currently, DCAF can only obtain the UE's IP address based on packets originating from the source IP address. After DCAF sends the UE's IP address to NEF, NEF obtains the UE's SUPI from BSF. Then, NEF uses UDM to convert the SUPI into an application-specified UE identifier (such as GPSI or other formats). Only then can DCAF obtain the application-specified UE identifier retrieved by NEF. This process affects the speed of intelligent analysis, increasing the latency of network data collection and analysis. Furthermore, existing technologies involve many asynchronous signaling interactions, further increasing latency. Summary of the Invention

[0003] This invention aims to at least solve one of the technical problems existing in the prior art. To this end, this invention proposes an optimized method, system, and storage medium for application programs to retrieve UE identifiers, which can effectively improve response speed and reduce latency.

[0004] On one hand, embodiments of the present invention provide an optimized method for an application to retrieve a UE identifier, comprising the following steps:

[0005] When the DCAF needs to obtain the UE identifier, the UDM synchronously receives a first authentication request sent by the NEF and a second authentication request sent by the AMF. The first authentication request includes the analysis ID and a first IP address, and the second authentication request includes the subscription hidden identifier and a second IP address. The NEF interacts with the DCAF, the AMF interacts with the RAN, and both the DCAF and the RAN interact with the UE.

[0006] When the UDM determines that the first IP address and the second IP address are identical, the UDM converts the subscription hidden identifier into a subscription permanent identifier, and determines that the UE authentication is successful based on the subscription permanent identifier. The UDM then returns authentication response information to the NEF, which includes the subscription permanent identifier and the analysis ID.

[0007] The NEF generates an external UE identifier in a preset format based on the subscription permanent identifier and sends the external UE identifier to the DCAF.

[0008] In some embodiments, when the DCAF needs to obtain the UE identifier, the method further includes the following steps:

[0009] The UE sends a first analysis request to the DCAF, and the DCAF sends a second analysis request to the NEF based on the first analysis request. The first analysis request includes a first IP address, and the second analysis request includes an analysis ID and the first IP address.

[0010] The UE sends a third analysis request to the RAN, and the RAN forwards the third analysis request to the AMF. The third analysis request includes a subscription hidden identifier and a second IP address.

[0011] Specifically, the time when the UE sends the first analysis request to the DCAF is synchronized with the time when the UE sends the third analysis request to the RAN; the time when the DCAF sends the second analysis request to the NEF is synchronized with the time when the RAN forwards the third analysis request to the AMF.

[0012] In some embodiments, the DCAF sends a second analysis request to the NEF based on the first analysis request, including:

[0013] DCAF assigns the analysis ID and the first IP address to form the second analysis request, and sends the second analysis request to the NEF.

[0014] In some embodiments, after determining that UE authentication is successful based on the subscription persistent identifier, the method further includes the following steps:

[0015] The UDM sends an authentication pass message to the AMF.

[0016] In some embodiments, generating an external UE identifier in a preset format based on the subscription permanent identifier includes:

[0017] The subscription permanent identifier is converted into the external UE identifier corresponding to the application.

[0018] On the other hand, embodiments of the present invention provide an optimized system for retrieving UE identifiers by an application, comprising:

[0019] The first module is used to receive, when the DCAF needs to obtain the UE identifier, the UDM synchronously receives a first authentication request sent by the NEF and a second authentication request sent by the AMF. The first authentication request includes an analysis ID and a first IP address, and the second authentication request includes a subscription hidden identifier and a second IP address. The NEF interacts with the DCAF, the AMF interacts with the RAN, and both the DCAF and the RAN interact with the UE.

[0020] The second module is used to convert the subscription hidden identifier into a subscription permanent identifier when the UDM determines that the first IP address and the second IP address are the same, and to determine that the UE authentication is successful based on the subscription permanent identifier, and to return authentication response information to the NEF, wherein the authentication response information includes the subscription permanent identifier and the analysis ID;

[0021] The third module is used by the NEF to generate an external UE identifier in a preset format based on the subscription permanent identifier, and to send the external UE identifier to the DCAF.

[0022] In some embodiments, when the DCAF needs to obtain the UE identifier, the method further includes the following steps:

[0023] The UE sends a first analysis request to the DCAF, and the DCAF sends a second analysis request to the NEF based on the first analysis request. The first analysis request includes a first IP address, and the second analysis request includes an analysis ID and the first IP address.

