Method and device for distributing terminal temporary identifier

By assigning temporary identifiers to the terminal and establishing a correspondence relationship with SUPI, the privacy and security risks caused by access network devices to obtain terminal SUPI are solved, and the privacy and security guarantee of the terminal is achieved.

CN120151849APending Publication Date: 2025-06-13HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311708317.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-13
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In the N2 interface architecture, access network devices obtaining the terminal's user permanent identity (SUPI) may lead to the leakage of the terminal's privacy information, bringing security risks.

Method used

Assign temporary identifiers to the terminal and communicate through these temporary identifiers to avoid access network devices from directly obtaining the terminal's SUPI. The specific steps include the access network device assigning a first temporary identifier to the terminal, sending a message to the AMF network element, and AMF network element obtaining the terminal's SUPI in the UDM network element, and establishing a correspondence between the temporary identifier and the SUPI.

Benefits of technology

Communication through temporary identification effectively avoids access network equipment to obtain the terminal's SUPI and ensures the privacy and security of the terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151849A_ABST
    Figure CN120151849A_ABST
Patent Text Reader

Abstract

A method and apparatus for allocating a terminal temporary identifier, the method comprising: an access network device allocates a first temporary identifier to a terminal, and sends a first message to an AMF network element, the first message comprising the first temporary identifier; and when the AMF network element receives the first message, acquiring the SUPI of the terminal at the UDM network element, and establishing a corresponding relationship between the first temporary identifier and the SUPI of the terminal. Afterwards, the access network device can communicate with the core network element based on the first temporary identifier. In the embodiment of the invention, the access network equipment communicates with the core network element based on the first temporary identifier of the terminal, and the core network element can map the first temporary identifier into the SUPI of the terminal, so that the access network equipment is prevented from acquiring the SUPI of the terminal, and the privacy and security of the terminal are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method and apparatus for allocating a temporary identifier for a terminal. Background Art

[0002] In the N2 interface architecture, an access network device can access other core network elements on the control plane only through relay by an access and mobility management function (AMF) network element. In the N2 interface service-based architecture, an access network device can access each core network element in one hop. Since a core network element can only identify a terminal through the subscription permanent identifier (SUPI) of the terminal. If the access network device obtains the SUPI of the terminal, communication is performed with the core network element based on the SUPI of the terminal. When the access network device is untrusted, it may lead to leakage of the terminal's privacy information and pose a certain security risk to the terminal. Summary of the Invention

[0003] Embodiments of this application provide a method and apparatus for allocating a temporary identifier for a terminal, so as to allocate a temporary identifier for the terminal, avoid the access network device from obtaining the SUPI of the terminal, and ensure the privacy and security of the terminal.

[0004] In a first aspect, a method for allocating a temporary identifier for a terminal is provided. The method is applied to an access network device and includes: allocating a first temporary identifier for the terminal; and sending a first message to an access and mobility management function network element, where the first message includes the first temporary identifier, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network element.

[0005] Through the above design, the access network device allocates a first temporary identifier for the terminal, the AMF network element can allocate a second temporary identifier for the terminal, and the access network device and the first core network element communicate based on the first temporary identifier and the second temporary identifier, which can avoid the access network device from obtaining the SUPI of the terminal and ensure the privacy and security of the terminal.

[0006] In a possible design, the first temporary identifier is further used to identify the terminal in a message sent by the first core network element to the access network device.

[0007] In a possible design, it further includes: receiving a second message from the access and mobility management function network element, where the second message includes the second temporary identifier of the terminal, and the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

[0008] In a possible design, it further includes: sending a third message to the first core network element, where the third message includes the first temporary identifier; receiving a fourth message from the first core network element, where the fourth message includes the first temporary identifier or the second temporary identifier.

[0009] In a possible design, the third message further includes the identification information of the access and mobility management function network element.

[0010] In a second aspect, a method for allocating a terminal temporary identifier is provided. The method is applied to an access and mobility management function network element and includes: receiving a first message from an access network device, where the first message includes a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network element.

[0011] In a possible design, the first temporary identifier is further used to identify the terminal in a message sent by the first core network element to the access network device.

[0012] In a possible design, it further includes: allocating a second temporary identifier for the terminal, where the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device; sending a second message to the access network device, where the second message includes the second temporary identifier.

[0013] In a possible design, it further includes: sending a fifth message to the first core network element, where the fifth message includes: the user permanent identifier SUPI of the terminal and the first temporary identifier. Optionally, the fifth message further includes the second temporary identifier. Optionally, the fifth message further includes the identification information of the access network device that allocates the first temporary identifier.

[0014] Through the above design, the AMF network element configures the correspondence between the temporary identifier of the terminal and the SUPI of the terminal for the first core network element. When the first core network element receives a message from the access network device, it can obtain the temporary identifier included in the message and map the temporary identifier to the SUPI of the terminal. The first core network element and the access network device can communicate through the temporary identifier of the terminal, and the first core network element can map the temporary identifier of the terminal to the SUPI of the terminal, avoiding the access network device from obtaining the SUPI of the terminal and ensuring the privacy and security of the terminal.

[0015] In a possible design, it further includes: receiving a request message from a first core network element, where the request message includes the first temporary identifier; determining the SUPI of the terminal according to the correspondence between the first temporary identifier and the SUPI of the terminal; and sending a response message to the first core network element, where the response message includes the SUPI of the terminal.

[0016] Through the above design, when the first core network element receives a message from the access network device, it can obtain the temporary identifier of the terminal in the message and send the temporary identifier to the AMF network element to request the SUPI of the terminal corresponding to the temporary identifier from the AMF network element. The AMF network element sends the SUPI of the terminal to the first core network element, thereby realizing communication between the first core network element and the access network device through the temporary identifier of the terminal, avoiding the access network device from obtaining the SUPI of the terminal, and ensuring the privacy and security of the terminal.

[0017] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the identifier information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. Optionally, the request message further includes the identifier information of the access network device that allocates the first temporary identifier.

[0018] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Optionally, the request message further includes the second temporary identifier.

[0019] In a possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identifier information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. Optionally, the request message further includes the identifier information of the access network device that allocates the first temporary identifier.

[0020] A third aspect is a corresponding method for the first aspect and the second aspect. For the beneficial effects, refer to the description of the first aspect. A communication method is provided. The method is applied to a first core network element and includes: receiving a third message from an access network device, where the third message includes a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in the message sent by the access network device to the first core network element; and sending a fourth message to the access network device, where the fourth message includes the first temporary identifier or the second temporary identifier.

[0021] In a possible design, when the fourth message includes the first temporary identifier, the first temporary identifier is further used to identify the terminal in the message sent by the access network device to the first core network element.

[0022] In a possible design, when the fourth message includes the second temporary identifier, the second temporary identifier is used to identify the terminal in the message sent by the first core network element to the access network device.

[0023] In a possible design, it further includes: determining the SUPI of the terminal according to the correspondence between the first temporary identifier and the permanent user identifier SUPI of the terminal.

[0024] In a possible design, it further includes: receiving a fifth message from an access and mobility management function network element, where the fifth message includes: the SUPI of the terminal and the first temporary identifier; determining the correspondence between the first temporary identifier and the SUPI of the terminal.

[0025] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0026] In a possible design, the fifth message further includes the identification information of the access network device that allocates the first temporary identifier.

[0027] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0028] In a possible design, the fifth message further includes the second temporary identifier.

[0029] In a possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0030] In a possible design, the fifth message further includes the identification information of the access network device that allocates the first temporary identifier.

[0031] In a possible design, the third message further includes the identification information of the access and mobility management function network element, and further includes: sending a request message to the access and mobility management function network element according to the identification information of the access and mobility management function network element, where the request message includes the first temporary identifier; receiving a response message from the access and mobility management function network element, where the response message includes the SUPI of the terminal.

[0032] In a possible design, the request message further includes the identification information of the access network device that allocates the first temporary identifier.

[0033] In a possible design, the response message further includes the first temporary identifier of the terminal.

[0034] In a possible design, the request message and the response message further include the second temporary identifier.

[0035] In a fourth aspect, a method for allocating a terminal temporary identifier is provided. The method is applied to a second core network element and includes: receiving a sixth message from an access network device, where the sixth message includes a third temporary identifier of the terminal, and the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network element; after the terminal passes network security authentication, sending a seventh message to the access network device, where the seventh message includes a fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in the message sent by the second core network element to the access network device.

[0036] Through the above design, the access network device allocates a third temporary identifier to the terminal, the second core network element allocates a fourth temporary identifier to the terminal, and the access network device and the second core network element communicate based on the third temporary identifier and the fourth temporary identifier. The access network device can avoid obtaining the SUPI of the terminal, ensuring the privacy and security of the terminal.

[0037] A fifth aspect is the corresponding method for the fourth aspect. For the beneficial effects, refer to the description of the fourth aspect. A method for allocating a terminal temporary identifier is provided. The method is applied to an access network device and includes: sending a sixth message to a second core network element, where the sixth message includes a third temporary identifier of the terminal, and the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network element; after the terminal passes network security authentication, receiving a seventh message from the second core network element, where the seventh message includes a fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in the message sent by the second core network element to the access network device.

