Method and device for activating 5G user
By receiving and processing the message of authentication requests in the core network entity of the 5G system, and using information in unified data management to determine the terminal connection permissions, the problem of difficulty in permission assignment in the 5G system is solved, and user experience optimization and multi-operator service provision are achieved.
Patent Information
- Application Number
- CN202510160356.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-08-12
- Filing Date
- 2020-09-28
- Publication Date
- 2025-05-13
AI Technical Summary
In current 5G systems, the permissions of the terminal are assigned based on subscriber information, making it difficult to optimize performance and provide an improved user experience through user identifiers, especially providing services to devices and users other than 3GPP operators.
By receiving a message requesting authentication of the second terminal in the core network entity of the wireless communication system, the information in Unified Data Management (UDM) is used to determine whether the second terminal can be connected to the first terminal, and the authentication result message is sent. If the second terminal is able to connect, an authentication result message is sent to the first terminal.
It realizes activation of 5G user ID through user identifiers, optimizes network configuration information, provides improved user experience, and provides services to devices and users other than 3GPP operators.
Smart Images

Figure CN119996997A_ABST
Abstract
Description
[0001] This application is a divisional application of a patent application with an application date of September 28, 2020, application number 2020800686344, and invention name “Method and device for activating 5G users”. Technical Field
[0002] The present disclosure relates to a wireless communication system, and more particularly, to a method for activating a 5G user through a subscriber terminal in a cellular mobile communication system (5G system). Background Art
[0003] In order to meet the demand for wireless data services that has increased since the deployment of the fourth generation (4G) communication system, efforts have been made to develop an improved fifth generation (5G) or pre-5G communication system. Therefore, the 5G or pre-5G communication system is also referred to as a "beyond 4G network" communication system or a "post-Long Term Evolution (post-LTE)" system.
[0004] 5G communication systems are considered to be implemented in ultra-high frequency (mmWave) bands (e.g., 60 GHz bands) in order to achieve higher data rates. In order to reduce the propagation loss of radio waves in the ultra-high frequency bands and increase the transmission distance, beamforming, massive multiple-input multiple-output (MIMO), full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and massive antenna technologies are discussed in 5G communication systems.
[0005] In addition, in the 5G communication system, development for system network improvement is being carried out based on advanced small cells, cloud radio access network (RAN), ultra-dense network, device-to-device (D2D) communication, wireless backhaul, mobile network, cooperative communication, coordinated multi-point (CoMP), receiving-end interference cancellation, etc.
[0006] In 5G systems, hybrid FSK and QAM modulation (FQAM) and sliding window superposition coding (SWSC) have also been developed as advanced coding modulation (ACM), and filter bank multi-carrier (FBMC), non-orthogonal multiple access (NOMA) and sparse code multiple access (SCMA) as advanced access technologies.
[0007] For the 5G system, research is being conducted to support a wider range of services than the existing 4G system. For example, the most representative services of the 5G system include enhanced mobile broadband (eMBB) service, ultra-reliable low-latency communication (URLLC) service, massive machine type communication (mMTC) service, evolved multimedia broadcast / multicast service (eMBMS), etc. In addition, a system for providing URLLC services may be referred to as a URLLC system, and a system for providing eMBB services may be referred to as an eMBB system. In addition, the terms "service" and "system" may be used interchangeably.
[0008] Among these services, the URLLC service is a service that is reconsidered in the 5G system compared to the existing 4G system and is required to meet ultra-high reliability (e.g., a packet error rate of about 10-5) and low latency (e.g., about 0.5msec) conditions compared to other services. In order to meet such strict requirements, the URLLC service may need to apply a transmission time interval (TTI) shorter than that of the eMBB service, and various operation methods using this are under consideration.
[0009] The Internet, which is a human-centered connected network in which humans generate and consume information, is now evolving toward the Internet of Things (IoT) in which distributed entities such as things exchange and process information without human intervention. The Internet of Everything (IoE), which is a combination of IoT technology and big data processing technology connected to a cloud server, has emerged. As IoT implementations have required technical elements such as "sensing technology", "wired / wireless communication and network infrastructure", "service interface technology", and "security technology", sensor networks, machine-to-machine (M2M) communications, machine type communications (MTC), etc. have been recently studied.
[0010] Such an IoT environment can provide intelligent Internet technology services that create new value for human life by collecting and analyzing data generated among connected things. IoT can be applied to various fields including smart homes, smart buildings, smart cities, smart cars or connected cars, smart grids, health care, smart appliances, and advanced medical services through the integration and combination between existing information technology (IT) and various industrial applications.
[0011] In line with this, various attempts have been made to apply 5G communication systems to IoT networks. For example, technologies such as sensor networks, machine type communications (MTC), and machine-to-machine (M2M) communications can be implemented through beamforming, MIMO, and array antennas. Cloud radio access networks (RANs) as an application of the above-mentioned big data processing technology can also be considered as an example of the fusion of 5G technology and IoT technology.
[0012] At the same time, 3GPP, which is responsible for cellular mobile communication standards, has named the new core network structure 5G Core (5GC) and standardized it to complete the evolution from the existing 4G LTE system to the 5G system.
[0013] Compared with the Evolved Packet Core (EPC), which is the network core of the existing 4G network, 5GC supports the following differentiated functions.
[0014] First, the network slicing function is introduced in 5GC. As a 5G requirement, 5GC needs to support a wide variety of terminal types and services. Examples are enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), and massive machine type communication (mMTC). Such terminals / services have different requirements for the corresponding core networks. For example, eMBB services require high data rates, and URLLC services require high stability and low latency. The technology proposed to meet such various service requirements is the network slicing solution.
[0015] The network slicing scheme obtains multiple logical networks through the virtualization of a single physical network, and each network slice instance (NSI) can have different characteristics. Therefore, each NSI has a network function (NF) suitable for the characteristics, thereby meeting various service requirements. An NSI suitable for the characteristics of the required service can be allocated to each terminal, thereby efficiently supporting various 5G services.
[0016] Secondly, 5GC can promote network virtualization support by separating the mobility management function and the session management function. In the existing 4G LTE, each terminal is able to receive services from the network by exchanging signals with a single core device called the Mobility Management Entity (MME), which is responsible for registration, authentication, mobility management, and session management functions. However, 5G has an exponentially growing number of terminals and a detailed classification of mobility and service / session characteristics to be supported according to terminal type, and if a single device such as MME supports all functions, the scalability for adding entities for each necessary function is inevitably degraded. Therefore, various functions are being developed based on a structure that separates the mobility management function and the session management function in order to improve scalability in terms of signaling load and function / implementation complexity of the core device responsible for the control plane. Summary of the invention
[0017]
Technical issues
[0018] The technical subjects pursued in the present disclosure may not be limited to the above-mentioned technical subjects, and other technical subjects not mentioned may be clearly understood by those skilled in the art to which the present disclosure belongs through the following description.
[0019] [Solution to the problem] According to one aspect, according to an embodiment of the present disclosure, a method performed by a core network entity in a wireless communication system may include: receiving a first message from a first terminal requesting authentication of a second terminal, the first message including an identifier of the second terminal that has requested to be connected to the first terminal; determining whether the second terminal is able to connect to the first terminal based on at least one of information about the first terminal, information about the second terminal, or authentication information about the second terminal obtained from a unified data management (UDM); and if the second terminal is able to connect to the first terminal, sending a second message including an authentication result to the first terminal.
[0020] Additionally, the core network entity may be an Access and Mobility Management Function (AMF) or a Session Management Function (SMF).
[0021] In addition, the method may further include: sending a third message requesting information about the first terminal to the UDM; and receiving a fourth message including the information about the first terminal from the UDM.
[0022] In addition, the method may further include: performing authentication of the second terminal to the server; and receiving a response message including authentication information for the second terminal from the server.
[0023] In addition, the method may further include: sending a fifth message requesting information about the second terminal to a network entity associated with the second terminal; and receiving a sixth message including the information about the second terminal from the network entity associated with the second terminal.
[0024] In addition, the network entity associated with the second terminal may be at least one of the UDM, a policy and control function (PCF), or a UDM associated with the second terminal.
[0025] In accordance with another aspect, according to an embodiment of the present disclosure, a core network entity in a wireless communication system may include: a transceiver; and a controller, the controller being configured to: receive a first message requesting authentication of a second terminal from a first terminal through the transceiver, the first message including an identifier of the second terminal that has requested to be connected to the first terminal, determine whether the second terminal can be connected to the first terminal based on at least one of information about the first terminal, information about the second terminal, or authentication information about the second terminal obtained from a unified data management (UDM), and if the second terminal can be connected to the first terminal, send a second message including an authentication result to the first terminal through the transceiver.
[0026] [Beneficial effects of the invention] If the terminal requests activation of the 5G user ID at the request of an application or user in the terminal, the AMF may confirm whether the user is an authorized user by using UDM, may perform necessary authentication, may receive profile information about the 5G user ID of the terminal, and may transmit the authorized profile information to the UE, thereby activating the 5G user ID.
[0027] In addition, embodiments of the present disclosure may provide a method for configuring a network by using network configuration information about a user ID different from subscriber information provided by a subscriber terminal. In addition, embodiments of the present disclosure may provide a function for generating a connection between a subscriber terminal and a user and stopping the connection.
[0028] Advantageous effects that may be obtained from the present disclosure may not be limited to the above-mentioned effects, and other effects that are not mentioned may be clearly understood by those skilled in the art to which the present disclosure belongs through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 is a diagram showing a network architecture of a 5G system according to an embodiment of the present disclosure.
[0030] Figure 2 is a diagram showing a network structure for 5G users according to an embodiment of the present disclosure.
[0031] Figure 3 is a diagram illustrating a process of activating a 5G user by using a registration process for registering a UE with a 5G system according to an embodiment of the present disclosure.
[0032] Figure 4 is a diagram illustrating a process in which a UE requests 5G user authentication and user authentication information from a 5G system according to an embodiment of the present disclosure.