[0024] The UE sends a third analysis request to the RAN, and the RAN forwards the third analysis request to the AMF. The third analysis request includes a subscription hidden identifier and a second IP address.

[0025] Specifically, the time when the UE sends the first analysis request to the DCAF is synchronized with the time when the UE sends the third analysis request to the RAN; the time when the DCAF sends the second analysis request to the NEF is synchronized with the time when the RAN forwards the third analysis request to the AMF.

[0026] In some embodiments, the DCAF sends a second analysis request to the NEF based on the first analysis request, including:

[0027] DCAF assigns the analysis ID and the first IP address to form the second analysis request, and sends the second analysis request to the NEF.

[0028] On the other hand, embodiments of the present invention provide an optimized system for retrieving UE identifiers by an application, comprising:

[0029] At least one memory for storing programs;

[0030] At least one processor is configured to load the program to execute the optimized method for retrieving the UE identifier from the application.

[0031] On the other hand, embodiments of the present invention provide a computer storage medium storing a computer-executable program, which, when executed by a processor, is used to implement the optimized method for retrieving UE identifiers by the application program.

[0032] The optimized method for retrieving UE identifiers by an application provided in this embodiment of the invention has the following beneficial effects:

[0033] In this embodiment, when the DCAF needs to obtain the UE identifier, the UDM simultaneously receives a first authentication request from the NEF (including an analysis ID and a first IP address) and a second authentication request from the AMF (including a subscription hidden identifier and a second IP address). Upon verifying that the first IP address and the second IP address are identical, the UDM converts the subscription hidden identifier into a subscription permanent identifier. After confirming successful UE authentication based on the subscription permanent identifier, the UDM returns authentication response information including the subscription permanent identifier and the analysis ID to the NEF. This allows the NEF to generate an external UE identifier in a preset format based on the subscription permanent identifier and send the external UE identifier to the DCAF. This embodiment improves response speed by sending requests to different network elements of the 5G core network and improves the efficiency of the DCAF in obtaining the UE identifier by synchronously sending authentication information, thereby reducing latency.

[0034] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0035] The present invention will be further described below with reference to the accompanying drawings and embodiments, wherein:

[0036] Figure 1 This is a flowchart illustrating an optimized method for retrieving a UE identifier by an application according to an embodiment of the present invention;

[0037] Figure 2 This is a schematic diagram illustrating an application scenario of an optimized method for retrieving UE identifiers by an application according to an embodiment of the present invention. Detailed Implementation

[0038] Embodiments of the present invention are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.

[0039] In the description of this invention, it should be understood that the orientation descriptions, such as up, down, front, back, left, right, etc., are based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limiting this invention.

[0040] In the description of this invention, "several" means one or more, "multiple" means two or more, "greater than," "less than," and "exceeding" are understood to exclude the stated number, while "above," "below," and "within" are understood to include the stated number. The use of "first" and "second" in the description is merely for distinguishing technical features and should not be construed as indicating or implying relative importance, or implicitly indicating the number of indicated technical features, or implicitly indicating the order of the indicated technical features.

[0041] In the description of this invention, unless otherwise explicitly defined, terms such as "set up," "install," and "connect" should be interpreted broadly, and those skilled in the art can reasonably determine the specific meaning of the above terms in this invention in conjunction with the specific content of the technical solution.

[0042] In the description of this invention, the terms "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0043] Before describing specific embodiments, the terms used in the embodiments of this application are explained as follows:

[0044] 5GC: 5G Core Network, is the core of the 5G mobile network. It establishes reliable and secure network connections for end users and provides access to their services. The core domain handles various essential functions in the mobile network, such as connectivity and mobility management, authentication and authorization, user data management, and policy management. 5G core network functions are entirely software-based and designed to be cloud-native, meaning they are independent of the underlying cloud infrastructure, enabling greater deployment agility and flexibility.

[0045] AMF stands for Access and Mobility Management Function, which includes functions such as connectivity management, reachability management, mobility management, and access authorization.

[0046] 3GPP stands for 3rd Generation Partnership Project. The goal of 3GPP is to achieve a smooth transition from 2G to 3G networks, ensure backward compatibility of future technologies, and support easy network deployment and roaming and compatibility between systems. Its function is to develop third-generation technology specifications based on the GSM core network and using UTRA as the radio interface. UTRA specifies FDD for W-CDMA technology and TDD for TD-SCDMA technology.

[0047] UE stands for User Equipment. User equipment can be a mobile phone, tablet, laptop, or other device.

