A method for a user equipment to access a mobile network and apparatuses therefor

CN117813802BActive Publication Date: 2026-09-29BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280002733.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-02
Publication Date
2026-09-29
Estimated Expiration
2042-08-02

AI Technical Summary

Technical Problem

[0005]然而,对于不支持NR的卫星终端,目前还没有3GPP网络为这种不支持NR的卫星终端提供服务的解决方案

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117813802B_ABST
    Figure CN117813802B_ABST
Patent Text Reader

Abstract

The method for a user equipment to access a mobile network and the device thereof are disclosed in the embodiments of the present disclosure. The method is performed by a user equipment, and the method comprises: accessing the user equipment to the mobile network through an untrusted or trusted non-3rd Generation Partnership Project (3GPP) access network; wherein the user equipment is a satellite terminal which does not support New Radio (NR), and the user equipment has satellite access and Non-Access Stratum (NAS) capabilities. Through the embodiments of the present disclosure, the satellite terminal which does not support NR can be accessed to the mobile network, so that the mobile network can provide services for the satellite terminal which does not support NR.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a method and apparatus for user equipment to access a mobile network. Background Technology

[0002] Satellites are spacecraft carrying telecommunications transmitters with bent pipe payloads or regenerative payloads. They are typically placed in low Earth orbit (LEO) at altitudes of 300 to 2,000 kilometers and in medium Earth orbit (MEO) at altitudes of 8,000 to 20,000 kilometers, or in geostationary Earth orbit (GEO) at an altitude of 35,786 kilometers.

[0003] In existing satellite access solutions defined by 3GPP (3rd Generation Partnership Project), satellite NG-RAN (Next Generation Radio Access Network) is an NG-RAN that provides satellite access to UE (User Equipment) using NR (New Radio Interface). UE should support NR access to the 3GPP network via satellite.

[0004] TS22.261 includes a requirement that 5G (5th Generation Mobile Communication Technology) systems with satellite access should support different configurations, where the radio access network is either a satellite NG-RAN or a non-3GPP satellite access network, or both.

[0005] However, there is currently no solution from 3GPP networks to provide services for satellite terminals that do not support NR. Summary of the Invention

[0006] This disclosure provides a method and apparatus for user equipment to access a mobile network. By using an untrusted or trusted non-3GPP access network, a satellite terminal that does not support NR can be connected to the mobile network, so that the mobile network can provide services to the satellite terminal that does not support NR.

[0007] In a first aspect, embodiments of this disclosure provide a method for a user equipment to access a mobile network, the method being performed by the user equipment, the method comprising:

[0008] The user equipment is connected to the mobile network through an untrusted or trusted non-3GPP access network;

[0009] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0010] In this technical solution, satellite terminals that do not support NR are connected to the mobile network through an untrusted or trusted non-3GPP access network, so that the mobile network can provide services to satellite terminals that do not support NR.

[0011] In one implementation, connecting the user equipment to the mobile network via an untrusted non-3GPP access network includes:

[0012] The authentication process connects to the untrusted non-3GPP access network.

[0013] When the user equipment decides to connect to the 5G core network, it selects the non-3GPP interoperability function N3IWF in the 5G public terrestrial mobile network PLMN.

[0014] An Internet Security Protocol (IPsec) tunnel is established with the selected N3IWF, and during the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network.

[0015] In one implementation, connecting the user equipment to the mobile network via a trusted non-3GPP access network includes:

[0016] Connect to the trusted non-3GPP access network;

[0017] The process based on the Extensible Authentication Protocol (EAP) registers with the 5G core network through the trusted non-3GPP access network.

[0018] The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation; the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

[0019] In one possible implementation, the connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

[0020] In one possible implementation, connecting the user equipment to the mobile network via an untrusted or trusted non-3GPP access network includes: selecting, based on pre-configured information in the user equipment, to connect the user equipment to the mobile network via an untrusted or trusted non-3GPP access network.

[0021] In one possible implementation, the non-3GPP access network is a satellite access network; the pre-configuration information includes a combination of satellite access and 5G core network information.

[0022] Secondly, embodiments of this disclosure provide another method for a user equipment to access a mobile network, the method being performed by a non-3GPP interoperability function N3IWF, the method comprising:

[0023] User equipment connected to an untrusted non-3GPP access network is connected to the mobile network;

[0024] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0025] In this technical solution, N3IWF is used to connect user equipment (satellite terminals that do not support NR) connected to an untrusted non-3GPP access network to the mobile network, so that the mobile network can provide services to satellite terminals that do not support NR.

[0026] In one implementation, the non-3GPP access network is a satellite access network.

[0027] In one possible implementation, during the process of connecting a user equipment connected to an untrusted non-3GPP access network to the mobile network, the method further includes sending a Radio Access Type (RAT) to the Access and Mobility Management Function (AMF) in an N2 message.

[0028] In one possible implementation, the RAT type includes at least one of the following types:

[0029] Trusted or untrusted LEO satellite access types;

[0030] Trusted or untrusted MEO satellite access types;

[0031] Trusted or untrusted geostationary satellite GEO satellite access type;

[0032] Other satellites, whether trusted or untrusted, are available for OTHERSAT satellite access.

[0033] Thirdly, embodiments of this disclosure provide another method for a user equipment to access a mobile network, the method being performed by an Access and Mobility Management Function (AMF), the method comprising:

[0034] Authenticate user equipment connected to an untrusted non-3GPP access network to enable access to the mobile network via the non-3GPP interoperability function N3IWF; or

[0035] Authenticate user equipment connected to a trusted non-3GPP access network to enable the user equipment to access the mobile network;

[0036] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0037] In this technical solution, the AMF authenticates user equipment (satellite terminals that do not support NR) connected to untrusted or trusted non-3GPP access networks, so that the N3IWF can connect the non-NR satellite terminal to the mobile network, enabling the mobile network to provide services to the non-NR satellite terminal.

[0038] In one implementation, the method further includes: when authenticating a user equipment connected to an untrusted non-3GPP access network, receiving the Radio Access Type (RAT) type sent by the N3IWF in the N2 message; or

[0039] When authenticating a user equipment connected to a trusted non-3GPP access network, the Radio Access Type (RAT) type is received in the N2 message from the trusted non-3GPP gateway function within the non-3GPP access network.

[0040] In one implementation, the method further includes: when registering with the Unified Data Management UDM, providing the UDM with an access type and RAT type configured as non-3GPP access based on a first RAT type.

[0041] In one possible implementation, the non-3GPP access type is satellite access.

[0042] In one possible implementation, the first RAT type is the RAT type received by the AMF; or, the first RAT type is the RAT type configured between the untrusted satellite access network and the AMF.

[0043] In one possible implementation, the RAT type includes at least one of the following types:

[0044] Trusted or untrusted LEO satellite access types;

[0045] Trusted or untrusted MEO satellite access types;

[0046] Trusted or untrusted geostationary satellite GEO satellite access type;

[0047] Other OTHERSAT satellite access types, whether trusted or untrusted.

[0048] Fourthly, embodiments of this disclosure provide another method for a user equipment to access a mobile network, the method being performed by a trusted non-3GPP access network, the method comprising:

[0049] User equipment connected to the trusted non-3GPP access network is connected to the mobile network;

[0050] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0051] In this technical solution, satellite terminals that do not support NR are connected to the mobile network through a trusted non-3GPP access network, so that the mobile network can provide services to satellite terminals that do not support NR.

[0052] In one implementation, the non-3GPP access network is a satellite access network.

[0053] In one implementation, the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

[0054] In one possible implementation, the connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

[0055] In one possible implementation, the method further includes sending the Radio Access Type (RAT) to the Access and Mobility Management Function (AMF) in an N2 message via a trusted non-3GPP gateway function.

[0056] In one possible implementation, the RAT type includes at least one of the following types:

[0057] Access types for untrusted or trusted LEO satellites;

[0058] Access types for medium Earth orbit (MEO) satellites, whether untrusted or trusted.

[0059] Access types for untrusted or trusted geostationary satellites in Earth orbit (GEO);

[0060] Other satellite access types, whether untrusted or trusted.

[0061] Fifthly, embodiments of this disclosure provide an apparatus for a user equipment to access a mobile network, the apparatus being configured on the user equipment, the apparatus comprising:

[0062] A processing unit is configured to connect the user equipment to the mobile network via an untrusted or trusted non-3GPP access network.

[0063] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0064] Sixthly, embodiments of this disclosure provide another apparatus for user equipment to access a mobile network, the apparatus being configured on a non-3GPP interoperability function N3IWF, the apparatus comprising:

[0065] A processing unit is configured to connect user equipment connected to an untrusted non-3GPP access network to the mobile network;

[0066] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0067] In a seventh aspect, embodiments of this disclosure provide another apparatus for a user equipment to access a mobile network, the apparatus being configured on an Access and Mobility Management Function (AMF), the apparatus comprising:

[0068] Processing unit, configured to authenticate user equipment connected to an untrusted non-3GPP access network, so as to enable the user equipment to access the mobile network via the non-3GPP interoperability function N3IWF; or

[0069] Used to authenticate user equipment connected to a trusted non-3GPP access network in order to access the mobile network;

[0070] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0071] Eighthly, embodiments of this disclosure provide another apparatus for a user equipment to access a mobile network, the apparatus being configured on a trusted non-3GPP access network, the apparatus comprising:

[0072] Processing unit, configured to connect user equipment connected to the trusted non-3GPP access network to the mobile network;

[0073] The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0074] Ninth aspect, embodiments of this disclosure provide a system for a user equipment to access a mobile network, the system including a user equipment, a non-3GPP interoperability function (N3IWF) and an access and mobility management function (AMF), wherein the user equipment performs the method described in the first aspect embodiment, the N3IWF performs the method described in the second aspect embodiment, and the AMF performs the method described in the third aspect embodiment.