[0033] Figure 5is a diagram illustrating a process for authenticating a 5G user of a UE according to an embodiment of the present disclosure.
[0034] Figure 6a and Figure 6b It is a user profile update process disclosed by AF according to an embodiment of the present disclosure.
[0035] Figure 7 This is a 5G user confirmation process according to an embodiment of the present disclosure.
[0036] Figure 8 It is a description of the 5G ProSe UE to network relay session model.
[0037] Fig. 9 An example of a remote UE authentication and usage permission method controlled by a network in a dedicated relay session model according to an embodiment of the present disclosure is shown.
[0038] Fig.10 An example of a usage permission operation of a remote UE in the case of a shared relay session model according to an embodiment of the present disclosure is shown.
[0039] Fig.11 is a diagram showing a configuration of a UE according to the present disclosure.
[0040] Fig.12 is a diagram showing a configuration of a network entity according to the present disclosure. DETAILED DESCRIPTION
[0041] Hereinafter, embodiments of the present disclosure will be described in detail in conjunction with the accompanying drawings. In addition, when describing the present disclosure, when it is determined that the description may make the subject matter of the present disclosure unnecessarily unclear, the detailed description of the known functions or configurations incorporated herein will be omitted. The terms to be described below are terms defined in consideration of the functions in the disclosure, and may be different according to the user, the user's intention or habit. Therefore, the terms should be defined based on the content throughout this specification. In the following description, a base station is an entity that allocates resources to a terminal, and may be at least one of an eNode B (eNB), a Node B, a base station (BS), a radio access network (RAN), an access network (AN), a RAN node, a NR NB, a gNB, a radio access unit, a base station controller, and a node on a network. The terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smart phone, a computer, or a multimedia system capable of performing a communication function. In the present disclosure, "downlink" refers to a radio link via which a base station sends a signal to a terminal, and "uplink" refers to a radio link via which a terminal sends a signal to a base station. In addition, in the following description of the embodiments of the present disclosure, the LTE or LTE-A system will be described by way of example, but the embodiments of the present disclosure may be applied to other communication systems having similar technical backgrounds or channel types. In addition, based on determinations made by those skilled in the art, the embodiments of the present disclosure may also be applied to other communication systems with some modifications without significantly departing from the scope of the present disclosure.
[0042] Figure 1 is a diagram showing a network architecture of a 5G system according to an embodiment of the present disclosure.
[0043] The unit for performing each function provided by the 5G network system can be defined as a network function (NF). The structure of the 5G mobile communication network is Figure 1. A representative NF includes an access and mobility management function (AMF) 120 for managing network access and mobility of a user equipment (UE) 110, a session management function (SMF) 130 for performing session-related functions for the UE, a user plane function (UPF) 125 responsible for the delivery of user data and controlled by the SMF, an application function (AF) 180 for communicating with the 5GC to obtain provisioning, a network exposure function (NEF) 170 supporting communication between the 5GC and the AF 180, a unified data management (UDM) and a unified data repository (UDR) 160 for data storage and management, a policy and control function (PCF) 150 for managing policies, and a data network (DN) 140 (e.g., the Internet through which user data is delivered). In addition to the NF, there may also be an operation, maintenance, and management (OAM) (not shown) as a system for managing UEs and 5G mobile communication networks. Session information includes QoS information, charging information, and packet processing information. In addition, the 5G network system may further include a base station 115 , an authentication server function (AUSF) 165 , a network slice selection function (NSSF) 175 , and a network repository function (NRF) 155 .
[0044] Figure 2 is a diagram showing a 5G network architecture supporting 5G user ID according to an embodiment of the present disclosure.
[0045] The 5G user ID may be different from the subscription permanent identifier managed by the 5G system. In this case, the user may refer to an actual user (person) using the subscriber UE, an application running in the UE, an application running together with the UE, or a device connected to the backend of the subscriber UE (e.g., a gateway UE).
[0046] The 5G user ID can be used to identify the user (person) using the subscriber UE. In this case, the user can identify the user through the user interface of the subscriber UE and access the 5G network through the authentication process or use permission process required in the 5G network through the user identification information and the user's credential information. The 5G user ID can be used to identify the application running on the subscriber UE. When the subscriber UE works as a gateway UE, the 5G user ID can be used to identify the device connected to the gateway UE.
[0047] According to an embodiment, in Figure 2 In the architecture supporting 5G users shown, several different users can share one subscriber UE. In addition, a function can be provided to automatically change the service configuration (i.e., user profile) preconfigured by the mobile communication service provider according to the user configuration. In order to provide this function, the user must be identified in a different way from the existing subscription identifier. The 5G user ID can be used for this purpose.
[0048] For example, in a household, a mother subscribes to operator TTT and a son can surf the Internet using his mother's tablet. Both mother and son can use the network of the TTT operator to use the Internet. However, the mother and son each have different user identifiers, and different service configurations can be used for each user identifier. For example, when a mother applies for youth protection services, and when accessed with her son's identifier, she can protect her son from the impact of traffic to a specific site.
[0049] For example, when the son uses the fingerprint sensor of the tablet (UE) to unlock the tablet and tries to use the tablet, the son can select his own user account and perform a user authentication process for his own user account. The user authentication process can be performed in the operator network and the UE.
[0050] If the user authentication is successful through the 3GPP network, the son is able to use the Internet.User-specific configurations (eg, web filters) in the operator's network may be managed individually for each user or may be linked to subscriber information subscribed by his mother.
[0051] If the son who used the Internet does not use the tablet thereafter, the tablet may be automatically locked after a certain period of time and the user's account may be deactivated.
[0052] After that, when the user (son) uses the tablet again, the user account can be reactivated with a simple process. The network communication configuration is configured for each user, so, for example, if the son makes a call using the logged-in tablet, he can make a call to his own phone number.
[0053] After this, when the mother unlocks the tablet again and selects her user account, the tablet and the network can perform authentication. In this case, service configuration information such as web filters can be reconfigured to the mother's user profile information.
[0054] According to an embodiment, in Figure 2 In the illustrated architecture supporting 5G users, a method may be provided in which an operator operates as an identity provider to enable automatic login and single sign-on to the operator's services or services provided by the operator's partners.
[0055] For example, the first user is a subscriber of operator TTT and he can log in to the user account with his subscriber UE. That is, the user account of the first user can be successfully authenticated by the 3GPP system. In addition, if the first user has an account of K Bank, and when the first user opens the K Bank account, the K Bank account may have been linked to the user account of operator TTT.
[0056] In this case, the first user can use the first user's subscriber UE to replace the authentication required in the online banking service of K Bank. The first user has been authenticated with the first user's user account in the 3GPP system. Based on this trust level, the K Bank system can authorize the first user's request to access the bank account without the first user using additional credentials to authenticate by the following facts: the first user is using his subscribed UE, the first user authenticated the user using the user login process, and the subscriber UE is in the same location as the first user's home address.
[0057] Thereafter, when the first user requests to use the money transfer service through the banking system, the banking system may perform a stronger re-authentication process (eg, authentication through fingerprint recognition, etc.) to confirm that the user using the subscriber UE in the 3GPP system is a genuine user.
[0058] A user profile identified by a 5G User ID may have the following attributes.
[0059] ● User type: user (person), application or device connected to the backend of the gateway UE ●Whether and how to require certification ● Scope of use: within the mobile operator or service provider identifier ●User-specific configuration ●Subscription profile information for each user: This information may be the content or part of the subscription information for each subscriber of the UDM, and more specifically, may be access and mobility subscription information such as user-specific allowed areas and user-specific restricted areas, or session management related subscription information such as user-subscribed single network slice selection assistance information (S-NSSAI) and user-subscribed data network name (DNN). The subscription profile information for each user may include information such as access and mobility management (AM) subscription information and session management (SM) subscription information, as well as whether activation is allowed in a roaming operator, a list of agreed operators that can be activated, etc.
[0060] ● Billing profile per user: online or offline billing method ●User-specific configuration information or profiles for external use The 5G user ID disclosed in the present disclosure may be managed in the form of a General Public Subscription Identifier (GPSI).
[0061] <First Embodiment> The first embodiment of the present disclosure is a method for activating a 5G user. Such a process follows Figure 3 The process shown.
[0062] A user, device or application identified by a 5G user ID can perform a 5G user activation process to access a mobile communication network using a mobile communication subscriber UE. This 5G user activation process can be performed by utilizing a registration process of the subscriber UE.
[0063] The subscriber UE may start the 5G user activation process in the following circumstances.
[0064] ● User activated request via the user interface (e.g. user login) ● Requests from devices connected to the subscriber UE ● Requests from applications running on the subscriber UE ● Requests from applications running on devices connected to the subscriber UE The subscriber UE may send an indicator for requesting 5G user activation, an identifier of the 5G user, and an identifier of the subscriber UE (e.g., Subscription Hidden Identifier (SUCI)) to the AMF. The 5G user activation request refers to a request by a 5G user specified by the 5G user identifier for permission to use the subscriber UE to access the mobile communication operator network.
[0065] When the AMF receives a 5G user activation request from a subscriber UE, the AMF determines whether the 5G user is able to use the 5G network through the subscriber UE that has sent the request message.
[0066] 1) UDM may pre-store the subscribed 5G user identifiers allowed for each subscriber UE. The AMF may determine whether to allow the requested 5G user ID activation by requesting subscription information about the subscriber ID from the UDM and identifying whether the subscribed 5G user identity information exists in the subscription information received from the UDM.
[0067] 2) AMF may determine whether activation of the 5G user ID requires additional authentication of the 5G user based on the operator's unique configuration (local configuration) or configuration information included in the subscription information received through the UDM. In this embodiment, the configuration information included in the subscription information corresponds to a user authentication profile. If additional authentication is required, the AMF initiates an authentication process for the 5G user identifier. When the authentication performed with the authentication server for the 5G user ID is successfully performed, the AMF may determine that the activation of the 5G user ID is to be allowed by using the subscriber UE that has sent the 5G user activation request message. If the authentication is unsuccessful, the AMF may reject the request to activate the 5G user ID.