[0048] RAN: The full name of the English term is Radio Access Network. It acts as an interface, enabling users to conveniently and economically enjoy various widescreen multimedia information.

[0049] AF: The full name of the English word is Application Function. It refers to various services at the application layer. It can be an application within the operator (similar to the VoLTE AF in 4G) or a third-party AF (such as a video server or a service server). If it is an AF within the operator, it is in the same trusted domain as other NFs and can directly interact and access other NFs. However, a third-party AF is not in the trusted domain and must access other NFs through a NEF.

[0050] NF stands for Network Function.

[0051] DCAF stands for Data Collection Application Function.

[0052] DCCF stands for Data Collection Coordination Function.

[0053] BSF stands for Binding Support Function.

[0054] UDM stands for Unified Data Management, which provides operators with integrated data management for various networking scenarios including 2G, 3G, 4G, and 5G. It has efficient user data processing capabilities, simplifies network setup, is compatible with existing services, can expand 5G services, protects operators' investments, and provides users with the possibility of seamless network switching.

[0055] NEF stands for Network Exposure Function, which is located between the 5G core network and external third-party application functionalities. It manages all external applications that want to access network data exposed to the outside world. External applications wishing to access data within the 5G core network must go through the NEF. The NEF provides corresponding security guarantees to ensure the security of external applications accessing the 3GPP network, offering functions such as external application QoS customization capabilities, mobility state event subscription, and AF request distribution.

[0056] SUPI stands for Subscription Permanent Identifier.

[0057] SUCI: The full English name is Subscription Concealed Identifier.

[0058] S-NSSAI stands for Single Network Slice Selection Assistance Information.

[0059] GPSI stands for Generic Public Subscription Identifier.

[0060] NWDAF: The full English name is Network Data Analytics Function. It is a network element in the 5G core network responsible for providing network analysis services based on network service request data.

[0061] OAM stands for Operation Administration and Maintenance. It refers to the management of network elements, typically categorized into three main areas based on the actual needs of network operation: Operation, Administration, and Maintenance. Operation primarily involves the analysis, forecasting, planning, and configuration of daily network and service operations; Maintenance mainly involves routine operational activities such as testing and fault management of the network and its services.

[0062] In related technologies, due to the rapid development of artificial intelligence, more and more communication scenarios are becoming increasingly intelligent. The newly proposed 5G technology, combined with AI applications, significantly improves the utilization rate of communication resources, providing more possibilities for operators and users, and helping 5G networks ensure better network service quality. Currently, an increasing number of 5G-based intelligent applications are under development and deployment, including vehicle-to-everything (V2X), virtual reality, high-definition live streaming, and intelligent manufacturing. These intelligent application scenarios all rely on the characteristics of 5G technology: high speed and low latency. Therefore, how to reduce the latency of intelligent business processes in 5G and improve the speed of signaling transmission is a crucial problem that needs to be solved.

[0063] NWDAF is a network element with network data analysis capabilities. It automatically senses and analyzes the network based on network data and participates in the entire lifecycle of network planning, construction, operation and maintenance, network optimization, and operation. This makes the network easier to maintain and control, improves the efficiency of network resource utilization, and enhances the user service experience. An artificial intelligence network model is deployed on this network element to collect raw data from NF, AF, and OAM, and intelligently analyze the raw data. The analyzed data is then output to NF, AF, OAM, etc., to optimize the network and services.

[0064] Existing technologies that retrieve UE identifiers via DCAF are not efficient because DCAF can only obtain the UE's IP address based on packets from the source IP address. After DCAF sends the UE's IP address to NEF, NEF obtains the UE's SUPI from BSF. Then, NEF converts the SUPI into an application-specified UE identifier (such as GPSI or other formats) through UDM. Only then can DCAF obtain the application-specified UE identifier retrieved by NEF. This process affects the speed of intelligent analysis and increases the latency of network data collection and analysis. In addition, existing technologies involve many asynchronous signaling interactions, which further increase latency.

[0065] Based on this, refer to Figure 1This invention provides an optimized method for an application to retrieve a UE identifier, including but not limited to the following steps:

[0066] Step S110: When the DCAF needs to obtain the UE identifier, the UDM synchronously receives the first authentication request sent by the NEF and the second authentication request sent by the AMF. The first authentication request includes the analysis ID and the first IP address, and the second authentication request includes the subscription hidden identifier and the second IP address. The NEF interacts with the DCAF, the AMF interacts with the RAN, and both the DCAF and the RAN interact with the UE.

