Registration enhancements for multiple access
By executing specific processor instructions in terminal devices and network devices, the serial number race conditions and EAP authentication session management problems in the registration enhancement and network slice selection authentication and authorization process in multi-access technology are solved, and a more efficient and stable registration process is achieved.
Patent Information
- Application Number
- CN202280100721.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-16
- Publication Date
- 2025-05-13
Smart Images

Figure CN119999249A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments relate to the field of communications, and in particular to devices, methods, apparatuses, and computer-readable storage media for registration enhancement for multiple access. Background Art
[0002] Registration via multiple access technologies may occur in new communication systems, which may also involve a Network Slice Selection Authentication and Authorization (NSSAA) procedure. Registration enhancements for multiple access need to be studied. Summary of the invention
[0003] In general, example embodiments of the present disclosure provide devices, methods, apparatus, and computer-readable storage media for multi-access registration (eg, NSSAA) enhancement.
[0004] In a first aspect, a terminal device is provided. The terminal device includes: at least one processor, and at least one memory storing instructions. When the instructions are executed by the at least one processor, the terminal device at least: initiates a first registration process with a first network device of a first public land mobile network PLMN; and initiates a second registration process with a second network device of a second PLMN based on determining that the first registration process is completed.
[0005] In a second aspect, a terminal device is provided. The terminal device includes: at least one processor, and at least one memory storing instructions. When the instructions are executed by the at least one processor, the terminal device at least: receives a request message for an EAP identifier EAP ID for a second extensible authentication protocol EAP authentication from a second network device, the request message including single network slice selection auxiliary information S-NSSAI; determines that a first EAP authentication for S-NSSAI is in progress based at least in part on the request message; and sends a response message to the second network device based on the determination, the response message including an indication indicating that the first EAP authentication is in progress.
[0006] In a third aspect, a second network device is provided. The second network device includes: at least one processor, and at least one memory storing instructions. When the instructions are executed by the at least one processor, the second network device at least: sends a request message for an EAP identity EAP ID for a second extensible authentication protocol EAP authentication to a terminal network device, the request message including single network slice selection auxiliary information S-NSSAI; and receives a response message from the terminal network device, the response message including an indication that a first EAP authentication for S-NSSAI is in progress.
[0007] In a fourth aspect, a second network device is provided. The second network device includes: at least one processor, and at least one memory storing instructions. When the instructions are executed by the at least one processor, the second network device at least: sends an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device to a third network device, the authentication request message at least including: single network slice selection auxiliary information S-NSSAI, and a general public subscription identifier GPSI; and receives an authentication rejection message from the third network device, the first authentication rejection message at least including: S-NSSAI, and an indication that a first NSSAA for S-NSSAI is in progress.
[0008] In a fifth aspect, a third network device is provided. The third network device includes: at least one processor, and at least one memory storing instructions. When the instructions are executed by the at least one processor, the third network device at least: receives an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device from a second network device, the authentication request message at least including: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and determines, based at least in part on the authentication request message, that a first NSSAA of the terminal device for the S-NSSAI is in progress, and the first NSSAA is associated with the first network device.
[0009] In a sixth aspect, a third network device is provided. The third network device includes: at least one processor, and at least one memory storing instructions. When the instructions are executed by at least one processor, the third network device at least: receives an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device from a second network device, the authentication request message at least including: single network slice selection auxiliary information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; and sends a first authentication protocol message to a fourth network device, the first authentication protocol message at least including: S-NSSAI, first AMF information, and GPSI.
[0010] In a seventh aspect, a fourth network device is provided. The fourth network device includes: at least one processor, and at least one memory storing instructions, which, when executed by the at least one processor, causes the fourth network device to at least: receive a first authentication protocol message for a second extensible authentication protocol EAP authentication of a terminal device from a third network device, the first authentication protocol message at least including: single network slice selection auxiliary information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; determine that a first EAP authentication of the terminal device for S-NSSAI is in progress based at least in part on the first authentication protocol message; and send a second authentication protocol message to the third network device, the second authentication protocol message at least including: S-NSSAI, first AMF information, GPSI, and an indication that the first EAP authentication is in progress.
[0011] In an eighth aspect, a method is provided, comprising: initiating a first registration process with a first network device of a first public land mobile network (PLMN) at a terminal device; and initiating a second registration process with a second network device of a second PLMN based on determining that the first registration process is completed.
[0012] In a ninth aspect, a method is provided. The method includes: receiving, at a terminal device, a request message for an EAP identity EAP ID for a second extensible authentication protocol EAP authentication from a second network device, the request message including single network slice selection auxiliary information S-NSSAI; determining, based at least in part on the request message, that a first EAP authentication for the S-NSSAI is in progress; and sending a response message to the second network device based on the determination, the response message including an indication that the first EAP authentication is in progress.
[0013] In a tenth aspect, a method is provided. The method includes: sending a request message for an EAP identity EAP ID for a second extensible authentication protocol EAP authentication to a terminal network device at a second network device, the request message including single network slice selection auxiliary information S-NSSAI; and receiving a response message from the terminal network device, the response message including an indication that a first EAP authentication for S-NSSAI is in progress.
[0014] In an eleventh aspect, a method is provided. The method includes: sending, at a second network device, an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device to a third network device, the authentication request message including at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and receiving an authentication rejection message from the third network device, the first authentication rejection message including at least: S-NSSAI, and an indication that a first NSSAA for the S-NSSAI is in progress.
[0015] In a twelfth aspect, a method is provided. The method includes: receiving, at a third network device, an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device from a second network device, the authentication request message including at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and determining, based at least in part on the authentication request message, that a first NSSAA for the S-NSSAI of the terminal device is in progress, and the first NSSAA is associated with the first network device.
[0016] In a thirteenth aspect, a method is provided. The method includes: receiving, at a third network device, an authentication request message for a second network slice specific authentication and authorization NSSAA of a terminal device from a second network device, the authentication request message including at least: single network slice selection auxiliary information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; and sending a first authentication protocol message to a fourth network device, the first authentication protocol message including at least: S-NSSAI, first AMF information, and GPSI.
[0017] In a fourteenth aspect, a method is provided. The method includes: receiving, at a fourth network device, a first authentication protocol message for a second extensible authentication protocol EAP authentication of a terminal device from a third network device, the first authentication protocol message including at least: single network slice selection auxiliary information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; determining, based at least in part on the first authentication protocol message, that a first EAP authentication of the terminal device for S-NSSAI is in progress; and sending a second authentication protocol message to the third network device, the second authentication protocol message including at least: S-NSSAI, first AMF information, GPSI, and an indication that the first EAP authentication is in progress.
[0018] In a fifteenth aspect, an apparatus is provided, comprising means for performing the method according to the eighth, ninth, tenth, eleventh, twelfth, thirteenth or fourteenth aspect.
[0019] In a sixteenth aspect, a computer readable medium is provided, comprising program instructions. When the instructions are executed by an apparatus, the apparatus performs the method according to the eighth, ninth, tenth, eleventh, twelfth, thirteenth or fourteenth aspect.
[0020] In a seventeenth aspect, there is provided a computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least a method according to the eighth, ninth, tenth, eleventh, twelfth, thirteenth or fourteenth aspect.
[0021] In an eighteenth aspect, a device is provided. The device includes circuitry for performing the method according to the eighth, ninth, tenth, eleventh, twelfth, thirteenth or fourteenth aspect.
[0022] Other features and advantages of the embodiments of the present disclosure will also be apparent when the following description of specific embodiments is read in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of the embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The embodiments of the present disclosure are presented in the form of examples, and their advantages are explained in more detail below with reference to the accompanying drawings, in which
[0024] Figure 1A An example communication system is shown in which implementations of the present disclosure may be implemented;
[0025] Figure 1B shows an example NSSAA procedure with which some embodiments of the present disclosure may be implemented;
[0026] Figure 1C An example diagram showing a UE registered with two PLMNs or with a PLMN and a Standalone Non-Public Network (SNPN), with which certain embodiments of the present disclosure may be implemented;
[0027] Figure 1D An example diagram showing a UE registered with two PLMNs or registered with two SNPNs with which some embodiments of the present disclosure may be implemented;
[0028] Figure 1E An example diagram showing a UE registering twice in the same network, with which some embodiments of the present disclosure may be implemented;
[0029] Figure 2A An example flow chart showing an example process according to some embodiments of the present invention is shown;
[0030] Figure 2B shows an example signaling diagram showing an example process according to some embodiments of the present disclosure;
[0031] Figure 2C Another example signaling diagram showing an example process according to some embodiments of the present disclosure is shown;
[0032] Figure 2D Another example signaling diagram showing an example process according to some embodiments of the present disclosure is shown;
[0033] Figure 3 shows an example signaling diagram showing an example process of maintaining a single NSSAA session with a control registration process in accordance with some embodiments of the present disclosure;
[0034] Figure 4 shows an example signaling diagram showing an example process for a single NSSAA session controlled by a UE according to some embodiments of the present disclosure;
[0035] Figure 5 shows an example signaling diagram showing an example process for a single NSSAA session controlled by an NSSAA AF according to some embodiments of the present disclosure;
[0036] Figure 6 An example signaling diagram showing an example process for reauthentication of a single NSSAA session controlled by the NSSAAF is shown in accordance with some embodiments of the present disclosure;
[0037] Figure 7 shows an example signaling diagram showing an example process for a single NSSAA session controlled by AAA-S according to some embodiments of the present disclosure;
[0038] Figure 8 A flowchart showing an example method implemented at a terminal device according to some embodiments of the present disclosure is shown;
[0039] Fig. 9 A flowchart illustrating an example method implemented at a second network device according to some embodiments of the present disclosure;
[0040] Fig.10 A flowchart showing another example method implemented at a second network device according to some embodiments of the present disclosure is shown;
[0041] Fig.11 A flowchart illustrating an example method implemented at a third network device according to some embodiments of the present disclosure;
[0042] Fig.12 A flowchart showing another example method implemented at a third network device according to some embodiments of the present disclosure;
[0043] Fig.13A flowchart illustrating an example method implemented at a fourth network device according to some embodiments of the present disclosure;
[0044] Fig.14 shows a simplified block diagram of a device suitable for implementing an example embodiment of the present disclosure; and
[0045] Fig.15 A block diagram of an example computer-readable medium is shown in accordance with some embodiments of the present disclosure.