[0075] In a tenth aspect, embodiments of this disclosure provide another system for a user equipment to access a mobile network, the system comprising a user equipment, a trusted non-3GPP access network, and an access and mobility management function (AMF), wherein the user equipment performs the method described in the first aspect embodiment, the AMF performs the method described in the third aspect embodiment, and the trusted non-3GPP access network performs the method described in the fourth aspect embodiment.

[0076] Eleventhly, embodiments of this disclosure provide an apparatus for a satellite terminal to access a mobile network. The apparatus includes a processor and a memory, the memory storing a computer program; the processor executes the computer program stored in the memory to cause the apparatus to perform the method described in the first aspect above.

[0077] In a twelfth aspect, embodiments of this disclosure provide another apparatus for a satellite terminal to access a mobile network, the apparatus including a processor and a memory, the memory storing a computer program; the processor executes the computer program stored in the memory to cause the apparatus to perform the method described in the second aspect above.

[0078] In a thirteenth aspect, embodiments of this disclosure provide another apparatus for a satellite terminal to access a mobile network, the apparatus including a processor and a memory, the memory storing a computer program; the processor executes the computer program stored in the memory to cause the apparatus to perform the method described in the third aspect above.

[0079] In a fourteenth aspect, embodiments of this disclosure provide another apparatus for a satellite terminal to access a mobile network, the apparatus including a processor and a memory storing a computer program; the processor executes the computer program stored in the memory to cause the apparatus to perform the method described in the fourth aspect above.

[0080] In a fifteenth aspect, embodiments of this disclosure provide a computer-readable storage medium for storing instructions for use by the user equipment described above, which, when executed, cause the user equipment to perform the method described in the first aspect.

[0081] In a sixteenth aspect, embodiments of this disclosure provide another readable storage medium for storing instructions used by the aforementioned non-3GPP interoperability function N3IWF, which, when executed, causes the N3IWF to perform the method described in the second aspect above.

[0082] In a seventeenth aspect, embodiments of this disclosure provide another readable storage medium for storing instructions used by the aforementioned Access and Mobility Management Function (AMF), which, when executed, cause the AMF to perform the method described in the third aspect above.

[0083] In an eighteenth aspect, embodiments of this disclosure provide another readable storage medium for storing instructions for use by the aforementioned trusted non-3GPP access network, which, when executed, cause the trusted non-3GPP access network to perform the method described in the fourth aspect. Attached Figure Description

[0084] To more clearly illustrate the technical solutions in the embodiments or background art of this disclosure, the accompanying drawings used in the embodiments or background art of this disclosure will be described below.

[0085] Figure 1 This is a schematic diagram of the architecture of a satellite terminal accessing a mobile network provided in an embodiment of this disclosure;

[0086] Figure 2 This is a schematic diagram of the architecture of another satellite terminal accessing a mobile network provided in an embodiment of this disclosure;

[0087] Figure 3 This is a flowchart illustrating a method for a user equipment to access a mobile network according to an embodiment of this disclosure;

[0088] Figure 4 This is a flowchart illustrating another method for a user equipment to access a mobile network provided in an embodiment of this disclosure;

[0089] Figure 5 This is a schematic diagram of the registration process through an untrusted non-3GPP access network provided in an embodiment of this disclosure;

[0090] Figure 6 This is a flowchart illustrating another method for a user equipment to access a mobile network provided in an embodiment of this disclosure;

[0091] Figure 7This is a schematic diagram of the registration process through a trusted non-3GPP access network provided in an embodiment of this disclosure;

[0092] Figure 8 This is a flowchart of another method for a user equipment to access a mobile network provided in this disclosure embodiment;

[0093] Figure 9 This is a flowchart of another method for a user equipment to access a mobile network provided in this disclosure embodiment;

[0094] Figure 10 This is a flowchart of another method for a user equipment to access a mobile network provided in this disclosure embodiment;

[0095] Figure 11 This is a flowchart of another method for a user equipment to access a mobile network provided in this disclosure embodiment;

[0096] Figure 12 A schematic diagram of a device for a user equipment to access a mobile network, provided in an embodiment of this disclosure;

[0097] Figure 13 This is a schematic diagram of another device for a user equipment to access a mobile network, provided as an embodiment of this disclosure. Detailed Implementation

[0098] The embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure. In the description of this disclosure, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist, for example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone.

[0099] Satellites are spacecraft carrying telecom transmitters with curved or regenerative payloads. They are typically placed in low Earth orbit (LEO) at altitudes of 300 to 2,000 kilometers and in medium Earth orbit (MEO) at altitudes of 8,000 to 20,000 kilometers, or in geostationary Earth orbit (GEO) at an altitude of 35,786 kilometers.

[0100] In existing satellite access solutions defined by 3GPP (3rd Generation Partnership Project), satellite NG-RAN (Next Generation Radio Access Network) is an NG-RAN that provides satellite access to UE (User Equipment) using NR (New Radio Interface). UE should support NR access to the 3GPP network via satellite.

[0101] TS22.261 includes a requirement that 5G (5th Generation Mobile Communication Technology) systems with satellite access should support different configurations, where the radio access network is either a satellite NG-RAN or a non-3GPP satellite access network, or both.

[0102] However, there is currently no solution from 3GPP networks to provide services for satellite terminals that do not support NR.

[0103] To address the technical challenge of how mobile networks can provide services to satellite terminals that do not support NR, this disclosure makes the following assumptions: 1) User Equipment (UE) has satellite access and NAS (Non-Access Stratum) capabilities; 2) UE access to 5GC (5G core network) involves two types of satellite access: trusted and untrusted, which are pre-configured in the UE based on a combination of satellite access and 5GC information (such as PLMN (Public Land Mobile Network) ID).

[0104] Optionally, this disclosure allows satellite terminals that do not support NR to access the mobile network via either an untrusted or a trusted non-3GPP access network. The communication system architecture will differ depending on the satellite access method used by the user equipment to access the 5G core network. Two communication systems are described below to correspond to the untrusted and trusted satellite access methods, respectively.

[0105] To better understand the method for a user equipment to access a mobile network disclosed in this disclosure, the communication system to which this disclosure applies is first described below.

[0106] Please see Figure 1 , Figure 1This is a schematic diagram of the architecture of a satellite terminal accessing a mobile network according to an embodiment of this disclosure. The system corresponds to an untrusted satellite access method. The system may include, but is not limited to, a user equipment 101, an untrusted non-3GPP access network 102, an N3IWF (Non-3GPP InterWorking Function) 103, an AMF (Access and Mobility Management Function) 104, an SMF (Session Management Function) 105, a UPF (User Plane Function) 106, and a DN (Data Network) 107. Figure 1 The number and form of devices shown are for illustrative purposes only and do not constitute a limitation on the embodiments of this disclosure. In actual applications, it may include two or more user equipment, two or more untrusted non-3GPP access networks, two or more N3IWF, two or more AMF, two or more SMF, two or more UPF, and two or more DN. Figure 1 The system shown is an example comprising a network device 101, an untrusted non-3GPP access network 102, an N3IWF 103, an AMF 104, an SMF 105, a UPF 106, and a DN 107.

[0107] It should be noted that the technical solutions of this disclosure can be applied to various communication systems. For example, fifth-generation (5G) mobile communication systems, 5G new radio (NR) systems, or other future new mobile communication systems.

[0108] The untrusted non-3GPP access network 102 in this embodiment includes satellite and S-AGF (Satellite Access Gateway Function).

[0109] The user equipment 101 in this disclosure is a user-side entity used to receive or transmit signals, such as a mobile phone. This user equipment 101 can also be referred to as an enhancing satellite terminal. The user equipment 101 can be a satellite terminal that does not support NR, and it possesses satellite access and non-access stratum (NAS) capabilities. The user equipment 101 can be a car with communication functions, a smart car, a mobile phone, a wearable device, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, etc. This disclosure does not limit the specific technology or device form used in the user equipment.

[0110] It should be noted that, in the embodiments of this disclosure, user equipment 101 and AMF 104 have an N1 interface. User equipment 101 and N3IWF 103 have an NWu interface. N3IWF 103 and AMF 104 have an N2 interface. N3IWF 103 and UPF 106 have an N3 interface. AMF 104 and SMF 105 have an N11 interface. SMF 105 and UPF 106 have an N4 interface. UPF 106 and DN 107 have an N6 interface.

[0111] Please see Figure 2 , Figure 2 This is a schematic diagram of the architecture of another satellite terminal accessing a mobile network provided in an embodiment of this disclosure. The system corresponds to a trusted satellite access method. The system may include, but is not limited to, a user equipment 201, a trusted non-3GPP access network 202, an AMF 203, an AUSF (Authentication Server Function) 204, an SMF 205, a UPF 206, and a DN 207. Figure 2The number and form of devices shown are for illustrative purposes only and do not constitute a limitation on the embodiments of this disclosure. In actual applications, it may include two or more user equipment, two or more trusted non-3GPP access networks, two or more AMFs, two or more ASFs, two or more SMFs, two or more UPFs, and two or more DNs. Figure 2 The system shown is an example comprising a network device 201, a trusted non-3GPP access network 202, an AMF 203, an AUSF 204, an SMF 205, a UPF 206, and a DN 207.

