User equipment roaming method, electronic equipment and storage medium based on SNPN private network

By introducing the secure edge protection proxy function SEPP network element between 5G private networks, the problem of user equipment roaming between different SNPN private networks is solved, achieving secure roaming and improved data security.

CN117580025BActive Publication Date: 2025-09-23IPLOOK NETWORKS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311517026.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-14
Publication Date
2025-09-23
Estimated Expiration
2043-11-14

AI Technical Summary

Technical Problem

Current 5G private network technology does not define a method for user devices to roam between different SNPN private networks, resulting in insufficient data security and interoperability.

Method used

By introducing the secure edge protection proxy function SEPP network element between the SNPN private network, secure interconnection between the first third-party certificate holder and the second third-party certificate holder is achieved, and the SEPP network element is used for signaling interaction and topology hiding to ensure data security.

Benefits of technology

It enables secure roaming of user devices between different SNPN private networks, improves data security and interoperability, and ensures security protection during signaling interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117580025B_ABST
    Figure CN117580025B_ABST
Patent Text Reader

Abstract

The present application provides a user equipment roaming method, electronic device, and storage medium based on an SNPN private network, wherein the user equipment roaming method includes: when a user equipment UE of a first SNPN private network initiates a PDU session request through a network function NF network element of the first SNPN private network, searching for a network register function NRF network element of a second first SNPN private network through a network register function NRF network element of the first SNPN private network, a network register function NRF network element of a first third-party certificate holder, and a network register function NRF network element of a second third-party certificate holder, so that the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network; the user equipment UE of the first SNPN private network performs signaling interaction with the second SNPN private network based on the network element address of the second SNPN private network. The present application can realize CH interconnection and terminal roaming between SNPNs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of 5G technology, and more specifically, to a user equipment roaming method, electronic device, and storage medium based on an SNPN private network. Background Art

[0002] With the in-depth development of 5G technology and the in-depth exploration of its applications across various industries, 5G will continue to integrate closely with various vertical industries. Due to the diverse business scenarios, terminal form factors, high data confidentiality requirements, and exclusive customer resources in various vertical industries, the demand for non-public network (NPN) networks will continue to increase in pursuit of more reliable and tailored solutions to various industry needs (such as industrial control in manufacturing and smart healthcare in healthcare).

[0003] However, in the current 5G private network technology, there is no defined method for CH interconnection and terminal roaming between SNPNs. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide a user equipment roaming method, electronic device and storage medium based on an SNPN private network, so as to realize CH interconnection and terminal roaming between SNPNs.

[0005] In a first aspect, the present invention provides a user equipment roaming method based on an SNPN private network, the method applying the SNPN private network communication system, the SNPN private network communication system including a first SNPN private network, a second SNPN private network, a first third-party certificate holder, and a second third-party certificate holder, the first SNPN private network being communicated with the first third-party certificate holder through an N32 interface, the second SNPN private network being communicated with the second third-party certificate holder through an N32 interface, the first third-party certificate holder being communicated with the second third-party certificate holder through an N32 interface, the first SNPN private network, the second SNPN private network, the first third-party certificate holder, and the second third-party certificate holder being all deployed with a security edge protection proxy function SEPP network element and a network register function NRF network element, the network register function NRF network element being used to discover an external network, and the N32 interface being a control plane interface between the security edge protection proxy function SEPP network elements;

[0006] When the user equipment UE of the first SNPN private network initiates a PDU session request through the network function NF network element of the first SNPN private network, the network register function NRF network element of the second first SNPN private network is found through the network register function NRF network element of the first SNPN private network, the network register function NRF network element of the first third-party certificate holder, and the network register function NRF network element of the second third-party certificate holder, so that the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network.

[0007] This application can realize the secure interconnection between the first third-party certificate holder and the second third-party certificate holder through the security edge protection proxy function SEPP network element, and then realize the interconnection between the first third-party certificate holder and the second third-party certificate holder, and finally realize the roaming of the user equipment between the two SNPN private networks, that is, the user equipment can initiate a PDU session request through the network function NF network element of the first SNPN private network, and the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network, wherein the security edge protection proxy function SEPP network element can perform security protection and topology hiding, and then during signaling interaction, the signaling needs to pass through multiple layers of security edge protection proxy function SEPP network elements, thereby improving data security.