[0038] Sixth aspect, a device is provided, which can implement the method of the first aspect or the fifth aspect above. For example, the device includes means corresponding to the first aspect or the fifth aspect above. The device can be implemented by hardware, by software, or by hardware executing corresponding software.

[0039] In a possible design, the device includes units for executing the first aspect or the fifth aspect above.

[0040] In a possible design, the device includes a processor, and the processor is used to execute the method of the first aspect or the fifth aspect above.

[0041] In a possible design, the device includes a processor and an interface circuit. The interface circuit is used to receive signals from other devices outside the device and transmit them to the processor, or send signals from the processor to other devices outside the device. The processor uses logic circuits or executes code instructions to implement the method in the first aspect or the fifth aspect above.

[0042] In a possible design, the device includes a processor and a memory. The processor is used to execute computer programs or instructions stored in the memory, so that the device implements the method of the first aspect or the fifth aspect above.

[0043] Optionally, the device can be the first device, or a module or unit (such as a chip, or a chip system, or a circuit) corresponding one by one to the method / operation / step / action described in the first aspect or the fifth aspect in the first device, or can be used in matching with the first device.

[0044] Seventh aspect, a device is provided, which can implement the method of the third aspect or the fourth aspect above. For example, the device includes means corresponding to the third aspect or the fourth aspect above. The device can be implemented by hardware, by software, or by hardware executing corresponding software.

[0045] In a possible design, the device includes units for executing the third aspect or the fourth aspect above.

[0046] In a possible design, the device includes a processor, and the processor is used to execute the method of the third aspect or the fourth aspect above.

[0047] In a possible design, the device includes a processor and an interface circuit. The interface circuit is used to receive signals from other devices outside the device and transmit them to the processor, or send signals from the processor to other devices outside the device. The processor uses logic circuits or executes code instructions to implement the method in the third aspect or the fourth aspect above.

[0048] In a possible design, the device includes a processor and a memory. The processor is configured to execute the computer program or instructions stored in the memory, so that the device implements the method of the third or fourth aspect described above.

[0049] Optionally, the device may be a second device, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the method / operation / step / action described in the third or fourth aspect in the second device, or a device that can be used in combination with the second device.

[0050] In an eighth aspect, a device is provided, which can implement the method of the second aspect described above. For example, the device includes means corresponding to the second aspect described above. The device can be implemented by hardware, by software, or by hardware executing corresponding software.

[0051] In a possible design, the device includes a unit for implementing the second aspect described above.

[0052] In a possible design, the device includes a processor, and the processor is configured to execute the method of the second aspect described above.

[0053] In a possible design, the device includes a processor and an interface circuit. The interface circuit is configured to receive signals from other devices outside the device and transmit them to the processor, or send signals from the processor to other devices outside the device. The processor uses logic circuits or executes code instructions to implement the method in the second aspect described above.

[0054] In a possible design, the device includes a processor and a memory. The processor is configured to execute the computer program or instructions stored in the memory, so that the device implements the method of the second aspect described above.

[0055] Optionally, the device may be a third device, or a module or unit (e.g., a chip, or a chip system, or a circuit) corresponding one by one to the method / operation / step / action described in the second aspect in the third device, or a device that can be used in combination with the third device.

[0056] In a ninth aspect, a computer-readable storage medium is provided, storing a computer program or instructions. When the computer program or instructions are run on a computer, the computer implements the method of any one of the first to fifth aspects described above.

[0057] In a tenth aspect, a computer program product is provided, including a computer program or instructions. When the computer program or instructions are run on a computer, the method of any one of the first to fifth aspects described above is executed.

[0058] In an eleventh aspect, a chip is provided, including a processor coupled to a memory and configured to execute a computer program or instructions stored in the memory, so that the chip implements the method according to any one of the first to fifth aspects described above.

[0059] In a twelfth aspect, a communication system is provided, including: a first communication device and a second communication device; wherein, the first communication device is configured to implement the method according to the first aspect described above, and the second communication device is configured to implement the method according to the third aspect described above. Optionally, the second communication device is further configured to implement the method according to the second aspect described above. Alternatively, the first communication device is configured to implement the method according to the fourth aspect described above, and the second communication device is configured to implement the method according to the fifth aspect described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 Schematic diagram of the architecture of the communication system provided by an embodiment of the present application;

[0061] Figure 2 N2 interface architecture provided by an embodiment of the present application;

[0062] Figure 3 Service-oriented architecture of the N2 interface provided by an embodiment of the present application;

[0063] Figure 4 Schematic diagram of a process provided by an embodiment of the present application;

[0064] Figure 5 and Figure 6 is Figure 4 Schematic diagram of the specific implementation of the process shown in the process schematic diagram;

[0065] Figure 7 Another schematic diagram of a process provided by an embodiment of the present application;

[0066] Figure 8 is Figure 7 Schematic diagram of the specific implementation of the process shown in the process schematic diagram;

[0067] Figure 9 and Figure 10 Schematic diagram of the structure of the device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0068] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods, function descriptions, etc. in the method embodiments can also be applied to the device embodiments or system embodiments.

[0069] In the embodiments of the present application, the various digital numbers and terms such as "first" and "second" involved are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The magnitude of the sequence numbers of the above processes does not mean the order of execution, and the order of execution of each process is determined by its function and internal logic.

[0070] In the embodiments of the present application, for the number of nouns, unless otherwise specified, it means "singular noun or plural noun", that is, "one or more". "At least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural.

[0071] Figure 1 A possible and non-limiting system schematic diagram is shown. As Figure 1 shown, the communication system 10 includes a terminal 100, a radio access network (RAN) 200, and a core network (CN) 300.

[0072] Among them, the terminal 100 can also be referred to as a terminal device, a user equipment (UE), a mobile station, a mobile terminal, etc. The terminal can be widely applied to various scenarios, such as device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, remote medical treatment, smart grid, smart furniture, smart office, smart wearables, smart transportation, smart city, etc. The terminal can be a mobile phone, a head-mounted display device, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, a drone, a helicopter, an airplane, a ship, a robot, a robotic arm, a smart home device, etc. The embodiments of the present application do not limit the device form of the terminal.

[0073] RAN200 includes at least one RAN node. The terminal 100 can be connected to the RAN node wirelessly. The RAN node is connected to the core network 300 wirelessly or wiredly. The core network devices in the core network 300 and the RAN nodes in the RAN200 can be different physical devices respectively, or the same physical device integrating the logical functions of the core network devices and the logical functions of the radio access devices.

[0074] RAN200 can be a cellular system related to the 3rd generation partnership project (3GPP), for example, the 4th generation (4G) mobile communication system, the 5th generation (5G) mobile communication system, or an evolved system for the future, for example, the 6th generation (6G) mobile communication system. RAN200 can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. RAN 200 can also be a communication system integrating two or more of the above systems.

[0075] In a possible scenario, the RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a next generation base station in the 6G mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system, etc. The RAN node can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, or a radio controller in a CRAN scenario. Optionally, the RAN node can also be a server, a wearable device, a vehicle or an in-vehicle device, etc. For example, the access network device in vehicle to everything (V2X) technology can be a road side unit (RSU). All or part of the functions of the RAN node in the embodiments of the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The RAN node in the embodiments of the present application can also be a logical node, a logical module or software that can implement all or part of the functions of the RAN node.

[0076] In another possible scenario, multiple RAN nodes cooperate to assist a terminal in achieving wireless access, and different RAN nodes respectively implement partial functions of a base station. For example, the RAN nodes can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be set separately, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0077] In different systems, the CU (or CU-CP and CU-UP), DU, or RU can also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, the CU can also be called an O-CU (open CU), the DU can also be called an O-DU, the CU-CP can also be called an O-CU-CP, the CU-UP can also be called an O-CU-UP, and the RU can also be called an O-RU. For ease of description, in this application, the CU, CU-CP, CU-UP, DU, and RU are used as examples for description. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through a software module, a hardware module, or a combination of a software module and a hardware module.

[0078] RAN nodes, sometimes also called access network devices, RAN entities, or access nodes, etc., form part of a communication system to help a terminal achieve wireless access. In the subsequent description of this application, if there is no special indication, the description will be made using "access network device". The multiple RAN nodes in the RAN 200 can be of the same type of nodes or different types of nodes. In the access network service-based architecture, the "access network device" can also be replaced by an access network function (ANF) network element.

[0079] The core network 300 includes one or more core network elements. For example, as Figure 1As shown in the figure, the core network 300 includes data plane function network elements, such as user plane function (UPF) network elements, and control plane function network elements, such as access and mobility management function (AMF) network elements, session management function (SMF) network elements, policy control function (PCF) network elements, and unified data management (UDM) network elements, etc. Optionally, the access and mobility management function network element can also be replaced by an access management function network element or a registration management function network element.

[0080] It can be understood that the names of the various network elements in the core network 300 are not limited. For example, in a 5G communication system, the network element that implements the signaling processing part is called an AMF network element. In a 6G communication system, the network element that implements the above functions can also be called other names, etc., without limitation. In the following description, the names of the various network elements in 5G are mainly used as examples to describe the solutions of the embodiments of the present application. Optionally, the core network 300 may also include other control plane function network elements. For example, network exposure function (NEF) network elements, application function (AF) network elements, network slice selection function (NSSF) network elements, authentication server function (AUSF) network elements, network repository function (NRF) network elements, unified data repository (UDR) network elements, network data analytics function (NWDAF) network elements, or location management function (LMF) network elements, etc.