[0068] 3) AMF can verify and determine the additional conditions for 5G user activation from UDM in order to determine the activation of 5G users. The additional conditions may include accessed radio access technology (RAT) information, accessed radio frequency information, roaming status, accessed UE location information (location information on the network), accessible time information, and the maximum number of 5G users that the subscriber UE can activate simultaneously. AMF determines whether to activate the 5G user by verifying the additional conditions.
[0069] If the AMF determines that the activation request of the 5G user is to be approved, the AMF may request a separate 5G user profile for the 5G user ID from the UDM. If the storage device storing the 5G user profile is stored in a separate storage device other than the UDM, the AMF may receive the 5G user profile information from a separate 5G user profile storage device within the operator or an external storage device.
[0070] When the AMF determines whether to approve the 5G user's activation request, the AMF may deliver the result of the 5G user activation request (e.g., activation success / failure) to the subscriber UE. If the 5G user activation request is successful and the UE requires the 5G user's profile, the AMF may deliver the 5G user profile context information to the UE.
[0071] More detailed process follows Figure 3 The detailed process is as follows.
[0072] Figure 3 is a diagram illustrating a process for activating a 5G user by using a registration process for registering a UE with a 5G system according to an embodiment of the present disclosure.
[0073] In step 310, UE 301 may send a registration request message including a 5G user activation request indicator and a 5G user identifier to be activated to AMF 302. The registration request message sent by UE 301 to AMF 302 may be sent through a base station (RAN) (not shown).
[0074] In step 315, the AMF 302 may perform authentication of the subscriber UE, if necessary.
[0075] In step 320, AMF 302 may send a request message to UDM 303 to request subscription information of the subscriber UE. The request message may include an identifier (eg, a subscription permanent identifier (SUPI)) of the subscriber UE 301. In addition, the request message may be an SDM get request message.
[0076] In addition, in step 330, UDM 303 may transmit subscription information of subscriber UE 301 stored together with the identifier of subscriber UE 301 to AMF 302. In this case, the subscription information may be sent to AMF 302 by being included in a response message, and the response message may be an SDM get response message. The subscription information may include the following information.
[0077] ●Registered 5G user IDs or a list of registered 5G user identifiers ●5G user authentication profile: whether authentication is performed, authentication method, available credentials, authentication server address ● Wildcard 5G User ID: This is an indicator indicating whether activation of a 5G user ID that is not explicitly registered is allowed. Upon receiving a request for a 5G user ID that is not included in the list of explicitly subscribed 5G user identifiers, the AMF 302 that receives this indicator can determine whether to allow it based on the authentication result from the external server.
[0078] ●User profile subscribed by 5G user identifier: User profile information of 5G user identifier, such as S-NSSAI, subscription AMBR and allowed area.
[0079] Upon receiving the request message from AMF 302 in step 320, UDM 303 may determine whether UE 301 is roaming through the request message from AMF 302 in step 325. UDM 303 may determine whether 5G user activation is allowed during roaming according to a policy of the home operator network, an agreement with the visited operator, or configuration information stored in UDM 303. When UE 301 is in a roaming state and 5G user activation in the service network of UDM 303 is not allowed, UDM 303 may reject the request for 5G user activation. When UDM 303 rejects the activation of the 5G user, UDM 303 may send a response message to AMF 302 in step 330 without including a subscribed 5G user ID. Alternatively, when UDM 303 rejects the activation of the 5G user, UDM 303 may include an indicator that 5G user activation is not supported in the roaming state in the response message of step 330 and deliver the response message to AMF 302.
[0080] According to an embodiment, in step 310, UE 301 may request activation of a 5G user and may not deliver a 5G user ID. When AMF 302 receives a 5G user activation request in step 310 but does not receive a 5G user ID, AMF 302 may request a 5G user ID from subscriber UE 301 in step 340. UE 301 may receive the 5G user ID request and, in response thereto, may send the 5G user ID to AMF 302 in step 345.
[0081] In step 350, when it is determined that authentication is required for 5G user activation by an operator policy or local configuration, when authentication is specified in the 5G user authentication profile information received from the UDM 303, or when the 5G user identifier requested by the UE 301 is not included in the subscribed 5G user list but the wildcard 5G user identifier information is in the subscription information, the AMF 302 may perform an additional 5G user authentication procedure. The additional 5G user authentication procedure may be performed through an Extensible Authentication Protocol (EAP) procedure, and the 5G user ID may be included in all procedures. In addition, the authentication procedure for the 5G user may be as follows Figure 5 The operation is described in more detail in .
[0082] Figure 5 is a diagram illustrating a process for authenticating a 5G user of a UE according to an embodiment of the present disclosure.
[0083] refer to Figure 5 , the AMF 302 and 502 may determine an authentication server (Authentication, Authorization, and Accounting (AAA)) 306, 504, and 505 to perform 5G user authentication according to a 5G user identifier, preconfiguration information, or user authentication profile information received from the UDM 303. The AMF 302 and 502 initiates the authentication process by delivering a message requesting authentication initiation to the authentication server 306, 504, and 505. The authentication server 306, 504, and 505 may perform the authentication process together with the UE 301 and 501, the AMF 302 and 502, and the AUSF 305 and 503. When the authentication is successfully completed, the authentication server 306, 504, and 505 may send a message including content of authentication success to the AMF 302 and 502. When the authentication fails, the authentication server 306, 504, and 505 may send a message including an authentication result notifying the AMF 302 and 502 of the authentication failure. In addition, AMF 302 and 502 can send a message including the authentication result to UE 301 and 501.
[0084] More specifically, in step 510, the AMF 502 may determine that an additional 5G user authentication process is required.
[0085] In step 515, the AMF 502 may send a NAS MM message including an EAP ID Request to the UE 501. In step 520, the AMF 502 may receive a NAS MM message including an EAP ID Response from the UE 501.
[0086] In step 525, the AMF 502 may send an EAP messaging message including the EAP ID response, the authentication server address, and the 5G user ID received from the UE 501 to the AUSF 503. In step 530, the AUSF 503 may send an EAP messaging message to the authentication server (AAA-P) 504. The EAP messaging message sent to the authentication server (AAA-P) 504 may include the EAP ID response, the authentication server address, the 5G user ID, the S-NSSAI, etc.
[0087] In step 535 , AAA-P 504 may issue an authentication request to AAA-H 505 , and in step 540 , AAA-H 505 may send an authentication response thereto to AAA-P 504 .
[0088] In step 545, AAA-P 504 may send an EAP messaging response to AUSF 503 in response to the EAP messaging message sent in step 530, and the response message may include an EAP message, a 5G user ID, an S-NSSAI, etc. In step 550, AUSF 503 may send an EAP messaging response to AMF 502, and the response message may include an EAP message, a 5G user ID, an S-NSSAI, etc.
[0089] In step 555, the AMF 502 may send a NAS MM message including an EAP message to the UE 501. In step 560, the UE 501 may send a NAS MM message including an EAP message to the AMF (502).
[0090] In step 565, the AMF 502 may send an EAP messaging message including the EAP message received from the UE 501, the authentication server address, the 5G user ID, etc. to the AUSF 503. In step 570, the AUSF 503 may send an EAP messaging message to the authentication server (AAA-P) 504.
[0091] In step 575, AAA-P 504 may make an authentication request to AAA-H 505, and in step 580, AAA-H 505 may send an authentication response to AAA-P 504. The authentication response may include information about whether EAP is performed successfully or failed, 5G user ID, S-NSSAI, etc.
[0092] In step 585, AAA-P 504 may send an EAP messaging response to AUSF 503 in response to the EAP messaging message sent in step 570, and the response message may include information about whether EAP is successfully performed or failed, 5G user ID, S-NSSAI, etc. In step 590, AUSF 503 may send an EAP messaging response to AMF 502, and the response message may include information about whether EAP is successfully performed or failed, 5G user ID, S-NSSAI, etc.
[0093] In step 595, the AMF 502 may send a NASMM message including information about EAP success or failure to the UE 501.
[0094] Return to reference Figure 3 In step 355, AMF 302 may ultimately determine whether to activate the requested 5G user by identifying a subscribed 5G user identifier or a list of 5G user identifiers connected to the subscriber UE 301, circumstances when authentication is required, whether authentication is successful, roaming status, whether the 5G user is located in a licensed area, whether the RAT accessed by the 5G user is allowed access, and whether the maximum user ID is allowed in the subscriber UE.
[0095] In step 360, if the AMF 302 determines that the 5G user of the subscriber UE 301 is to be activated and the user profile of the 5G user identifier is not received in advance, the AMF 302 may request the user profile of the 5G user identifier from the UDM 303. The UDM 303 may receive the 5G user identifier in step 365 and send the 5G user profile corresponding to the 5G identifier to the AMF 302. According to an embodiment, if the operator has a separate 5G user profile storage device other than the UDM 303, the AMF 302 may request the 5G user profile from a designated 5G user profile server (not shown) instead of the UDM 303. The 5G user profile may include the following information.
[0096] Individual 5G user profiles may include the following information, such as Figure 2 The 5G user profile data (separate DB) is illustrated in the example.
[0097] 5G user identifier (or user profile index) ● Access and mobility management profiles for each user: S-NSSAI, allowed zones, RFID index and allowed RAT information ● Session management profile for each user: DNN, AMBR (aggregate maximum bit rate) and subscription QoS profile information • Profile Provider Identifier: The identifier of the service provider associated with the profile, and can be the Home Network Operator, Visited Network Operator, or a third party service provider.
[0098] The above-mentioned 5G user profile information may be stored in the UDM 303 and may be managed by the UDM 303 or a separate network function that manages user profiles.