[0008] In an optional embodiment, before searching for the network register function NRF network element of the second first SNPN private network through the network register function NRF network element of the first SNPN private network, the network register function NRF network element of the first third-party credential holder, and the network register function NRF network element of the second third-party credential holder, the method further includes:

[0009] The network function NF network element of the first SNPN private network initiates a subscription data acquisition request to the first third-party certificate holder, so that the first third-party certificate holder returns the subscription data of the user equipment UE of the first SNPN private network;

[0010] The network function NF network element of the first SNPN private network verifies the subscription data of the user equipment UE of the first SNPN private network.

[0011] This optional implementation manner can verify the subscription data of the user equipment UE of the first SNPN private network through the network function NF network element of the first SNPN private network to achieve identity authentication of the user equipment UE.

[0012] In an optional implementation manner, the first third-party credential holder is further deployed with a rights management network element, and the rights management network element of the first third-party credential holder is configured to receive the subscription data acquisition request and return the subscription data of the user equipment UE of the first SNPN private network.

[0013] This optional implementation method can receive the contract data through the rights management network element.

[0014] In an optional implementation manner, the authority management network element of the first third-party credential holder is one of a unified data management function UDM network element and an authentication service function AUSF network element.

[0015] In an optional embodiment, the method further comprises:

[0016] The unified data management function UDM network element or the authentication service function AUSF network element receives a registration request of the user equipment UE of the first SNPN private network, and generates subscription data of the user equipment UE of the first SNPN private network based on the registration request.

[0017] In this optional implementation mode, you can receive a registration request of the user equipment UE of the first SNPN private network based on the unified data management function UDM network element or the authentication service function AUSF network element, and generate the subscription data of the user equipment UE of the first SNPN private network based on the registration request.

[0018] In an optional embodiment, the network function NF network element of the first SNPN private network includes an access mobility management function AMF network element, wherein the session management function SMF network element is used to receive a PDU session request sent by a user equipment UE of the first SNPN private network, and manage the session of the user equipment UE of the first SNPN private network.

[0019] This optional implementation manner can receive the PDU session request sent by the user equipment UE of the first SNPN private network through the session management function SMF network element, and manage the session of the user equipment UE of the first SNPN private network.

[0020] In an optional implementation, the network function NF network element of the first SNPN private network also includes a session management function SMF network element, and the mobility management function AMF network element is used to verify the subscription data of the user equipment UE of the first SNPN private network.

[0021] This optional implementation method can verify the contract data of the user equipment UE of the first SNPN private network through the mobility management function AMF network element.

[0022] In an optional implementation, the network register function NRF network element of the first SNPN private network discovers the authority management network element of the first third-party certificate holder and returns the network element address of the authority management network element of the first third-party certificate holder, so that the user equipment UE of the first SNPN private network initiates the registration request based on the network element of the authority management network element of the first third-party certificate holder.

[0023] This optional implementation method can discover the authority management network element of the first third-party certificate holder through the network register function NRF network element of the first SNPN private network, and return the network element address of the authority management network element of the first third-party certificate holder, so that the user equipment UE of the first SNPN private network initiates the registration request based on the network element of the authority management network element of the first third-party certificate holder.

[0024] In a second aspect, the present invention provides an electronic device, comprising:

[0025] processor; and

[0026] The memory is configured to store machine-readable instructions, which, when executed by the processor, execute the user equipment roaming method based on the SNPN private network as described in any one of the aforementioned implementations.

[0027] The electronic device of the present application can realize the secure interconnection between the first third-party certificate holder and the second third-party certificate holder through the security edge protection proxy function SEPP network element by executing the user device roaming method based on the SNPN private network, and then realize the interconnection of the two SNPN private networks through the interconnection between the first third-party certificate holder and the second third-party certificate holder, and finally realize the roaming of the user device between the two SNPN private networks, that is, the user device can initiate a PDU session request through the network function NF network element of the first SNPN private network, and the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user device UE of the first SNPN private network, wherein the security edge protection proxy function SEPP network element can perform security protection and topology hiding, and then during signaling interaction, the signaling needs to pass through multiple layers of security edge protection proxy function SEPP network elements, thereby improving data security.

[0028] In a third aspect, the present invention provides a storage medium storing a computer program, wherein the computer program is executed by a processor to implement a user equipment roaming method based on an SNPN private network as described in any one of the aforementioned implementations.