[0067] Step S120: When UDM determines that the first IP address and the second IP address are the same, UDM converts the subscription hidden identifier into a subscription permanent identifier, and determines that the UE authentication is successful based on the subscription permanent identifier, and returns authentication response information to NEF, wherein the authentication response information includes the subscription permanent identifier and the analysis ID;

[0068] Step S130: NEF generates an external UE identifier in a preset format based on the subscription permanent identifier, and sends the external UE identifier to the DCAF.

[0069] In this embodiment, when the DCAF needs to obtain the UE identifier, the UE sends a first analysis request to the DCAF, causing the DCAF to send a second analysis request to the NEF based on the first analysis request. Simultaneously, the UE sends a third analysis request to the RAN, causing the RAN to forward the third analysis request to the AMF. In this embodiment, the first analysis request includes a first IP address, the second analysis request includes an analysis ID and the first IP address, and the third analysis request includes a subscription hidden identifier and a second IP address. The time the UE sends the first analysis request to the DCAF is synchronized with the time the UE sends the third analysis request to the RAN; the time the DCAF sends the second analysis request to the NEF is synchronized with the time the RAN forwards the third analysis request to the AMF. Specifically, the DCAF allocates an analysis ID and a first IP address to form the second analysis request and sends the second analysis request to the NEF.

[0070] In this embodiment, after confirming successful UE authentication based on the subscription permanent identifier, the UDM also sends authentication success information to the AMF to promptly inform the AMF that the UE's authentication has been successful. In this embodiment, when generating an external UE identifier in a preset format based on the subscription permanent identifier, the subscription permanent identifier can be converted into an external UE identifier corresponding to the application.

[0071] Exemplary, the optimized method for application retrieval of UE identifier provided in this application embodiment is... Figure 2In the interactive scenario shown, when the UE initiates an intelligent analysis request to the DCAF, the DCAF only obtains the UE's IP address. Based on the UE's IP address, the DCAF needs to verify the UE's identity information and subscription information. The DCAF needs to interact with multiple network elements to complete these verifications. This embodiment optimizes the DCAF's retrieval of the UE identifier to complete the user authentication process through the following steps:

[0072] Step 1a: The UE sends a first analysis request to the DCAF, wherein the first analysis request carries the UE's IP address, which is referred to as the first IP address.

[0073] Step 1b: The UE sends a third analysis request to the RAN, wherein the third analysis request carries the SUCI and the UE's IP address, and the IP address here is used as the second IP address;

[0074] Step 2a: DCAF sends a second analysis request Nnef_UEId_Get_Request to NEF based on the first analysis request, wherein the second analysis request carries an analysis ID and an IP address;

[0075] Step 2b: The RAN forwards a third analysis request from the UE to the AMF. The third analysis request carries the SUCI and the second IP address.

[0076] Step 3a: NEF sends a first authentication request Nudm_SDM_Get_Request to UDM based on the second analysis request, wherein the first authentication request includes the analysis ID and the first IP address;

[0077] Step 3b: AMF sends a second authentication request to UDM, wherein the second authentication request includes SUCI and a second IP address;

[0078] Step 4: UDM verifies whether the first IP address sent by NEF is consistent with the second IP address sent by AMF. If they are consistent, SUCI is converted to SUPI and UE authentication is performed. After successful authentication, a message of successful authentication is sent back to AMF.

[0079] Step 5: UDM sends an authentication response message Nudm_SDM_Get_Response to NEF, which includes SUPI and analysis ID;

[0080] Step 6: NEF converts SUPI into an application-specific external UE identifier and sends the external UE identifier to DCAF via Nnef_UEId_Get_Response.

[0081] In this process, steps 1a and 1b involve the UE issuing requests synchronously to reduce the waiting latency of signaling interaction. Similarly, steps 2a and 2b are performed simultaneously, as are steps 3a and 3b, to accelerate the efficiency of DCAF in retrieving the UE identifier.

[0082] In this embodiment, the following steps are summarized from the above application scenarios:

[0083] Step 1: The UE simultaneously sends analysis requests to both the RAN and DCAF, including sending the UE IP address to the DCAF and sending the SUCI and UE IP address to the RAN.

[0084] Step 2: After receiving the analysis request message (UE IP address) sent by the UE, the DCAF assigns an analysis ID and sends the analysis ID and the UE IP address to the NEF via Nnef_UEId_Get_Request. At the same time, the RAN forwards the analysis request (SUCI, UE IP address) sent by the UE to the AMF.