[0046] Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. DETAILED DESCRIPTION
[0047] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these embodiments are only for illustrative purposes, and contribute to those skilled in the art to understand and implement the present disclosure, without implying any limitation to the scope of the present disclosure. The present disclosure described herein can be implemented in various ways except for the modes described below.
[0048] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0049] References in this disclosure to "one embodiment," "an embodiment," "an example embodiment," etc. indicate that the embodiment may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. In addition, these phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in conjunction with an example embodiment, it should be considered that it is within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in conjunction with other embodiments, whether or not explicitly described.
[0050] It should be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish the functions of the various elements. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.
[0051] The term used herein is only used to describe the purpose of specific embodiment, and is not intended to limit example embodiment.As used herein, the singular form "one", "one" and "the" are also intended to include plural forms, unless the context clearly states otherwise.It will also be understood that the terms "include", "comprise", "contain", "have", "have", "include" and / or "contain", when used herein, specify the existence of the features, elements and / or components, but do not exclude the existence or addition of one or more other features, elements, components and / or their combinations.As used herein, "at least one of the following: <list of two or more elements>" and "at least one of <list of two or more elements>" and similar wording, wherein the list of two or more elements is connected by "and" or "or", representing at least any one element, or at least any two or more elements, or at least all elements.
[0052] As used in this application, the term "circuitry" may refer to one or more or all of the following:
[0053] (a) hardware circuit implementation only (e.g., implementation only in analog and / or digital circuitry) and
[0054] (b) a combination of hardware circuitry and software such as (where applicable):
[0055] (i) a combination of analog and / or digital hardware circuits and software / firmware and
[0056] (ii) any portion of hardware processor(s) with software (including digital signal processor(s), software and memory(s) that work together to enable a device (such as a mobile phone or server) to perform various functions) and
[0057] (c) Hardware circuits and / or processor(s), such as microprocessor(s) or portions of microprocessor(s), that require software (e.g., firmware) to operate, but where the software is not required for operation, the software may not be present.
[0058] This definition of circuitry applies to all uses of the term in this application, including in any claims. As a further example, as used in this application, the term "circuitry" also covers an implementation of only a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term "circuitry" also covers, for example, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in a server, cellular network device, or other computing or network device, if applicable to the particular claim element.
[0059] As used herein, the term "communication network" refers to a network that complies with any appropriate communication standard, such as a fifth generation (5G) system, long term evolution (LTE), advanced LTE (LTE-A), wideband code division multiple access (WCDMA), high speed packet access (HSPA), narrowband Internet of Things (NB-IoT), etc. In addition, the communication between the terminal device and the network device in the communication network can be performed according to any appropriate generation communication protocol, including but not limited to the fourth generation (4G), 4.5G, future fifth generation (5G) new radio (NR) communication protocol and / or any other protocol currently known or to be developed in the future. The embodiments of the present disclosure can be applied to various communication systems. In view of the rapid development of communication, there will certainly be future types of communication technologies and systems, using which the present disclosure can be embodied. This should not be regarded as limiting the scope of the present disclosure to the above-mentioned systems.
[0060] As used herein, the term "network device" refers to a node in a communication network, via which a terminal device accesses the network and receives services from it. Depending on the terminology and technology applied, a network device may refer to a base station (BS) or an access point (AP), such as a NodeB (NodeB or NB), an evolved NodeB (eNodeB or eNB), a NR next-generation NodeB (gNB), a remote radio unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, a low-power node (such as a femto node, a micro node), etc. The RAN split architecture includes a gNB-CU (centralized unit, hosting RRC, SDAP and PDCP) that controls multiple gNB-DUs (distributed units, hosting RLC, MAC and PHY). A relay node may correspond to the DU portion of an IAB node.
[0061] The term "terminal device" refers to any terminal device that can perform wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, a user equipment (UE), a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). The terminal device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, a voice over IP (VoIP) phone, a wireless local loop phone, a tablet computer, a wearable terminal device, a personal digital assistant (PDA), a portable computer, a desktop computer, an image capture terminal device (such as a digital camera), a game terminal device, a music storage and playback device, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop embedded device (LEE), a laptop mounted device (LME), a USB dongle, a smart device, a wireless client device (CPE), an Internet of Things (IoT) device, a watch or other wearable device, a head mounted display (HMD), a vehicle, a drone, medical equipment and applications (such as remote surgery), industrial equipment and applications (such as robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronic devices, equipment operating on commercial and / or industrial wireless networks, etc. The terminal device may also correspond to the mobile terminal (MT) part of an integrated access and backhaul (IAB) node (also known as a relay node). In the following description, the terms "terminal device", "communication device", "terminal", "user equipment" and "UE" may be used interchangeably.
[0062] Although in various example embodiments, the functions described herein may be performed in fixed and / or wireless network nodes, in other example embodiments, the functions may be implemented in a user equipment device (such as a mobile phone or tablet or laptop or desktop or mobile IoT device or fixed IoT device). The user equipment device may, for example, be equipped with corresponding functions as associated with fixed and / or (multiple) wireless network nodes as required. The user equipment device may be a user device and / or a control device, such as a chipset or processor, configured to control the user device when installed in the user device. Examples of such functions include boot server functions and / or home subscriber servers, which may be implemented in the user equipment device by providing the user equipment device with software configured to cause the user equipment device to perform from the perspective of these functions / nodes.
[0063] As mentioned above, registration via multiple access technologies may occur in the new communication system. This scenario may involve several procedures, such as UE registration via 3GPP access and non-3GPP access simultaneously and subsequent NSSAA. Depending on the network selection of the UE, registration via both access types may occur in one public land mobile network (PLMN) or in two different PLMNs.
[0064] The principles and implementations of the present disclosure will be described below with reference to Figure 1A to 16 are described in detail. Figure 1A An example communication system 100 in which embodiments of the present disclosure may be implemented is shown. The system 100 may include a terminal device (e.g., UE) 110, a first access point (e.g., gNB) 120, and a second access point (e.g., WLAN device) 130. The terminal device 110 may access a network through the first access point 120 and / or the second access point 130. The first access point 120 interacts with a first network device (e.g., first AMF AMF#1) 140, and the second access point 130 interacts with a second network device (e.g., second AMF AMF#2) 150. As an example, the first access point 120 and the first network device 140 may belong to a first PLMN (PLMN#1), and the second access point 130 and the second network device 150 may belong to a second PLMN (PLMN#2). Note that the first access point 120, the first network device 140, the second access point 130, and the second network device 150 may also belong to the same PLMN.
[0065] AMF#1 140 and AMF#2 150 communicate with a third network device (e.g., a network slice specific authentication and authorization function NSSAAF) 160. NSSAAF 160 interacts directly with a fourth network device (e.g., an authentication, authorization, and accounting server AAA-S) 170, or interacts indirectly with AAA-S 170 via an AAA proxy (AAA-P) 180. In some embodiments, AAA-P 180 may also be referred to as a fourth network device. The system 100 may also include a unified data management (UDM) 190, which may communicate with NSSAAF 160, AMF#1 140, and / or AMF#2 150. It should be understood that the number of network devices and terminal devices and the specific interactions therebetween are for illustrative purposes only and do not imply any limitation. The system 100 may include any suitable number of network devices and terminal devices suitable for implementing embodiments of the present disclosure.
[0066] The communication in the system 100 can be implemented according to any appropriate (multiple) communication protocols, including but not limited to cellular communication protocols of the first generation (1G), second generation (2G), third generation (3G), fourth generation (4G) and fifth generation (5G), wireless local area network communication protocols (such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, etc.) and / or any other protocol currently known or to be developed in the future. In addition, the communication can utilize any appropriate wireless communication technology, including but not limited to: code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplexer (FDD), time division duplexer (TDD), multiple input multiple output (MIMO), orthogonal frequency division multiple access (OFDMA) and / or any other technology currently known or to be developed in the future.
[0067] This section describes the general NSSAA process. Figure 1B An example NSSAA process is shown with which some embodiments of the present disclosure may be implemented. Figure 1B As shown, if necessary, during the registration process, NSSAA is triggered by AMF 140 for S-NSSAI. UE 110, AMF 140, NSSAAF 160, AAA-S 170 and AAA-P 180 are the entities involved in the process, and they should maintain the following information to complete the interaction process. Specifically, UE maps between EAP id and (SUPI / GPSI+S-NSSAI), AAA-S maps between EAP Id and (GPSI+S-NSSAI), NSSAAF maps between AMF id and (GPSI+S-NSSAI) and between S-NSSAI and AAA server, AMF maps between SUPI and GPSI, and AMF maps between SUPI and GPSI. SUPI is the abbreviation of Subscription Permanent Identifier. In Figure 1B In , EAP Id response and EAP message are encapsulated in EAP packets, which are passed transparently through the 3GPP network and are invisible to AMF or NSSAAF. EAP Id is used to identify the authentication session between UE and AAA. (GPSI+S-NSSAI) is used to identify the NSSAA session between AAA, NSSAA and AMF.