[0081] It can be understood that the access network device and the core network network element can be called communication devices. For example, the access network device can be understood as a communication device with base station functions, and the core network network element can be understood as a communication device with core network functions. For example, an AMF network element can be understood as a communication device with AMF functions.

[0082] In a network architecture, the interface between the access network device and the AMF network element is the N2 interface. The access network device accesses other core network elements of the control plane function through the relay of the AMF network element. For example, as Figure 2 shown, the access network device accesses the UDM network element, the SMF network element, the PCF network element, the AUSF network element, or the LMF network element, etc. through the relay of the AMF network element. This network architecture is called the N2 interface architecture. Among them, the access network device and the AMF network element communicate based on the temporary identifier of the terminal. In the core network, the AMF network element and other core network elements communicate based on the subscription permanent identifier (SUPI) of the terminal. After the terminal passes the security authentication, the AMF network element obtains the SUPI of the terminal in the UDM network element, and the AMF network element establishes a correspondence between the temporary identifier of the terminal and the SUPI of the terminal. In the uplink communication, the AMF network element maps the temporary identifier of the terminal to the SUPI of the terminal according to the correspondence between the temporary identifier of the terminal and the SUPI of the terminal. In the downlink communication, the AMF network element maps the SUPI of the terminal to the temporary identifier of the terminal according to the correspondence between the temporary identifier of the terminal and the SUPI of the terminal. For example, the access network device requests the positioning of a terminal from the LMF network element. In a possible implementation: the access network device may send a request message to the AMF network element, and the request message includes the temporary identifier of the terminal. The AMF network element, as a relay, maps the temporary identifier of the terminal to the SUPI of the terminal. The AMF network element forwards the request message to the LMF, and the request message includes the SUPI of the terminal. When the LMF receives the request message, it obtains the SUPI of the terminal in the request message. The LMF network element locates the terminal according to the SUPI of the terminal and obtains the positioning result. Further, the LMF network element sends the positioning result to the access network device through the relay of the AMF network element. In a possible implementation, the LMF network element may send the positioning result and the SUPI of the terminal to the AMF network element. The AMF network element may map the SUPI of the terminal to the temporary identifier of the terminal. The AMF network element sends the positioning result and the temporary identifier of the terminal to the access network device. In this solution, the access network device and the AMF network element communicate based on the temporary identifier of the terminal, the AMF network element and other core network elements communicate based on the SUPI of the terminal, and the access network device cannot obtain the SUPI of the terminal, ensuring the privacy and security of the terminal.

[0083] In another network architecture, the access network device can access each core network element in one hop, that is, the access network device directly communicates with the core network element without going through the relay and / or forwarding of the AMF network element. For example, as Figure 1 shown, the access network device can directly communicate with Figure 1 the AMF network element, the SMF network element, the PCF network element or the UDM network element, etc. shown. Or, as Figure 3As shown, the access network device can directly communicate with Figure 3 the UDM network element, SMF network element, PCF network element, AUSF network element, LMF network element, AMF network element, etc. shown in the figure. Figure 1 Or Figure 3 the network architecture shown in the figure, which is called the N2 interface service-oriented architecture. The core network element identifies the terminal through the SUPI of the terminal. In a possible implementation, the access network device can obtain the SUPI of the terminal and communicate with the core network element based on the SUPI of the terminal. For example, the message sent by the access network device to the core network element carries the SUPI of the terminal, and the core network element performs corresponding operations on the corresponding terminal based on the SUPI of the terminal. If the access network device is not trusted and the access network device obtains the SUPI of the terminal, it may lead to the leakage of the terminal's privacy information and pose a security risk to the terminal.

[0084] In view of this, the embodiments of the present application provide a method and device for allocating a temporary identifier for a terminal. The method includes: the access network device allocates a first temporary identifier for the terminal and sends a first message to the AMF network element. The first message includes the first temporary identifier. When the AMF network element receives the first message, it obtains the SUPI of the terminal in the UDM network element and establishes a correspondence between the first temporary identifier and the SUPI of the terminal. After that, the access network device can communicate with the core network element based on the first temporary identifier. For example, the message sent by the access network device to the core network element carries the first temporary identifier of the terminal. The core network element maps the first temporary identifier to the SUPI of the terminal based on the above correspondence between the first temporary identifier and the SUPI of the terminal. The core network element performs corresponding operations according to the SUPI of the terminal. In the embodiments of the present application, the access network device communicates with the core network element based on the first temporary identifier of the terminal, and the core network element can map the first temporary identifier to the SUPI of the terminal, thereby avoiding the access network device from obtaining the SUPI of the terminal and ensuring the privacy and security of the terminal.

[0085] As Figure 4 shown, the embodiments of the present application provide a process schematic diagram, including:

[0086] Step 400: The access network device allocates a first temporary identifier for the terminal.

[0087] For example, the terminal is in the radio resource control (RRC) connected state or the inactive state. When the access network device and the AMF network element first interact with the associated message of the terminal, a first temporary identifier is allocated for the terminal.

[0088] Step 410: The access network device sends a first message to the AMF network element, and the AMF network element receives the first message from the access network device.

[0089] For example, the first message includes a first temporary identifier. When the AMF network element receives the first message, it can trigger the corresponding network element to perform network security verification on the terminal. After the terminal passes the network security verification, the AMF network element can obtain the SUPI of the terminal in the UDM network element. The AMF network element establishes and stores the correspondence between the first temporary identifier and the SUPI of the terminal. Optionally, the "correspondence" described in the embodiments of the present application can be replaced by an "association relationship" or a "mapping relationship", etc. The first message may be the information related to the terminal in the first interaction between the access network device and the AMF network element. For example, the first message is the registration request message of the terminal, and the second message below is the registration response message of the terminal.

[0090] Optionally, since the first temporary identifier is assigned by the access network device, it may happen that different access network devices assign the same temporary identifier to different terminals, that is, the first temporary identifier may not uniquely identify a terminal. To achieve the purpose of uniquely identifying a terminal, the AMF network element can obtain the identification information of the access network device. For example, the identity document (ID) of the access network device, the uniform resource locator (URL) address of the access network device, or the transport network layer (TNL) address of the access network device, etc. Optionally, the ID of the access device can be reported by the access network device. For example, the first message further includes the ID of the access network device. The AMF network element establishes and stores the correspondence between the first temporary identifier, the information of the access network device that assigns the first temporary identifier, and the SUPI of the terminal.

[0091] In another possible implementation, after the terminal passes the network security verification, the AMF network element can assign a second temporary identifier to the terminal. The AMF network element establishes and stores the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Further, optionally, the AMF network element can also obtain the identification information of the access network device that assigns the first temporary identifier, and the AMF network element establishes and stores the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that assigns the first temporary identifier, and the SUPI of the terminal.

[0092] Step 420: The AMF network element sends a second message to the access network device, and the access network device receives the second message from the AMF network element. Step 420 is optional, and the AMF network element may not execute step 420.

[0093] For example, the second message is a response message to the first message, and the second message includes a first temporary identifier or a second temporary identifier. There is no restriction on whether the second message includes other information. For example, when the second message includes the first temporary identifier, it further includes the second temporary identifier. Or, when the second message includes the second temporary identifier, it further includes the first temporary identifier.

[0094] For example, the interface between the AMF network element and the access network device is the N2 interface, and the first message and the second message can be referred to as N2 interface messages related to the terminal. The first temporary identifier is assigned by the access network device to the terminal. The terminal is represented as UE, and the access network device is represented as CU. The first temporary identifier can be represented as the UE-CU-specific temporary identifier. The second temporary identifier is assigned by the core network (CN) network element, the AMF network element. The second temporary identifier can be represented as the UE-CN-specific temporary identifier.

[0095] In a possible implementation, the first temporary identifier is used to identify the terminal in the message sent by the access network device to the first core network device. There is no restriction on whether the first temporary identifier has other uses. For example, the first temporary identifier is also used to identify the terminal in the message sent by the first core network device to the access network device.

[0096] For example, in the scenario where the AMF network element does not assign a second temporary identifier to the terminal: During the uplink communication and downlink communication processes, the first temporary identifier is used to identify the terminal. For example, during the uplink communication process, the message sent by the access network device to the first core network element includes the first temporary identifier. The first core network element can determine the SUPI of the terminal based on the first temporary identifier. For the process by which the first core network element determines the SUPI of the terminal, see the description below. During the downlink communication process, the message sent by the first core network device to the access network device includes the first temporary identifier. The access network device can identify the terminal based on the first temporary identifier. At this time, optionally, the second message includes the first temporary identifier.

[0097] For example, in the scenario where the AMF network element assigns a second temporary identifier to the terminal: The second temporary identifier is used to identify the terminal in the message sent by the first core network element to the access network device, that is, the second temporary identifier is used to identify the terminal during the downlink communication process. At this time, the second message includes the second temporary identifier to notify the access network device of the second temporary identifier assigned by the AMF network element.