[0112] It should be noted that the technical solutions of this disclosure can be applied to various communication systems. For example, fifth-generation (5G) mobile communication systems, 5G new radio (NR) systems, or other future new mobile communication systems.

[0113] The trusted non-3GPP access network 202 in this embodiment may include a Trusted Non-3GPP Access Point (TNAP) and a Trusted Non-3GPP Gateway Function (TNGF). The TNAP may be a satellite, and the TNGF may be an S-AGF.

[0114] The user equipment 201 in this disclosure is a user-side entity used to receive or transmit signals, such as a mobile phone. This user equipment 201 can also be referred to as an enhanced satellite terminal. The user equipment 201 can be a satellite terminal that does not support NR, and it possesses satellite access and non-access stratum (NAS) capabilities. The user equipment 201 can be a car with communication functions, a smart car, a mobile phone, a wearable device, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, etc. This disclosure does not limit the specific technology or device form used in the user equipment.

[0115] It should be noted that, in the embodiments of this disclosure, user equipment 101 and AMF 203 have an N1 interface. User equipment 201 and TNGF have an NWu interface. TNAP and TNGF have a Ta interface. TNGF and AMF 203 have an N2 interface. AMF 203 and SMF 205 have an N11 interface. SMF 205 and UPF 206 have an N4 interface. UPF 206 and DN 207 have an N6 interface.

[0116] It is understood that the satellite terminal accessing the mobile network system described in the embodiments of this disclosure is for the purpose of more clearly illustrating the technical solutions of the embodiments of this disclosure, and does not constitute a limitation on the technical solutions provided in the embodiments of this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this disclosure are also applicable to similar technical problems.

[0117] The method and apparatus for user equipment to access a mobile network provided in this disclosure will be described in detail below with reference to the accompanying drawings.

[0118] Please see Figure 3 , Figure 3This is a flowchart illustrating a method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method in this embodiment is executed by the user equipment. Figure 3 As shown, the method may include, but is not limited to, the following steps:

[0119] In step 301, the user equipment is connected to the mobile network via an untrusted or trusted non-3GPP access network.

[0120] In some embodiments of this disclosure, the user equipment may be a satellite terminal that does not support NR, and the user equipment may have satellite access and NAS capabilities.

[0121] In one implementation, the user equipment can be connected to the mobile network via either an untrusted or a trusted non-3GPP access network, based on pre-configured information in the user equipment. Optionally, in some embodiments of this disclosure, the non-3GPP access network is a satellite access network; the pre-configured information may include a combination of satellite access and 5G core network information.

[0122] In other words, in this embodiment of the disclosure, user equipment accesses the 5G core network through two satellite access methods: trusted and untrusted. This selection can be pre-configured in the user equipment based on a combination of satellite access and 5G core network information (such as the PLMN ID).

[0123] For example, if the combined satellite access and 5G core network information pre-configured in the user equipment (UE) is the first PLMN ID, then the UE can be connected to the mobile network via an untrusted non-3GPP access network. Conversely, if the combined satellite access and 5G core network information pre-configured in the UE is the second PLMN ID, then the UE can be connected to the mobile network via a trusted non-3GPP access network.

[0124] By implementing embodiments of this disclosure, satellite terminals that do not support NR can be accessed to a mobile network through an untrusted or trusted non-3GPP access network, so that the mobile network can provide services to satellite terminals that do not support NR.

[0125] In some embodiments of this disclosure, satellite terminals that do not support NR can access a mobile network through an untrusted, non-3GPP access network. Optionally, please refer to... Figure 4 , Figure 4 This is a flowchart illustrating another method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method in this embodiment is executed by the user equipment. Figure 4 As shown, the method may include, but is not limited to, the following steps:

[0126] In step 401, a connection is made to an untrusted non-3GPP access network based on the authentication process.

[0127] Optionally, the user equipment connects to an untrusted non-3GPP access network through any appropriate authentication process and is assigned an IP (Internet Protocol) address. For example, non-3GPP authentication methods can be used, such as no authentication (in the case of free WLAN), EAP (Extensible Authentication Protocol) with a pre-shared key, username / password, etc.

[0128] In step 402, when the user equipment decides to connect to the 5G core network, a non-3GPP interoperability function N3IWF is selected in the 5G public terrestrial mobile network (PLMN).

[0129] Optionally, when a user equipment decides to connect to the 5G core network, the user equipment may select N3IWF in the 5G PLMN, as described in Clause 6.3.6 of TS23.501.

[0130] In step 403, an Internet Security Protocol (IPsec) tunnel is established with the selected N3IWF. During the IPsec tunnel establishment process, the user equipment will be authenticated by the 5G core network and attached to the 5G core network.

[0131] Optionally, the user equipment can establish an IPsec tunnel with a selected N3IWF, and during the IPsec tunnel establishment process, the user equipment will be authenticated by the 5G core network and attached to the 5G core network, so that the user equipment connected to the untrusted non-3GPP access network can access the mobile network.

[0132] To better understand the method for user equipment to access a mobile network disclosed in this embodiment, the following will be combined with... Figure 5 Describes the registration process through an untrusted, non-3GPP access network.

[0133] like Figure 5 As shown, in step 1a, the user equipment connects to the untrusted non-3GPP access network through any appropriate authentication process and is assigned an IP address. For example, non-3GPP authentication methods can be used, such as no authentication (in the case of free WLAN), EAP with a pre-shared key, username / password, etc. In step 1b, when the user equipment decides to connect to the 5GC network, the user equipment selects the N3IWF in the 5G PLMN, as described in Clause 6.3.6 of TS 23.501.

[0134] In step 2, the user equipment initiates an initial IKE (Internet Key Exchange) exchange according to RFC 7296, and continues to establish an IPsec (Internet Protocol Security) Security Association (SA) with the selected N3IWF. After step 2, all subsequent IKE messages are encrypted and their integrity protected using the IKE SA established in this step. In other words, step 2 corresponds to the IKE SA process, which establishes a secure transmission channel in an incomplete network environment for the subsequent 5G-NAS authentication process, ensuring the security of 5G-NAS authentication message transmission; after this step, all IKE messages are encrypted and protected for integrity.

[0135] In step 3, the user equipment (UE) should initiate an IKE_AUTH exchange by sending an IKE_AUTH (Internet Key Exchange Authentication) request message. The AUTH payload, not included in the IKE_AUTH request message, indicates that the IKE_AUTH exchange should use EAP signaling (in this case, EAP-5G signaling). If the UE supports MOBIKE (Mobility and Multihoming Protocol), the UE should include a Notify payload in the IKE_AUTH request, indicating MOBIKE support as specified in RFC 4555. Furthermore, as specified in TS 33.501, if the UE provides an N3IWF root certificate, the UE should include a CERTREQ payload in the IKE_AUTH request message to request the N3IWF certificate.

[0136] In step 4, the user equipment (UE) may receive an IKE_AUTH response message from N3IWF. Optionally, N3IWF responds using the IKE_AUTH response message, which includes an EAP-Request / 5G-Start packet. The EAP-Request / 5G-Start packet notifies the UE to initiate an EAP-5G session, i.e., to begin sending NAS messages encapsulated in EAP-5G packets. If N3IWF has received the CERTREQ payload from the UE, N3IWF should include the CERT payload in the IKE_AUTH response message containing the N3IWF certificate. How the UE uses the N3IWF certificate is specified in TS 33.501.

[0137] In step 5, the user equipment (UE) should verify the N3IWF certificate and confirm that the N3IWF identifier matches the N3IWF selected by the UE. If the UE's certificate request or identity verification fails, the lack of an N3IWF certificate will result in connection failure. The UE should send an IKE_AUTH request, which includes an EAP-Response / 5G-NAS packet containing access network parameters (AN parameters) and a registration request message. The AN parameters contain information used by the N3IWF to select an AMF in the 5G core network. For example, this information may include a GUAMI (Globally Unique Access and Mobility Management Function Identifier), the selected PLMN ID (or PLMN ID and NID, see Clause 5.30 of TS23.501), the requested NSSAI (Network Slice Selection Assistance Information, also known as the network slice identifier), and the establishment reason. This establishment reason provides the reason for requesting to establish a signaling connection with the 5G core network. Whether and how a user equipment includes the requested NSSAI as part of the AN parameter depends on the value of the access layer connection establishment NSSAI inclusion mode parameter, as specified in Section 5.15.9 of TS23.501.

[0138] However, N3IWF does not send an EAP-Identity request because the user equipment includes its identity in the first IKE_AUTH. This complies with clause 3.16 of RFC 7296.

[0139] In step 6, according to Clause 6.3.5 of TS 23.501, the N3IWF should select an AMF based on the received AN parameters and local policy. Then, the N3IWF should forward the registration request received from the user equipment to the selected AMF within an N2 message. This message contains N2 parameters, including the selected PLMN ID and the establishment reason. The N3IWF sends the RAT type to the AMF in the N2 message. In some embodiments of this disclosure, the RAT type may include at least one of the following types:

[0140] Trusted or untrusted LEO satellite access types;

[0141] Trusted or untrusted MEO satellite access types;

[0142] Trusted or untrusted geostationary satellite GEO satellite access type;

[0143] Other satellites, whether trusted or untrusted, are available for OTHERSAT satellite access.

[0144] As one possible implementation, the RAT type can be one of the values ​​shown in Table 1 below:

[0145] Table 1 Enumeration of RAT type

[0146]

[0147] It is understood that each element in Table 1 above exists independently. These elements are listed in the same table as an example, but this does not mean that all elements in the table must exist simultaneously as shown in the table. The value of each element is independent of the values ​​of any other element in Table 1. Therefore, those skilled in the art will understand that the value of each element in Table 1 is an independent embodiment. It should be noted that the embodiments of this disclosure include multiple tables, and each of these tables is similar to Table 1, combining multiple independent embodiments into the same table, and each element in these tables should also be considered an independent embodiment.