[0068] Regarding NSSAA enhancements for multi-access, some potential scenarios are described below. There may be a situation where NSSAA occurs in two simultaneous registrations of a single PLMN. Similar to the primary authentication in the two-registration scenario, a single AMF is responsible for both 3gpp and non-3gpp registrations, so the AMF can control the sequence of NSSAA, for example, if the NSSAA procedure for the S-NSSAI of the first access type is successful, the AMF may decide not to trigger the NSSAA procedure for the S-NSSAI of the second access type, or trigger the NSSAA for the S-NSSAI of the second access type only after the NSSAA procedure for the S-NSSAI of the first access type is completed.
[0069] There may be a situation where there is an NSSAA procedure in two registrations for two PLMNs. In theory, the AMF for one access type in PLMN-1 can independently trigger the NSSAA procedure even if there is an ongoing NSSAA procedure for another access type in PLMN-2. The UE, NSSAAF and AAA-S may be able to decide whether to accept the second NSSAA for the S-NSSAI while there is another NSSAA procedure for the S-NSSAI in progress. According to the information listed in slice 2, only one EAP authentication session is supported, which is identified by EAP Id or GPSI+S-NSSAI. In particular, it requires that "regardless of the access type, the UE shall not attempt to re-register with the S-NSSAI included in the pending NSSAI list until the network slice specific authentication and authorization procedures have been completed."
[0070] Multiple registration has been studied in Rel-18 and previous versions of TS 33.501. This study involves multiple registration in different PLMNs. The UE shall independently maintain and use two different 5G security contexts, one for each serving PLMN network. Each security context shall be established separately via a successful primary authentication process with the home PLMN. If the USIM supports 5G parameter storage, the ME shall store the two different 5G security contexts on the USIM. If the USIM does not support 5G parameter storage, the ME shall store the two different 5G security contexts in the ME non-volatile memory. Both different 5G security contexts are current 5G security contexts. The latest K following a successful completion of the latest primary authentication AUSF The result shall be used by the UE and the HN regardless of the access network type (3GPP or non-3GPP) through which it was generated. The HN shall keep the latest K generated during a successful authentication on a given access, even if the UE deregisters from that access, but the UE is registered via another access. AUSF .
[0071] This study also covers multiple active non-access stratum (NAS) connections with different PLMNs. TS 23.501 has a scenario when the UE is registered to the serving network of a visited PLMN (VPLMN) via 3GPP access and is simultaneously registered to the serving network of another VPLMN or a home PLMN (HPLMN) via non-3GPP access. When a UE is registered in the serving network of one PLMN via a certain type of access (e.g. 3GPP) and is registered in the serving network of another PLMN via another type of access (e.g. non-3GPP), the UE has two active NAS connections with different AMFs in different PLMNs. As described in clause 6.3.2.1 of TS 33.501, the UE shall independently maintain and use two different 5G security contexts, one for each PLMN serving network. The 5G security context maintained by the UE shall contain the complete set of 5G parameters, including NAS context parameters for 3GPP and non-3GPP access types for each PLMN. In case of connection to two different PLMNs, a complete 5G NAS security context needs to be maintained independently for each PLMN, each 5G NAS security context has all associated parameters (such as two pairs of NAS COUNTs, one for 3GPP access and one for non-3GPP access). Each security context should be established separately via a successful primary authentication process with the home PLMN. All NAS and AS security mechanisms defined for a single registration mode can be applied independently on each access using the corresponding 5G security context. The UE belongs to a single HPLMN.
[0072] Regarding the rules related to parallel NAS connections, the UE shall not initiate NAS registration with the AMF of the same network over a second NAS connection before the primary authentication on the first NAS connection is completed.
[0073] From the SA1 approved studies, multiple registrations have been studied in Rel-19. In the new Rel-19 SA1 study S1-221231 "Study on Upper layer traffic steering, switching and split over dual3GPP access", the objectives include: Study additional use cases and potential service requirements that may benefit from 5GS supporting upper layer steering, splitting and switching of UE traffic (e.g. belonging to the same data session) over two 3GPP access links, assuming only a single subscription to the PLMN, including the following scenarios:
[0074] Single PLMN, PLMN plus (standalone) non-public network (NPN), two PLMNs;
[0075] Same or different 3GPP RAT (NR or Non-Terrestrial Network (NTN), plus one of NR, NTN or LTE).
[0076] NTN refers to NR-based satellite access, including different orbits (e.g., GEO / MEO / LEO). For the PLMN plus PLMN / NPN scenario, the two networks can be managed by the same operator or by different operators (assuming there is a service agreement between them).
[0077] Figure 1C-1E Accordingly, an example diagram of multiple UE registrations is shown. For example, a UE may register with two PLMNs (e.g., Figure 1C and 1D PLMN-1 and PLMN-2 in the ), register with the PLMN and SNPN (for example, Figure 1C ), or registering twice in the same network (for example, Figure 1E PLMN-1 in ).
[0078] NSSAA enhancements for multi-access may involve AMF information as shown in Table 1 below.
[0079] Table 1: Definition of type AmfInfo
[0080]
[0081] Based on the above, multiple simultaneous NSSAAs may be triggered by AMFs of different PLMNs for the following reasons. For example, before the NSSAA of the S-NSSAI triggered in the first network is completed, the UE may initiate registration with the AMF of the second network, which may trigger NSSAA on the S-NSSAI. This scenario is not currently clearly specified in the existing technical specifications, but if this occurs, the EAP layer in the UE will not be able to handle parallel EAP authentications with the same EAP server and EAP id. Therefore, how to handle this scenario needs to be clearly stated in the specification. From the network side, the AAA-S that authenticates the UE for the network slice during the NSSAA process may initiate re-authentication and re-authorization of the UE at any time after authentication for any reason. If this happens, the behavior of the NSSAF receiving the re-authentication request is not clearly defined, and the NSSAAF may trigger either or both AMFs to initiate (multiple) new NSSAA processes. This may cause rising conditions in the UE involving the AMFs in the two networks.
[0082] There are some potential issues with the above gaps in the current existing solutions. For example, there is no clear requirement or solution to address the potential race condition issue regarding the sequence number (SQN) value caused by multiple registrations in multiple (e.g., two) PLMNs during primary authentication. In addition, there is no clear requirement or solution on how the UE handles multiple EAP ID requests for the same S-NSSAI from different PLMNs. In addition, there is no clear requirement or solution on how the NSSAAF handles the same (GPSI+S-NSSAI) EAP messages from multiple AMFs in different PLMNs and distributes the EAP messages from AAA-S to AMFs. In addition, if there is an ongoing EAP authentication session, there is no clear requirement or solution on AAA-S on how to handle the same (GPSI+S-NSSAI) EAP ID response when the EAP IDs are the same or different.
[0083] According to an embodiment of the present disclosure, NSSAA enhancements for multiple access are provided. The details of the registration enhancements for multiple access will be referred to below. Figures 2A to 7 is described.
[0084] Figure 2A An example flow chart showing an example process 200 according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process 200 will refer to Figure 1A The process 200 may involve a terminal device (eg, UE) 110 .
[0085] At block 201, the terminal device 110 initiates a first registration process with a first network device (e.g., AMF#1 140) of a first PLMN. At block 202, based on determining that the first registration process is completed, the terminal device 110 initiates a second registration process with a second network device (e.g., AMF#2 150) of a second PLMN.
[0086] In some embodiments, the terminal device 110 may also determine a first pending NSSAI set associated with the first registration process based on a registration acceptance message of the first registration process from the first network device. In addition, the terminal device 110 may also map the first pending NSSAI set to a second pending NSSAI set associated with the second registration process. In some embodiments, the terminal device 110 may also exclude the S-NSSAI set in the second pending NSSAI set from the requested NSSAI set associated with the second registration process.
[0087] Figure 2B An example signaling diagram showing an example process 210 according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process 210 will refer to Figure 1AThe process 210 may involve a terminal device (eg, UE) 110 and a second network device (eg, AMF#2) 150.
[0088] like Figure 2B As shown, the second network device 150 sends 211 a request message 212 for the EAP ID for the second EAP authentication to the terminal network device. The request message includes the S-NSSAI. After receiving 213 the request message 212 for the EAP ID for the second EAP authentication, the terminal device 110 determines 214 that the first EAP authentication for the S-NSSAI is in progress based at least in part on the request message. The terminal device 110 then sends 215 a response message 216 to the second network device based on the determination. The response message includes an indication that the first EAP authentication is in progress. The second network device 150 receives 217 the response message.
[0089] Figure 2C Another example signaling diagram showing an example process 220 according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process 220 will refer to Figure 1A The process 220 may involve the second network device (eg, AMF#2) 150 and the third network device (eg, NSSAAF) 160.
[0090] like Figure 2C As shown, the second network device 150 sends 221 an authentication request message 222 for a second NSSAA of the terminal device to the third network device. The authentication request message includes at least the S-NSSAI and the GPSI. After receiving 223 the authentication request message 222, the third network device 160 determines 224 that a first NSSAA of the terminal device for the S-NSSAI is in progress based at least in part on the authentication request message. The first NSSAA is associated with the first network device.
[0091] The third network device 160 may then send 225 an authentication rejection message 226 to the second network device based on the determination. The authentication rejection message includes at least: S-NSSAI, GPSI, and an indication that the first NSSAA is ongoing. The second network device 150 receives 227 the authentication rejection message 226.
[0092] Figure 2D Another example signaling diagram showing an example process 230 according to some embodiments of the present disclosure is shown. For the purpose of discussion, process 220 will refer to Figure 1A The process 220 may involve a second network device (eg, AMF#2) 150, a third network device (eg, NSSAAF) 160, and a fourth network device (eg, AAA-S) 170.
[0093] like Figure 2D As shown, the second network device 150 sends 231 an authentication request message 232 of a second NSSAA for a terminal device to the third network device. The authentication request message includes at least: S-NSSAI, the first AMF information of the second network device, and GPSI. After receiving 233 the authentication request message 232, the third network device 160 sends 234 a first authentication protocol message to the fourth network device. The authentication protocol message includes at least: S-NSSAI, the first AMF information, and GPSI.