[0098] In a possible implementation, the second temporary identifier is also used to identify the terminal in the message sent by the access network device to the first core network element, that is, the second temporary identifier is used to identify the terminal in both the uplink communication and the downlink communication. At this time, the first temporary identifier is used to identify the terminal in both the uplink communication and the downlink communication. At this time, during the uplink communication and the downlink communication, a temporary identifier pair composed of the first temporary identifier and the second temporary identifier is used to identify the terminal. For example, during the uplink communication, the message sent by the access network device to the first core network element includes the first temporary identifier and the second temporary identifier. During the downlink communication, the message sent by the first core network element to the access network device includes the first temporary identifier and the second temporary identifier. At this time, the second message includes the first temporary identifier and the second temporary identifier. When the access network device receives the second message, it establishes and stores the correspondence between the first temporary identifier and the second temporary identifier.

[0099] It can be understood that the access network device may include a CU and a DU. The "access network device" in the embodiments of the present application may be replaced by "CU". For example, the CU assigns the first temporary identifier to the terminal, the CU sends the first message to the AMF network element, and the AMF network element sends the second message to the CU, etc.

[0100] For example, the "first temporary identifier" or, "the first temporary identifier and the second temporary identifier" in the embodiments of the present application are valid within the effective area. The effective area may refer to the public land mobile network (PLMN), registration area (RA), or tracking area (TA) of the terminal, etc. Taking the PLMN as an example, that is, the "first temporary identifier" or "the first temporary identifier and the second temporary identifier" can identify the terminal within the PLMN range of the terminal. Beyond the PLMN range of the terminal, the "first temporary identifier" or "the first temporary identifier and the second temporary identifier" becomes invalid and can no longer identify the terminal.

[0101] It can be understood that the application scenario in the embodiments of the present application may be: the access network device accesses the first core network element in one hop, that is, the access network device can directly communicate with the first core network element without passing through the forwarding of the AMF network element. Of course, the solution in the embodiments of the present application can also be applied to other scenarios without limitation. The "first core network element" in the embodiments of the present application may be other core network elements except the AMF network element.

[0102] Through the above design, the access network device assigns the first temporary identifier to the terminal, the AMF network element can assign the second temporary identifier to the terminal, and the access network device and the first core network element communicate based on the first temporary identifier and the second temporary identifier, which can avoid the access network device from obtaining the SUPI of the terminal and ensure the privacy and security of the terminal.

[0103] The following continues to describe how the first core network element determines the SUPI of the terminal according to the first temporary identifier included in the message when receiving a message from the access network device.

[0104]

An example

[0105] The AMF network element receives the first message from the access network device, and the AMF network element establishes and stores the correspondence between the first temporary identifier and the SUPI of the terminal. The AMF network element configures the correspondence between the first temporary identifier and the SUPI of the terminal to the first core network element through the fifth message. When the first core network element receives a message from the access network device, it determines the SUPI of the terminal according to the first temporary identifier included in the message and the correspondence between the first temporary identifier and the SUPI of the terminal configured by the AMF network element.

[0106] As Figure 5 shown, an embodiment of the present application provides a schematic flowchart, which is a specific implementation of the schematic flowchart shown in Figure 4 and includes:

[0107] Step 500: The access network device assigns a first temporary identifier to the terminal.

[0108] Step 510: The access network device sends a first message to the AMF network element, and the AMF network element receives the first message from the access network device. The first message includes the first temporary identifier.

[0109] Optionally, in step 520: The AMF network element sends a second message to the access network device, and the access network device receives the second message from the AMF network element.

[0110] For the specific implementation process of steps 500 to 520, refer to Figure 4 the description of steps 400 to 420 therein.

[0111] Step 530: The AMF network element sends a fifth message to the first core network element, and the first core network element receives the fifth message from the AMF network element.

[0112] In a possible implementation manner, the fifth message is used for the AMF network element to configure the correspondence between the first temporary identifier of the terminal and the SUPI of the terminal to the first core network element. The fifth message is a configuration message related to the terminal. The fifth message includes the first temporary identifier and the SUPI of the terminal. When the first core network element receives the fifth message, it obtains the first temporary identifier and the SUPI of the terminal in the fifth message. The first core network element establishes the correspondence between the first temporary identifier and the SUPI of the terminal.

[0113] Optionally, since the first temporary identifier is assigned by the access network device, it is possible that different access network devices assign the same temporary identifier to different terminals, that is, the first temporary identifier may not be able to uniquely identify a terminal. To achieve the purpose of uniquely identifying a terminal, the fifth message further includes: the identifier information of the access network device that assigns the first temporary identifier. The correspondence between the first temporary identifier established by the first core network element and the SUPI of the terminal is specifically: the correspondence between the first temporary identifier, the identifier information of the access network device that assigns the first temporary identifier, and the SUPI of the terminal. At this time, it is considered that the AMF network element configures the correspondence to the first core network element through the fifth message, specifically: the correspondence between the first temporary identifier, the identifier information of the access network device that assigns the first temporary identifier, and the SUPI of the terminal.

[0114] In another possible implementation, after the terminal passes the network security authentication, the AMF network element can also assign a second temporary identifier to the terminal. For the process of the AMF network element assigning the second temporary identifier to the terminal, see the description in Figure 4 The correspondence between the first temporary identifier established by the first core network element and the SUPI of the terminal is specifically: the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. In this possible implementation, the fifth message includes at least the first temporary identifier and the SUPI of the terminal. The first core network element can determine the second temporary identifier corresponding to the first temporary identifier included in the fifth message based on the stored pair of temporary identifiers, and further establish the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Alternatively, the fifth message further includes the second temporary identifier, and the first core network element can obtain the second temporary identifier from the fifth message. At this time, it is considered that the AMF network element configures the correspondence to the first core network element through the fifth message, specifically: the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0115] Optionally, the correspondence between the first temporary identifier, the second temporary identifier, and the SUIPI of the terminal established by the first core network element is specifically: the correspondence between the first temporary identifier, the second temporary identifier, the identifier information of the access network device that assigns the first temporary identifier, and the SUPI of the terminal. Optionally, the fifth message further includes the identifier information of the access network device that assigns the first temporary identifier. At this time, it is considered that the AMF network element configures the correspondence to the first core network element through the fifth message, specifically: the correspondence between the first temporary identifier, the second temporary identifier, the identifier information of the access network device that assigns the first temporary identifier, and the SUPI of the terminal.

[0116] For example, Figure 5As shown, the fifth message includes a list of information of the terminal. The list of information of the terminal includes: the SUPI of the terminal, the identification information of the access network device that allocates the first temporary identifier, and the temporary identifier of the terminal. For example, the first temporary identifier of the terminal, or the first temporary identifier and the second temporary identifier of the terminal.

[0117] Step 540: The access network device sends a third message to the first core network element, and the first core network element receives the third message from the access network device.

[0118] For example, the first core network element may be other core network elements except the AMF network element, such as the UDM network element, the SMF network element, the PCF network element, the AUSF network element, or the LMF network element, etc. The interface between the access network device and the first core network element may be Nx, and the third message may be an Nx message related to the terminal. The third message includes the first temporary identifier, and there is no restriction on whether the third message further includes other information. For example, the third message further includes the second temporary identifier, or the identification information of the access network device, etc.

[0119] In a possible implementation, when receiving the third message, the first core network element obtains the first temporary identifier in the third message. The first core network element determines the SUPI of the terminal according to the correspondence between the first temporary identifier and the SUPI of the terminal. Alternatively, further, the first core network element may also obtain the identification information of the access network device. For example, since the access network device communicates with the first core network element, the first core network element may obtain identification information such as the URL address of the access network device. Or, the third message further includes the identification information of the access network device, and the first core network element may obtain the identification information of the access network device in the third message. The first core network element determines the SUPI of the terminal according to the correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0120] In another possible implementation, when receiving the third message, the first core network element obtains the first temporary identifier in the third message. Optionally, the third message further includes the second temporary identifier, and the first core network element obtains the second temporary identifier in the third message. Or, the first core network element obtains the second temporary identifier corresponding to the first temporary identifier according to the stored pair of temporary identifiers. The first core network element determines the SUPI of the terminal according to the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Alternatively, further, the first core network element also obtains the identification information of the access network device, and the first core network element determines the SUPI of the terminal according to the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0121] For example, as Figure 5As shown, the third message includes the identification information of the access network device and the temporary identifier of the terminal. The temporary identifier may include a first temporary identifier, or the temporary identifier includes a first temporary identifier and a second temporary identifier.

[0122] After the first core network element obtains the SUPI of the terminal, corresponding operations are performed on the terminal according to the SUPI of the terminal. For example, if the first core network element is an LMF network element, the access network device requests the LMF network element to locate the terminal, and the third message may be a positioning request message related to the terminal. When the LMF network element receives the positioning request message, it determines the SUPI of the terminal according to information such as the first temporary identifier of the terminal included in the positioning request message. The LMF network element performs a positioning operation on the terminal corresponding to the SUPI and obtains a positioning result. Further, the LMF network element may send the positioning result to the access network device. For example, the fourth message in step 550 below may be a positioning response message, and the positioning response message includes the positioning result of the terminal. Further, in order for the access network device to identify the terminal corresponding to the positioning result, the positioning response message may also include information such as the first temporary identifier or the second temporary identifier of the terminal.

[0123] Step 550: The first core network element sends a fourth message to the access network device, and the access network device receives the fourth message from the first core network element.