[0148] In steps 7a and 7b, the selected AMF can determine whether to request a SUCI (Subscribed User Implicit Identity) by sending a NAS Identity Request message to the user equipment. This NAS Identity Request message and all subsequent NAS messages are encapsulated within an EAP / 5G-NAS packet and sent to the user equipment.

[0149] In step 8 (including steps 8a to 8h), the AMF may decide to authenticate the user equipment by invoking the AUSF (Authentication Server Function). In this case, the AMF will select the AUSF based on the SUPI (Subscriber Permanent Identifier) ​​or SUCI, as specified in Section 6.3.4 of TS 23.501. The AUSF performs user equipment authentication as specified in TS 33.501. The AUSF selects a UDM as described in Section 6.3.8 of TS 23.501 and obtains authentication data from the UDM. The authentication data packet is encapsulated in a NAS authentication message, which is encapsulated in an EAP / 5G-NAS packet. Upon successful authentication, in step 8h, the AUSF should send an anchor key (Security Anchor Function (SEAF) key) to the AMF, which the AMF uses to derive the NAS security key and the N3IWF security key (N3IWF key). The user equipment also derives the anchor key (SEAF key) and from it derives the NAS security key and the N3IWF security key (N3IWF key). The N3IWF key is used by the user equipment and N3IWF to establish an IPsec security association (in step 11).

[0150] In step 8h, if AMF provided SUCI to AUSF in step 8a, then AUSF should also include SUPI.

[0151] It should be noted that EAP-AKA' or 5G-AKA allows authentication of user equipment via non-3GPP access, as described in TS33.501. Figure 5 Only the authentication process using EAP-AKA is shown. As specified in Annex I of TS33.501, user equipment accessing SNPN (Standalone Non-Public Network) services via PLMN is also permitted to use authentication methods other than EAP-AKA or 5G-AKA.

[0152] In step 9a, the AMF will send a NAS security mode command message to the user equipment to activate NAS security. If the EAP-AKA authentication was successfully performed in step 8, the AMF should encapsulate the EAP-Success received from the AUSF in the NAS security mode command message.

[0153] In step 9b, the N3IWF should forward the NAS security mode command message to the user equipment in the EAP / 5G-NAS packet.

[0154] In step 9c, the user equipment completes EAP-AKA' authentication (if initiated in step 8), creates the NAS security context and N3IWF key, and sends a NAS security mode completion message in the EAP / 5G-NAS packet.

[0155] In step 9d, the N3IWF relays the NAS security mode completion message to the AMF.

[0156] In step 10a, after receiving the NAS security mode, the AMF should send an NGAP (Next Generation Application Protocol) initial context setup request message containing the N3IWF key.

[0157] In step 10b, this triggers the N3IWF to send EAP-Success to the user equipment, thus completing the EAP-5G session. No further EAP-5G packets are exchanged.

[0158] In step 11 (including steps 11a and 11b), an IPsec SA is established between the user equipment (UE) and the N3IWF using the public N3IWF key created in the UE in step 9c and received by the N3IWF in step 10a. This IPsec SA is referred to as the "signaling IPsec SA". After establishing the signaling IPsec SA, the N3IWF notifies the AMF to create a UE context (including security) by sending an NGAP Initial Context Setup response message. The signaling IPsec SA should be configured to operate in tunnel mode, and the N3IWF should assign an "internal" IP address to the UE. If the N3IWF has received an indication that the UE supports MOBIKE (see step 3), the N3IWF should include a Notify payload in the IKE_AUTH response message sent in step 11a, indicating that MOBIKE should be supported, as specified in RFC 4555.

[0159] All subsequent NAS messages exchanged between the User Equipment (UE) and the N3IWF should be sent via IPsec Signaling SA and carried over TCP / IP. The UE should send the NAS message within a TCP / IP packet, with the source address being the UE's "internal" IP address and the destination address being the NAS_IP_ADDRESS received in step 11a. The N3IWF should send the NAS message within a TCP / IP packet, with the source address being NAS_IP_ADDRESS and the destination address being the UE's "internal" IP address. The TCP connection for reliable NAS transport between the UE and the N3IWF should be initiated by the UE immediately after the establishment of the IPsec Signaling SA in step 11a. The UE should send the TCP connection request to NAS_IP_ADDRESS and the TCP port number specified in TS24.502.

[0160] In step 12, the AMF sends a NAS registration acceptance message to the N3IWF. The N2 message includes NSSAI (Network Slice Selection Assistance Information) indicating whether the user equipment access type is permitted.

[0161] In step 13, the N3IWF forwards the NAS registration acceptance message to the user equipment via the established IPsec SA signaling. If the N3IWF receives the NAS registration acceptance message before establishing the IPsec SA, the N3IWF should store the NAS registration acceptance message and only forward it to the user equipment after the IPsec SA signaling is established.

[0162] In some embodiments of this disclosure, when registering with the UDM, the AMF provides the UDM with an access type and RAT type set to "Non-3GPP access" based on the RAT type received in step 6b, or based on the configuration between the untrusted satellite access network and the AMF. As an example, if a RAT type is received in step 6b, the AMF can provide the UDM with an access type set to "non-3GPP access" and the RAT type based on the received RAT type when registering with the UDM. As another example, if no RAT type is received in step 6b, the AMF can provide the UDM with an access type and RAT type set to "Non-3GPP access" when registering with the UDM, based on the configuration between the untrusted satellite access network and the AMF.

[0163] In embodiments of this disclosure, the RAT type may include at least one of the following types:

[0164] Trusted or untrusted LEO satellite access types;

[0165] Trusted or untrusted MEO satellite access types;

[0166] Trusted or untrusted geostationary satellite GEO satellite access type;

[0167] Other satellites, whether trusted or untrusted, are available for OTHERSAT satellite access.

[0168] As one possible implementation, the RAT type can be one of the values ​​shown in Table 1 above.

[0169] By implementing embodiments of this disclosure, satellite terminals that do not support NR can be accessed to a mobile network through an untrusted non-3GPP access network, enabling the mobile network to provide services to satellite terminals that do not support NR.

[0170] In some embodiments of this disclosure, satellite terminals that do not support NR can access a mobile network through a trusted non-3GPP access network. Optionally, please refer to... Figure 6 , Figure 6 This is a flowchart illustrating another method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method in this embodiment is executed by the user equipment. Figure 6 As shown, the method may include, but is not limited to, the following steps:

[0171] In step 601, a connection is made to a trusted non-3GPP access network (TNAN).

[0172] In step 602, the EAP-based process registers with the 5G core network through a trusted non-3GPP access network.

[0173] In the embodiments of this disclosure, the link between the user equipment and the trusted non-3GPP access network can be any data link (L2) that supports EAP encapsulation, such as PPP (Point-to-Point Protocol), PANA (Protocol for carrying Authentication for Network Access), Ethernet, IEEE (Institute of Electrical and Electronics Engineers) 802.3, IEEE 802.11, etc.

[0174] In embodiments of this disclosure, the trusted non-3GPP access network (TNAN) may include a trusted non-3GPP access point (TNAP) and a trusted non-3GPP gateway function (TNGF), with the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function being an AAA interface. The trusted non-3GPP access point (TNAP) may be a satellite, and the trusted non-3GPP gateway function (TNGF) is an S-AGF.

[0175] To better understand the method for user equipment to access a mobile network disclosed in this embodiment, the following will be combined with... Figure 7 Describes the registration process through a trusted non-3GPP access network.

[0176] like Figure 7 As shown, in step 0, the user equipment selects a PLMN and a TNAN to connect to the PLMN using a trusted non-3GPP access network selection procedure. During this process, the user equipment discovers that the TNAN supports a PLMN with trusted connectivity (e.g., "5G connectivity").

[0177] In step 1, an L2 (Layer-2) connection is established between the user equipment and the trusted non-3GPP access point (TNAP), which can be a satellite connection between the user equipment and the satellite.

[0178] In steps 2 and 3, the EAP procedure is initiated. The EAP message is encapsulated in L2 data packets, such as IEEE 802.3 / 802.1x packets, IEEE 802.11 / 802.1x packets, or PPP packets. The NAI (Network Access Identifier) ​​provided by the user equipment instructs the user equipment to request a "5G connection" to a specific PLMN, for example, NAI = "<any_username> @nai.5gc.mnc <mnc>.mcc <mcc>The NAI (Network Address Translation) is located at ".3gppnetwork.org". This NAI triggers TNAP to send an AAA request to TNGF, which acts as an AAA agent. Between TNAP and TNGF, EAP packets are encapsulated into AAA messages. The AAA request also includes a TNAP identifier, which can be considered as user location information.

[0179] In steps 4 through 10, the EAP-5G process is executed. The key points of executing the EAP-5G process are as follows:

[0180] Upon successful authentication, a TNGF key is created in the user equipment and the AMF. In step 10a (within the N2 Initial Context Setup Request message), the TNGF key is transferred from the AMF to the TNGF. The TNGF derives a TNAP key, which is provided to the TNAP. The TNAP key depends on the non-3GPP access technology (e.g., in the case of IEEE Std 802.11, the TNAP key is a pair of master keys).

[0181] In step 5, the UE should include the requested NSSAI in the AN parameters only if trusted non-3GPP access is permitted. The UE should also include the UE Id in the AN parameters, for example, if a 5G-GUTI (5th Generation Mobile Technology - Globally Unique Temporary Identifier) ​​is available from prior registration with the same PLMN.