[0085] Step 3: After receiving the UE identifier retrieval request from the DCAF, the NEF initiates a request to the UDM to obtain user data, Nudm_SDM_Get_Request (analysis ID, UE IP address). Correspondingly, after receiving the analysis request forwarded by the RAN, the AMF sends an authentication request (SUCI, UE IP address) to the UDM.

[0086] Step 4: UDM authenticates the UE and verifies whether the UE IP sent by NEF is consistent with the UE IP sent by AMF. If they are consistent, UDM converts the UE's SUCI to SUPI to verify the user's identity. After successful verification, UDM sends a successful verification reply to AMF.

[0087] Step 5: UDM returns the requested data type (SUPI, analysis ID) to NEF;

[0088] Step 6: After converting the SUPI into an application-specific external identifier, the NEF sends a reply to the DCAF confirming the successful acquisition of the UE identifier, returning the requested data type (GPSI or other application-specific external identifier).

[0089] As can be seen from the above, this application embodiment improves processing speed by having the UE simultaneously send requests to different network elements of the 5G core network, and associates authentication results with intelligent analysis requests based on the UE IP address, so as to handle the situation where request messages sent by the UE to different network elements do not arrive at the UDM at the same time, thereby effectively reducing latency.

[0090] This invention provides an optimized system for retrieving UE identifiers from applications, comprising:

[0091] The first module is used when the DCAF needs to obtain the UE identifier, the UDM synchronously receives the first authentication request sent by the NEF and the second authentication request sent by the AMF. The first authentication request includes the analysis ID and the first IP address, and the second authentication request includes the subscription hidden identifier and the second IP address. The NEF and DCAF interact, the AMF interacts with the RAN, and both the DCAF and the RAN interact with the UE.

[0092] The second module is used when the UDM determines that the first IP address and the second IP address are the same. The UDM converts the subscription hidden identifier into a subscription permanent identifier, and determines that the UE authentication is successful based on the subscription permanent identifier. The UDM then returns authentication response information to the NEF, which includes the subscription permanent identifier and the analysis ID.

[0093] The third module is used by NEF to generate an external UE identifier in a preset format based on the subscribed permanent identifier, and then send the external UE identifier to DCAF.

[0094] In this embodiment, when the DCAF needs to obtain the UE identifier, the UE sends a first analysis request to the DCAF, causing the DCAF to send a second analysis request to the NEF based on the first analysis request. Simultaneously, the UE sends a third analysis request to the RAN, causing the RAN to forward the third analysis request to the AMF. In this embodiment, the first analysis request includes a first IP address, the second analysis request includes an analysis ID and the first IP address, and the third analysis request includes a subscription hidden identifier and a second IP address. The time the UE sends the first analysis request to the DCAF is synchronized with the time the UE sends the third analysis request to the RAN; the time the DCAF sends the second analysis request to the NEF is synchronized with the time the RAN forwards the third analysis request to the AMF. Specifically, the DCAF allocates an analysis ID and a first IP address to form the second analysis request and sends the second analysis request to the NEF.

[0095] The content of the method embodiments of the present invention is applicable to the system embodiments. The specific functions implemented in the system embodiments are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods.

[0096] This invention provides an optimized system for retrieving UE identifiers from applications, comprising:

[0097] At least one memory for storing programs;

[0098] At least one processor is used to load the program for execution. Figure 1 The example shown is an optimized method for retrieving UE identifiers from applications.

[0099] The content of the method embodiments of the present invention is applicable to the system embodiments. The specific functions implemented in the system embodiments are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods.

[0100] This invention provides a computer storage medium storing a computer-executable program, which, when executed by a processor, is used to implement... Figure 1 The example shown is an optimized method for retrieving UE identifiers from applications.

[0101] The content of the method embodiments of the present invention is applicable to the storage medium embodiments. The specific functions implemented by the storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods.

[0102] Furthermore, embodiments of the present invention also provide a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to perform... Figure 1 The example shown is an optimized method for retrieving UE identifiers from applications.

[0103] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the above embodiments, and various changes can be made within the scope of knowledge possessed by those skilled in the art without departing from the spirit of the present invention. Furthermore, the embodiments of the present invention and the features thereof can be combined with each other unless otherwise specified.