[0124] For example, the fourth message is a response message to the third response. The fourth message may be an Nx message related to the terminal. The fourth message includes a first temporary identifier or a second temporary identifier. For example, the fourth message includes a first temporary identifier, and there is no restriction on whether the fourth message includes other information. For example, the fourth message does not include other information, or the fourth message further includes a second temporary identifier, etc. Or, the fourth message includes a second temporary identifier, and there is no restriction on whether the fourth message includes other information. For example, the fourth message does not include other information, or the fourth message further includes a first temporary identifier, etc.

[0125] In a possible implementation manner, in the scenario where the terminal is assigned a temporary identifier, that is, the first temporary identifier, the fourth message includes the first temporary identifier. When the access network device receives the fourth message, it can determine the specific terminal corresponding to the fourth message according to the first temporary identifier included in the fourth message.

[0126] In another possible implementation, the terminal is assigned two temporary identifiers, namely, a first temporary identifier assigned by the access network device and a second temporary identifier assigned by the AMF network element. In a scenario where the first temporary identifier is used for uplink communication and the second temporary identifier is used for downlink communication, the third message includes the first temporary identifier, and the fourth message includes the second temporary identifier. Alternatively, in a scenario of uplink and downlink communication, when using the temporary identifier to identify the terminal, both the third message and the fourth message include the first temporary identifier and the second temporary identifier.

[0127] For example, the first temporary identifier is assigned by the access network device to the terminal. The first temporary identifier can be expressed as: terminal - access network device - specific temporary identifier. For example, if the terminal is represented as UE and the access network device is represented as CU, the first temporary identifier is specifically UE - CU - specific temporary identifier. The second temporary identifier is assigned by the core network element AMF network element to the terminal. The second temporary identifier is expressed as: terminal - core network (CN) - specific temporary identifier. For example, the second temporary identifier is specifically UE - CN - specific temporary identifier.

[0128] It can be understood that in Figure 5 the scenario, taking the access network device taking the initiative to initiate communication as an example, the communication between the access network device and the first core network element can also be initiated by the first core network element. For example, the first core network element obtains the SUPI of the terminal, and according to the stored correspondence between the temporary identifier and the SUPI of the terminal, obtains the temporary identifier of the terminal. The message sent by the first core network element to the access network device includes the temporary identifier of the terminal, and this temporary identifier can be the first temporary identifier, the second temporary identifier, or both the first temporary identifier and the second temporary identifier, etc.

[0129] Through the above design, the AMF network element configures the correspondence between the temporary identifier of the terminal and the SUPI of the terminal to the first core network element. When the first core network element receives the message from the access network device, it can obtain the temporary identifier included in the message, map the temporary identifier to the SUPI of the terminal. The first core network element and the access network device can communicate through the temporary identifier of the terminal, and the first core network element can map the temporary identifier of the terminal to the SUPI of the terminal, avoiding the access network device obtaining the SUPI of the terminal and ensuring the privacy and security of the terminal.

[0130]

Another example

[0131] When the first core network element receives the third message from the access network device, it can send information such as the first temporary identifier included in the third message to the AMF network element. The AMF network element determines the SUPI of the terminal according to the stored correspondence and sends the SUPI of the terminal to the first core network element. The first core network element can perform corresponding operations according to the SUPI of the terminal.

[0132] As shown Figure 6 in the figure, an embodiment of the present application provides a process schematic diagram, which is a specific implementation of the process schematic diagram shown Figure 4 in the figure, and includes:

[0133] Step 600: The access network device assigns a first temporary identifier to the terminal.

[0134] Step 610: The access network device sends a first message to the AMF network element, and the AMF network element receives the first message from the access network device. The first message includes the first temporary identifier.

[0135] Optionally, step 620: The AMF network element sends a second message to the access network device, and the access network device receives the second message from the AMF network element.

[0136] For the specific implementation process of steps 600 to 620, refer to Figure 4 the description of steps 400 to 420 in

[0137] Step 630: The access network device sends a third message to the first core network element, and the first core network element receives the third message from the access network device.

[0138] For example, as Figure 6 shown in the figure, the third message includes the first temporary identifier of the terminal and the identification information of the AMF network element. For example, the identification information of the AMF network element may be the ID of the AMF network element, or the URL address of the AMF network element, etc. There is no limitation on whether other information is included in the third message. For example, the third message further includes a second temporary identifier. The third message further includes the identification information of the access network device, etc.

[0139] Step 640: The first core network element sends a request message to the AMF network element according to the identification information of the AMF network element, and the AMF network element receives the request message from the first core network element.

[0140] For example, the request message is used to request the AMF network element to retrieve the SUPI of the terminal, and the request message may be a retrieval request. The request message includes the first temporary identifier. There is no limitation on whether other information is included in the request message. For example, the request message further includes a second temporary identifier. The request message further includes the identification information of the access network device that assigns the first temporary identifier. Since the access network device that sends the third message in step 630 is the access network device that assigns the first temporary identifier, the identification information of the access network device that assigns the first temporary identifier is the identification information of the access network device that sends the third message.

[0141] Step 650: The AMF network element sends a response message to the first core network element, and the first core network element receives the response message from the AMF network element.

[0142] For example, the response message includes the SUPI of the terminal. In one possible implementation, when receiving the request message, the AMF network element obtains the first temporary identifier in the request message. The AMF network element determines the SUPI of the terminal according to the corresponding relationship between the first temporary identifier stored and the SUPI of the terminal. Alternatively, in another possible implementation, the request message further includes the identification information of the access network device. When receiving the request message, the AMF network element obtains the first temporary identifier and the identification information of the access network device in the request message. The AMF network element determines the SUPI of the terminal according to the corresponding relationship between the first temporary identifier stored, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. Alternatively, in another possible implementation, when receiving the request message, the AMF network element obtains the second temporary identifier. For example, when the AMF network element obtains the first temporary identifier in the request message, it obtains the second temporary identifier corresponding to the first temporary identifier according to the stored pair of temporary identifiers. Alternatively, the request message further includes the second temporary identifier, and the AMF network element obtains the second temporary identifier in the request message. The AMF network element determines the SUPI of the terminal according to the corresponding relationship between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal. Optionally, the request message further includes the identification information of the access network device, and the AMF network element determines the SUPI of the terminal according to the corresponding relationship between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal. The AMF network element sends a response message including the SUPI of the terminal to the first core network element. When receiving the response message, the first core network element obtains the SUPI of the terminal in the response message and performs corresponding operations according to the SUPI of the terminal.

[0143] Step 660: The first core network element sends a fourth message to the access network device, and the access network device receives the fourth message from the first core network element.

[0144] For example, the fourth message may be a response message to the third message, and both the third message and the fourth message are terminal-related information. The fourth message may include the first temporary identifier or the second temporary identifier, etc. There is no restriction on whether other information is included in the fourth message.

[0145] It can be understood that in Figure 6In the scenario, the access network device takes the initiative to initiate communication as an example. The communication between the access network device and the first core network element can also be initiated by the first core network element. For example, when the first core network element obtains the SUPI of the terminal, it sends the SUPI of the terminal to the AMF network element. The AMF network element maps the SUPI of the terminal to a temporary identifier of the terminal and sends the temporary identifier of the terminal to the first core network element. The message sent by the first core network element to the access network device includes the temporary identifier of the terminal, and the temporary identifier can be a first temporary identifier, a second temporary identifier, or a first temporary identifier and a second temporary identifier.

[0146] Through the above design, when the first core network element receives a message from the access network device, it can obtain the temporary identifier of the terminal in the message and send the temporary identifier to the AMF network element to request the SUPI of the terminal corresponding to the temporary identifier from the AMF network element. The AMF network element sends the SUPI of the terminal to the first core network element, thereby realizing communication between the first core network element and the access network device through the temporary identifier of the terminal, avoiding the access network device from obtaining the SUPI of the terminal, and ensuring the privacy and security of the terminal.

[0147] The embodiment of the present application further provides a method and device for allocating a temporary identifier. In this method: when the access network device and a certain core network element first interact with the relevant information of the terminal, the access network device allocates a temporary identifier for the terminal, and the temporary identifier is used to identify the terminal in the uplink communication, that is, the temporary identifier is used to identify the terminal in the message sent by the access network device to the core network element. After the terminal passes the security authentication of the network, the core network element allocates another temporary identifier for the terminal, and the temporary identifier is used to identify the terminal in the downlink communication, that is, the other temporary identifier is used to identify the terminal in the message sent by the core network element to the access network device.

[0148] As Figure 7 shown, a process schematic diagram is provided, including:

[0149] Step 710: The access network device sends a sixth message to the second core network element, and the second core network element receives the sixth message from the access network device.

[0150] For example, when the access network device interacts with the second core network element for the first time about the relevant information of the terminal, it may allocate a third temporary identifier to the terminal, and the sixth message includes the third temporary identifier. The third temporary identifier is used to identify the terminal during the uplink communication process, that is, the third temporary identifier is used to identify the terminal in the message sent by the access network device to the second core network element. The terminal may be in the RRC connected state, or the inactive state, etc., without limitation. There is no limitation on whether the sixth message includes other information. The interface between the access network device and the second core network element is the Nx interface, and the sixth message and the seventh message can be referred to as Nx messages related to the terminal.

[0151] Step 720: The authentication and authorization network element performs network security authentication on the terminal.