[0029] The storage medium of the present application can realize the secure interconnection between the first third-party certificate holder and the second third-party certificate holder through the security edge protection proxy function SEPP network element by executing the user equipment roaming method based on the SNPN private network, and then realize the interconnection of the two SNPN private networks through the interconnection between the first third-party certificate holder and the second third-party certificate holder, and finally realize the roaming of the user equipment between the two SNPN private networks, that is, the user equipment can initiate a PDU session request through the network function NF network element of the first SNPN private network, and the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network, wherein the security edge protection proxy function SEPP network element can perform security protection and topology hiding, and then during signaling interaction, the signaling needs to pass through multiple layers of security edge protection proxy function SEPP network elements, thereby improving data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0031] Figure 1 This is a flowchart of a method for roaming a user device based on an SNPN private network disclosed in an embodiment of the present application;

[0032] Figure 2 This is a schematic diagram of the architecture of an SNPN private network communication system disclosed in an embodiment of the present application;

[0033] Figure 3 This is a schematic diagram of the architecture of another SNPN private network communication system disclosed in an embodiment of the present application;

[0034] Figure 4 This is a schematic diagram of a process disclosed in an embodiment of the present application for a roaming SNPN B network element to discover CH Y, a home SNPN A network element and its CH X;

[0035] Figure 5 This is a schematic diagram of another process disclosed in an embodiment of the present application for a roaming SNPN B network element to discover CH Y, a home SNPN A network element and its CH X;

[0036] Figure 6 This is a schematic diagram of a user equipment UE roaming between SNPNs disclosed in an embodiment of the present application;

[0037] Figure 7This is a structural diagram of an electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION

[0038] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0039] Implementation

[0040] See also Figure 1 , Figure 1 This is a flow chart of a user equipment roaming method based on an SNPN private network disclosed in an embodiment of the present application, wherein the method is applied to an SNPN private network communication system, including a first SNPN private network, a second SNPN private network, a first third-party certificate holder, and a second third-party certificate holder. The first SNPN private network is connected to the first third-party certificate holder through an N32 interface, and the second SNPN private network is connected to the second third-party certificate holder through an N32 interface. The first third-party certificate holder is connected to the second third-party certificate holder through an N32 interface. The first SNPN private network, the second SNPN private network, the first third-party certificate holder, and the second third-party certificate holder are all deployed with a security edge protection proxy function SEPP network element and a network register function NRF network element. The network register function NRF network element is used to discover external networks, and the N32 interface is a control plane interface between security edge protection proxy function SEPP network elements. Figure 1 As shown, the method of the embodiment of the present application includes the following steps:

[0041] 101. When the user equipment UE of the first SNPN private network initiates a PDU session request through the network function NF network element of the first SNPN private network, the network register function NRF network element of the second first SNPN private network is found through the network register function NRF network element of the first SNPN private network, the network register function NRF network element of the first third-party certificate holder, and the network register function NRF network element of the second third-party certificate holder, so that the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network;

[0042] 102. The user equipment UE of the first SNPN private network performs signaling interaction with the second SNPN private network based on the network element address of the second SNPN private network.

[0043] The embodiment of the present application can realize secure interconnection between the first third-party certificate holder and the second third-party certificate holder through the security edge protection proxy function SEPP network element, and then realize the interconnection of the two SNPN private networks through the interconnection between the first third-party certificate holder and the second third-party certificate holder, and finally realize roaming of the user equipment between the two SNPN private networks, that is, the user equipment can initiate a PDU session request through the network function NF network element of the first SNPN private network, and the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network, wherein the security edge protection proxy function SEPP network element can perform security protection and topology hiding, and then during signaling interaction, the signaling needs to pass through multiple layers of security edge protection proxy function SEPP network elements, thereby improving data security.

[0044] In the embodiment of the present application, specifically, the interconnection topology of the first SNPN private network, the second SNPN private network, the first third-party certificate holder, and the second third-party certificate holder can be found in FIG. Figure 2 ,in, Figure 2 This is a schematic diagram of the architecture of a SNPN private network communication system disclosed in the embodiment of this application. Figure 2 As shown, the first SNPN private network is connected to the first third-party certificate holder through the N32 interface, the second SNPN private network is connected to the second third-party certificate holder through the N32 interface, and the first third-party certificate holder is connected to the second third-party certificate holder through the N32 interface. The first SNPN private network, the second SNPN private network, the first third-party certificate holder and the second third-party certificate holder are all deployed with security edge protection proxy function SEPP network elements and network register function NRF network elements. The network register function NRF network element is used to discover external networks, and the N32 interface is the control plane interface between the security edge protection proxy function SEPP network elements.