[0182] It should be noted that, in the embodiments of this disclosure, the TNGF includes UE location information (ULI) in the N2 message sent in step 6b, which contains an "empty" IP address (e.g., 0.0.0.0) because an IP address has not yet been assigned to the user equipment. After the user equipment is assigned an IP address, the TNGF will include this IP address in subsequent N2 messages. The TNGF sends the RAT type to the AMF in the N2 message. In some embodiments of this disclosure, the RAT type may include at least one of the following types:

[0183] Access types for untrusted or trusted LEO satellites;

[0184] Access types for medium Earth orbit (MEO) satellites, whether untrusted or trusted.

[0185] Access types for untrusted or trusted geostationary satellites in Earth orbit (GEO);

[0186] Other satellite access types, whether untrusted or trusted.

[0187] As one possible implementation, the RAT type can be one of the values ​​shown in Table 1 below:

[0188] Table 2 Enumeration of RAT type

[0189]

[0190]

[0191] It is worth noting that after receiving the TNGF key from the AMF in step 10a, the TNGF should send an EAP-Request / 5G-Notification packet containing "TNGF Contact Info" to the user equipment, including the TNGF's IP address. In step 10d, after receiving the EAP-Response / 5G-Notification packet from the user equipment in step 10c, the TNGF should send a message containing an EAP-Success packet.

[0192] In step 11, the TNAP key is used to establish L2 (Layer-2) security between the user equipment and TNAP. In the case of IEEE Std 802.11, a four-way handshake is performed to establish a security context between the satellite and the user equipment to protect unicast and multicast traffic over the air.

[0193] In step 12, the user equipment receives IP configuration information from the TNAN (Trusted Non-3GPP Access Network), for example, using DHCP (Dynamic Host Configuration Protocol). At this point, the user equipment has successfully connected to the TNAN and obtained the IP configuration information.

[0194] In step 13 (including steps 13a to 13c), the user equipment establishes a secure NWt connection with the TNGF. The establishment of this secure NWt connection between the user equipment and the TNGF is as follows:

[0195] The user equipment (UE) initiates an IKE_INIT exchange using the IP address of the TNGF received during the EAP-5G signaling in step 10b. Subsequently, the UE initiates an IKE_AUTH exchange and provides its identity. The identity provided by the UE in the IKEv2 (second version of IKE) signaling should be the same as the UE ID contained in the AN parameters in step 5. This allows the TNGF to create a TNGF key for the UE before locating it during authentication in step 8. The TNGF key is used for mutual authentication. Null encryption is negotiated between the UE and the TNGF as specified in RFC 2410.

[0196] It should be noted that in step 13c, the TNGF provides the UE with its "internal" IP address, NAS_IP_ADDRESS, TCP port number, and DSCP (Differentiated Services Code Point) value. Following this step, an IPsec SA is established between the UE and the TNGF. This is called a "signaling IPsec SA" and operates in tunnel mode. Tunnel mode operation allows the IPsec SA to be re-established using MOBIKE when the UE's IP address changes during a mobility event. All IP packets exchanged between the UE and the TNGF via the "signaling IPsec SA" should be labeled with the aforementioned DSCP value. The UE and TNAP can map the DSCP value to a QoS (Quality of Service) level (e.g., EDCA access level) supported by the underlying non-3GPP access network.

[0197] It is worth noting that after the "Signaling IPsec SA" is established, the user equipment will establish a TCP connection with the TNGF using NAS_IP_ADDRESS and the TCP port number received in step 13c. The user equipment should send a NAS message in the TCP / IP packet, with the source address being the user equipment's "internal" IP address and the destination address being NAS_IP_ADDRESS. The TNGF should send a NAS message in the TCP / IP packet, with the source address being NAS_IP_ADDRESS and the destination address being the UE's "internal" IP address.

[0198] In step 14, after successfully establishing the NWt connection, the TNGF responds to the AMF with the N2 Initial Context Setup Response Message.

[0199] In step 15 (including steps 15a and 15b), the NAS registration acceptance message is sent by the AMF and forwarded to the user equipment via the established NWt connection. At this time, the user equipment can use TNAN to transmit non-seamless offloading traffic and establish one or more PDU sessions. When registering with the UDM, the AMF provides the UDM with an access type and RAT type set to "Non-3GPP Access" based on the RAT type received from the TNGF in step 6b, or based on the configuration of the trusted satellite access network in the AMF. As an example, if a RAT type is received from the TNGF in step 6b, the AMF can provide the UDM with an access type and RAT type set to "Non-3GPP Access" based on the received RAT type when registering with the UDM. As another example, if no RAT type is received from the TNGF in step 6b, the AMF can provide the UDM with an access type and RAT type set to "Non-3GPP Access" based on the configuration of the trusted satellite access network in the AMF when registering with the UDM.

[0200] In embodiments of this disclosure, the RAT type may include at least one of the following types:

[0201] Access types for untrusted or trusted LEO satellites;

[0202] Access types for medium Earth orbit (MEO) satellites, whether untrusted or trusted.

[0203] Access types for untrusted or trusted geostationary satellites in Earth orbit (GEO);

[0204] Other satellite access types, whether untrusted or trusted.

[0205] As one possible implementation, the RAT type can be one of the values ​​shown in Table 2 above.

[0206] By implementing embodiments of this disclosure, satellite terminals that do not support NR can be connected to a mobile network through a trusted non-3GPP access network, enabling the mobile network to provide services to satellite terminals that do not support NR.

[0207] It is understood that the above embodiments describe the implementation of the method for user equipment to access a mobile network according to the embodiments of this disclosure from the user equipment side. This disclosure also proposes another method for user equipment to access a mobile network, which involves connecting the user equipment to the mobile network through an untrusted non-3GPP access network. The implementation of this method for user equipment to access a mobile network will be described below from the N3IWF side. Please refer to... Figure 8 , Figure 8 This is a flowchart illustrating another method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method for a user equipment to access a mobile network according to this embodiment can be executed by an N3IWF, such as... Figure 8 As shown, the method may include, but is not limited to, the following steps.

[0208] In step 801, the user equipment connected to the untrusted non-3GPP access network is connected to the mobile network.

[0209] In the embodiments disclosed herein, the user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities.

[0210] In some embodiments of this disclosure, the non-3GPP access network is a satellite access network.

[0211] In one implementation, during the process of connecting a user equipment connected to an untrusted non-3GPP access network to the mobile network, the N3IWF sends a RAT type to the AMF in an N2 message. In embodiments of this disclosure, the RAT type may include at least one of the following types:

[0212] Trusted or untrusted LEO satellite access types;

[0213] Trusted or untrusted MEO satellite access types;

[0214] Trusted or untrusted geostationary satellite GEO satellite access type;

[0215] Other satellites, whether trusted or untrusted, are available for OTHERSAT satellite access.

[0216] In embodiments of this disclosure, N3IWF can be used with, for example... Figure 1 The system interacts with other devices shown to connect user equipment connected to an untrusted non-3GPP access network to the mobile network. This implementation process can be found above. Figure 5 The implementation method of registration through an untrusted non-3GPP access network, as shown, will not be described in detail here.

[0217] It is understood that the above embodiments describe the implementation of the user equipment accessing a mobile network method according to the embodiments of this disclosure from the perspectives of the user equipment and the N3IWF, respectively. This disclosure also proposes another method for user equipment to access a mobile network, which involves connecting the user equipment to the mobile network through an untrusted non-3GPP access network. The implementation of this user equipment accessing a mobile network method will be described below from the AMF side. Please refer to... Figure 9 , Figure 9 This is a flowchart illustrating another method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method for a user equipment to access a mobile network according to this embodiment can be executed by an AMF (Automatic Mobile Frame), such as... Figure 9 As shown, the method may include, but is not limited to, the following steps.

[0218] In step 901, user equipment connected to an untrusted non-3GPP access network is authenticated to enable access to the mobile network via N3IWF.

[0219] In the embodiments disclosed herein, the user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. As one implementation, the non-3GPP access type can be satellite access.

[0220] In one implementation, the AMF can receive the Radio Access Type (RAT) type sent by the N3IWF in the N2 message.

[0221] In one implementation, when the AMF registers with the Unified Data Management UDM, it provides the UDM with the access type and RAT type configured for non-3GPP access based on the first RAT type.

[0222] In the embodiments disclosed herein, the first RAT type is the RAT type received by the AMF; or, the first RAT type is the RAT type configured between the untrusted satellite access network and the AMF.

[0223] In embodiments of this disclosure, the RAT type may include at least one of the following types:

[0224] Trusted or untrusted LEO satellite access type;

[0225] Trusted or untrusted MEO satellite access type;

[0226] Trusted or untrusted GEO satellite access type;

[0227] Trusted or untrusted OTHERSAT satellite access type.

[0228] As one possible implementation, the RAT type can be one of the values ​​shown in Table 1 above.

[0229] In embodiments of this disclosure, AMF can be used with, for example... Figure 1 The system interacts with other devices shown to connect user equipment connected to an untrusted non-3GPP access network to the mobile network. This implementation process can be found above. Figure 5 The implementation method of registration through an untrusted non-3GPP access network, as shown, will not be described in detail here.