[0094] After receiving 236 the first authentication protocol message, the fourth network device 170 determines 237 that a first EAP authentication for the S-NSSAI of the terminal device is in progress, based at least in part on the first authentication protocol message. Then, the fourth network device 170 sends 238 a second authentication protocol message 239 to the third network device. The second authentication protocol message includes at least: the S-NSSAI, the first AMF information, the GPSI, and an indication that the first EAP authentication is in progress. The third network device 160 receives 240 the second authentication protocol message 239.
[0095] Figure 3 An example signaling diagram showing an example process for maintaining a single NSSAA session with a control registration process according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process will refer to Figure 1A The process may involve UE 110, AMF#1 140, AMF#2 150, UDM 190, NSSAAF 160 and AAA-S 170.
[0096] In this case, if UE 110 is performing registration through one access and intends to perform registration through another access in a different PLMN, UE 110 should not initiate registration through the other access until the registration process (including primary authentication) at the first access is completed. In addition, UE 110 should not attempt to re-register with an S-NSSAI included in the pending NSSAI list accepted by the registration through the first access.
[0097] like Figure 3As shown, the following process may be performed. 1. UE 110 registers to AMF#1 140 of the first PLMN (e.g., for 3gpp access) using S-NSSAI-1 and S-NSSAI-2 in the requested NSSAI. 2. AMF#1 140 triggers primary authentication for UE 110. 3-4. After primary authentication and authorization, AMF#1 140 sends a registration accept to UE 110. Since S-NSSAI-1 is affected by NSSAA, S-NSSAI-1 is placed in a pending NSSAI. UE 110 sends a registration complete message back to the network.
[0098] In parallel with procedures 3 and 4, AMF#1 140 triggers the NSSAA procedure for S-NSSAI-1. At A01-A02, UE 110 registers to another PLMN (e.g., for non-3gpp access). After receiving the registration acceptance for the first registration, UE 110 checks the pending NSSAI, maps the S-NSSAI of the pending NSSAI for the first PLMN to the S-NSSAI for the second PLMN based on the serving PLMN S-NSSAI to HPLMN S-NSSAI mapping of the (multiple) PLMNs, and excludes the mapped pending S-NSSAI for the second PLMN from the requested NSSAI of the second registration. Then at A1, after completing the first registration, UE 110 initiates another registration with AMF#2 150 of the second PLMN (e.g., for non-3gpp access). It may only include S-NSSAI-2 in the requested NSSAI because S-NSSAI-1 is in the pending list of the first registration.
[0099] At A2, another primary authentication is triggered for the second access. Then, at A3-A4, after the primary authentication and authorization, AMF#2 150 sends a Registration Accept to UE 110, where S-NSSAI-2 is in the allowed NSSAI. UE 110 sends a Registration Complete back to the network.
[0100] After NSSAA for the first access, at 6, AMF#1 140 may trigger UE 110 to configure an update and update S-NSSAI-1 from a pending S-NSSAI to an allowed S-NSSAI. Then, at A5, UE 110 may send a Registration Request / Update for non-3gpp access with an updated requested NSSAI including S-NSSAI-1. After authorization, at A6-A7, AMF#2 150 sends a Registration Accept to UE 110. Since S-NSSAI-1 is subject to NSSAA, S-NSSAI-1 is placed in the pending NSSAI. UE 110 sends a registration complete message back to the network. At A8, AMF#2 150 triggers the NSSAA process for S-NSSAI-1.
[0101] Figure 4 An example signaling diagram showing an example process for a single NSSAA session controlled by a UE according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process will refer to Figure 1A is described. The process may involve UE 110, AMF#1 140, AMF#2 150, NSSAAF 160, AAA-P 180, and AAA-S 170. In this case, if there is an ongoing EAP authentication session on the S-NSSAI, or the UE responds with an indication (such as to try later), the UE discards the EAP ID Request (or negative answer) for the same S-NSSAI from the AMF#2 of the second PLMN. The AMF#2 of the second PLMN may send the EAP ID Request again later and try several times based on the configuration / policy.
[0102] like Figure 4 As shown, the following process may be performed. 1. For S-NSSAI that requires NSSAA, AMF#1 may trigger the start of the NSSAA process based on changes in subscription information or triggered by AAA-S. 2.AMF#1 may request the UE user ID for EAP authentication (EAP ID) for S-NSSAI in the NASMM transfer message including the S-NSSAI. 3.The UE provides the EAP ID for S-NSSAI and the S-NSSAI to AMF#1 in the NAS MM transfer message. 4.AMF#1 sends an EAP ID response to the NSSAAF that provides an interface with AAA. 5.NSSAAF forwards the EAP ID response message directly / indirectly to AAA-S. AAA-S uses the EAP-ID and S-NSSAI to identify which UE and slice authorization is requested.
[0103] At A1, AMF#2 decides to trigger slice-specific authentication and authorization towards the UE, at A2, AMF#2 may request the UE user ID for EAP authentication (EAP ID) for the S-NSSAI in the NAS MM transport message including the S-NSSAI. Then, at A3, the UE checks the S-NSSAI and identifies the ongoing EAP authentication for the same S-NSSAI. At A4, the UE responds to AMF#2 in the EAP ID response with a failure cause of 5GMM reason "ongoing_EAP_IND". Similar to the AMF monitoring of EAP-success behavior, the UE NAS layer will monitor the EAP-success for the first EAP authentication scenario, and if no EAP-success is received, the NAS will respond with a 5GMM failure cause of "ongoing_EAP_IND".
[0104] At A5, AMF#2 starts a timer based on the operator configuration, and after timeout, AMF#2 retrigger the slice specific authentication and authorization procedure. If the retry attempts are exhausted, AMF#2 stops the slice specific authentication and authorization procedure. If AMF#2 stops the slice specific authentication and authorization procedure (i.e., after the retry attempts have been exhausted or when the UE becomes unreachable), the AMF shall set the "Status" attribute to "Pending". AMF#2 may initiate slice specific authentication and authorization of the S-NSSAI with user "Pending" status in the next UE uplink activity.
[0105] At process 6-11, EAP messages are exchanged with the UE via AMF#1. One or more iterations of these processes may occur. Then, at step 12, EAP authentication is completed. The EAP success / failure message is passed to NSSAAF / AAA-P together with GPSI and S-NSSAI / ENSI. At process 13, NSSAAF sends an Nnssaaf_NSSAA_Authenticate response (EAP success / failure, S-NSSAI, GPSI) to AMF#1. At process 14, AMF#1 sends a NAS MM transfer message (EAP success / failure) to the UE. At process 15, based on the result of the slice-specific authentication (EAP-success / failure), if a new allowed NSSAI or a new rejected NSSAI needs to be passed to the UE, or if AMF#1 needs to be reallocated, AMF#1 initiates a UE configuration update process for each access type.
[0106] If AMF#2 re-triggers the NSSAA procedure after procedure 15 and sends an EAP ID Request to the UE, the UE may respond with an EAP ID since there is no NSSAA going on in parallel. Then another NSSAA procedure will start as usual.
[0107] Figure 5 An example signaling diagram showing an example process for a single NSSAA session controlled by an NSSAAF according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process will refer to Figure 1A The process may involve UE 110, AMF #1 140, AMF #2 150, NSSAAF 160, AAA-P 180, and AAA-S 170. In this case, if the UE is registered in two PLMNs, the NSSAA towards the UE will be initiated by the AMF in the corresponding PLMN (because the AMFs in the corresponding PLMNs are not coordinated). The NSSAA authentication request towards the AAA-S will be received at the NSSAAF in the HPLMN.
[0108] When an EAP ID Response NSSAF with the same GPSI+S-NSSAI is received at the NSSAF from the AMF#2 of the second PLMN, the NSSAAF discards the message or returns an error to AMF#2 to indicate that there is an ongoing NSSAA for the same GPSI+S-NSSAI combination. The AMF#2 of the second PLMN may later attempt to initiate NSSAA again by sending authentication requests to the NSSAAF multiple times based on the configuration / policy. The message sent from the NSSAAF to AMF#2 to indicate 1) authentication for (EAP-ID, GPSI, S-NSSAI) is ongoing, 2) authentication for (EAP-ID, GPSI, S-NSSAI) has been completed, and possibly new services / messages will be defined.
[0109] like Figure 5 As shown, the following process may be performed. 1. For S-NSSAI that requires NSSAA, AMF#1 may trigger the start of the NSSAA process based on changes in subscription information or triggered by AAA-S. 2.AMF#1 may request the UE user ID for EAP authentication (EAP ID) for S-NSSAI in the NASMM transfer message including S-NSSAI. 3.The UE provides the EAP ID for S-NSSAI and the S-NSSAI to AMF#1 in the NAS MM transfer message. 4.AMF#1 sends the EAP ID to the NSSAAF that provides the interface with AAA in the Nnssaaf_NSSAA_Authenticate request (EAP ID response, GPSI, S-NSSAI). 5.NSSAAF forwards the EAP ID response message to the NSSAAF and directly / indirectly to AAA-S170. AAA-S170 uses the EAP-ID and S-NSSAI to identify which UE and slice authorization is requested.
[0110] At A1, AMF#2 decides to trigger slice-specific authentication and authorization towards the UE. At A2, AMF#2 may request the UE user ID for EAP authentication (EAP ID) for S-NSSAI in a NAS MM transport message including S-NSSAI. At A3, the UE provides an EAP ID response for S-NSSAI and the S-NSSAI in a NAS MM transport message towards AMF#2. At A4, AMF#2 forwards the message with EAP ID response, GPSI, S-NSSAI with PLMN_ID#2 to NSSAAF.