[0045] In the embodiments of this application, please refer to Figure 3 , Figure 3 This is a schematic diagram of the architecture of another SNPN private network communication system disclosed in the embodiment of this application. Figure 3As shown, the first SNPN private network is connected to the first third-party certificate holder through the N32 interface, the second SNPN private network is connected to the second third-party certificate holder through the N32 interface, and the first third-party certificate holder is connected to the second third-party certificate holder through the N32 interface. The first SNPN private network, the second SNPN private network, the first third-party certificate holder and the second third-party certificate holder are all deployed with a security edge protection proxy function SEPP network element and a network register function NRF network element. The network register function NRF network element is used to discover external networks, and the N32 interface is the control plane interface between the security edge protection proxy function SEPP network elements. In addition, in this system, the SNPN private network also includes a DN (Data Network) network element. It should be noted that Figure 2 It is built based on the LBO (Local Breakout) framework of the existing 5G network. Figure 3 It is built based on the HR framework of the existing 5G network. For the differences in principle between the LBO framework and the HR framework, please refer to the prior art, and this embodiment of the present application will not go into details.

[0046] In the embodiment of the present application, the user equipment UE of the first SNPN private network may be a mobile device joined to the first SNPN private network, such as a mobile phone.

[0047] In the embodiments of this application, SNPN refers to Software-Defined Networking (SDN) for 5G CoreNetworks (SNPN), which is an independent non-public network in Chinese. For a detailed description, please refer to the prior art. In the embodiments of this application, SEPP refers to Security Edge Protection Proxy, which is a security edge protection proxy function in Chinese. For a detailed description, please refer to the prior art.

[0048] In the embodiment of the present application, PDU refers to Protocol Data Unit, which is also known as Protocol Data Unit in Chinese.

[0049] In the embodiment of the present application, UE refers to User Equipment. In an optional implementation manner, before finding the network register function NRF network element of the second first SNPN private network through the network register function NRF network element of the first SNPN private network, the network register function NRF network element of the first third-party certificate holder, and the network register function NRF network element of the second third-party certificate holder, the method of the embodiment of the present application further includes the following steps:

[0050] The network function NF of the first SNPN private network initiates a subscription data acquisition request to the first third-party certificate holder, so that the first third-party certificate holder returns the subscription data of the user equipment UE of the first SNPN private network;

[0051] The network function NF network element of the first SNPN private network verifies the subscription data of the user equipment UE of the first SNPN private network.

[0052] This optional implementation manner can verify the subscription data of the user equipment UE of the first SNPN private network through the network function NF network element of the first SNPN private network to achieve identity authentication of the user equipment UE.

[0053] In an optional implementation manner, the first third-party credential holder is further deployed with a rights management network element, and the rights management network element of the first third-party credential holder is configured to receive a subscription data acquisition request and return subscription data of the user equipment UE of the first SNPN private network.

[0054] This optional implementation method can receive the contract data through the rights management network element.

[0055] In an optional implementation manner, the rights management network element of the first third-party credential holder is one of a unified data management function UDM network element and an authentication service function AUSF network element.

[0056] In an optional embodiment, the method of the embodiment of the present application further includes the following steps:

[0057] The unified data management function UDM network element or the authentication service function AUSF network element receives a registration request of the user equipment UE of the first SNPN private network, and generates subscription data of the user equipment UE of the first SNPN private network based on the registration request.

[0058] In this optional implementation mode, you can receive a registration request of the user equipment UE of the first SNPN private network based on the unified data management function UDM network element or the authentication service function AUSF network element, and generate the subscription data of the user equipment UE of the first SNPN private network based on the registration request.

[0059] In an optional embodiment, the network function NF network element of the first SNPN private network includes an access mobility management function AMF network element, wherein the session management function SMF network element is used to receive a PDU session request sent by a user equipment UE of the first SNPN private network, and manage the session of the user equipment UE of the first SNPN private network.