[0152] In a possible implementation, the authentication and authorization network element may be the identity identification function (IDfuction, IDF) network element of the terminal, or the UDM network element and the AUSF network element, or a newly defined network element, etc., without limitation. After authentication and authorization, the legitimacy of the terminal can be determined. If both authentication and authorization are passed, it is determined that the terminal is legal; if at least one of authentication and authorization fails, it is determined that the terminal is illegal. When the terminal is legal, the second core network element may allocate a fourth temporary identifier to the terminal and notify the access network device of the fourth temporary identifier through the seventh message below. The fourth temporary identifier is used to identify the terminal during the downlink communication process, that is, the fourth temporary identifier is used to identify the terminal in the message sent by the second core network element to the access network device. Further, the second core network element requests the SUPI of the terminal from the AMF network element, and establishes and stores the correspondence relationship between the third temporary identifier, the fourth temporary identifier and the SUPI of the terminal. Further, the sixth message also includes the identification information of the access network device that allocates the third temporary identifier, and the second core network element may establish and store the correspondence relationship between the third temporary identifier, the fourth temporary identifier, the identification information of the access network device that allocates the third temporary identifier and the SUPI of the terminal. Or, the second core network element may obtain the identification information of the access network device through other means. For example, since the second core network element and the access network device can communicate, the second core network element can obtain identification information such as the URL address of the access network device. Or, when the terminal is illegal, the process ends, and the third temporary identifier and the fourth temporary identifier are no longer enabled. That is to say, in the embodiments of the present application, only when the terminal passes the network security authentication and is legal, will the third temporary identifier and the fourth temporary identifier be enabled. Optionally, the "authentication and authorization" in the embodiments of the present application may be a conventional "authentication and authorization" process, or a simplified "authentication and authorization" process, etc., without limitation.

[0153] Step 730: The second core network element sends a seventh message to the access network device, and the access network device receives the seventh message from the second core network element.

[0154] For example, the seventh message includes a fourth temporary identifier. There is no limitation on whether the seventh message further includes other information. For example, the seventh message further includes a third temporary identifier. In a possible implementation, the third temporary identifier is allocated by the access network device and is used to identify the terminal in the message sent by the access network device to the second core network element. The terminal is represented as UE, the access network device is represented as CU, the second core network element is represented as NFx, and the third temporary identifier is represented as UE-CU-NFx-specific temporary identifier. The fourth temporary identifier is allocated by the second core network element and is used to identify the terminal in the message sent by the second core network element to the access network device, and the fourth temporary identifier is represented as UE-NFx-CU-specific temporary identifier.

[0155] In a possible implementation, the second core network element may be other network elements except the AMF network element. The application scenario of the embodiments of the present application may be: the access network device accesses the second core network element in one hop, that is, the access network device can directly communicate with the second core network element without the forwarding of the AMF network element in the middle. Of course, the solution of the embodiments of the present application can also be applied to other scenarios except the above scenarios without limitation. After the interaction of the above steps 710 to 730, both the access network device and the second core network element can obtain the third temporary identifier and the fourth temporary identifier of the terminal. After that, the access network device and the second core network element can communicate based on the third temporary identifier and the fourth temporary identifier. It can be understood that although it is described above that the third temporary identifier is used to identify the terminal in the uplink communication process and the fourth temporary identifier is used to identify the terminal in the downlink communication process. There is no limitation on whether the third temporary identifier and the fourth temporary identifier are used for other purposes. For example, the third temporary identifier can also be used to identify the terminal in the downlink communication process, and the fourth temporary identifier can also be used to identify the terminal in the uplink communication process. For example, the third temporary identifier and the fourth temporary identifier form a temporary identifier pair, and the temporary identifier pair is used to identify the terminal in both the uplink communication process and the downlink communication process. For example, in the uplink communication process, the access network device sends an eighth message to the second core network element, and the eighth message includes the third temporary identifier and the fourth temporary identifier. The second core network element determines the SUPI of the terminal according to the correspondence between the third temporary identifier, the fourth temporary identifier, and the SUPI of the terminal, and performs corresponding operations according to the SUPI of the terminal. The second core network element sends a ninth message to the access network device, and the ninth message includes the third temporary identifier and the fourth temporary identifier, etc.

[0156] For example, the "third temporary identifier and fourth temporary identifier" in the embodiments of the present application are valid within the valid area. The valid area may refer to the PLMN, RA, or TA of the terminal, etc. Taking the PLMN as an example, that is, the "third temporary identifier and fourth temporary identifier" can identify the terminal within the PLMN range of the terminal. Beyond the PLMN range of the terminal, the "third temporary identifier and fourth temporary identifier" become invalid and can no longer identify the terminal.

[0157] Through the above design, the access network device allocates a third temporary identifier for the terminal, and the second core network element allocates a fourth temporary identifier for the terminal. The access network device and the second core network element communicate based on the third temporary identifier and the fourth temporary identifier. The access network device can avoid obtaining the SUPI of the terminal, ensuring the privacy and security of the terminal.

[0158] Such as Figure 8 shown, the embodiments of the present application further provide a process schematic diagram, which is a specific implementation of the process schematic diagram shown in Figure 7 shown, including:

[0159] Step 810: The access network device sends N2 message 1 to the AMF network element, and the AMF network element receives N2 message 2 from the access network device.

[0160] For example, the interface between the access network device and the AMF network element is the N2 interface, and the messages exchanged between the access network device and the AMF network element are described as N2 messages. When the access network device and the AMF network element first exchange the relevant information of the terminal, the access network device allocates a temporary identifier A for the terminal, and the temporary identifier A can be expressed as UE - access network device - AMF network element - specific temporary identifier. N2 message 1 includes the temporary identifier A.

[0161] Step 820: The authentication and authorization network element performs network security authentication on the terminal.

[0162] In a possible implementation, after the terminal passes the network security authentication, the AMF network element allocates another temporary identifier B for the terminal, and the temporary identifier B can be expressed as UE - AMF network element - access network device - specific temporary identifier. The temporary identifiers allocated by the access network device and the AMF network element can form a pair of temporary identifiers, that is, the temporary identifier A and the temporary identifier B form a pair of temporary identifiers. The AMF network element obtains the SUPI of the terminal in the UDM network element. The AMF network element establishes and stores the correspondence between the temporary identifier A, the temporary identifier B, and the SUPI of the terminal.

[0163] Step 830: The AMF network element sends N2 message 2 to the access network device, and the access network device receives N2 message 2 from the AMF network element.

[0164] For example, N2 message 2 is a response message to N2 message 1, and N2 message 2 includes a temporary identifier B. Optionally, N2 message 2 further includes a temporary identifier A. The AMF network element and the access network device can communicate based on the temporary identifier A and the temporary identifier B.

[0165] Step 840: The access network device sends Nx message 1 to the second core network element, and the second core network element receives Nx message 1 from the access network device.

[0166] For example, the interface between the access network device and the second core network element is the Nx interface, and the messages exchanged between the access network device and the second core network element are called Nx messages. When the access network device and the second core network element first exchange the relevant information of the terminal, the access network device assigns a temporary identifier C to the terminal, and the temporary identifier C can be expressed as UE-access network device-second core network element-specific temporary identifier. Nx message 1 includes the temporary identifier C.

[0167] Step 850: The authentication and authorization network element performs network security authentication on the terminal.

[0168] In a possible implementation, the authentication and authorization network element can perform simplified network security authentication on the terminal. After the network security authentication is passed, the second core network element assigns a temporary identifier D to the terminal, and the temporary identifier D can be expressed as UE-second core network element-access network device-specific temporary identifier. The temporary identifier C and the temporary identifier D form a pair of temporary identifiers. The second core network element can be other network elements except the AMF network element, and the second core network element can obtain the SUPI of the terminal in the AMF network element. The second core network element establishes and stores the correspondence relationship among the temporary identifier C, the temporary identifier D, and the SUPI of the terminal.

[0169] Step 860: The second core network element sends Nx message 2 to the access network device, and the access network device receives Nx message 2 from the second core network element.

[0170] For example, Nx message 2 includes the temporary identifier D. Optionally, Nx message 2 further includes the temporary identifier C. The second core network element and the access network device can communicate based on the temporary identifier C and the temporary identifier D. It can be understood that Nx message 1 and Nx message in the embodiments of the present application are Figure 7 A specific implementation of the sixth message and the seventh message in the process. The temporary identifier C and the temporary identifier D are Figure 7 A specific implementation of the third temporary identifier and the fourth temporary identifier in the process.

[0171] Through the above design, the access network device and the second core network element can communicate based on the assigned temporary identifier, which can avoid the access network device from obtaining the SUPI of the terminal and ensure the privacy and security of the terminal.

[0172] It can be understood that in the embodiments of the present application:

[0173] 1. The differences between different processes are mainly described, and the descriptions of different processes can be referred to each other.

[0174] 2. In each process, the sequence of different steps is not limited. For example, Figure 5 step 530 in [description] can be executed after step 520, or step 530 can be executed before step 520. And in each process, it may include fewer steps or more steps than those shown in the process schematic diagram or described in words.