[0111] Then, at A5, the NSSAAF identifies that there is an ongoing NSSAA authentication for another PLMN using GPSI and S-NSSAI. At A6, the NSSAAF silently discards the message or sends a Nssaaf_NSSAA_Authenticate_Reject message to AMF#2 with the failure cause being "ongoing_EAP_IND". At A7, AMF#2 starts a timer based on the operator configuration, and after timeout, AMF#2 retriggering the slice-specific authentication and authorization. If the retry attempts are exhausted, the AMF stops the slice-specific authentication and authorization process. If AMF#2 stops the slice-specific authentication and authorization process (i.e., when the retry attempts are exhausted or the UE becomes unreachable), the AMF shall set the "status" attribute to "PENDING". AMF#2 may initiate slice-specific authentication and authorization for the S-NSSAI in the "PENDING" state in the next UE uplink activity.
[0112] At process 6-11, EAP messages are exchanged with the UE via AMF#1. One or more iterations of these steps may occur. At process 12, EAP authentication is completed. The EAP-success / failure message is passed to the NSSAAF / AAA-P along with GPSI, PLMN_ID#1 and S-NSSAI / ENSI. At process 13, the NSSAAF sends an Nnssaaf_NSSAA_Authenticate response (EAP-success / failure, S-NSSAI, GPSI) to AMF#1. At process 14, AMF#1 sends a NAS MM transfer message (EAP-success / failure) to the UE. At process 15, based on the result of the slice-specific authentication (EAP-success / failure), if a new allowed NSSAI or a new rejected NSSAI needs to be passed to the UE, or if AMF#1 reallocation is required, AMF#1 initiates a UE configuration update process for each access type.
[0113] If AMF#2 re-triggers the NSSAA procedure after procedure 15, the NSSAAF may continue the new NSSAA procedure upon receiving the Nnssaaf_NSSAA_Authenticate request from AMF#2.
[0114] Figure 6 An example signaling diagram showing an example process for a single NSSAA session controlled by the NSSAAF for reauthentication according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process will refer to Figure 1A is described. The procedure may involve UE 110, AMF#1 140, AMF#2 150, UDM 190, NSSAAF 160 and AAA-S 170. In this case, a reauthentication and reauthorization request is received from AAA-S and the NSSAAF gets the AMF ID from UDM using Nudm_UECM_Get with the GPSI in the received AAA message. If the NSSAAF receives two different AMF addresses from UDM, the NSSAAF shall serialize the reauthentication, i.e. notify one AMF first and then notify the other AMF only after the first NSSAA procedure is completed.
[0115] like Figure 6 As shown, the following process can be performed. At process 1-2, after receiving the re-authentication request for the S-NSSAI of the UE from the NSSAAF, the NSSAAF obtains the AMF from the UDM. At process 3a-4a, the NSSAAF sends a notification to one AMF to trigger re-authentication. Then, at process 3b-4b, after completing the re-authentication triggered by the first AMF, the NSSAAF can send a notification to another AMF to trigger re-authentication.
[0116] Figure 7 An example signaling diagram showing an example process for a single NSSAA session controlled by AAA-S according to some embodiments of the present disclosure is shown. For the purpose of discussion, the process will refer to Figure 1A is described. The process may involve UE 110, AMF#1 140, AMF#2150, NSSAAF 160, AAA-P 180 and AAA-S 170. In this case, if an EAP ID response with the same GPSI+S-NSSAI is received from the NSSAAF for authentication, the AAA-S checks the EAP ID in the response. If it is the same as the ID of the ongoing authentication session, the AAA-S may send an error back to the NSSAAF. If it times out, if the NSSAAF is still maintaining the session, the NSSAAF will send a timeout error to AMF#2. Otherwise, the AMF / PLMN ID is required to identify AMF#2.
[0117] like Figure 7 As shown, the following process may be performed. 1. For S-NSSAI that requires NSSAA, AMF#1 may trigger the start of the NSSAA process based on changes in subscription information or triggered by AAA-S. 2.AMF#1 may request the UE user ID for EAP authentication (EAP ID) for S-NSSAI in the NASMM transfer message including S-NSSAI. 3.The UE provides the EAP ID for S-NSSAI and the S-NSSAI to AMF#1 in the NAS MM transfer message. 4.AMF#1 sends the EAP ID to the NSSAAF that provides the interface with AAA in the Nnssaaf_NSSAA_Authenticate request (EAP ID response, GPSI, S-NSSAI, AMF_Info#1). 5.NSSAAF forwards the EAP ID response message directly / indirectly to AAA-S. AAA-S uses EAP-ID and S-NSSAI to identify which UE and slice authorization are requested.
[0118] At A1, AMF#2 decides to trigger slice-specific authentication and authorization towards the UE. At A2, AMF#2 may request the UE user ID for EAP authentication (EAP ID) for S-NSSAI in a NAS MM transport message including S-NSSAI. At A3, the UE provides the EAP ID for S-NSSAI and the S-NSSAI to AMF#2 in a NAS MM transport message. At A4, AMF#2 forwards the message with EAP ID response, GPSI, S-NSSAI and AMF_Info#2 to NSSAF. At A5, NSSAAF forwards the AAA protocol message to AAA-S.
[0119] Then, at A6, AAA-S identifies that there is an ongoing NSSAA authentication for another PLMN using GPSI, AMF_Info#2 and S-NSSAI. At A7, AAA-S responds to NSSAAF with a failure cause of "ongoing_EAP_IND" using AMF_Info. At A8, NSSAAF forwards the Nssaaf_NSSAA_Authenticate_Reject message with a failure cause of "ongoing_EAP_IND" to AMF#2 based on AMF_Info. At A9, AMF#2 starts a timer based on the operator configuration, and after timeout, AMF#2 retrigger the slice-specific authentication and authorization.
[0120] Thereafter, at process 6-11, EAP messages are exchanged with the UE via AMF#1. One or more iterations of these steps may occur. At process 12, EAP authentication is completed. The EAP-success / failure message is passed to the NSSAAF / AAA-P along with the GPSI and S-NSSAI / ENSI. At process 13, the NSSAAF sends an Nnssaaf_NSSAA_Authenticate response (EAP-success / failure, S-NSSAI and GPSI) to AMF#1. At process 14, AMF#1 sends a NAS MM transfer message (EAP-success / failure) to the UE. At process 15, based on the result of the slice-specific authentication (EAP-success / failure), if a new allowed NSSAI or a new rejected NSSAI needs to be passed to the UE, or if AMF#1 reallocation is required, AMF#1 will initiate a UE configuration update process for each access type.
[0121] If AMF#2 re-triggers the NSSAA procedure after step 15, AAA-S may continue the new NSSAA procedure upon receiving the AAA protocol message from the NSSAAF.
[0122] Figure 8 800 is a flowchart of an example method 800 implemented at a terminal device according to some embodiments of the present disclosure. For discussion purposes, the method 800 will be described from the perspective of the terminal device 110, for example, Figure 1A , 2B and as shown in 4.
[0123] At block 810, the terminal device 110 receives a request message for an EAP ID for a second EAP authentication from a second network device (e.g., AMF#2 150). The request message includes the S-NSSAI. At block 820, the terminal device 110 determines that a first EAP authentication for the S-NSSAI is in progress based at least in part on the request message. At block 830, the terminal device 110 sends a response message to the second network device based on the determination. The second message includes an indication that the first EAP authentication is in progress.
[0124] In some embodiments, to determine that the first EAP authentication for the S-NSSAI is in progress, the terminal device 110 may monitor for a message indicating an EAP success for the first EAP authentication and determine that no message indicating an EAP success is received.
[0125] In some embodiments, the first EAP authentication may be associated with a first network device (eg, AMF#1 140). Additionally, the first network device may include a first AMF in a first PLMN, and the second network device may include a second AMF in a second PLMN.
[0126] Fig. 9 1 is a flowchart of an example method 900 implemented at a second network device according to some embodiments of the present disclosure. For discussion purposes, the method 900 will be described from the perspective of the second network device (eg, AMF#2) 150. Figure 1A , 2B and as shown in 5.
[0127] At block 910, the second network device 150 sends a request message for an EAP ID for a second EAP authentication to a terminal network device (e.g., UE 110). The request message includes a single S-NSSAI. At block 920, the second network device 150 receives a response message from the terminal network device. The response message includes an indication that the first EAP authentication for the S-NSSAI is in progress.
[0128] In some embodiments, the second network device 150 may remain in a pending state based on the first EAP authentication being in progress. In addition, the second network device 150 may initiate another EAP authentication for the S-NSSAI in the next uplink activity of the terminal device.
[0129] In some embodiments, the first EAP authentication may be associated with a first network device (eg, AMF#1 140). Additionally, the first network device may include a first AMF in a first PLMN, and the second network device may include a second AMF in a second PLMN.
[0130] Fig.10 1 is a flowchart of another example method 1000 implemented at a second network device according to some embodiments of the present disclosure. For discussion purposes, the method 1000 will be described from the perspective of the second network device (eg, AMF#2) 150, such as Figure 1A , 2C , 2D and shown in 6 to 8.
[0131] At block 1010, the second network device 150 sends an authentication request message for a second NSSAA for a terminal device (e.g., UE 110) to a third network device (e.g., NSSAAF 160). The authentication request message includes at least: S-NSSAI and GPSI. At block 1020, the second network device 150 receives an authentication rejection message from the third network device. The first authentication rejection message includes at least: S-NSSAI, and an indication that the first NSSAA for the S-NSSAI is in progress.
[0132] In some embodiments, each of the authentication request message and the authentication rejection message may also include an EAP ID response from the terminal device. The EAP ID response may be used for EAP authentication for S-NSSAI. Alternatively or additionally, each of the authentication request message and the authentication rejection message may also include AMF information of the second network device.