[0060] This optional implementation manner can receive the PDU session request sent by the user equipment UE of the first SNPN private network through the session management function SMF network element, and manage the session of the user equipment UE of the first SNPN private network.

[0061] In an optional implementation, the network function NF network element of the first SNPN private network also includes a session management function SMF network element, and the mobility management function AMF network element is used to verify the subscription data of the user equipment UE of the first SNPN private network.

[0062] This optional implementation method can verify the contract data of the user equipment UE of the first SNPN private network through the mobility management function AMF network element.

[0063] In an optional implementation, the network register function NRF network element of the first SNPN private network discovers the authority management network element of the first third-party certificate holder and returns the network element address of the authority management network element of the first third-party certificate holder, so that the user equipment UE of the first SNPN private network initiates a registration request based on the network element of the authority management network element of the first third-party certificate holder.

[0064] This optional implementation method can discover the authority management network element of the first third-party certificate holder through the network register function NRF network element of the first SNPN private network, and return the network element address of the authority management network element of the first third-party certificate holder, so that the user equipment UE of the first SNPN private network initiates a registration request based on the network element of the authority management network element of the first third-party certificate holder.

[0065] For the embodiment of this application, as an example, please refer to Figure 4 and Figure 5 ,in, Figure 4 This is a schematic diagram of a process in which a roaming SNPN B network element discovers CH Y, a home SNPN A network element, and its CH X, disclosed in an embodiment of the present application. Figure 5 This is a schematic diagram of another process disclosed in an embodiment of the present application for a roaming SNPN B network element to discover CH Y, a home SNPN A network element and its CH X, wherein SNPN A refers to a first SNPN private network, SNPN B refers to a second SNPN private network, CHX refers to a first third-party certificate holder, and CHY refers to a second third-party certificate holder. Figure 4 As shown, there are:

[0066] Interconnection between SNPN and CH:

[0067] 1a. Establish an N32 connection between SEPP B and SEPP Y;

[0068] 2a. Establish N32 connection between SEPP Y and SEPP X;

[0069] 3a. Establish an N32 connection between SEPP X and SEPP A;

[0070] The network element in SNPN B discovers AUSF / DUM in CH Y:

[0071] 2. The network element in SNPN B discovers the AUSF / UDM Y network element in CH Y from NRF B

[0072] 3. NRF B finds the peer NRF Y through the N32 connection between SEPP B and SEPP Y, and then finds AUSF / UDM Y through NRF Y

[0073] 4. SEPP B sends the signaling request to SEPP Y via N32

[0074] 5. SEPP Y finds and discovers AUSF / UDM Y through NRF Y

[0075] 6. NRF Y discovered AUSF / UDM Y

[0076] 7.AUSF / UDM Y returns the network element address

[0077] 8-11. Return the AUSF / UDM Y address to the network element in SNPN B via the path in 2-7. The network element in SNPN B discovers the AUSF / UDM in CH X:

[0078] 12. The network element in SNPN B discovers the AUSF / UDM X network element in CH X from NRF B;

[0079] 13. NRF B finds the peer NRF Y through the N32 connection between SEPP B and SEPP Y;

[0080] 14. SEPP B sends a signaling request to SEPP Y via N32.

[0081] 15. SEPP Y finds and discovers AUSF / UDM X in CH X through NRF Y;

[0082] 16. NRF Y finds the peer NRF X through the N32 connection between SEPP Y and SEPP X, and then finds AUSF / UDM X through NRF X;

[0083] 17. SEPP Y sends a signaling request to SEPP X via N32.

[0084] 18. SEPP X finds and discovers AUSF / UDM X through NRF X;

[0085] 19. NRF X discovered AUSF / UDM X;

[0086] 20.AUSF / UDM X returns the network element address;

[0087] 21-27. Return the AUSF / UDM Y address to the network element in SNPN B via the path in 12-20.

[0088] Further, if Figure 5 As shown, there are:

[0089] The network element in SNPN B discovers the network element in SNPN A:

[0090] 28. The network elements in SNPN B discover the network elements in SNPN A from NRF B.