[0230] It is understood that this disclosure also proposes another method for user equipment (UE) to access a mobile network, which connects the UE to the mobile network through a trusted non-3GPP access network (TNAN). The implementation of this UE access method will be described below from the perspective of the trusted non-3GPP access network (TNAN). Please refer to... Figure 10 , Figure 10 This is a flowchart illustrating another method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method for a user equipment to access a mobile network according to this embodiment can be executed by a trusted non-3GPP access network, such as... Figure 10 As shown, the method may include, but is not limited to, the following steps.

[0231] In step 1001, the user equipment connected to the trusted non-3GPP access network is connected to the mobile network.

[0232] In the embodiments disclosed herein, the user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. As an example, the non-3GPP access network is a satellite access network.

[0233] In some embodiments of this disclosure, the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, wherein the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

[0234] In one implementation, the connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

[0235] In embodiments of this disclosure, the Radio Access Type (RAT) is sent to the Access and Mobility Management Function (AMF) in the N2 message via a trusted non-3GPP gateway function. In embodiments of this disclosure, the RAT type includes at least one of the following types:

[0236] Untrusted or trusted LEO satellite access types;

[0237] MEO satellite access types: untrusted or trusted;

[0238] Untrusted or trusted GEO satellite access types;

[0239] Untrusted or trusted OTHERSAT satellite access types.

[0240] As one possible implementation, the RAT type can be one of the values ​​shown in Table 2 above.

[0241] In embodiments of this disclosure, a trusted non-3GPP access network (TNAN) can be connected with, for example... Figure 2 The system interacts with other devices shown to connect user equipment connected to a trusted non-3GPP access network to the mobile network. This implementation process is described above. Figure 7 The implementation method of registration through a trusted non-3GPP access network, as shown, will not be elaborated here.

[0242] It is understood that the above embodiments describe the implementation of the user equipment accessing a mobile network method according to the embodiments of this disclosure from the perspectives of the user equipment and the trusted non-3GPP access network (TNAN). This disclosure also proposes another method for user equipment to access a mobile network, which connects the user equipment to the mobile network through a trusted non-3GPP access network. The implementation of this user equipment accessing a mobile network method will be described below from the AMF (Advanced Management Network) side. Please refer to... Figure 11 , Figure 11 This is a flowchart illustrating another method for a user equipment to access a mobile network according to an embodiment of this disclosure. It should be noted that the method for a user equipment to access a mobile network according to this embodiment can be executed by an AMF (Automatic Mobile Frame), such as... Figure 11 As shown, the method may include, but is not limited to, the following steps.

[0243] In step 1101, user equipment connected to a trusted non-3GPP access network is authenticated to enable access to the mobile network.

[0244] In the embodiments disclosed herein, the user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. As one implementation, the non-3GPP access type is satellite access.

[0245] In some embodiments of this disclosure, the AMF can receive the Radio Access Type (RAT) type sent in the N2 message by a trusted non-3GPP gateway function in a non-3GPP access network.

[0246] In some embodiments of this disclosure, the AMF may provide the UDM with an access type and RAT type configured as non-3GPP access based on a first RAT type when registering with the Unified Data Management UDM.

[0247] In the embodiments of this disclosure, the first RAT type is the RAT type received by the AMF; or, the first RAT type is the RAT type configured between the untrusted satellite access network and the AMF.

[0248] In embodiments of this disclosure, the RAT type includes at least one of the following types:

[0249] Untrusted or trusted LEO satellite access types;

[0250] MEO satellite access types: untrusted or trusted;

[0251] Untrusted or trusted GEO satellite access types;

[0252] Untrusted or trusted OTHERSAT satellite access types.

[0253] As an example of a possible implementation, the RAT type can be one of the values ​​shown in Table 2 above.

[0254] In embodiments of this disclosure, AMF can be used with, for example... Figure 2 The system interacts with other devices shown to connect user equipment connected to a trusted non-3GPP access network to the mobile network. This implementation process is described above. Figure 7 The implementation method of registration through a trusted non-3GPP access network, as shown, will not be elaborated here.

[0255] The methods provided in the embodiments of this disclosure above have been described from the perspectives of user equipment, N3IWF, AMF, and trusted non-3GPP access network. To implement the functions of the methods provided in the embodiments of this disclosure above, the user equipment, N3IWF, AMF, and trusted non-3GPP access network may include hardware structures and software modules, and may implement the above functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. One of the above functions may be executed in the form of hardware structures, software modules, or a combination of hardware structures and software modules.

[0256] Please see Figure 12 This is a schematic diagram of the structure of a user equipment accessing a mobile network device 120 provided in an embodiment of this disclosure. Figure 12 The apparatus 120 shown may include a transceiver unit 1201 and a processing unit 1202. The transceiver unit 1201 may include a sending unit and / or a receiving unit. The sending unit is used to implement the sending function, and the receiving unit is used to implement the receiving function. The transceiver unit 1201 can implement both the sending and / or receiving functions.

[0257] Device 120 can be a user equipment, a device within a user equipment, or a device compatible with a user equipment. Alternatively, device 120 can be an N3IWF network element, a device within an N3IWF network element, or a device compatible with an N3IWF network element. Alternatively, device 120 can be an AMF network element, a device within an AMF network element, or a device compatible with an AMF network element. Alternatively, device 120 can be a trusted non-3GPP access network, a device within a trusted non-3GPP access network, or a device compatible with a trusted non-3GPP access network.

[0258] The device 120 is a user equipment: In one implementation, the processing unit 1202 is used to connect the user equipment to a mobile network via an untrusted or trusted non-3GPP access network. The user equipment is a satellite terminal that does not support New Radio (NR) and possesses satellite access and non-access stratum (NAS) capabilities.

[0259] In one possible implementation, the processing unit 1202 connects the user equipment to the mobile network via an untrusted non-3GPP access network as follows: connects to the untrusted non-3GPP access network based on an authentication process; when the user equipment decides to connect to the 5G core network, selects a non-3GPP interworking function N3IWF in the 5G public terrestrial mobile network (PLMN); establishes an Internet Security Protocol (IPsec) tunnel with the selected N3IWF, and during the IPsec tunnel establishment process, the user equipment is authenticated by the 5G core network and attached to the 5G core network.

[0260] In one possible implementation, the processing unit 1202 connects the user equipment to the mobile network through a trusted non-3GPP access network as follows: connecting to the trusted non-3GPP access network; registering with the 5G core network through the trusted non-3GPP access network via a process based on the Extensible Authentication Protocol (EAP); wherein the link between the user equipment and the trusted non-3GPP access network is a data link supporting EAP encapsulation; the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

[0261] In one possible implementation, the connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

[0262] In embodiments of this disclosure, processing unit 1202 can select, based on pre-configured information in the user equipment, to connect the user equipment to the mobile network via an untrusted or trusted non-3GPP access network. As an example, the non-3GPP access network is a satellite access network; the pre-configured information includes a combination of satellite access and 5G core network information.

[0263] In the case of untrusted non-3GPP access, device 120 is an N3IWF: In one implementation, processing unit 1202 is used to connect user equipment connected to the untrusted non-3GPP access network to the mobile network; wherein the user equipment is a satellite terminal that does not support New Radio (NR) and has satellite access and non-access stratum (NAS) capabilities. As an example, the non-3GPP access network is a satellite access network.

[0264] In one possible implementation, processing unit 1202 sends the Radio Access Type (RAT) to the Access and Mobility Management Function (AMF) in the N2 message. In embodiments of this disclosure, the RAT type includes at least one of the following types:

[0265] Trusted or untrusted LEO satellite access types;

[0266] Trusted or untrusted MEO satellite access types;

[0267] Trusted or untrusted geostationary satellite GEO satellite access type;

[0268] Other satellites, whether trusted or untrusted, are available for OTHERSAT satellite access.

[0269] In the case of untrusted non-3GPP access, device 120 is an AMF: In one implementation, processing unit 1202 is used to authenticate user equipment connected to an untrusted non-3GPP 3GPP access network to enable the user equipment to access the mobile network via the non-3GPP interoperability function N3IWF; wherein the user equipment is a satellite terminal that does not support New Radio (NR) and has satellite access and non-access stratum (NAS) capabilities. As an example, the access type of the non-3GPP access is satellite access.

[0270] In one possible implementation, the processing unit 1202 is also used to receive the Radio Access Type (RAT) type sent by N3IWF in the N2 message.

[0271] In one possible implementation, the processing unit 1202 is further configured to provide the Unified Data Management (UDM) with an access type and RAT type configured as non-3GPP access based on a first RAT type when registering with the Unified Data Management (UDM). In embodiments of this disclosure, the first RAT type is the RAT type received by the AMF; or, the first RAT type is the RAT type configured between the untrusted satellite access network and the AMF.

[0272] In embodiments of this disclosure, the RAT type includes at least one of the following types:

[0273] Trusted or untrusted LEO satellite access types;

[0274] Trusted or untrusted MEO satellite access types;

[0275] Trusted or untrusted geostationary satellite GEO satellite access type;

[0276] Other OTHERSAT satellite access types, whether trusted or untrusted.

[0277] In the case of trusted non-3GPP access, device 120 is a trusted non-3GPP access network: In one implementation, processing unit 1202 is used to connect user equipment connected to the trusted non-3GPP access network to the mobile network; wherein the user equipment is a satellite terminal that does not support New Radio (NR) and has satellite access and non-access stratum (NAS) capabilities. As an example, the non-3GPP access network is a satellite access network.

[0278] In one possible implementation, the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, with the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function being an AAA interface.

[0279] In one possible implementation, the connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

[0280] In one possible implementation, processing unit 1202 is further configured to send the Radio Access Type (RAT) to the Access and Mobility Management Function (AMF) in the N2 message via a trusted non-3GPP gateway function. In embodiments of this disclosure, the RAT type includes at least one of the following types:

[0281] Access types for untrusted or trusted LEO satellites;

[0282] Access types for medium Earth orbit (MEO) satellites, whether untrusted or trusted.