[0175] 3. In the process of [description], the access network device, AMF network element, or core network element, etc. are taken as examples of the execution entities for description. It can be understood that in each process, the functions of the access network device can be implemented by the access network device, or by modules (such as chips or circuits, etc.) in the access network device, or by logical nodes, logical modules, or software that can fully or partially implement the functions of the access network device. The functions of the AMF network element or core network element can be implemented by the AMF network element or core network element, or by modules (such as chips or circuits, etc.) in the AMF network element or core network element. Figures 4 to 8

[0176] 4. In the embodiments of the present application, "receive information from (such as the AMF network element) by (such as the access network device)" can be understood that the source end of the information is the AMF network element and the destination end is the access network device, and it may include the AMF network element directly or indirectly receiving information from the access network device. Necessary processing may be performed on the information between the source end and the destination end of the information transmission, such as format conversion, etc., but the destination end can understand the valid information from the source end. Similar expressions in the present application can be understood similarly and will not be elaborated here.

[0177] In the above embodiments provided by the present application, the methods provided by the embodiments of the present application are introduced from the perspectives of the interactions among the access network device, AMF network element, and core network element. To implement each function in the methods provided by the embodiments of the present application, the access network device, AMF network element, or core network element, etc. may include a hardware structure and / or software module, and implement the above functions in the form of a hardware structure, software module, or a combination of a hardware structure and a software module. Which way to execute a certain function among the above functions, namely in the form of a hardware structure, software module, or a combination of a hardware structure and a software module, depends on the design constraints of the specific application of the technical solution.

[0178] Figure 9 Figure 10 and Figure 10This is a schematic structural diagram of a possible communication device provided by an embodiment of the present application. These communication devices can implement one or more corresponding functions in the above method embodiments. For example, functions implemented by an access network device, an AMF network element, or a core network element, etc., and thus may achieve the beneficial effects possessed by the above method embodiments. In an embodiment of the present application, the communication device may be, for example, Figure 1 the access network device in the RAN200 shown, or the core network element in the core network 300, or a module (such as a chip) applied to the access network device or the core network element.

[0179] For example, Figure 9 as shown, the communication device 900 includes a processing unit 910 and a transceiver unit 920. The communication device 900 is used to implement the functions of the access network device, the AMF network element, or the core network element in any of the above Figures 4 to 8 shown method embodiments.

[0180] Optionally, the transceiver unit 920 may also be referred to as an output unit, an interface unit, or a communication unit, etc. In a possible implementation manner, the transceiver unit 920 includes at least one of a sending unit or a receiving unit. The sending unit and the receiving unit may be integrated together, or may be two independent units, etc.

[0181] When the communication device 900 is used to implement the Figures 4 to 6 functions of the access network device in, specifically:

[0182] The processing unit 910 is used to allocate a first temporary identifier to the terminal; the transceiver unit 920 is used to send a first message to the access and mobility management function network element, where the first message includes the first temporary identifier, and the first temporary identifier is used to identify the terminal in the message sent by the access network device to the first core network element.

[0183] In a possible design, the first temporary identifier is also used to identify the terminal in the message sent by the first core network element to the access network device.

[0184] In a possible design, it further includes: the transceiver unit 920 is further used to receive a second message from the access and mobility management function network element, where the second message includes a second temporary identifier of the terminal, and the second temporary identifier is used to identify the terminal in the message sent by the first core network element to the access network device.

[0185] In a possible design, it further includes: the transceiver unit 920 is further used to send a third message to the first core network element, where the third message includes the first temporary identifier, and to receive a fourth message from the first core network element, where the fourth message includes the first temporary identifier or the second temporary identifier.

[0186] In a possible design, the third message further includes identification information of the access and mobility management function network element.

[0187] When the communication device 900 is used to implement Figures 4 to 6 the function of the AMF network element in

[0188] a transceiver unit 920, configured to receive a first message from an access network device, where the first message includes a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network element.

[0189] In a possible design, the first temporary identifier is further used to identify the terminal in a message sent by the first core network element to the access network device.

[0190] In a possible design, a processing unit 910 is configured to allocate a second temporary identifier for the terminal, where the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device; the transceiver unit 920 is further configured to send a second message to the access network device, where the second message includes the second temporary identifier.

[0191] In a possible design, the transceiver unit 920 is further configured to send a fifth message to the first core network element, where the fifth message includes: a subscriber permanent identifier SUPI of the terminal and the first temporary identifier.

[0192] In a possible design, the fifth message further includes the second temporary identifier.

[0193] In a possible design, the fifth message further includes identification information of the access network device that allocates the first temporary identifier.

[0194] In a possible design, it further includes: the transceiver unit 920 is further configured to receive a request message from the first core network element, where the request message includes the first temporary identifier; the processing unit 910 is further configured to determine the SUPI of the terminal according to the correspondence between the first temporary identifier and the SUPI of the terminal; the transceiver unit 920 is further configured to send a response message to the first core network element, where the response message includes the SUPI of the terminal.

[0195] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0196] In a possible design, the request message further includes identification information of an access network device that allocates the first temporary identifier.

[0197] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0198] In a possible design, the request message further includes the second temporary identifier.

[0199] In a possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0200] In a possible design, the request message further includes identification information of an access network device that allocates the first temporary identifier.

[0201] When the communication device 900 is used to implement Figure 5 or Figure 6 the function of the first core network element in

[0202] The transceiver unit 920 is configured to receive a third message from an access network device, where the third message includes a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to the first core network element; the processing unit 910 is configured to generate a fourth message; the transceiver unit 920 is further configured to send the fourth message to the access network device, and the fourth message includes the first temporary identifier or the second temporary identifier.

[0203] In a possible design, when the fourth message includes the first temporary identifier, the first temporary identifier is further used to identify the terminal in a message sent by the access network device to the first core network element.

[0204] In a possible design, when the fourth message includes the second temporary identifier, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

[0205] In a possible design, the processing unit 910 is further configured to determine the SUPI of the terminal according to the correspondence between the first temporary identifier and the subscriber permanent identifier SUPI of the terminal.

[0206] In a possible design, the transceiver unit 920 is further configured to receive a fifth message from an access and mobility management function network element, where the fifth message includes the SUPI of the terminal and the first temporary identifier; the processing unit 910 is configured to determine the correspondence between the first temporary identifier and the SUPI of the terminal.

[0207] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes the correspondence between the first temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0208] In a possible design, the fifth message further includes the identification information of the access network device that allocates the first temporary identifier.

[0209] In a possible design, the correspondence between the first temporary identifier and the SUPI of the terminal includes the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

[0210] In a possible design, the fifth message further includes the second temporary identifier.

[0211] In a possible design, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes the correspondence between the first temporary identifier, the second temporary identifier, the identification information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

[0212] In a possible design, the fifth message further includes the identification information of the access network device that allocates the first temporary identifier.

[0213] In a possible design, the third message further includes the identification information of the access and mobility management function network element, and the processing unit 910 is further configured to send a request message to the access and mobility management function network element according to the identification information of the access and mobility management function network element, where the request message includes the first temporary identifier; the processing unit 920 is further configured to receive a response message from the access and mobility management function network element, where the response message includes the SUPI of the terminal.

[0214] In a possible design, the request message further includes the identification information of the access network device that allocates the first temporary identifier.

[0215] In a possible design, the response message further includes the first temporary identifier of the terminal.

[0216] In a possible design, the request message and the response message further include the second temporary identifier.

[0217] When the communication device 900 is used to implement Figure 7 or Figure 8 the function of the second core network element in

[0218] The transceiver unit 920 is configured to receive a sixth message from an access network device, where the sixth message includes a third temporary identifier of a terminal, and the third temporary identifier is used to identify the terminal in a message sent by the access network device to the second core network element; the processing unit 910 is configured to generate a seventh message; the transceiver unit 920 is further configured to, after the terminal passes network security authentication, send the seventh message to the access network device, where the seventh message includes a fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in a message sent by the second core network element to the access network device.

[0219] When the communication device 900 is used to implement Figure 7 and Figure 8 the function of the access network device in

[0220] The processing unit 910 is configured to generate a sixth message; the transceiver unit 920 is configured to send the sixth message to the second core network element, where the sixth message includes a third temporary identifier of a terminal, and the third temporary identifier is used to identify the terminal in a message sent by the access network device to the second core network element; the transceiver unit 920 is further configured to, after the terminal passes network security authentication, receive a seventh message from the second core network element, where the seventh message includes a fourth temporary identifier, and the fourth temporary identifier is used to identify the terminal in a message sent by the second core network element to the access network device.

[0221] For a more detailed description of the processing unit 910 and the transceiver unit 920, reference may be made to the description in the above method embodiments Figures 4 to 8 and will not be elaborated here.

[0222] It can be understood that the division of units in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, there may be other division methods. In addition, each functional unit in the embodiments of the present application may be integrated in a physical device (for example, a processor), or each functional unit may be a separate physical device, or two or more units may be integrated in one unit. The above integrated units may be implemented in the form of hardware, or in the form of software functional modules, etc.

[0223] Such as Figure 10As shown, the communication device 1000 includes a processor 1010 and an interface circuit 1020. The processor 1010 and the interface circuit 1020 are coupled to each other. It can be understood that the interface circuit 1020 can be a transceiver or an input / output interface. Optionally, the communication device 1000 may further include a memory 1030, which is used to store instructions executed by the processor 1010, or input data required for the processor 1010 to run the instructions, or data generated after the processor 1010 runs the instructions.