[0091] 29. NRF B finds the peer NRF Y through the N32 connection between SEPP B and SEPP Y

[0092] 30. SEPP B sends the signaling request to SEPP Y via N32

[0093] 31. SEPP Y finds and discovers the network elements in SNPN A through NRF Y

[0094] 32. NRF Y finds the peer NRF X through the N32 connection between SEPP Y and SEPP X, and then finds the network elements in SNPN A through NRF X

[0095] 33. SEPP Y sends the signaling request to SEPP X via N32

[0096] 34.SEPP X finds and discovers the network elements in SNPN A through NRF X

[0097] 35. NRF X finds the peer NRF A through the N32 connection between SEPP X and SEPP A, and then finds the network elements in SNPN A through NRF A

[0098] 36. SEPP X sends the signaling request to SEPP A via N32

[0099] 37. SEPP A finds and discovers the network elements in SNPN A through NRF A;

[0100] 38.NRF A discovers network elements in SNPN A

[0101] 39-49. The address of the network element in SNPN A is returned to the network element in SNPN B through the path in 28-38. The signaling between the two SNPN private networks and the corresponding CHs is transmitted through N32 established between SEPPs. The process will pass through multiple layers of SEPPs to provide topological protection for both SNPN private networks and the corresponding CHs to ensure security.

[0102] Further, see Figure 6 , Figure 6 This is a schematic diagram of a user equipment UE roaming between SNPNs disclosed in an embodiment of the present application. Figure 6 As shown, there are:

[0103] 1. The UE initiates a registration request or a PDU session establishment request. 2. The network element in SNPN B transmits signaling via the N32 connection between SEPPs. 3. SEPP B transmits signaling to SEPP Y via N32. 4. SEPP Y transmits signaling to SEPPX via N32. 5. The AUSF / UDM receives signaling initiated by the network element in SNPN A. 6-10. The signaling data is returned via the path in 1-5.

[0104] 11. The network elements in SNPN B exchange signaling via the N32 connection between SEPPs;

[0105] 12. SEPP B transmits signaling to SEPP Y via N32;

[0106] 13. SEPP Y transmits signaling to SEPP X via N32;

[0107] 14. SEPP X transmits signaling to SEPP A via N32;

[0108] 15. The network element in SNPN A receives the signaling sent by the network element in SNPN B;

[0109] 16. Signaling data is returned via the path in steps 11-15 for signaling exchange. Signaling exchanges between the home SNPN A and the roaming SNPN B must pass through N32 between SEPPs. Both the SNPN and the CH must be deployed according to the 5G SA architecture and comply with inter-network roaming protocols.

[0110] Example 2

[0111] See also Figure 7 , Figure 7 is a structural diagram of an electronic device disclosed in an embodiment of the present application, such as Figure 7 Shown, including:

[0112] Processor 201; and

[0113] The memory 202 is configured to store machine-readable instructions. When the instructions are executed by the processor 201, the method for user equipment roaming based on the SNPN private network as described in any one of the aforementioned embodiments is executed.

[0114] The electronic device of the embodiment of the present application can realize the secure interconnection between the first third-party certificate holder and the second third-party certificate holder through the security edge protection proxy function SEPP network element by executing the user device roaming method based on the SNPN private network, and then realize the interconnection of the two SNPN private networks through the interconnection between the first third-party certificate holder and the second third-party certificate holder, and finally realize the roaming of the user device between the two SNPN private networks, that is, the user device can initiate a PDU session request through the network function NF network element of the first SNPN private network, and the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user device UE of the first SNPN private network, wherein the security edge protection proxy function SEPP network element can perform security protection and topology hiding, and then during signaling interaction, the signaling needs to pass through multiple layers of security edge protection proxy function SEPP network elements, thereby improving data security.

[0115] Example 3

[0116] An embodiment of the present application provides a storage medium storing a computer program, and the computer program is executed by a processor as a user equipment roaming method based on an SNPN private network as described in any of the aforementioned implementations.

[0117] The storage medium of the present application can realize the secure interconnection between the first third-party certificate holder and the second third-party certificate holder through the security edge protection proxy function SEPP network element by executing the user equipment roaming method based on the SNPN private network, and then realize the interconnection of the two SNPN private networks through the interconnection between the first third-party certificate holder and the second third-party certificate holder, and finally realize the roaming of the user equipment between the two SNPN private networks, that is, the user equipment can initiate a PDU session request through the network function NF network element of the first SNPN private network, and the network register function NRF network element of the second SNPN private network returns the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network, wherein the security edge protection proxy function SEPP network element can perform security protection and topology hiding, and then during signaling interaction, the signaling needs to pass through multiple layers of security edge protection proxy function SEPP network elements, thereby improving data security.