[0133] In some embodiments, the first EAP authentication may be associated with a first network device (eg, AMF#1 140). Additionally, the first network device may include a first AMF in a first PLMN, and the second network device may include a second AMF in a second PLMN.
[0134] The third network device may include a NSSAAF.
[0135] Fig.11 1 is a flow chart of an example method 1100 implemented at a third network device according to some embodiments of the present disclosure. For discussion purposes, the method 1100 will be described from the perspective of the third network device (eg, NSSAAF) 160, such as Figure 1A , 2C and as shown in 6 to 7.
[0136] At block 1110, the third network device 160 receives an authentication request message for a second NSSAA of a terminal device (e.g., UE 110) from a second network device (e.g., AMF#2 150). The authentication request message includes at least: S-NSSAI and GPSI. At block 1120, the third network device 160 determines that a first NSSAA of the terminal device for S-NSSAI is in progress based at least in part on the authentication request message. The first NSSAA is associated with the first network device (e.g., AMF#1 140).
[0137] In some embodiments, the third network device 160 may discard the authentication request message. Alternatively, the third network device 160 may send an authentication rejection message to the second network device based on the determination. The authentication rejection message may include at least: S-NSSAI, GPSI, and an indication that the first NSSAA is in progress.
[0138] In some embodiments, each of the authentication request message and the authentication rejection message may also include an EAP ID response from the terminal device. The EAP ID response may be used for EAP authentication for the S-NSSAI. In some embodiments, the third network device 160 may receive a re-authentication request message for the S-NSSAI of the terminal device from the fourth network device. The third network device 160 may send a first notification to one of the first network device and the second network device to trigger a first re-authentication of the terminal device. Based on determining that the first re-authentication has been completed, the third network device 160 may send a second notification to the other of the first network device and the second network device to trigger a second re-authentication of the terminal device.
[0139] In some embodiments, the first network device may include a first AMF in a first PLMN. The second network device may include a second AMF in a second PLMN. The third network device may include an NSSAAF. The fourth network device may include AAA-S or AAA-P.
[0140] Fig.12 1 is a flowchart of another example method 1200 implemented at a third network device according to some embodiments of the present disclosure. For discussion purposes, the method 1200 will be described from the perspective of the third network device (eg, NSSAAF) 160, for example, Figure 1A , 2D and as shown in 8.
[0141] At block 1210, the third network device 160 receives an authentication request message of a second NSSAA for a terminal device (e.g., UE 110) from a second network device (e.g., AMF#2 150). The authentication request message includes at least: a single S-NSSAI, first AMF information of the second network device, and GPSI. At block 1220, the third network device 160 sends a first authentication protocol message to the fourth network device. The first authentication protocol message includes at least: S-NSSAI, first AMF information, and GPSI.
[0142] In some embodiments, each of the authentication request message and the first authentication protocol message may further include an EAP ID response from the terminal device. The EAP ID response may be used for the second EAP authentication for the S-NSSAI.
[0143] In some embodiments, the third network device 160 may receive a second authentication protocol message from the fourth network device. The second authentication protocol message may include at least: S-NSSAI, GPSI, and an indication that the first EAP authentication for S-NSSAI is in progress. In some embodiments, the third network device 160 may send an authentication rejection message to the second network device. The authentication rejection message may include at least: S-NSSAI, GPSI, and an indication.
[0144] In some embodiments, the first NSSAA and the first EAP authentication may be associated with a first network device. The first network device may include a first AMF in a first PLMN. The second network device may include a second AMF in a second PLMN. The third network device may include an NSSAAF. The fourth network device may include AAA-S or AAA-P.
[0145] Fig.13 1 is a flow chart of an example method 1300 implemented at a fourth network device according to some embodiments of the present disclosure. For discussion purposes, the method 1300 will be described from the perspective of the fourth network device (eg, AAA-S) 170, such as Figure 1A , 2D and as shown in 8.
[0146] At block 1310, the fourth network device 170 receives a first authentication protocol message for a second EAP authentication of a terminal device (e.g., UE 110) from a third network device (e.g., NSSAAF 160). The first authentication protocol message includes at least: S-NSSAI, first AMF information of the second network device (e.g., AMF#2 150), and GPSI.
[0147] At block 1320, the fourth network device 170 determines that the first EAP authentication for the S-NSSAI of the terminal device is in progress based at least in part on the first authentication protocol message. At block 1330, the fourth network device 170 sends a second authentication protocol message to the third network device. The second authentication protocol message includes at least: S-NSSAI, first AMF information, GPSI, and an indication that the first EAP authentication is in progress.
[0148] In some embodiments, the first EAP authentication may be associated with the first network device. The second EAP authentication may be associated with the second network device. The first network device may include a first AMF in the first PLMN. The second network device may include a second AMF in the second PLMN. The third network device may include an NSSAAF. The fourth network device may include an AAA-S.
[0149] In some embodiments, an apparatus capable of executing any of the methods 800 (e.g., terminal device 110) may include a component for executing the corresponding steps of the method 800. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module.
[0150] In some embodiments, the apparatus includes a component for: receiving a request message for an EAP identifier (EAP ID) for a second extensible authentication protocol (EAP) authentication from a second network device, the request message including single network slice selection assistance information (S-NSSAI); determining, based at least in part on the request message, that a first EAP authentication for the S-NSSAI is in progress; and sending a response message to the second network device based on the determination, the second message including an indication that the first EAP authentication is in progress.
[0151] In some embodiments, the means for determining that the first EAP authentication of the S-NSSAI is in progress includes means for: monitoring a message indicating an EAP success for the first EAP authentication; and determining that a message indicating an EAP success was not received. In some embodiments, the first EAP authentication is associated with a first network device, the first network device including a first access and mobility management function AMF in a first public land mobile network PLMN, and the second network device including a second AMF in a second PLMN.
[0152] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 800. In some embodiments, the means comprises: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to cause execution of the apparatus together with the at least one processor.
[0153] In some embodiments, an apparatus capable of executing any of the methods in method 900 (e.g., second network device 150) may include a component for executing the corresponding steps of method 900. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module.
[0154] In some embodiments, the apparatus includes a component for: sending a request message for an EAP identifier for a second extensible authentication protocol EAP authentication to a terminal network device, the request message including single network slice selection auxiliary information S-NSSAI; and receiving a response message from the terminal network device, the response message including an indication that a first EAP authentication for S-NSSAI is in progress.
[0155] In some embodiments, the apparatus further comprises means for: remaining in a pending state based on the first EAP authentication being in progress; and initiating an additional EAP authentication for the S-NSSAI in a next uplink activity of the terminal device. In some embodiments, the first EAP authentication is associated with a first network device, the first network device comprising a first access and mobility management function AMF in a first public land mobile network PLMN, and the second network device comprising a second AMF in a second PLMN.
[0156] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 900. In some embodiments, the apparatus comprises: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to cause execution of the apparatus together with the at least one processor.
[0157] In some embodiments, an apparatus capable of executing any of the methods in method 1000 (e.g., second network device 150) may include a component for executing the corresponding steps of method 1000. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module.
[0158] In some embodiments, the apparatus includes a component for: sending an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device to a third network device, the authentication request message including at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and receiving an authentication rejection message from the third network device, the first authentication rejection message including at least: S-NSSAI and an indication that a first NSSAA for the S-NSSAI is in progress.
[0159] In some embodiments, each of the authentication request message and the authentication rejection message further includes at least one of the following: an Extensible Authentication Protocol Identifier EAP ID response from the terminal device, wherein the EAP ID response is used for EAP authentication for the S-NSSAI; or access and mobility management function AMF information of the second network device. In some embodiments, the first NSSAA is associated with the first network device, the first network device includes a first access and mobility management function AMF in a first public land mobile network PLMN, the second network device includes a second AMF in a second PLMN, and the third network device includes a network slice specific authentication and authorization function NSSAAF.
[0160] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 1000. In some embodiments, the means comprises: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to cause execution of the apparatus together with the at least one processor.
[0161] In some embodiments, a device capable of executing any of the methods 1100 (e.g., the third network device 160) may include a component for executing the corresponding steps of the method 1100. The component may be implemented in any suitable form. For example, the component may be implemented as a circuit or a software module.
[0162] In some embodiments, the apparatus includes a component for: receiving an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device from a second network device, the authentication request message including at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and determining, based at least in part on the authentication request message, that a first NSSAA for the S-NSSAI of the terminal device is in progress, the first NSSAA being associated with the first network device.
[0163] In some embodiments, the apparatus further comprises a component for: discarding the authentication request message; or sending an authentication rejection message to the second network device based on the determination, the authentication rejection message comprising at least: S-NSSAI, GPSI, and an indication that the first NSSAA is in progress. In some embodiments, each of the authentication request message and the authentication rejection message further comprises: an extensible authentication protocol identifier EAP ID response from the terminal device, wherein the EAP ID response is used for EAP authentication for the S-NSSAI.
[0164] In some embodiments, the apparatus further includes a component for: receiving a reauthentication request message for the S-NSSAI of the terminal device from a fourth network device; sending a first notification to one of the first network device and the second network device to trigger a first reauthentication of the terminal device; and based on determining that the first reauthentication has been completed, sending a second notification to the other of the first network device and the second network device to trigger a second reauthentication of the terminal device.
[0165] In some embodiments, the first network device includes a first access and mobility management function AMF in a first PLMN, the second network device includes a second AMF in a second PLMN, the third network device includes a network slice specific authentication and authorization function NSSAAF, and the fourth network device includes: an authentication, authorization and accounting server AAA-S or an AAA proxy AAA-P.
[0166] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 1100. In some embodiments, the means comprises: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to cause execution of the apparatus together with the at least one processor.
[0167] In some embodiments, a device capable of executing any of the methods of method 1200 (e.g., third network device 160) may include a component for executing the corresponding steps of method 1200. The component may be implemented in any suitable form. For example, the component may be implemented as a circuit or a software module.