[0099] In step 370, the AMF 302 may send a UECM registration request message to the UDM 303. If the AMF 302 permits activation of the 5G user ID requested by the UE 301, the AMF 302 may include the 5G user ID in the UECM registration message and send it to the UDM 303. In step 375, the UDM 303 may send a UECM registration response message to the registration request to the AMF 302. The UDM 303 stores whether the 5G user ID was activated when the subscriber UE 301 was registered. Thereafter, in the process in which another NF identifies to the UDM 303 whether the 5G user ID is activated, information on whether the 5G user ID stored in the UDM 303 is activated may be provided to another NF.
[0100] If the AMF 302 determines the activation of the 5G user ID of the subscriber UE 301 in step 380, the AMF 302 may request an access and mobility (AM) policy for the 5G user ID from the PCF 304 according to the local policy. In addition, the AMF 302 may receive the AM policy for the 5G user ID from the PCF 304. According to the local policy, the AMF 302 may perform an AM policy association procedure with the (V-) PCF 304.
[0101] If the AMF 302 has not previously obtained an access and mobility (AM) policy for the 5G user ID, and determines that a separate AM profile application for the 5G user ID is necessary, or the AM policy for the subscriber in the AMF 302 is no longer valid, the AMF 302 may receive the operator policy for the UE 301 from the PCF 304 and apply the operator policy. The AMF 302 may request a connection for AM policy control from the (V-)PCF 304. The request message may include a subscriber UE identifier (e.g., SUPI), a 5G user identifier, an internal group identifier, a subscription notification indicator, a service area restriction, an RFSP index, a subscribing UE AMBR, an allowed NSSAI, a GPSI received from the UDM 303, and access type, RAT, PEI, UE location information, UE time zone, serving network information, etc.
[0102] In response, the (V-)PCF 304 may deliver the AM policy (e.g., service area restriction information) to the AMF 302. In addition, the (V-)PCF 304 may send a policy control request trigger for the AM policy to the AMF 302. The AMF 302 subscribes to a notification service that implicitly requests notification of changed information when the policy changes in the PCF 304, and the AMF may receive notifications from the (V-)PCF 304 when the policy changes in the (V-)PCF 304.
[0103] AMF 302 may apply an AM policy. Applying an AM policy includes the following operations.
[0104] ●Storage service regional restrictions and PCRT (Policy Control Report Trigger), ●Provide service area restriction information to UE 301.
[0105] ●Provide RFSP index, UE-AMBR and service area restriction information to RAN.
[0106] In step 385, AMF 302 may send the result of whether 5G user activation is permitted in step 355 to UE 301 in the 5G user activation result information. The registration permission message includes the service area restriction information of the subscriber UE 301 and the service area restriction information of the 5G user, and may be delivered to UE 301.
[0107] In step 390, AMF 302 may establish a connection with PCF 304 to send the UE policy. AMF 302 may deliver the 5G user ID to PCF 304 so that PCF 304 further includes the UE policy for the 5G user ID in the UE policy including the URSP (UE routing policy) and ANSP delivered to UE 301, and delivers the UE policy. In addition to the 5G user ID, AMF 302 may also send an indicator to PCF 304 requesting delivery of the UE policy for the 5G user ID.
[0108] The PCF 304 receives an indicator requesting delivery of a 5G user ID or a UE policy for the 5G user ID in the UE policy-related connection request message received from the AMF 302, and can identify the UE policy for the 5G user ID. The PCF 304 identifies the UE policy for the 5G user ID and the UE policy for the subscriber UE (SUPI), identifies whether the two policies conflict, and can generate a UE policy to which the two types of policies can be reflected. In addition, the PCF 304 delivers the regenerated UE policy to the UE 301.
[0109] Meanwhile, according to an embodiment, when the registration of the 5G user (or UE) 301 permitted to be registered is released, the UDM 303 may delete the 5G user profile information.
[0110] <Second Embodiment> In this embodiment, a process of a method for a UE to request generation of 5G verification information for a user ID in a 5G core network and to generate verification information for the requested 5G user ID is described.
[0111] Figure 4 is a diagram illustrating a process in which a UE requests 5G user authentication and user authentication information from a 5G system according to an embodiment of the present disclosure.
[0112] When a user requests to use subscriber UE 401, an application running on subscriber UE 401, or subscriber UE 401 operates as a gateway UE, subscriber UE 401 receives a request from a device connected to the backend of the gateway UE or an application running on the device, and initiates a 5G user authentication information generation request process.
[0113] refer to Figure 4 In step 410, the subscriber UE 401 may send a request message including an indicator for requesting generation of user authentication information in a registration request message, a user identifier, and a subscriber identifier (e.g., SUCI, 5G-GUTI, SUPI, etc.) to the AMF 402. According to an embodiment, the 5G user identifier may be omitted from the request message.
[0114] In step 410, if the subscriber UE 401 does not send the 5G user identifier to the AMF 402, the AMF 402 may send a message requesting a 5G identifier to the subscriber UE 401 in order to obtain the 5G user identifier in step 415. The subscriber UE 401 may receive the user identifier request message in step 520 and send a user identifier for a 5G user confirmation request to the AMF 402. The AMF 402 may obtain the 5G user identifier from the subscriber UE 401.
[0115] The AMF 402 may receive a user authentication information generation request, a subscriber identifier (e.g., SUCI, 5G-GUTI, SUPI, etc.), and a user identifier from the subscriber UE 401, and may initiate an authentication procedure for the subscriber. In step 425, the AMF (SEAF) 402 may send an authentication request message to the AUSF 403. The authentication request message may include an identifier (SUCI or SUPI) of the subscriber UE 401, a serving network name, a 5G user identifier, and a 5G user key generation request indicator, and may send the authentication request message to the AUSF 403.
[0116] The AUSF 402 may receive the authentication request message from the AMF (SEAF) 402 and may request authentication information of the subscriber UE 401 from the UDM 404 in step 430 . In step 435 , the AUSF 403 may receive a 5G authentication vector (5G HE AV: Home Environment Authentication Vector) from the UDM 404 .
[0117] AUSF 403 may receive an authentication request message, a 5G user key generation request, and a 5G user identifier of subscriber UE 401 from AMF 402, and may receive a 5G authentication vector of subscriber UE 401 from UDM 404. In addition, using this, in step 440, AUSF 403 may generate a key (K for the 5G user identifier) 5guser ).
[0118] In step 445 , the AUSF 403 may send the 5G authentication vector to the AMF (SEAF) 402 .
[0119] In step 450, AMF 402 may send RAND, AUTH, ngKGI and ABBA parameters to UE 401.
[0120] UE 401 may send a response to the authentication request to AMF 402 in step 455. In this case, the response message may include RES .
[0121] AMF 402 may, in step 460, Include RES in the authentication request message Sent to AUSF 403.
[0122] AUSF 403 Computing RES , verifies whether the response received from UE 401 is appropriate, and can determine whether the authentication of subscriber UE 401 is successful.
[0123] If the AUSF 403 determines that the authentication of the UE 401 is successful, and the 5G user identifier and key generation request are received in the previous step 425, then in step 470, the AUSF 403 may send a 5G user identifier and key generation request to the UDM 404 including the generated user key (K 5guser ), user identifier and subscriber UE identifier to request UDM 404 to store the key for the regenerated 5G user.
[0124] In step 475, the AUSF 403 may send an authentication response message to the AMF 402, which includes an authentication result indicating whether the authentication has been successfully performed, a key (Kseaf) to be used in the AMF (SEAF) 402, a subscriber identifier, and a 5G user key generation result indicating whether the 5G user key is successfully generated in the authentication response message and the 5G user identifier.
[0125] In step 480, AMF 402 may send a request for subscriber information of subscriber UE 401 to UDM 404. In addition, in step 483, AMF 402 receives permission information from UDM 404 regarding whether to allow generation of 5G user authentication information for each 5G user identifier and a list of 5G user identifiers of subscribed subscriber UEs or to expose the generated user authentication information to the outside.
[0126] AMF 402 may determine whether to generate authentication information for a 5G user by verifying the information received from UDM 404. More specifically, AMF 402 may determine whether to generate 5G user authentication information by identifying whether the 5G user requested by subscriber UE 401 is a subscribed user received from UDM 404, subscription information about whether separate key generation for the 5G user is allowed, and self-configuration information of the operator. When AMF 402 determines that 5G user authentication information is to be generated, AMF 402 may send a 5G user authentication information generation request to UDM 404 in step 485.
[0127] In step 485, the UDM (404) that has received the 5G user authentication information generation request from the AMF (402) may identify the user profile information of the UDR (not shown) storing the user profile managed by the UDM 404 and generate the 5G user authentication information in step 490. The 5G user authentication information may include information such as a 5G user identifier, an application identifier using the 5G user identifier, 5G application service provider information and application organization information required by the 5G user, access information of an application connected to the subscriber UE to access a server of the service provider (e.g., URL, etc.). The UDM 404 may generate the 5G user authentication information and transmit the generated 5G user authentication information to the AMF 402 in step 493.
[0128] In step 493, AMF 402 may receive 5G user authentication information in response to the 5G user generation request from UDM 404. In step 495, AMF 402, which has successfully received the 5G user authentication information from UDM 404, sends a 5G user authentication result and 5G user authentication information indicating whether the 5G user confirmation is successful to UE 401.
[0129] According to an embodiment, in step 493, if authentication of the subscriber UE 401 has failed in step 475, the AUSF has failed to authenticate the user, the AUSF has failed to generate a user key, or as a result of the AMF 402 identifying the subscription information of the UDM 404, if the 5G user requested by the subscribing UE 401 is not subscribed, or if the subscribing UE 401 fails to verify an additional 5G user, etc., then the AMF 402 may notify the UE 402 including information indicating that the 5G user verification result has failed.
[0130] Subscriber UE 401 may receive the 5G user confirmation result and the 5G user verification information.