[0118] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or network elements can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.

[0119] In addition, the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0120] Furthermore, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0121] It should be noted that if the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0122] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any actual relationship or order between these entities or operations.

[0123] The above are merely examples of the present application and are not intended to limit the scope of protection of the present application. Those skilled in the art will appreciate that various modifications and variations are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of protection of the present application.

Claims

1. A roaming method for user equipment based on SNPN private network, characterized in that: The method applies the SNPN private network communication system, which includes a first SNPN private network, a second SNPN private network, a first third-party credential holder, and a second third-party credential holder. The first SNPN private network is connected to the first third-party credential holder through an N32 interface, and the second SNPN private network is connected to the second third-party credential holder through an N32 interface. The first third-party credential holder is connected to the second third-party credential holder through an N32 interface. The first SNPN private network, the second SNPN private network, the first third-party credential holder, and the second third-party credential holder are all deployed with a security edge protection proxy function SEPP network element and a network register function NRF network element. The network register function NRF network element is used to discover an external network. The N32 interface is a control plane interface between the security edge protection proxy function SEPP network elements. When the user equipment UE of the first SNPN private network initiates a PDU session request through the network function NF network element of the first SNPN private network, the network register function NRF network element of the first SNPN private network, the network register function NRF network element of the first third-party certificate holder, and the network register function NRF network element of the second third-party certificate holder are found to enable the network register function NRF network element of the second SNPN private network to return the network element address of the second SNPN private network to the user equipment UE of the first SNPN private network; The user equipment UE of the first SNPN private network performs signaling interaction with the second SNPN private network based on the network element address of the second SNPN private network.

2. The method according to claim 1, wherein Before searching for the network register function NRF network element of the second SNPN private network through the network register function NRF network element of the first SNPN private network, the network register function NRF network element of the first third-party certificate holder, and the network register function NRF network element of the second third-party certificate holder, the method further includes: The network function NF network element of the first SNPN private network initiates a subscription data acquisition request to the first third-party certificate holder, so that the first third-party certificate holder returns the subscription data of the user equipment UE of the first SNPN private network; The network function NF network element of the first SNPN private network verifies the subscription data of the user equipment UE of the first SNPN private network.

3. The method according to claim 2, wherein The first third-party certificate holder is further deployed with a rights management network element, and the rights management network element of the first third-party certificate holder is used to receive the subscription data acquisition request and return the subscription data of the user equipment UE of the first SNPN private network.

4. The method according to claim 3, wherein The authority management network element of the first third-party certificate holder is one of a unified data management function UDM network element and an authentication service function AUSF network element.

5. The method according to claim 4, wherein The method further comprises: The unified data management function UDM network element or the authentication service function AUSF network element receives a registration request of the user equipment UE of the first SNPN private network, and generates subscription data of the user equipment UE of the first SNPN private network based on the registration request.

6. The method according to claim 4, wherein The network function NF network element of the first SNPN private network includes a session management function SMF network element, wherein the session management function SMF network element is used to receive a PDU session request sent by a user equipment UE of the first SNPN private network and manage the session of the user equipment UE of the first SNPN private network.

7. The method according to claim 6, wherein The network function NF network element of the first SNPN private network also includes a mobility management function AMF network element, and the mobility management function AMF network element is used to verify the subscription data of the user equipment UE of the first SNPN private network.

8. The method according to claim 5, wherein The network register function NRF network element of the first SNPN private network discovers the authority management network element of the first third-party certificate holder and returns the network element address of the authority management network element of the first third-party certificate holder, so that the user equipment UE of the first SNPN private network initiates the registration request based on the network element of the authority management network element of the first third-party certificate holder.

9. An electronic device, characterized in that: include: processor; as well as The memory is configured to store machine-readable instructions, which, when executed by the processor, execute the user equipment roaming method based on the SNPN private network according to any one of claims 1 to 8.

10. A storage medium, characterized in that: The storage medium stores a computer program, and the computer program is executed by a processor to implement the SNPN private network-based user equipment roaming method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Access network equipment selection method and device

    CN116567615A

  • Satellite-based roaming call method and system, and storage medium

    CN117041938A