[0168] In some embodiments, the apparatus includes a component for: receiving an authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device from a second network device, the authentication request message including at least single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; and sending a first authentication protocol message to a fourth network device, the first authentication protocol message including at least: S-NSSAI, first AMF information, and GPSI.
[0169] In some embodiments, each of the authentication request message and the first authentication protocol message further includes an Extensible Authentication Protocol Identifier (EAP ID) response from the terminal device, wherein the EAP ID response is used for a second EAP authentication for the S-NSSAI.
[0170] In some embodiments, the apparatus further comprises a component for receiving a second authentication protocol message from a fourth network device, the second authentication protocol message comprising at least: S-NSSAI, GPSI, and an indication that a first EAP authentication for S-NSSAI is in progress. In some embodiments, the apparatus further comprises a component for sending an authentication rejection message to the second network device, the authentication rejection message comprising at least: S-NSSAI, GPSI, and an indication.
[0171] In some embodiments, the first NSSAA and the first EAP authentication are associated with a first network device, the first network device includes a first access and mobility management function AMF in a first PLMN, the second network device includes a second AMF in a second PLMN, the third network device includes a network slice specific authentication and authorization function NSSAAF, and the fourth network device includes: an authentication, authorization and accounting server AAA-S or an AAA proxy AAA-P.
[0172] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 1200. In some embodiments, the means comprises: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to cause execution of the apparatus together with the at least one processor.
[0173] In some embodiments, a device capable of executing any of the methods 1300 (e.g., the fourth network device 170) may include a component for executing the corresponding steps of the method 1300. The component may be implemented in any suitable form. For example, the component may be implemented as a circuit or a software module.
[0174] In some embodiments, the apparatus includes a component for: receiving a first authentication protocol message for a second extensible authentication protocol EAP authentication of a terminal device from a third network device, the first authentication protocol message including at least: single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; determining, based at least in part on the first authentication protocol message, that a first EAP authentication of the terminal device for S-NSSAI is in progress; and sending a second authentication protocol message to the third network device, the second authentication protocol message including at least: S-NSSAI, first AMF information, GPSI, and an indication that the first EAP authentication is in progress.
[0175] In some embodiments, the first EAP authentication is associated with a first network device, the second EAP authentication is associated with a second network device, the first network device includes a first access and mobility management function AMF in a first PLMN, the second network device includes a second AMF in a second PLMN, the third network device includes a network slice specific authentication and authorization function NSSAAF, and the fourth network device includes an authentication, authorization, and accounting server AAA-S.
[0176] In some embodiments, the apparatus further comprises means for performing other steps in some embodiments of method 1300. In some embodiments, the means comprises: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code being configured to cause execution of the apparatus together with the at least one processor.
[0177] Fig.14 1 is a simplified block diagram of a device 1400 suitable for implementing embodiments of the present disclosure. The device 1400 may be provided to implement a communication device, such as Figure 1AThe terminal device 110, the first access point 120, the second access point 130, the first network 140, the second network 140, the third network device 160, the fourth network device 170, the AAA-P 180 and the UDM 190 are shown. As shown in the figure, the device 1400 includes one or more processors 1410, one or more memories 1420 coupled to the processor 1410, and one or more communication modules (TX / RX) 1440 coupled to the processor 1410.
[0178] TX / RX 1440 is used for bidirectional communication. TX / RX 1440 has at least one antenna to facilitate communication. The communication interface may represent any interface necessary to communicate with other network elements.
[0179] Processor 1410 may be of any type suitable for the local technology network, and may include, as non-limiting examples, one or more of: a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. Device 1400 may have multiple processors, such as application specific integrated circuit chips, which are time-slaved to a clock synchronized with a main processor.
[0180] The memory 1420 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1424, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disk (CD), digital video disk (DVD), and other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1422 and other volatile memories that will not persist for the duration of a power outage.
[0181] Computer program 1430 includes computer executable instructions executed by associated processor 1410. Program 1430 may be stored in ROM 1424. Processor 1410 may perform any suitable actions and processes by loading program 1430 into RAM 1422.
[0182] The exemplary embodiments of the present disclosure may be implemented by the program 1430 so that the device 1400 may perform the operations described in reference to FIG. Fig.13 Any process of the present disclosure discussed. The embodiments of the present disclosure may also be implemented by hardware or a combination of software and hardware.
[0183] In some example embodiments, program 1430 may be tangibly embodied in a computer-readable medium, which may be included in device 1400 (such as in memory 1420) or in other storage devices accessible by device 1400. Device 1400 may load program 1430 from the computer-readable medium to RAM 1422 for execution. Computer-readable media may include any type of non-transitory storage media, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. Fig.15 Examples of computer readable medium 1500 in the form of CD, DVD are shown. Computer readable medium 1500 has program 1430 stored thereon.
[0184] Generally, various embodiments of the present disclosure may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be performed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are shown and described in block diagrams, flow charts, or using some other graphical representations, it should be understood that, as non-limiting examples, the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices, or some combination thereof.
[0185] The present disclosure also provides at least one computer program product tangibly stored on a transient or non-transitory computer-readable storage medium. The computer program product includes computer executable instructions (such as those included in a program module) that are executed in a device on a target real or virtual processor to perform the above-referenced Figures 8 to 13 Described method 800 to 1400.Usually, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types.The functions of program modules can be combined or split between program modules according to the needs of various embodiments.Machine executable instructions for program modules can be executed in local or distributed devices.In distributed devices, program modules can be located in both local and remote storage media.
[0186] The program code for executing the method of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code can be executed entirely on the machine, partially on the machine, as an independent software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0187] In the context of the present disclosure, instructions or related data may be carried by any suitable carrier to enable a device, apparatus or processor to perform various processes and operations as described above. Examples of carriers include signals, computer-readable media, etc.
[0188] The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or apparatuses, or any suitable combination of the foregoing. More specific examples of computer-readable storage media would include an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The term "non-transient" as used herein is a limitation on the medium itself (i.e., tangible, not a signal), not a limitation on the persistence of data storage (e.g., RAM vs. ROM).
[0189] In addition, although the operations are depicted in a particular order, it should not be understood as requiring the operations to be performed in the particular order shown or in a sequential order, or requiring all the operations shown to be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these details should not be interpreted as limitations on the scope of the present disclosure, but should be interpreted as descriptions of features that may be specific to a particular embodiment. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. On the contrary, the various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or implemented in any suitable sub-combination.
[0190] Although the present disclosure has been described in language specific to structural features and / or methodological acts, it should be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Instead, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1. A terminal device, comprising: at least one processor; as well as at least one memory storing instructions, which, when executed by the at least one processor, cause the terminal device to at least: Initiating a first registration procedure with a first network device of a first public land mobile network PLMN; as well as Based on determining that the first registration procedure is completed, a second registration procedure is initiated with a second network device of a second PLMN.
2. The terminal device according to claim 1, wherein the terminal device is further configured to: determining, based on a registration accept message of the first registration procedure from the first network device, a first pending network slice selection assistance information (NSSAI) set associated with the first registration procedure; and The first pending NSSAI set is mapped to a second pending NSSAI set associated with the second registration process.
3. The terminal device according to claim 2, wherein the terminal device is further configured to: The single slice selection assistance information, S-NSSAI set, in the second pending NSSAI set is excluded from the requested NSSAI set associated with the second registration procedure.
4. A terminal device, comprising: at least one processor; as well as at least one memory storing instructions, which, when executed by the at least one processor, cause the terminal device to at least: receiving, from the second network device, a request message for an EAP identity EAP ID for second extensible authentication protocol EAP authentication, wherein the request message includes single network slice selection auxiliary information S-NSSAI; Based at least in part on the request message, determining that a first EAP authentication for the S-NSSAI is in progress; as well as A response message is sent to the second network device based on the determination, the response message including an indication that the first EAP authentication is in progress.
5. The terminal device according to claim 4, wherein the terminal device determines that the first EAP authentication for the S-NSSAI is in progress by: monitoring for a message indicating an EAP success for the first EAP authentication; and It is determined that the message indicating that the EAP was successful was not received.
6. The terminal device according to claim 4 or claim 5, wherein: The first EAP authentication is associated with the first network device, The first network device comprises a first access and mobility management function AMF in a first public land mobile network PLMN, and The second network device includes a second AMF in a second PLMN.
7. A second network device comprises: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the second network device to at least: Sending a request message for an EAP identifier EAP ID for a second extensible authentication protocol EAP authentication to a terminal network device, wherein the request message includes single network slice selection auxiliary information S-NSSAI; as well as A response message is received from the terminal network device, the response message including an indication that a first EAP authentication for the S-NSSAI is in progress.
8. The second network device according to claim 7, wherein the second network device is further configured to: remaining in a pending state based on the first EAP authentication being ongoing; and Initiate another EAP authentication for the S-NSSAI in the next uplink activity of the terminal device.
9. The second network device according to claim 7 or 8, wherein: The first EAP authentication is associated with the first network device, The first network device comprises a first access and mobility management function AMF in a first public land mobile network PLMN, and The second network device includes a second AMF in a second PLMN.
10. A second network device, comprising: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the second network device to at least: Sending an authentication request message for a second network slice specific authentication and authorization NSSAA of the terminal device to a third network device, wherein the authentication request message includes at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and An authentication rejection message is received from the third network device, where the first authentication rejection message includes at least: the S-NSSAI and an indication that a first NSSAA for the S-NSSAI is in progress.
11. The second network device according to claim 10, wherein each of the authentication request message and the authentication rejection message further includes at least one of the following: An Extensible Authentication Protocol Identifier (EAP ID) response from the terminal device, wherein the EAP ID response is used for EAP authentication for the S-NSSAI; or Access and mobility management function AMF information of the second network device.