[0131] According to an embodiment, when the registration of the 5G user (or UE) 401 permitted to be registered is released, the UDM 404 may delete the 5G user authentication information.
[0132] <Third Embodiment> In this embodiment, a method of supplying a user profile from outside the 3GPP system network or from an Application Function (AF) agreed with a 3GPP operator will be described.
[0133] Figure 6a and Figure 6b It is a user profile update process disclosed by AF according to an embodiment of the present disclosure.
[0134] exist Figure 2In the structure shown, the user profile can be managed by the UDM or a separate independent NF that manages the user profile, and the user profile information can be stored in the UDR.
[0135] like Figure 6a and Figure 6b As shown, AF 608 may generate or change the user profile information disclosed in the present disclosure. In addition, AF 608 may associate the 5G user ID with the subscriber UE identified by GPSI. Alternatively, in step 610, AF 608 may send the 5G user ID described in the present disclosure to NEF 607 in GPSI format to generate or change the profile of the subscriber UE connected to GPSI.
[0136] The NEF 607 that has been requested to generate, change, or delete a user profile from the AF 608 in step 620 may provide the user profile to the UDM 604 and request the user profile as AM subscription information, or generate, change, or delete SM subscription information from the UDM 604 using a subscriber management service provided by the UDM 601. In step 620, the NEF 607 may send a message including GPSI, 5G user ID, AM subscription information, SM subscription information, etc. to the UDM 604. The UDM 604 that has been requested to generate / change / delete a user profile in step 620 may find the corresponding subscriber information from the corresponding GPSI in step 621, and identify an organization that changes the subscriber information externally. If the subscriber information can be modified externally, the UDM 604 may execute the request to generate, change, or delete the requested user profile.
[0137] exist Figure 6a and Figure 6bIn step 610 of , the NEF 607 that has received a request for generating, modifying or deleting a user profile from the AF 608 may determine whether the corresponding information is a type of profile that requires a change in UE policy. If the information for which the NEF 607 has received a request for modification is related to a UE policy such as a URSP, the NEF 607 may find the SUPI information from the GPSI. The NEF 607 may generate, modify or delete a URSP policy for a subscriber UE 601 identified by the GPSI or SUPI in the UDR. The URSP policy may include information such as a service descriptor (OSId, OSAppID, IP filter triplet, FQDN, and routing component). The service descriptor may be information such as an operating system identifier (OSID) of the UE, an application identifier (OSAppID), an IP destination address and port (IP triplet; i.e., an IP address, a layer 4 port number, and a protocol ID), a destination fully qualified domain name (FQDN), and a DNN (or APN). Additionally, the routing component may have values such as DNN (or APN), S-NSSAI, PDU session type (ie, IPv4, IPv6, or IPv4v6, Ethernet type, or unstructured data), and SSC mode. UE policies may include ANDSP policies.
[0138] In addition, the UDM 604 sends a UDM profile change instruction to the AMF 603 in step 623 , and thus the AMF 603 may perform a UE configuration update procedure with the UE 601 (through the RAN 602 ) in step 625 .
[0139] Additionally, UDM 604 may send a message including information on whether the UDM configuration file change has been successfully performed to NEF 607 in step 640 .
[0140] According to an embodiment, in step 610, NEF 607 may receive a request to report that the provisioning of UE policy has been completed or a message including information requesting the provisioning of UE policy to be applied from AF 608. Upon receiving the request, NEF 607 may send a corresponding request to PCF 606 in step 630.
[0141] In step 630, NEF 607 may provide PCF 606 with a user profile and request PCF 606 to generate, change, or delete a user policy provided by PCF 606. Together with this request, NEF 607 may send a message including a UE policy delivery completion report request and an immediate UE policy delivery request to PCF 606. PCF 606, which has been requested to generate, change, or delete a user policy in step 630, may search for corresponding subscriber information from the corresponding GPSI in step 631, and generate, change, or delete a policy for the corresponding user. In step 630, NEF 607 may send user policy information including GPSI, 5G user ID, and URSP policy to PCF 606. USRP policy information may include service descriptors, routing components, and the like.
[0142] The PCF 606, which has received the URSP policy of the UE 601 from the NEF 607, can obtain the existing URSP policy of the UE 601 identified by the subscriber identifier (e.g., GPSI or SUPI, etc.) of the corresponding UE 601 from the UDR 605 in step 633, and check the requested URSP rule. This check can be to determine whether it conflicts with the rules to be installed or installed in the UE or whether the requested rules comply with the operator's previous policies. In this process, the PCF 606 can determine the priority of the requested URSP rule. The PCF 606 can change the requested URSP rule or the existing URSP rule or generate a new URSP rule based on the requested URSP rule or the existing rule, and can rearrange the reconfigured URSP rules into priorities according to the operator policy and UE subscription information to determine or re-determine the priorities included in the various URSP rules. The URSP rules rearranged in this way can be reallocated in the policy part in consideration of the preconfigured NAS maximum transmission size. The reassigned policy part may be included in a UE policy container together with the operator's identifier and delivered to the UE 601 .
[0143] In addition, the PCF 606 may determine whether the requested UE policy (URSP or ANDSP) should be immediately delivered to the UE 601 in consideration of whether the immediate request indicator included in the provisioning request is included and the operator's policy. In the case where the URSP rule is as requested or a priority is added to the requested URSP rule, or in the case of a conflict with an existing policy or inconsistency with the operator's policy and subscriber information, the PCF 606 may resolve the inconsistency by changing the existing UE policy or the reinstalled UE policy, and may store the changed UE policy in the UDR 605 (step 633).
[0144] The PCF 606 may send a response message to the NF (NEF 607 in this example) that has requested the policy change of the UE 601 in step 641. If the policy for the requested UE 601 does not match the existing policy, the operator's policy, or the subscription information, the PCF 606 may deliver a result message including a failure or rejection of the provision of the UE policy to the requesting NF (NEF 607 in this example). Although it is illustrated in this embodiment that the NF requesting the PCF 606 is the NEF 607, it is also possible that the AF 608 directly requests the PCF 606. When the AF 608 requests a completion report on whether the UE 601 has been successfully provisioned with the UE policy by the NEF 607, the PCF 606 may determine whether to report the UE policy completion. In addition, when the PCF 606 determines that the UE policy completion report is to be performed, the PCF 606 may store the UE policy completion report in the PCF 606 or in the UDR 605. The PCF 606 may also respond to the NEF 607 with an indicator indicating that it has successfully subscribed to the completion reporting service.
[0145] In step 643 , the NEF 607 may deliver the provisioning result received from the PCF 606 to the AF 608 .
[0146] When PCF 606 determines in step 651 that the UE policy including URSP and ANDSP is to be immediately executed, PCF 606 may execute step 652 to immediately execute the UE policy delivery process. PCF 606 may determine that the UE policy is to be delivered while UE 601 is in the CM-CONNECTED state. In this case, PCF 606 may subscribe to the reporting service for CM state changes of UE 601 from AMF 603 in advance. In addition, if the reporting service is not subscribed in advance, PCF 606 may request AMF 603 to subscribe to the reporting service for CM state changes. If AMF 603 subscribes to the reporting service for CM state changes, PCF 606 may know the CM state of UE 601.
[0147] If the PCF 606 is configured to deliver UE policy only when the UE 601 is in the CM-CONNECTED state, the PCF 606 may know the CM state, and if the CM state is the CM-CONNECTED state, the PCF 606 may perform the UE policy delivery procedure.
[0148] When PCF 606 determines to update the UE policy, PCF 606 may send a message such as Namf_Communication_N1N2Message to AMF 603 (step 652). In this case, the message delivered to AMF 603 may include the UE policy.
[0149] According to an embodiment, a service request triggered in the network may be initiated between UE 601 and AMF 603 in step 653.
[0150] In step 654, the AMF 603 may transparently send the policy container to the UE 601 via the registered and reachable access.
[0151] When the UE 601 is in the CM-CONNECTED state through 3GPP access or non-3GPP access, the AMF 603 may transparently send the UE policy received from the PCF 606 to the UE 601. In an embodiment, the UE policy may include ANDSP and URSP.
[0152] UE 601 may update the UE policy provided from PCF 606. In addition, in step 655, UE 601 may send the update result to AMF 603. That is, UE 601 may send information about the updated policy to AMF 603.
[0153] When AMF 603 receives the UE policy and PCF 606 subscribes to receive the notified UE policy, in step 656, AMF 603 may send UE 601's response to PCF 606 using the Namf_N1MessageNotify message.
[0154] In step 660 , the PCF 606 may maintain the latest PSI list delivered from the UE 601 and update the latest PSI list of the UDR 605 by calling the Nudr_DM_Update (including SUPI, policy data, policy set item, updated PSI data, etc.) service operation.
[0155] If it is determined that the PCF 606 is subscribed to the UE policy delivery completion report, then in step 661 , the PCF 606 may notify the subscribed NF (eg, AF 608 ) whether the UE policy delivery has been successfully delivered.
[0156] When AF 608 subscribes to UE policy delivery report through NEF 607, this report may be delivered to AF 608 through NEF 607 (steps 663 and 665). Alternatively, PCF 606 may directly send the UE policy completion report based on the notification address (notification endpoint address) delivered by AF 608 upon subscription.
[0157] <Fourth Embodiment> In this embodiment, the 5G user confirmation process will be described. This embodiment describes how the AF operated by the operator or the AF of a third party that has reached an agreement with the operator identifies the 5G user information in the application layer of the UE by using the information generated in the user verification information generation process described in the second embodiment.
[0158] Figure 7 This is a 5G user identification process according to an embodiment of the present disclosure.
[0159] refer to Figure 7 In step 710, the application 702 of the UE in the subscriber UE 701 may request 5G user authentication information from the mobile terminal (MT) (or communication processor) 703 in the UE 701. The application 702 in the UE 701 may be an edge enabler client in the edge computing application layer. When the subscriber UE (UE) 701 supports AT commands by separating the MT and TE from each other, the TE may request 5G user authentication information through an AT command provided by the MT. Independent of Figure 1 As shown, as the subject requesting the 5G user identity, the user can Figure 2 The request message may include a 5G user identifier, a 5G activation request indicator, and a 5G user authentication information generation request indicator.