Claims

1. An optimized method for retrieving UE identifiers by an application, characterized in that, Includes the following steps: When the DCAF needs to obtain the UE identifier, the UDM synchronously receives a first authentication request sent by the NEF and a second authentication request sent by the AMF. The first authentication request includes the analysis ID and a first IP address, and the second authentication request includes the subscription hidden identifier and a second IP address. The NEF interacts with the DCAF, the AMF interacts with the RAN, and both the DCAF and the RAN interact with the UE. When the UDM determines that the first IP address and the second IP address are identical, the UDM converts the subscription hidden identifier into a subscription permanent identifier, and determines that the UE authentication is successful based on the subscription permanent identifier. The UDM then returns authentication response information to the NEF, which includes the subscription permanent identifier and the analysis ID. The NEF generates an external UE identifier in a preset format based on the subscription permanent identifier, and sends the external UE identifier to the DCAF; When the DCAF needs to obtain the UE identifier, the method further includes the following steps: The UE sends a first analysis request to the DCAF, and the DCAF sends a second analysis request to the NEF based on the first analysis request. The first analysis request includes a first IP address, and the second analysis request includes an analysis ID and the first IP address. The UE sends a third analysis request to the RAN, and the RAN forwards the third analysis request to the AMF. The third analysis request includes a subscription hidden identifier and a second IP address. Specifically, the time when the UE sends the first analysis request to the DCAF is synchronized with the time when the UE sends the third analysis request to the RAN; the time when the DCAF sends the second analysis request to the NEF is synchronized with the time when the RAN forwards the third analysis request to the AMF.

2. The optimized method for retrieving UE identifiers by an application program according to claim 1, characterized in that, The DCAF sends a second analysis request to the NEF based on the first analysis request, including: DCAF assigns the analysis ID and the first IP address to form the second analysis request, and sends the second analysis request to the NEF.

3. The optimized method for retrieving UE identifiers by an application according to claim 1, characterized in that, After determining that UE authentication is successful based on the subscription permanent identifier, the method further includes the following steps: The UDM sends an authentication pass message to the AMF.

4. The optimized method for retrieving UE identifiers by an application program according to claim 1, characterized in that, The step of generating an external UE identifier in a preset format based on the subscription permanent identifier includes: The subscription permanent identifier is converted into the external UE identifier corresponding to the application.

5. An optimized system for retrieving UE identifiers from an application, characterized in that, include: The first module is used to receive a first authentication request sent by NEF and a second authentication request sent by AMF when DCAF needs to obtain UE identifier. The first authentication request includes analysis ID and first IP address. The second authentication request includes subscription hidden identifier and second IP address. The NEF interacts with the DCAF, the AMF interacts with the RAN, and both the DCAF and the RAN interact with the UE. The second module is used to convert the subscription hidden identifier into a subscription permanent identifier when the UDM determines that the first IP address and the second IP address are the same, and to determine that the UE authentication is successful based on the subscription permanent identifier, and to return authentication response information to the NEF, wherein the authentication response information includes the subscription permanent identifier and the analysis ID; The third module is used by the NEF to generate an external UE identifier in a preset format based on the subscription permanent identifier, and to send the external UE identifier to the DCAF; When the DCAF needs to obtain the UE identifier, the first module is also used to perform the following steps: The UE sends a first analysis request to the DCAF, and the DCAF sends a second analysis request to the NEF based on the first analysis request. The first analysis request includes a first IP address, and the second analysis request includes an analysis ID and the first IP address. The UE sends a third analysis request to the RAN, and the RAN forwards the third analysis request to the AMF. The third analysis request includes a subscription hidden identifier and a second IP address. Specifically, the time when the UE sends the first analysis request to the DCAF is synchronized with the time when the UE sends the third analysis request to the RAN; the time when the DCAF sends the second analysis request to the NEF is synchronized with the time when the RAN forwards the third analysis request to the AMF.

6. An optimized system for retrieving UE identifiers from an application program according to claim 5, characterized in that, The DCAF sends a second analysis request to the NEF based on the first analysis request, including: DCAF assigns the analysis ID and the first IP address to form the second analysis request, and sends the second analysis request to the NEF.

7. An optimized system for retrieving UE identifiers from an application, characterized in that, include: At least one memory for storing programs; At least one processor is configured to load the program to execute the optimized method for retrieving the UE identifier by an application as described in any one of claims 1-4.

8. A computer storage medium, characterized in that, It contains a computer-executable program, which, when executed by a processor, is used to implement the optimized method for retrieving the UE identifier by an application program as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Subscription concealed identifier

    CN111133728A

  • Privacy protection method and device for terminal, and terminal

    CN112866988A