12. The second network device according to claim 10 or 11, wherein: The first NSSAA is associated with a first network device, The first network device comprises a first access and mobility management function AMF in a first public land mobile network PLMN, The second network device comprises a second AMF in a second PLMN, and The third network device includes a network slice specific authentication and authorization function NSSAAF.
13. A third network device, comprising: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the third network device to at least: Receive an authentication request message for a second network slice specific authentication and authorization NSSAA for the terminal device from the second network device, wherein the authentication request message includes at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; as well as Based at least in part on the authentication request message, it is determined that a first NSSAA of the terminal device for the S-NSSAI is in progress, the first NSSAA being associated with a first network device.
14. The third network device according to claim 13, wherein the third network device is further configured to perform one of the following: discarding the authentication request message; or Sending an authentication rejection message to the second network device based on the determination, the authentication rejection message at least comprising: The S-NSSAI, the GPSI, and an indication that the first NSSAA is ongoing.
15. The third network device according to claim 14, wherein each of the authentication request message and the authentication rejection message further comprises: An Extensible Authentication Protocol Identifier (EAP ID) response from the terminal device, wherein the EAP ID response is used for EAP authentication for the S-NSSAI.
16. The third network device according to any one of claims 13 to 15, wherein the third network device is further configured to: receiving, from a fourth network device, a re-authentication request message for the S-NSSAI of the terminal device; Sending a first notification to one of the first network device and the second network device to trigger a first re-authentication of the terminal device; and Based on determining that the first re-authentication has been completed, a second notification is sent to the other of the first network device and the second network device to trigger a second re-authentication of the terminal device.
17. The third network device according to any one of claims 13 to 16, wherein: The first network device comprises a first access and mobility management function AMF in the first PLMN, The second network device comprises a second AMF in a second PLMN, The third network device comprises a network slice specific authentication and authorization function NSSAAF, and The fourth network device includes: an authentication, authorization and accounting server AAA-S or an AAA proxy AAA-P.
18. A third network device, comprising: at least one processor; as well as at least one memory for storing instructions that, when executed by the at least one processor, cause the first network device to at least: Receive an authentication request message for a second network slice specific authentication and authorization NSSAA for the terminal device from the second network device, the authentication request message including at least: single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; and A first authentication protocol message is sent to the fourth network device, where the first authentication protocol message includes at least: the S-NSSAI, the first AMF information, and the GPSI.
19. The third network device according to claim 18, wherein each of the authentication request message and the first authentication protocol message further includes an Extensible Authentication Protocol Identifier (EAP ID) response from the terminal device, and wherein the EAP ID response is used for a second EAP authentication for the S-NSSAI.
20. The third network device according to claim 19, wherein the third network device is further configured to: A second authentication protocol message is received from the fourth network device, where the second authentication protocol message at least includes: The S-NS SAI, the GPSI, and an indication that a first EAP authentication for the S-NS SAI is in progress.
21. The third network device according to claim 20, wherein the third network device is further configured to: Sending an authentication rejection message to the second network device, the authentication rejection message at least including: The S-NSSAI, the GPSI, and the indication.
22. The third network device according to any one of claims 18 to 21, wherein: The first NSSAA and the first EAP authentication are associated with a first network device, The first network device comprises a first access and mobility management function AMF in the first PLMN, The second network device comprises a second AMF in a second PLMN, The third network device comprises a network slice specific authentication and authorization function NSSAAF, and The fourth network device includes: an authentication, authorization and accounting server AAA-S or an AAA proxy AAA-P.
23. A fourth network device, comprising: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the fourth network device to at least: A first authentication protocol message for a second extensible authentication protocol EAP authentication of a terminal device is received from a third network device, wherein the first authentication protocol message at least includes: Single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; Determining, based at least in part on the first authentication protocol message, that a first EAP authentication of the terminal device for the S-NSSAI is in progress; and Send a second authentication protocol message to the third network device, where the second authentication protocol message includes at least: the S-NSSAI, the first AMF information, the GPSI, and an indication that the first EAP authentication is in progress.
24. The fourth network device according to claim 23, wherein: The first EAP authentication is associated with the first network device, The second EAP authentication is associated with the second network device, The first network device comprises a first access and mobility management function AMF in the first PLMN, The second network device comprises a second AMF in a second PLMN, The third network device comprises a network slice specific authentication and authorization function NSSAAF, and The fourth network device comprises an authentication, authorization and accounting server AAA-S.
25. A method comprising: Initiating, at the terminal device, a first registration procedure with a first network device of a first public land mobile network PLMN; as well as Based on determining that the first registration procedure is completed, a second registration procedure is initiated with a second network device of a second PLMN.
26. A method comprising: Receiving, at the terminal device, from the second network device, a request message for an EAP identifier EAPID for second extensible authentication protocol EA P authentication, wherein the request message includes single network slice selection auxiliary information S-NSSAI; Based at least in part on the request message, determining that a first EAP authentication for the S-NSSAI is in progress; as well as A response message is sent to the second network device based on the determination, the response message including an indication that the first EAP authentication is in progress.
27. A method comprising: Sending, at the second network device, a request message for an EAP identifier EAP ID for second extensible authentication protocol EAP authentication to the terminal network device, wherein the request message includes single network slice selection auxiliary information S-NSSAI; as well as A response message is received from the terminal network device, the response message including an indication that a first EAP authentication for the S-NSSAI is in progress.
28. A method comprising: Sending, at the second network device, an authentication request message for a second network slice specific authentication and authorization NSSAA of the terminal device to the third network device, wherein the authentication request message includes at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and An authentication rejection message is received from the third network device, where the first authentication rejection message includes at least: the S-NSSAI and an indication that a first NSSAA for the S-NSSAI is in progress.
29. A method comprising: Receiving, at the third network device, an authentication request message for a second network slice specific authentication and authorization NSSAA for the terminal device from the second network device, the authentication request message comprising at least: single network slice selection assistance information S-NSSAI, and a general public subscription identifier GPSI; and Based at least in part on the authentication request message, it is determined that a first NSSAA of the terminal device for the S-NSSAI is in progress, the first NSSAA being associated with a first network device.
30. A method comprising: Receiving, at the third network device, an authentication request message for a second network slice specific authentication and authorization NSSAA for the terminal device from the second network device, the authentication request message comprising at least: single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; and A first authentication protocol message is sent to the fourth network device, where the first authentication protocol message includes at least: the S-NSSAI, the first AMF information, and the GPSI.
31. A method comprising: Receiving, at the fourth network device, from the third network device, a first authentication protocol message for second extensible authentication protocol EAP authentication of the terminal device, wherein the first authentication protocol message includes at least: single network slice selection auxiliary information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; Determining, based at least in part on the first authentication protocol message, that a first EAP authentication of the terminal device for the S-NSSAI is in progress; and Send a second authentication protocol message to the third network device, where the second authentication protocol message includes at least: the S-NSSAI, the first AMF information, the GPSI, and an indication that the first EAP authentication is in progress.
32. An apparatus comprising components for: Initiating, at the terminal device, a first registration procedure with a first network device of a first public land mobile network PLMN; and Based on determining that the first registration procedure is completed, a second registration procedure is initiated with a second network device of a second PLMN.
33. An apparatus comprising components for: Receiving, at the terminal device, from the second network device, a request message for an EAP identifier EAPID for second extensible authentication protocol EA P authentication, wherein the request message includes single network slice selection auxiliary information S-NSSAI; Based at least in part on the request message, determining that a first EAP authentication for the S-NSSAI is in progress; as well as A response message is sent to the second network device based on the determination, the response message including an indication that the first EAP authentication is in progress.
34. An apparatus comprising components for: Sending, at the second network device, a request message for an EAP identity EAP ID for second extensible authentication protocol EAP authentication to the terminal network device, wherein the request message includes single network slice selection auxiliary information S-NSSAI; and A response message is received from the terminal network device, the response message including an indication that a first EAP authentication for the S-NSSAI is in progress.
35. An apparatus comprising components for: An authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device is sent at the second network device to the third network device, where the authentication request message includes at least: Single Network Slice Selection Assistance Information S-NSSAI, and General Public Subscription Identifier GPSI; as well as An authentication rejection message is received from the third network device, where the first authentication rejection message includes at least: the S-NSSAI and an indication that a first NSSAA for the S-NSSAI is in progress.
36. An apparatus comprising components for: An authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device is received at the third network device from the second network device, the authentication request message comprising at least: Single Network Slice Selection Assistance Information S-NSSAI, and General Public Subscription Identifier GPSI; as well as Based at least in part on the authentication request message, it is determined that a first NSSAA of the terminal device for the S-NSSAI is in progress, the first NSSAA being associated with a first network device.
37. An apparatus comprising components for: An authentication request message for a second network slice specific authentication and authorization NSSAA for a terminal device is received at the third network device from the second network device, the authentication request message comprising at least: Single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and a general public subscription identifier GPSI; as well as A first authentication protocol message is sent to the fourth network device, where the first authentication protocol message includes at least: the S-NSSAI, the first AMF information, and the GPSI.
38. An apparatus comprising components for: A first authentication protocol message for second extensible authentication protocol EAP authentication of a terminal device is received from a third network device at a fourth network device, wherein the first authentication protocol message at least includes: Single network slice selection assistance information S-NSSAI, first access and mobility management function AMF information of the second network device, and general public subscription identifier GPSI; Determining, based at least in part on the first authentication protocol message, that a first EAP authentication of the terminal device for the S-NSSAI is in progress; as well as Send a second authentication protocol message to the third network device, where the second authentication protocol message includes at least: the S-NSSAI, the first AMF information, the GPSI, and an indication that the first EAP authentication is in progress.
39. A computer readable medium comprising program instructions which, when executed by an apparatus, cause the apparatus to perform at least one of the methods according to claims 25 to 31.