[0160] In step 720, when a 5G user identification request is received from an application in a UE to be identified by a 5G user, a user or a device connected to a gateway UE, or an application loaded on a device, the communication module ( Figure 7 The MT 703 or the communication processor in the subscriber UE 701 may perform the 5G user authentication information generation request process described in the second embodiment. If this process is successfully performed, the 5G user authentication information may be generated in the UDM 707. Figure 7 The MT 703 or the communication processor in the embodiment may receive a response indicating that the 5G user authentication information has been successfully generated. This may be performed together with the 5G user activation process in the first embodiment. Figure 7 Step 720.
[0161] The communication module 703 of the subscriber UE 701 that has successfully performed the 5G user identification process through step 720 may send user authentication information to the application 702 in step 730. The user authentication information may include a 5G user identification result, 5G user authentication information, a result of a 5G user activation request, and the like.
[0162] In step 710, when the device connected to the application 702, the edge enabler client, or the gateway UE receives the 5G user identification result, the application 702 may deliver an application layer message including the 5G user identifier and the 5G user authentication information to the AF 709. In this case, the application 702 may send the application layer message through the application logic.
[0163] Upon receiving the application layer message, in steps 750 and 753, AF 709 may send a 5G user identification request to UDM 707 through NEF 708 to identify whether the user is a registered user provided by the mobile communication service provider. The request message may include a 5G user identifier, GPSI, and 5G user authentication information. In addition, according to an embodiment, AF 709 agreed within the mobile communication service provider in step 755 may send a 5G user identification request directly to UDM 707 without going through NEF 708.
[0164] The UDM 707 may compare the 5G user authentication information of the 5G user identifier generated in the second embodiment with the 5G user authentication information received in steps 750 to 755, and determine whether the 5G user is permitted by the mobile communication operator. If it is determined that the 5G user request is appropriate, the UDM 707 may send a response of permitting the 5G user identifier to the AF 709 in steps 760, 763, and 765. The UDM 707 may send the response to the AF 709 via the NEF 708 (steps 760 and 763), or the UDM 707 may send the response directly to the AF 709 according to an embodiment (step 765).
[0165] In step 770, AF 709 receives the result of the 5G user identification request, and if the identification request is successfully verified, AF 709 can approve the application layer request sent by the 5G user's application 702 and send an appropriate response to the application layer request to the 5G user's application 702.
[0166] The following two embodiments are based on Figure 8 The illustrated 5G is based on the assumption of a Proximity Services (ProSe) UE to network relay session model. Figure 8The diagram depicted in is a diagram illustrating a UE-to-network relay network service provided by a remote UE via a UE-to-network relay UE via a PC5 link to a data network connected to a protocol data unit (PDU) session provided by a 5G core network. Figure 8 In the present invention, the remote UE can be connected to the UE-to-network relay through the relay UE and the PC5 (ProSe communication 5) connection, and the UE-to-network relay UE provides the remote UE with a connection to the data network through the PDU session.
[0167] Figure 8 The first model is a model in which one remote UE exclusively uses one PDU session generated by the UE-to-network relay. The UE-to-network relay provides the remote UE with a connection to the data network through one PDU session connected to the 5GC network for one remote UE. This model is called a dedicated UE-to-network relay session model (dedicated relay session model). This scenario is a scenario in which a dedicated remote UE uses a PDU session provided by the UE-to-network relay, and when the network operator runs a separate PDU session for each remote UE and provides separate billing and policies, this scenario can be usefully used when providing a connection to a separate slice or data network for each remote UE.
[0168] Figure 8 The second model is a model in which multiple remote UEs share one PDU session generated by a UE-to-network repeater. The UE-to-network repeater provides a connection to the data network to the remote UE via the UPF through multiple PC5 links connected to the multiple remote UEs for one PDU session generated together with the 5GC network. This model is called a shared UE-to-network relay session model (shared relay session model). This scenario is useful in a scenario where the UE-to-network repeater provides Internet connectivity to multiple remote UEs.
[0169] exist Figure 8 In the figure, the remote UE corresponds to the connection to Figure 2 The gateway UE (gateway terminal) is a separate device in Figure 8 The UE to network relay UE in the figure corresponds to Figure 2 Therefore, Figure 8 The 5G user ID described in is information corresponding to the remote UEID.
[0170] In addition, in the present disclosure, a network control method is described so that the network operator provides a function of allowing a remote UE to use a PDU session of a UE to a network relay. In the present disclosure, the 5GC authenticates the remote UE through information about the remote UE provided by the UE to the network relay (e.g., remote UE identifier information) and provides permission to use the remote UE. This process can be supported by the NF (e.g., SMF) in the 5G core network by identifying the subscriber information stored in the UDM, PCF or DN-AAA (Data Network Authentication Authorization Accounting) for the remote UE.
[0171] <Fifth Embodiment> In the fifth embodiment, a method of remote UE authentication and usage permission controlled by the network in a dedicated relay session model will be described. Fig. 9 Describe it.
[0172] Fig. 9 An example of a remote UE authentication and usage permission method controlled by a network in a dedicated relay session model according to an embodiment of the present disclosure is shown.
[0173] refer to Fig. 9 , steps 910 and 915 are the pre-configuration process of the remote UE 901 and the UE to the network relay 902.
[0174] A. Preconfiguration process of remote UE 901 (step 910). In the remote UE 901, information that can be used to connect to the UE-to-network relay 902 can be preconfigured. This information can be supplied to the remote UE 901 in advance through the 5GC network, or can be preconfigured in the remote UE 901 in advance. This information may include a dedicated relay session service code for finding a dedicated relay session. In addition, an appropriate UE routing policy (URSP) can be configured in the remote UE 901. For example, a ProSe UE-to-network offload indicator using a dedicated relay session model can be configured as a routing component.
[0175] B. Pre-configuration process of UE to network repeater 902 (step 915). In the UE to network repeater 902, information that can be used to manage the PC5 link can be pre-configured. This information can be supplied to the UE to network repeater 902 in advance through the 5GC network, or can be pre-configured to the UE to network repeater 902 in advance. This information is the same information as the dedicated relay session service code or the shared relay session service code, and the UE to network repeater 902 can use the pre-configuration information for the process of announcing the services provided by the UE to the network during the discovery process. The UE to network repeater 902 can be configured with a network controlled authentication / usage permission indicator. If this indicator is configured, the UE to network repeater 902 can perform the process described in the following process of the present disclosure in which the network controls the permission of the remote UE 901 for the PDU session of the UE to the network repeater 902.
[0176] Step 920 is a service discovery process for a relay service provided from the UE to the network by the remote UE 901. There may be two methods for the remote UE 901 to discover services provided by the UE to the network.
[0177] ● First, the UE-to-network relay 902 may periodically deliver the content of the service provided by itself, i.e., the relay service code, to the nearby remote UE 901 through a notification message (step 921). The relay service code may include a dedicated relay session service code in the case of a dedicated relay session model and a shared relay session service code in the case of a shared relay session model, respectively. The notification message may also include a layer 2 identifier of the UE-to-network relay 902 or an application layer identifier that provides the relay service together with the service code. The relay service code may use a separate code to indicate the relay session model. Alternatively, additional information specifying whether the relay session model is a dedicated relay session service model or a shared relay session model may be sent to the remote UE 901 through a separate indicator.
[0178] ● A second method for the remote UE 901 to discover services provided by the UE-to-network relay 902 is that the remote UE 901 first sends a discovery request message to the UE-to-network relay 902 (step 923), and then the UE-to-network relay 902 delivers the services provided by the UE-to-network relay 902 to the remote UE 901 as a response message to the requested content (step 925). The discovery request message may include and deliver a layer 2 identifier of the remote UE 901, an application layer identifier, and additional information about which service information is requested, such as a relay service code (dedicated relay session service or shared relay session service). Upon receiving the discovery request message, the UE-to-network relay 902 may deliver information about services provided by the UE-to-network relay 902 to the remote UE 901 as a discovery response message in response to the request. The response message may include information such as a relay service code, a layer 2 identifier of the UE-to-network relay 901, and an application layer identifier providing the relay service. In addition, the relay service code may use a separate code to represent a relay session model. Alternatively, additional information specifying whether the relay session model is a dedicated relay session service model or a shared relay session model may be transmitted to the remote UE 901 through a separate indicator.
[0179] In step 930, the remote UE 901 may determine direct communication request (DCR) message transmission and DCR message parameters. After the remote UE 901 discovers the UE-to-network relay 902, the remote UE 901 may initiate a process for establishing a PC5 link associated with the dedicated UE-to-network relay 902. The message of step 930 may include identifier information of the remote UE 901 (e.g., SUPI / SUCI or Layer 2 ID, etc.), a relay service code (e.g., a dedicated relay session service code, etc.), and information about parameters related to the PDU session (e.g., S-NSSAI, DNN, PDU session type, SSC mode, etc.) preset in step 910.
[0180] The remote UE 901 may determine whether to request UE-to-network relay session generation in a dedicated relay session mode or a shared relay session mode based on the content configured in step 910 .
[0181] When making a DCR request, the remote UE 901 may determine the DCR based on the content delivered from the URSP. The remote UE 901 may determine the PDU session parameters to be included in the DCR request message through information such as the state of the ProSe UE to the network relay in the non-seamless offload of the URSP, the dedicated relay session (DRS) / shared relay session (SRS) model, and in the case of DRS, through information such as PDU session parameters (e.g., S-NSSAI, DNN, PDU session type, SSC mode, etc.).
[0182] The remote UE 901 may send a direct communication request (DCR) message to the relay UE 902 found in step 920. The DCR message includes the service code configured in the remote UE 901 in step 910 and may be delivered to the relay UE 902. The service code used may include a dedicated relay PDU session service code or a shared relay PDU session service code.