[0283] Access types for untrusted or trusted geostationary satellites in Earth orbit (GEO);

[0284] Other satellite access types, whether untrusted or trusted.

[0285] In the case of trusted non-3GPP access, device 120 is an AMF (Advanced Mobile Network): In one implementation, processing unit 1202 is used to authenticate user equipment connected to a trusted non-3GPP 3GPP access network to enable the user equipment to access the mobile network; wherein the user equipment is a satellite terminal that does not support New Radio (NR) and has satellite access and non-access stratum (NAS) capabilities. As an example, the access type for non-3GPP access is satellite access.

[0286] In one possible implementation, the processing unit 1202 is further configured to receive the Radio Access Type (RAT) type sent in the N2 message by a trusted non-3GPP gateway function in a non-3GPP access network.

[0287] In one possible implementation, the processing unit 1202 is further configured to provide the UDM with an access type and RAT type configured as non-3GPP access based on the first RAT type when registering with the Unified Data Management UDM.

[0288] In embodiments of this disclosure, the first RAT type is the RAT type received by the AMF; or, the first RAT type is the RAT type configured between the untrusted satellite access network and the AMF.

[0289] In one possible implementation, the RAT type includes at least one of the following types:

[0290] Access types for untrusted or trusted LEO satellites;

[0291] Access types for medium Earth orbit (MEO) satellites, whether untrusted or trusted.

[0292] Access types for untrusted or trusted geostationary satellites in Earth orbit (GEO);

[0293] Other satellite access types, whether untrusted or trusted.

[0294] Regarding the apparatus in the above embodiments, the specific manner in which each unit performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0295] Please see Figure 13 , Figure 13 This is a schematic diagram of another user equipment (UE) accessing a mobile network device 130 provided in this embodiment of the disclosure. Device 130 can be a UE, an N3IWF, an AMF, a trusted non-3GPP access network, a chip, chip system, or processor that supports the UE in implementing the above methods, or a chip, chip system, or processor that supports the N3IWF, AMF, or trusted non-3GPP access network in implementing the above methods. This device can be used to implement the methods described in the above method embodiments; please refer to the description in the above method embodiments for details.

[0296] Device 130 may include one or more processors 1301. Processor 1301 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, while the central processing unit may be used to control communication devices (such as base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute computer programs, and process data from computer programs.

[0297] Optionally, the device 130 may further include one or more memories 1302, which may store a computer program 1304. The processor 1301 executes the computer program 1304 to cause the device 130 to perform the methods described in the above method embodiments. Optionally, the memory 1302 may also store data. The device 130 and the memory 1302 may be provided separately or integrated together.

[0298] Optionally, the device 130 may also include a transceiver 1305 and an antenna 1306. The transceiver 1305 may be referred to as a transceiver unit, transceiver, or transceiver circuit, etc., and is used to implement the transceiver function. The transceiver 1305 may include a receiver and a transmitter. The receiver may be referred to as a receiver or receiving circuit, etc., and is used to implement the receiving function; the transmitter may be referred to as a transmitter or transmitting circuit, etc., and is used to implement the transmitting function.

[0299] Optionally, the device 130 may further include one or more interface circuits 1307. The interface circuits 1307 are used to receive code instructions and transmit them to the processor 1301. The processor 1301 executes the code instructions to cause the device 130 to perform the methods described in the above method embodiments.

[0300] In one implementation, the processor 1301 may include a transceiver for implementing receive and transmit functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing receive and transmit functions may be separate or integrated. The aforementioned transceiver circuit, interface, or interface circuit can be used for reading and writing code / data, or it can be used for transmitting or relaying signals.

[0301] In one implementation, processor 1301 may store a computer program that runs on processor 1301, causing device 130 to perform the methods described in the above method embodiments. The computer program may be embedded in processor 1301; in this case, processor 1301 may be implemented in hardware.

[0302] In one implementation, device 130 may include circuitry capable of performing the transmitting, receiving, or communicating functions described in the foregoing method embodiments. The processor and transceiver described in this disclosure can be implemented on integrated circuits (ICs), analog ICs, radio frequency integrated circuits (RFICs), mixed-signal ICs, application-specific integrated circuits (ASICs), printed circuit boards (PCBs), electronic devices, etc. The processor and transceiver can also be manufactured using various IC process technologies, such as complementary metal oxide semiconductors (CMOS), n-metal-oxide-semiconductor (NMOS), positive-channel metal oxide semiconductors (PMOS), bipolar junction transistors (BJTs), bipolar CMOS (BiCMOS), silicon germanium (SiGe), gallium arsenide (GaAs), etc.

[0303] The apparatus described in the above embodiments may be a network device or a terminal device (such as the first terminal device in the foregoing method embodiments), but the scope of the apparatus described in this disclosure is not limited thereto, and the structure of the apparatus may vary. Figure 13 The device may be a standalone device or part of a larger device. For example, the device may be:

[0304] (1) Independent integrated circuit IC, or chip, or chip system or subsystem;

[0305] (2) A collection of one or more ICs, optionally including storage components for storing data and computer programs;

[0306] (3) ASIC, such as modem;

[0307] (4) Modules that can be embedded in other devices;

[0308] (5) Receivers, terminal equipment, smart terminal equipment, cellular phones, wireless equipment, handheld devices, mobile units, vehicle-mounted equipment, network equipment, cloud equipment, artificial intelligence equipment, etc.

[0309] (6) Others, etc.

[0310] Those skilled in the art will also understand that the various illustrative logical blocks and steps listed in the embodiments of this disclosure can be implemented by electronic hardware, computer software, or a combination of both. Whether such functionality is implemented in hardware or software depends on the specific application and the overall system design requirements. Those skilled in the art can implement the described functionality using various methods for each specific application, but such implementation should not be construed as exceeding the scope of protection of the embodiments of this disclosure.

[0311] This disclosure also provides a system for a user equipment to access a mobile network, the system comprising the aforementioned... Figure 12 The embodiments include the device as a user equipment, the device as an N3IWF, and the device as an AMF; or, the system includes the aforementioned. Figure 13 The embodiments include a device as a user equipment, a device as an N3IWF, and a device as an AMF.

[0312] This disclosure also provides another system for user equipment to access a mobile network, the system including the aforementioned Figure 12 The embodiments include devices as user equipment, devices as trusted non-3GPP access networks, and devices as AMFs; or, the system includes the aforementioned. Figure 13 The embodiments include a device as a user equipment, a device as a trusted non-3GPP access network, and a device as an AMF.

[0313] This disclosure also provides a readable storage medium having instructions stored thereon that, when executed by a computer, implement the functions of any of the above method embodiments.

[0314] This disclosure also provides a computer program product that, when executed by a computer, implements the functions of any of the above method embodiments.

[0315] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0316] Those skilled in the art will understand that the various numerical designations such as "first," "second," etc., used in this disclosure are merely for the convenience of description and are not intended to limit the scope of the embodiments of this disclosure, nor do they indicate the order of events.

[0317] At least one in this disclosure can also be described as one or more, and multiple can be two, three, four or more, and this disclosure does not impose any limitation. In the embodiments of this disclosure, for a technical feature, the technical features in that technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", etc., and there is no sequential order or size order among the technical features described by "first", "second", "third", "A", "B", "C" and "D".

[0318] The correspondences shown in the tables of this disclosure can be configured or predefined. The values ​​of the information in each table are merely examples and can be configured to other values; this disclosure is not limiting. When configuring the correspondences between information and parameters, it is not necessarily required to configure all the correspondences shown in each table. For example, the correspondences shown in some rows of the tables in this disclosure may not be configured. Furthermore, appropriate modifications and adjustments can be made based on the above tables, such as splitting, merging, etc. The names of the parameters shown in the headers of the above tables can also use other names that the communication device can understand, and the values ​​or representations of the parameters can also be other values ​​or representations that the communication device can understand. In the implementation of the above tables, other data structures can also be used, such as arrays, queues, containers, stacks, linear lists, pointers, linked lists, trees, graphs, structures, classes, heaps, hash tables, or hash tables, etc.

[0319] The predefined terms in this disclosure can be understood as defined, predefined, stored, pre-stored, pre-negotiated, pre-configured, solidified, or pre-burned.

[0320] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0321] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0322] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.< / mcc> < / mnc>

Claims

1. A method for a user equipment to access a mobile network, characterized in that, The method is performed by the user equipment, and the method includes: The user equipment is connected to the mobile network through an untrusted or trusted non-3GPP access network; The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. Accessing the user equipment to the mobile network via an untrusted non-3GPP access network includes: The authentication process connects to the untrusted non-3GPP access network. When the user equipment decides to connect to the 5G core network, it selects the non-3GPP interoperability function N3IWF in the 5G public terrestrial mobile network PLMN. An Internet Security Protocol (IPsec) tunnel is established with the selected N3IWF, and during the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network. Accessing the user equipment to the mobile network via a trusted non-3GPP access network includes: Connect to the trusted non-3GPP access network; The process based on the Extensible Authentication Protocol (EAP) registers with the 5G core network through the trusted non-3GPP access network. The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation; the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

2. The method as described in claim 1, characterized in that, The connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

3. The method according to any one of claims 1 to 2, characterized in that, The method of connecting the user equipment to the mobile network via an untrusted or trusted non-3GPP access network includes: Based on the pre-configured information in the user equipment, the user equipment is selected to access the mobile network via an untrusted or trusted non-3GPP access network.