[0224] When the communication device 1000 is used to implement Figures 4 to 8 the method shown, the processor 1010 is used to implement the functions of the above-mentioned processing unit 910, and the interface circuit 1020 is used to implement the functions of the above-mentioned transceiver unit 920.

[0225] When the above communication device is a module applied to an access network device, this module implements the functions of the access network device in the above method embodiment. This module receives information from other modules (such as a radio frequency module or an antenna) in the access network device, and this information is sent by the terminal to the access network device; or, this module sends information to other modules (such as a radio frequency module or an antenna) in the access network device, and this information is sent by the access network device to the terminal.

[0226] When the above communication device is a module applied to a core network element (for example, an AMF network element, a first core network element, or a second core network element, etc.), this module implements the functions of the core network element in the above method embodiment. This module receives information from other modules (such as a radio frequency module or an antenna) in the core network element, and this information is sent by the terminal to the core network element; or, this module sends information to other modules (such as a radio frequency module or an antenna) in the core network element, and this information is sent by the core network element to the terminal.

[0227] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0228] The memory in the embodiments of the present application may be a random access memory (RAM), a flash memory, a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), a register, a hard disk, a removable hard disk, a CD-ROM, or any other form of storage medium well-known in the art.

[0229] The method steps in the embodiments of the present application can be implemented in hardware or in software instructions executable by a processor. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable ROM, an erasable PROM, an electrically erasable PROM, a register, a hard disk, a removable hard disk, a CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. The storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC.

[0230] The embodiments of the present application further provide a communication device, which includes a processor and a memory. The processor and the memory are coupled, and the processor is used to implement Figures 4 to 6 the functions of the access network device, the AMF network element, or the first core network element in Figure 7 or Figure 8 the functions of the access network device or the second core network element in

[0231] The embodiments of the present application further provide a communication device, including a processor, and the processor is used to implement Figures 4 to 6 the functions of the access network device, the AMF network element, or the first core network element in Figure 7 or Figure 8 the functions of the access network device or the second core network element in

[0232] The embodiments of the present application further provide a computer-readable storage medium, and the computer-readable storage medium stores instructions, which can also be referred to as computer programs, computer program codes, etc. The instructions run on a computer, causing the computer to execute the functions of the access network device, the AMF network element, or the first core network element in the above method embodiments Figures 4 to 6 or Figure 7 or Figure 8 the functions of the access network device or the second core network element in

[0233] The embodiments of the present application further provide a computer program product, including a computer program or instructions. When the computer program or instructions run on a computer, it enables Figures 4 to 6 the functions of the access network device, AMF network element or the first core network element in Figure 7 or Figure 8 the functions of the access network device or the second core network element in

[0234] The embodiments of the present application further provide a chip, which includes a processor. The processor is coupled to a memory, and the processor is configured to execute the computer program or instructions stored in the memory, so that Figures 4 to 6 the functions of the access network device, AMF network element or the first core network element in Figure 7 or Figure 8 the functions of the access network device or the second core network element in

[0235] The embodiments of the present application further provide a communication system, including a first communication device and a second communication device.

[0236] Wherein, the first communication device and the second communication device can be respectively used to implement Figures 4 to 6 the functions of the access network device and the AMF network element in Figure 5 or Figure 6 the functions of the first core network element in Figure 7 or Figure 8 the functions of the access network device and the second core network element in

[0237] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disc; or it may be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0238] In various embodiments of the present application, if there is no special description and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.

Claims

1. A method for allocating a terminal temporary identifier, characterized in that, the method is applied to an access network device and includes: allocating a first temporary identifier for a terminal; sending a first message to an access and mobility management function network element, the first message including the first temporary identifier, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network element.

2. The method according to claim 1, characterized in that, the first temporary identifier is further used to identify the terminal in a message sent by the first core network element to the access network device.

3. The method according to claim 1, characterized in that, further includes: receiving a second message from the access and mobility management function network element, the second message including a second temporary identifier of the terminal, and the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

4. The method according to any one of claims 1 to 3, characterized in that, further includes: sending a third message to the first core network element, the third message including the first temporary identifier; receiving a fourth message from the first core network element, the fourth message including the first temporary identifier or the second temporary identifier.

5. The method according to claim 4, characterized in that, the third message further includes identification information of the access and mobility management function network element.

6. A method for allocating a terminal temporary identifier, characterized in that, the method is applied to an access and mobility management function network element and includes: receiving a first message from an access network device, the first message including a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to a first core network element.

7. The method according to claim 6, characterized in that, the first temporary identifier is further used to identify the terminal in a message sent by the first core network element to the access network device.

8. The method according to claim 6, characterized in that, further includes: allocating a second temporary identifier for the terminal, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device; sending a second message to the access network device, the second message including the second temporary identifier.

9. The method according to any one of claims 6 to 8, characterized in that, further includes: sending a fifth message to the first core network element, the fifth message including: the user permanent identifier SUPI of the terminal and the first temporary identifier.

10. The method according to claim 9, characterized in that, the fifth message further includes the second temporary identifier.

11. The method according to claim 9 or 10, characterized in that, the fifth message further includes identification information of the access network device that allocates the first temporary identifier.

12. The method according to any one of claims 6 to 8, characterized in that, further includes: receiving a request message from a first core network element, the request message including the first temporary identifier; Determine the SUPI of the terminal according to the corresponding relationship between the first temporary identifier and the SUPI of the terminal. Send a response message to the first core network element, where the response message includes the SUPI of the terminal.

13. The method according to claim 12, characterized in that the corresponding relationship between the first temporary identifier and the SUPI of the terminal includes: the corresponding relationship between the first temporary identifier, the identifier information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

14. The method according to claim 13, characterized in that the request message further includes the identifier information of the access network device that allocates the first temporary identifier.

15. The method according to claim 12, characterized in that the corresponding relationship between the first temporary identifier and the SUPI of the terminal includes: the corresponding relationship between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

16. The method according to claim 15, characterized in that the request message further includes the second temporary identifier.

17. The method according to claim 15 or 16, characterized in that the corresponding relationship between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the corresponding relationship between the first temporary identifier, the second temporary identifier, the identifier information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

18. The method according to claim 17, characterized in that the request message further includes the identifier information of the access network device that allocates the first temporary identifier.

19. A communication method, characterized in that the method is applied to a first core network element and includes: Receive a third message from an access network device, where the third message includes a first temporary identifier of a terminal, and the first temporary identifier is used to identify the terminal in a message sent by the access network device to the first core network element; Send a fourth message to the access network device, where the fourth message includes the first temporary identifier or the second temporary identifier.

20. The method according to claim 19, characterized in that when the fourth message includes the first temporary identifier, the first temporary identifier is further used to identify the terminal in a message sent by the access network device to the first core network element.

21. The method according to claim 19, characterized in that when the fourth message includes the second temporary identifier, the second temporary identifier is used to identify the terminal in a message sent by the first core network element to the access network device.

22. The method according to any one of claims 19 to 21, characterized in that further includes: Determine the SUPI of the terminal according to the corresponding relationship between the first temporary identifier and the permanent user identifier SUPI of the terminal.

23. The method according to claim 22, characterized in that further includes: Receive a fifth message from an access and mobility management function network element, where the fifth message includes: the SUPI of the terminal and the first temporary identifier; Determine the corresponding relationship between the first temporary identifier and the SUPI of the terminal.

24. The method according to claim 22 or 23, wherein, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the identifier information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

25. The method according to claim 24, wherein, the fifth message further includes the identifier information of the access network device that allocates the first temporary identifier.

26. The method according to claim 22 or 23, wherein, the correspondence between the first temporary identifier and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal.

27. The method according to claim 26, wherein, the fifth message further includes the second temporary identifier.

28. The method according to claim 26 or 27, wherein, the correspondence between the first temporary identifier, the second temporary identifier, and the SUPI of the terminal includes: the correspondence between the first temporary identifier, the second temporary identifier, the identifier information of the access network device that allocates the first temporary identifier, and the SUPI of the terminal.

29. The method according to claim 28, wherein, the fifth message further includes the identifier information of the access network device that allocates the first temporary identifier.

30. The method according to any one of claims 19 to 21, wherein, the third message further includes the identifier information of the access and mobility management function network element, and further includes: sending a request message to the access and mobility management function network element according to the identifier information of the access and mobility management function network element, the request message including the first temporary identifier; receiving a response message from the access and mobility management function network element, the response message including the SUPI of the terminal.

31. The method according to claim 30, wherein, the request message further includes the identifier information of the access network device that allocates the first temporary identifier.

32. The method according to claim 30 or 31, wherein, the response message further includes the first temporary identifier of the terminal.

33. The method according to any one of claims 30 to 32, wherein, the request message and the response message further include the second temporary identifier.

34. A communication device, wherein, it includes a unit for implementing the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 18, or the method according to any one of claims 19 to 33.

35. A communication device, wherein, it includes a processor, the processor is coupled to a memory, and the processor is configured to execute instructions to cause the device to execute the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 18, or the method according to any one of claims 19 to 33.

36. A computer-readable storage medium, wherein, Instructions are stored on the computer-readable storage medium, and the instructions are run on a computer, causing the computer to execute the method described in any one of claims 1 to 5, or the method described in any one of claims 6 to 18, or the method described in any one of claims 19 to 33.