[0183] The DCR message may include a Layer 3 UE to network relay session generation indicator, and a dedicated relay session service code (DRSC) or a shared relay session service code (SRSC) provided or self-configured from the 5GC in step 910.
[0184] When authentication of the remote UE (901) is provided by an application, user interaction or pre-configuration of the remote UE (901) and the capabilities of the remote UE (901), the remote UE 901 may include an indicator that authentication is possible for DCR or an indicator requesting user authentication. The remote UE 901 may request IPv4, IPv6, IPv4v6, Ethernet, and Unstructured Data as session type values in the DCR message.
[0185] In step 935, when the relay UE (i.e., UE-to-network relay) 902 receives the DCR message from the remote UE 901, the relay UE may determine permission to use the dedicated UE-to-network session according to the pre-configuration information in step 915. If the UE-to-network relay use permission indicator according to network control is configured in the UE-to-network relay UE 902 in step 915, the UE-to-network relay 902 may perform a PDU session establishment procedure so that the remote UE 901 requests permission to use the PDU session of the UE-to-network relay 902 in a dedicated mode. In this scenario, the UE-to-network relay 902 may send a request including a remote UE use permission request indicator, remote UE information (i.e., remote UE identification information, etc.), and an indicator indicating that the PDU session of the UE-to-network relay 902 is exclusively used to the SMF 905.
[0186] The relay UE 902 may determine whether to permit the use of the UE-to-network relay session. If the remote UE 901 requests the generation of a UE-to-network session including a relay service code, and the relay UE 902 is permitted to generate a UE-to-network session through information supplied to the relay UE 902, the relay UE 902 may determine the permission to use the UE-to-network. If the information supplied to the relay UE 902 includes an indicator indicating permission to use controlled by the 5GC, the relay UE 902 may determine whether the use is permitted through the PDU session generation (or change) process in the 5GC. That is, when the SMF 905 of the 5GC determines permission to use the UE-to-network session of the remote UE 901, the relay UE 902 may determine whether the use is permitted based on the decision.
[0187] The relay UE 902 may determine whether to use an existing PDU session or generate a new PDU session in consideration of the following. For example, the relay UE 902 may determine whether to generate a PDU session based on whether the DRSC is included in the content of the DCR message received by the relay UE 902 from the remote UE 901 or the 5GC network control indicator is included in the authorization information received in the relay UE 902 from the 5GC in step 915, or based on whether a PDU session matching the URSP information (in the service descriptor) received from the 5GC already exists in the relay UE 902 and whether the relay UE 902 provides the authentication relay function of the remote UE 901 in step 915. For example, if a request for generating a relay session (e.g., a dedicated relay session service code (DRSC)) is included in a direct communication request (DCR) message received from the remote UE 901 and a PDU session corresponding to the DRSC is not generated, and if the relay UE 902 has determined permission to use the relay session of the remote UE 901, the relay UE 902 may determine a request to generate a new PDU session. For another example, if a request for generating a relay session (e.g., a DRSC) is included in a DCR message received from the remote UE 901 and a PDU session corresponding to the DRSC is not generated, and if it is necessary to obtain permission to use from the 5GC for the relay UE 902 (e.g., if a network control authorization indicator is included in step 915), the relay UE 902 may determine a request to generate a PDU session. As another example, when PDU session parameters for a relay session are received in a DSR message from the remote UE 901, when a request is received in a shared relay session mode, and when a corresponding PDU session does not yet exist in the relay UE 902, the relay UE 902 may request to generate a new PDU session.
[0188] When the relay UE 902 determines the generation of the PDU session, the relay UE 902 may determine the PDU session parameters. The relay UE 902 may determine the PDU session parameters corresponding to the relay session through the service descriptor according to the URSP received in step 915 or the self-configuration of the relay UE 902. The PDU session parameters may be, for example, S-NSSAI, DNN, PDU session type, SSC mode, etc. When the relay UE 902 receives a DRSC request from the remote UE 901 and receives a PDU session parameter request from the remote UE 901, the relay UE 902 may determine the corresponding PDU session parameters. If the relay UE 902 determines the generation of the PDU session, the relay UE may send a PDU session request message to the SMF 905. In the present disclosure, the relay UE 902 has been used as the same concept as the UE to network relay UE.
[0189] In steps 940 and 945, a process for identifying subscriber information of the relay UE 902 may be performed. When the SMF 905 receives the PDU session establishment request including a request for permission to use the remote UE 901, the SMF 905 may obtain the subscription information of the UE to the network relay 902 from the UDM 906. The subscription information may include a list of allowed remote UE 901 identifier information and profile information associated with the remote UE 901. This profile information may include Figure 2 906. This profile information may include an authentication profile indicating whether secondary authentication is required. In order to obtain the profile of a specific remote UE 901, the SMF 905 may include the remote UE 901 identifier received in step 935 and the SUPI as the identifier information of the UE to the network relay 902 in the subscriber information message requesting the UDM 906 to be sent.
[0190] The subscriber information may include subscriber information about whether a relay service (UE to network relay PDU session) is provided and more specifically, whether a dedicated relay session service or a shared relay session service is provided. In addition, a list of remote UEs 901 for relay session service may be additionally written in the subscriber information. The relay session subscription information may include information about whether a dedicated relay service or a shared relay service is provided for each remote UE 901.
[0191] SMF 905 identifies subscriber information of relay UE 902. SMF 905 can be configured by itself to perform the relay session usage permission function of remote UE 901 in the 5GC core when the relay session permission for remote UE 901 is a network control method.
[0192] In step 950, an authentication process of the remote UE 901 may be performed.
[0193] Based on the authorization profile received in step 945, the SMF 905 may perform a secondary authentication / authorization process. This process may be performed together with the remote UE 901, the DN-AAA 908, and the SMF 905, and in this authentication process, the UE-to-network relay 902 may play a role of relaying authentication messages between the remote UE 901 and the SMF 905. The SMF 905 may initiate an authentication process with the remote UE 901 via the relay UE 902 so that the remote UE 901 determines permission to use the relay session. The SMF 905 may initiate an authentication process when the relay UE 902 performs network control, when a relay function of an authentication protocol for authentication of the remote UE 901 is supported, when subscriber information is received from the UDM 906, or when operator policy information received from the PCF 907 is set to require verification.
[0194] In steps 960 and 965, the SMF 905 may perform a permission procedure for using the relay session of the remote UE 901. The SMF 905 receives a policy and charging control (PCC) rule for supporting the PDU session of the remote UE 901 from the PCF 907 to the network relay 902 (step 965). In order for the SMF 905 to receive the policy of the remote UE 901, the SMF 905 may send identification information of the remote UE 901 to the PCF 907 (step 960). The PCF 907 may deliver the policy and profile for the remote UE 901 associated with the PDU session of the UE to the network relay 902 to the SMF 905 (step 965). The SMF 905 may receive the policy of the remote UE 901, and the SMF 905 may identify whether the remote UE 901 can use the corresponding PDU session.
[0195] When a dedicated relay service is provided in the profile of the remote UE 901, the separate profile of the remote UE 901 can be managed in the subscriber information or policy information of the remote UE 901 managed by the PCF 907. The SMF 905 can request the separate profile database of the remote UE 901 to identify the profile of the remote UE 901, and receive subscriber information about the PDU session parameters of the remote UE 901.
[0196] When SMF 905 receives the network controlled relay session authorization configured from PCF 907, SMF 905 can perform the relay session authorization function for the remote UE 901.
[0197] In step 970, the SMF 905 may determine permission to use the relay session of the remote UE 901 through identification of self-configuration information or subscriber information. The identification of such subscriber information may be determined through the UDM 906 or information received from the PCF 907. Alternatively, the SMF 905 may send some information included in a PDU session request to the PCF 907 to request the PCF 907 to determine whether to permit the use of the relay session, and the PCF 907 may determine whether to permit the use of the relay session and deliver the determined result to the SMF 905.
[0198] The SMF 905 may determine whether the remote UE 901 is permitted to use the UE-to-network relay PDU session based on the subscriber information and the profile information of the remote UE (901) received from the UDM (906) in step 945, the result of the authentication performed in step 950, and the policy of the remote UE 901 for associating with the UE-to-network relay session received from the PCF 907 in step 965. The SMF 905 may determine whether the requested PDU session parameters (e.g., S-NSSAI, DNN, PDU session type, etc.) are included in the profile of the remote UE 901, and determine whether to approve the request.
[0199] In step 975, if the usage permission determined by the SMF 905 in step 970 is successful, the SMF may send a UE-to-network relay PDU session generation approval message together with the usage permission approval result to the UE-to-network relay 902. If the usage permission is unsuccessful, the SMF 905 may include the reason for non-approval in a PDU session permission reject message and deliver it to the UE-to-network relay 902.
[0200] In step 975, when the remote UE 901 receives information that permits the use of the dedicated PDU session provided by the UE-to-network relay 902 and the generation of the PDU session is successful, the UE-to-network relay 902 may successfully perform the generation of the PC5 link in step 980. If the remote UE 901 has failed in permitting the use of the UE-to-network relay session, the UE-to-network relay 902 may reject the generation of the PC5 link.
[0201] In step 985, this process may be performed when the UE to the network relay 902 performs a separate IP allocation process such as Dynamic Host Configuration Protocol (DHCP) or IPv6 Stateless Address Auto-Configuration (SLAAC).
[0202] In step 990, the UE to network relay 902 may report to the SMF 905 the range of TCP / UDP port addresses assigned to the remote UE 901 in the case of IPv4, including the assigned IPv6 address when NAT (Network Address Translation) is used, and report the Ethernet MAC address of the remote UE 901 to the SMF 905 in the remote UE information when Ethernet is used.