4. The method as described in claim 3, characterized in that, The non-3GPP access network is a satellite access network; the pre-configuration information includes the combination information of the satellite access and the 5G core network.

5. A method for a user equipment to access a mobile network, characterized in that, The method is performed by the non-3GPP interoperability function N3IWF, and the method includes: User equipment connected to an untrusted non-3GPP access network is connected to the mobile network. The user equipment is connected to the untrusted non-3GPP access network during the authentication process. The non-3GPP interoperability function N3IWF is the N3IWF selected by the user equipment in the 5G public terrestrial mobile network (PLMN) when deciding to connect to the 5G core network. The user equipment is a satellite terminal that does not support New Radio (NR) and has satellite access and non-access stratum (NAS) capabilities. The N3IWF establishes an IPsec tunnel with the terminal device. During the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network.

6. The method as described in claim 5, characterized in that, The non-3GPP access network is satellite access.

7. The method as described in claim 5 or 6, characterized in that, In the process of connecting a user equipment connected to an untrusted non-3GPP access network to the mobile network, the method further includes: In the N2 message, the Radio Access Type (RAT) is sent to the Access and Mobility Management Function (AMF).

8. The method as described in claim 7, characterized in that, The RAT type includes at least one of the following types: Trusted or untrusted LEO satellite access types; Trusted or untrusted MEO satellite access types; Trusted or untrusted geostationary satellite GEO satellite access type; Other satellites, whether trusted or untrusted, are available for OTHERSAT satellite access.

9. A method for a user equipment to access a mobile network, characterized in that, The method is performed by the Access and Mobility Management Function (AMF), and the method includes: Authenticate user equipment connected to an untrusted non-3GPP access network to enable access to the mobile network via the non-3GPP interoperability function N3IWF; or Authenticate user equipment connected to a trusted non-3GPP access network to enable access to the mobile network; The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. Wherein, the user equipment accesses the mobile network through an untrusted non-3GPP access network, including: The authentication process connects to the untrusted non-3GPP access network. When the user equipment decides to connect to the 5G core network, it selects the non-3GPP interoperability function N3IWF in the 5G public terrestrial mobile network PLMN. An Internet Security Protocol (IPsec) tunnel is established with the selected N3IWF, and during the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network. The user equipment accesses the mobile network through a trusted non-3GPP access network, including: Connect to the trusted non-3GPP access network; The process based on the Extensible Authentication Protocol (EAP) registers with the 5G core network through the trusted non-3GPP access network. The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation; the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

10. The method as described in claim 9, characterized in that, Also includes: When authenticating a user equipment connected to an untrusted non-3GPP access network, the Radio Access Type (RAT) type sent by the N3IWF in the N2 message is received; or When authenticating a user equipment connected to a trusted non-3GPP access network, the Radio Access Type (RAT) type is received in the N2 message from a trusted non-3GPP gateway function within the non-3GPP access network.

11. The method as described in claim 9 or 10, characterized in that, Also includes: When registering with the Unified Data Management (UDM), the UDM is provided with an access type and RAT type configured as non-3GPP access based on the first RAT type.

12. The method as described in claim 11, characterized in that, The non-3GPP access type is satellite access.

13. The method as described in claim 12, characterized in that, The first RAT type is the RAT type received by the AMF; or, The first RAT type is the RAT type configured between the untrusted satellite access network and the AMF.

14. The method according to any one of claims 10 to 13, characterized in that, The RAT type includes at least one of the following types: Trusted or untrusted LEO satellite access types; Trusted or untrusted MEO satellite access types; Trusted or untrusted geostationary satellite GEO satellite access type; Other OTHERSAT satellite access types, whether trusted or untrusted.

15. A method for a user equipment to access a mobile network, characterized in that, The method is performed by a trusted non-3GPP access network, and the method includes: User equipment connected to the trusted non-3GPP access network is connected to the mobile network; The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation. The trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function. The interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface. The user equipment registers with the 5G core network through the trusted non-3GPP access network based on the Extensible Authentication Protocol (EAP).

16. The method as described in claim 15, characterized in that, The non-3GPP access network is satellite access.

17. The method as described in claim 15, characterized in that, The connection between the user equipment and the trusted non-3GPP access point is a satellite connection between the user equipment and the satellite.

18. The method as described in claim 15 or 17, characterized in that, Also includes: The Radio Access Type (RAT) is sent to the Access and Mobility Management Function (AMF) in the N2 message via a trusted non-3GPP gateway function.

19. The method as described in claim 18, characterized in that, The RAT type includes at least one of the following types: Access types for untrusted or trusted LEO satellites; Access types for medium Earth orbit (MEO) satellites, whether untrusted or trusted. Access types for untrusted or trusted geostationary satellites in Earth orbit (GEO); Other satellite access types, whether untrusted or trusted.

20. An apparatus for user equipment to access a mobile network, characterized in that, The device is configured on the user equipment, and the device includes: A processing unit is configured to connect the user equipment to the mobile network via an untrusted or trusted non-3GPP access network. The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. Accessing the user equipment to the mobile network via an untrusted non-3GPP access network includes: The authentication process connects to the untrusted non-3GPP access network. When the user equipment decides to connect to the 5G core network, it selects the non-3GPP interoperability function N3IWF in the 5G public terrestrial mobile network PLMN. An Internet Security Protocol (IPsec) tunnel is established with the selected N3IWF, and during the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network. Accessing the user equipment to the mobile network via a trusted non-3GPP access network includes: Connect to the trusted non-3GPP access network; The process based on the Extensible Authentication Protocol (EAP) registers with the 5G core network through the trusted non-3GPP access network. The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation; the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

21. An apparatus for user equipment to access a mobile network, characterized in that, The device is configured on a non-3GPP interoperability function N3IWF, and the device includes: The processing unit is used to connect a user equipment connected to an untrusted non-3GPP access network to the mobile network. The user equipment is connected to the untrusted non-3GPP access network during the authentication process. The non-3GPP interoperability function N3IWF is the N3IWF selected by the user equipment in the 5G public terrestrial mobile network PLMN when deciding to connect to the 5G core network. The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. The N3IWF establishes an IPsec tunnel with the terminal device. During the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network.

22. An apparatus for user equipment to access a mobile network, characterized in that, The device is configured on the Access and Mobility Management Function (AMF), and the device includes: Processing unit, configured to authenticate user equipment connected to an untrusted non-3GPP access network, so as to enable the user equipment to access the mobile network via the non-3GPP interoperability function N3IWF; or Used to authenticate user equipment connected to a trusted non-3GPP access network in order to access the mobile network; The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. Wherein, the user equipment accesses the mobile network through an untrusted non-3GPP access network, including: The authentication process connects to the untrusted non-3GPP access network. When the user equipment decides to connect to the 5G core network, it selects the non-3GPP interoperability function N3IWF in the 5G public terrestrial mobile network PLMN. An Internet Security Protocol (IPsec) tunnel is established with the selected N3IWF, and during the establishment of the IPsec tunnel, the user equipment will be authenticated by the 5G core network and attached to the 5G core network. The user equipment accesses the mobile network through a trusted non-3GPP access network, including: Connect to the trusted non-3GPP access network; The process based on the Extensible Authentication Protocol (EAP) registers with the 5G core network through the trusted non-3GPP access network. The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation; the trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function, and the interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface.

23. An apparatus for user equipment to access a mobile network, characterized in that, The device is configured on a trusted non-3GPP access network, and the device includes: Processing unit, configured to connect user equipment connected to the trusted non-3GPP access network to the mobile network; The user equipment is a satellite terminal that does not support New Radio (NR), and the user equipment has satellite access and non-access stratum (NAS) capabilities. The link between the user equipment and the trusted non-3GPP access network is a data link that supports EAP encapsulation. The trusted non-3GPP access network includes a trusted non-3GPP access point and a trusted non-3GPP gateway function. The interface between the trusted non-3GPP access point and the trusted non-3GPP gateway function is an AAA interface. The user equipment registers with the 5G core network through the trusted non-3GPP access network based on the Extensible Authentication Protocol (EAP).

24. A system for user equipment to access a mobile network, characterized in that, The system includes a user equipment, a non-3GPP interoperability function (N3IWF), and an access and mobility management function (AMF), wherein the user equipment performs the method as described in any one of claims 1 to 4, the N3IWF performs the method as described in any one of claims 5 to 8, and the AMF performs the method as described in any one of claims 9 to 14.

25. A system for user equipment to access a mobile network, characterized in that, The system includes a user equipment, a trusted non-3GPP access network, and an access and mobility management function (AMF), wherein the user equipment performs the method as described in any one of claims 1 to 4, the AMF performs the method as described in any one of claims 9 to 14, and the trusted non-3GPP access network performs the method as described in any one of claims 15 to 19.

26. A device for a satellite terminal to access a mobile network, characterized in that, The device includes a processor and a memory, the memory storing a computer program, the processor executing the computer program stored in the memory to cause the device to perform the method as claimed in any one of claims 1 to 4, or to cause the device to perform the method as claimed in any one of claims 5 to 8, or to cause the device to perform the method as claimed in any one of claims 9 to 14, or to cause the device to perform the method as claimed in any one of claims 15 to 19.

27. A computer-readable storage medium for storing instructions that, when executed, cause the method of any one of claims 1 to 4 to be implemented, or cause the method of any one of claims 5 to 8 to be implemented, or cause the method of any one of claims 9 to 14 to be implemented, or cause the method of any one of claims 15 to 19 to be implemented.