[0203] <Sixth Embodiment> Will pass Fig.10 The sixth embodiment is described in detail in the process of Figure 8 The shared relay session model described in the preceding paragraphs is used to allow the remote UE to operate with permission.
[0204] The operation of this embodiment is basically consistent with that of the fifth embodiment, and unless otherwise specified, it can be understood that the parts designated as dedicated relay session service code, dedicated relay session or dedicated relay session model in the fifth embodiment are replaced with shared relay session service code, shared relay session or shared relay session model in this embodiment, respectively.
[0205] Regardless of this, parts that are different from the fifth embodiment or need to be supplemented by the fifth embodiment are specified below for each individual process.
[0206] Fig.10 An example of a usage permission operation of a remote UE in the case of a shared relay session model according to an embodiment of the present disclosure is shown.
[0207] refer to Fig.10 , except that all contents corresponding to the dedicated relay session are replaced with the shared relay session, steps 1010 and 1015 are the same as those related to the fifth embodiment. Fig. 9 Steps 910 and 915 are the same. In addition, in this embodiment, step 1017 may be performed. Based on the information set in advance in step 1015, the UE to network relay 1002 may generate a PDU session in advance in step 1017 as a shared session model.
[0208] Step 1020 and Fig. 9 The illustrated step 920 is the same. However, the dedicated repeater may be understood to be replaced with a shared repeater.
[0209] Step 1030 and Fig. 9 The illustrated step 930 is the same. However, the dedicated repeater may be understood to be replaced with a shared repeater.
[0210] When the relay UE (i.e., UE-to-network relay) 1002 receives the DCR message from the remote UE 1001 in step 1030, the relay UE 1002 may determine permission to use the common UE-to-network session in step 1035 according to the information configured in advance in step 1015. If the UE-to-network relay use permission indicator according to network control is set in the UE-to-network relay UE 1002 in step 1015, the UE-to-network relay 1002 may perform a PDU session creation procedure so that the remote UE 1001 requests permission to use the PDU session of the UE-to-network relay 1002 in the public mode. In this scenario, the UE-to-network relay may send a request to the SMF 1005, the request including the remote UE use permission request indicator, the remote UE 1001 information (i.e., remote UE identification information, etc.), and an indicator that the PDU session of the UE-to-network relay 1002 is used in common.
[0211] The message delivered by the UE to the network relay 1002 to the SMF 1005 in this process can be sent while being included in the PDU session change request message. In this case, the PDU session change request message can include a remote UE authorization request indicator.
[0212] Steps 1040 to 1065 and Fig. 9 The steps 940 to 965 shown are the same. However, the dedicated repeater may be understood to be replaced with a shared repeater.
[0213] Step 1070 and Fig. 9 The steps 7075 shown are the same. However, the permission to use the PDU session parameters does not apply in this embodiment.
[0214] If the usage authorization determined by the SMF 1005 in step 7070 is successful, then in step 1075, the SMF 1005 may send a remote UE authorization response message together with the usage authorization approval result to the UE to network relay 1002. If the usage authorization is unsuccessful, the SMF 1005 may include the unapproved cause in the remote UE authorization response message to the UE to network relay 1002. This message may be delivered together with the PDU session modification command message.
[0215] In step 1075, when the remote UE 1001 receives information that permission to use the common PDU session provided by the UE-to-network relay 1002 is successful, the UE-to-network relay 1002 may successfully perform generation of the PC5 link in step 1080. If the remote UE 1001 fails to obtain permission to use the UE-to-network relay session, the UE-to-network relay 1002 may reject generation of the PC5 link.
[0216] Steps 1085 to 1090 with reference Fig. 9 The steps 985 to 990 described are the same. However, the dedicated repeater may be understood to be replaced with a shared repeater.
[0217] Fig.11 is a diagram showing a configuration of a UE according to the present disclosure.
[0218] refer to Fig.11 , the UE according to an embodiment of the present disclosure may include a transceiver 1120 and a controller 1110 that controls the overall operation of the UE. In addition, the transceiver 1120 may include a transmitter 1121 and a receiver 1123.
[0219] The transceiver 1120 may transmit / receive signals to / from other network entities.
[0220] The controller 1110 may control the UE to perform any one of the above embodiments. The controller 1110 and the transceiver 1120 do not necessarily have to be implemented as separate modules, and may be implemented as a single component in the form of a single chip. In addition, the controller 1110 and the transceiver 1120 may be electrically connected. In addition, for example, the controller 1110 may be a circuit, a dedicated circuit, or at least one processor. In addition, the operation of the UE may be implemented by providing a memory device storing a corresponding program code in any component in the UE.
[0221] Fig.12 is a diagram showing a configuration of a network entity according to the present disclosure.
[0222] The network entity of the present disclosure is a concept including network functions according to system implementation manners.
[0223] refer to Fig.12 , the network entity according to an embodiment of the present disclosure may include a transceiver 1220 and a controller 1210 that controls the overall operation of the network entity. In addition, the transceiver 1220 may include a transmitter 1121 and a receiver 1123.
[0224] The transceiver 1220 may transmit / receive signals to / from other network entities.
[0225] The controller 1210 may control the network entity to perform any one of the above embodiments. The controller 1210 and the transceiver 1220 do not necessarily have to be implemented as separate modules, and may be implemented as a single component in the form of a single chip. In addition, the controller 1210 and the transceiver 1220 may be electrically connected. In addition, for example, the controller 1210 may be a circuit, a dedicated circuit, or at least one processor. In addition, the operation of the network entity may be implemented by providing a memory device storing a corresponding program code in any component of the network entity.
[0226] The network entity can be any one of a base station (RAN), AMF, SMF, UPF, PCF, NF, NEF, NRF, NSSF, UDM, UDR, AF, DN, AUSF, SCP, UDSF, context storage device, OAM, EMS, AAA-P and AAA-H.
[0227] It should be noted that Figures 1 to 12 The configuration diagrams, control / data signal transmission methods, operation processes, and configuration diagrams shown are not intended to limit the scope of the present disclosure. That is, Figures 1 to 12 All components, entities, or operational steps described in the disclosure should not be construed as essential components for implementing the present disclosure, but even including some components, the present disclosure can be implemented within a scope that does not impair the essence of the present disclosure.
[0228] The operations of the above-mentioned base station or UE can be implemented by providing a memory device storing corresponding program codes in any component in the base station or UE device. That is, the controller of the base station or UE device can execute the above-mentioned operations by reading and executing the program codes stored in the memory device by a processor or a central processing unit (CPU).
[0229] The various components and modules of the entities, base stations or UE devices described in the present disclosure may be operated using hardware circuits such as, for example, complementary metal oxide semiconductor-based logic circuits, firmware, software and / or hardware and a combination of firmware and / or software embedded in a machine-readable medium. As an example, various electrical structures and methods may be implemented using circuits such as transistors, logic gates, and special semiconductors.
[0230] Although specific embodiments have been described in the detailed description of the present disclosure, various modifications and changes may be made thereto without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be defined as limited to the embodiments, but should be defined by the appended claims and their equivalents.
Claims
1. A method performed by a network open function entity in a wireless communication system, the method comprising: receiving from the application function AF a first request comprising user profile information related to a user equipment routing policy URSP; sending a second request associated with the user profile information related to the URSP to the unified data management (UDM); receiving from the UDM a result of a second request to create or change user profile information associated with the URSP; as well as The user profile information related to the URSP is sent to the policy and control function PCF.
2. The method according to claim 1, in, The user profile information related to the URSP includes at least one of a service descriptor or a routing parameter, and The routing selection parameters include at least one of a data network name DNN or a single network slice selection auxiliary S-NSSAI.
3. The method according to claim 1, in, The first request includes subscription information for notifying a result of the first request.
4. The method according to claim 3, further comprising: receiving a result of the first request from the PCF; as well as Sending a result of the first request to the AF.
5. A method performed by a policy and control function (PCF) entity in a wireless communication system, the method comprising: receiving user profile information related to the user equipment routing policy URSP from the network exposure function NEF; Creating or changing URSP rules based on existing URSP rules and user profile information associated with the URSP; and Perform UE policy delivery procedures.
6. The method according to claim 5, in, The user profile information related to the URSP includes at least one of a service descriptor or a routing parameter, and The routing selection parameters include at least one of a data network name DNN or a single network slice selection auxiliary S-NSSAI.
7. The method according to claim 5, further comprising: The result of the UE policy delivery process is sent to the NEF.
8. A network open function (NEF) entity in a wireless communication system, the NEF entity comprising: Transceiver; as well as A controller, the controller being configured to: receiving from the application function AF a first request comprising user profile information related to a user equipment routing policy URSP; Sending a second request associated with the user profile information related to the URSP to the unified data management (UDM); receiving from the UDM a result of a second request to create or change user profile information associated with the URSP; as well as The user profile information related to the URSP is sent to the policy and control function PCF.
9. The NEF entity according to claim 8, in, The user profile information related to the URSP includes at least one of a service descriptor or a routing parameter, and The routing selection parameters include at least one of a data network name DNN or a single network slice selection auxiliary S-NSSAI.
10. The NEF entity according to claim 8, in, The first request includes subscription information for notifying a result of the first request.
11. The NEF entity according to claim 10, wherein: The controller is also configured to: receiving a result of the first request from the PCF, and Sending a result of the first request to the AF.
12. A policy and control function (PCF) entity in a wireless communication system, the PCF comprising: Transceiver; as well as A controller, the controller being configured to: receiving user profile information related to the user equipment routing policy URSP from the network exposure function NEF; Creating or changing URSP rules based on existing URSP rules and user profile information associated with the URSP; and Perform UE policy delivery procedures.
13. The PCF entity according to claim 12, in, The user profile information related to the URSP includes at least one of a service descriptor or a routing parameter, and The routing selection parameters include at least one of a data network name DNN or a single network slice selection auxiliary S-NSSAI.
14. The PCF entity according to claim 12, wherein the controller is further configured to: The result of the UE policy delivery process is sent to the NEF.