Communication method and device
By adding specific information of environmental IoT devices to the core network equipment, the difficulty of IoT terminals when selecting network elements to perform security authentication processes is solved, and the reliability of normal access and communication of terminal devices is realized.
Patent Information
- Application Number
- CN202311733106.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-17
AI Technical Summary
In the field of IoT, due to its low power consumption and low complexity, the authentication process of environmental IoT terminals is inconsistent with ordinary 3GPP user equipment, which makes it difficult to select a suitable network element to perform the security authentication process, which may lead to failure of terminal equipment authentication and inability to access the network.
By adding capability information, service requester information or device type information of environmental IoT devices to the core network equipment, the mobile management device can select appropriate network elements to execute security processes based on the characteristics and capabilities of the terminal equipment.
It effectively avoids the failure of terminal equipment authentication, ensures that the Internet of Things terminals can access the network normally, and improves the reliability and stability of communication.
Smart Images

Figure CN120166397A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly, to a communication method and apparatus. Background Art
[0002] In the field of the Internet of Things, the ambient energy Internet of Things is an emerging technology field that has received much attention. The ambient energy Internet of Things is an Internet of Things terminal without a power supply or an internal battery, and these terminals extract energy from the environment to meet their working requirements.
[0003] Since the Internet of Things terminal is a low-power and low-complexity terminal device, its authentication process, authentication algorithm, etc. may not be the same as those of ordinary 3GPP user equipment, and a lightweight security authentication algorithm / process may be adopted to execute the security process of this type of terminal. In the network, not all network elements that perform security authentication support this new algorithm and process.
[0004] Therefore, how to select a suitable network element to execute the security authentication process of the Internet of Things terminal is an urgent problem to be solved. Summary of the Invention
[0005] This application provides a communication method and apparatus. In the network element selection and network element configuration information, the corresponding capability information, service requestor information, or device type information of the ambient Internet of Things device is newly added, enabling the core network device to select a suitable network element to execute the security process according to the service request or the characteristics and capabilities of the Internet of Things terminal, avoiding the failure of the terminal device to authenticate and thus being unable to access the network.
[0006] In a first aspect, a communication method is provided. The method includes a mobility management device obtaining a first message, where the first message includes the identification information of a terminal device, the first message indicates the device type of the terminal device, and the terminal device accesses the network using Internet of Things access technology; the mobility management device selecting an authentication service device according to the first message, where the authentication service device supports authenticating and / or authorizing a terminal device accessing the network using Internet of Things access technology; and the mobility management device sending a first authentication request message to the authentication service device, where the first authentication request message includes the identification information of the terminal device, and the first authentication request message is used to request to authenticate and / or authorize the terminal device.
[0007] By indicating to the mobility management device, such as an AMF network element, that the terminal device is an ambient Internet of Things device, the AMF can thus select a network element that can support the security authentication process or algorithm for the Internet of Things device for authentication and authorization.
[0008] According to the solution of the present application, by adding the device type information of the environmental Internet of Things devices, the core network can optimize and adapt the network function selection for the access process of the Internet of Things terminals, enabling the core network devices to select appropriate network functions to execute security processes according to service requests or the characteristics and capabilities of the Internet of Things terminals.
[0009] In the present application, the Internet of Things can be an environmental Internet of Things, an energy harvesting Internet of Things, an environmental energy harvesting Internet of Things, or a passive Internet of Things.
[0010] In the present application, the devices that access the network using the Internet of Things access technology can be devices in the environmental Internet of Things, the energy harvesting Internet of Things, the environmental energy harvesting Internet of Things, or the passive Internet of Things.
[0011] In combination with the first aspect, in some implementation manners of the first aspect, the first message includes device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The mobility management device determines that the terminal device is an Internet of Things device according to the first message. The mobility management device selects an authentication service device according to the first message, including: the mobility management device determines that the terminal device is an Internet of Things device according to the first message, and selects an authentication service device that supports authenticating and / or authorizing the Internet of Things device.
[0012] In a possible implementation manner, the indication information indicates that the terminal device accesses the network using the Internet of Things access technology.
[0013] The device type information can further indicate that the terminal device is an active terminal or a passive terminal. The indication information can be from a reader device. The reader device determines that the terminal device is an Internet of Things device according to the device identifier sent by the terminal device, and directly sends the indication information to the mobility management device.
[0014] In combination with the first aspect, in some implementation manners of the first aspect, the mobility management device sends a first request message to the network storage device according to the first message. The first request message is used to request to discover an authentication service device. The first request message includes at least one of the following: a group identifier, indication information, and device type information, where the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the mobility management device obtains first response information from the network storage device. The first response information includes the identifier information and / or address information of the authentication service device; the mobility management device selects an authentication service device according to the first response information.
[0015] In combination with the first aspect, in some implementations of the first aspect, the first response information is determined based on the first request message and the first configuration information of the authentication service device. The first configuration information includes at least one of the following: a first supported group identifier, first supported information, and first supported type information. The first supported group identifier corresponds to the first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first supported information indicates whether authentication and / or authorization of Internet of Things devices is supported. The first supported type information is used to indicate the type of device for which the authentication service device supports performing authentication and / or authorization.
[0016] In a possible implementation, the first supported information indicates support for authentication and / or authorization of Internet of Things devices.
[0017] In this application, there are multiple implementation manners for the group identifier to indicate the service requester. Exemplarily, the group identifier can be the identifier of the service requester. Additionally, exemplarily, there can be a corresponding relationship between the group identifier and the identifier of the service requester. The first supported group identifier indicating the first service requester also has multiple implementation manners. Exemplarily, the first supported group identifier can be the identifier of the first service requester. Additionally, exemplarily, there can be a corresponding relationship between the first supported group identifier and the identifier of the first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester.
[0018] When an authentication service device such as an AUSF network element registers with a network storage device such as an NRF network element, it can report the ability to support authentication of Internet of Things devices (or further report support for authentication of active or passive devices) and / or the range of supported device identifiers (such as the supported field for indicating the service requester). Thus, the mobility management device can dynamically discover, through the network storage device, the authentication service device that can support the authentication and / or authorization process of the terminal device.
[0019] According to the solution of this application, the core network device can select an AUSF network element based on the NRF discovery mechanism, so that the selected AUSF supports performing security processes on the IoT terminal, avoiding authentication failure and inability to access the network due to the selected AUSF not supporting the security process of the terminal.
[0020] In combination with the first aspect, in some implementations of the first aspect, the mobility management device sends a second request message to the network storage device. The second request message is used to request to discover the unified data management device. The second request message includes at least one of the following: identification information, group identification, indication information, and device type information. Among them, the group identification is included in the identification information. The group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The mobility management device obtains a second response message from the network storage device. The second response information includes the identification information and / or address information of the unified data management device. The mobility management device selects the unified data management device according to the second response message.
[0021] In combination with the first aspect, in some implementations of the first aspect, the second response information is determined according to the second request information and the second configuration information of the unified data management device. The second configuration information includes at least one of the following: the second supported group identification, the second supported information, and the second supported type information. Among them, the second supported group identification indicates the supported corresponding second service requester. The unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether it supports managing the subscription data of the Internet of Things device. The second supported type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0022] In a possible implementation, the second supported information indicates that it supports managing the subscription data of the Internet of Things device.
[0023] The second supported group identification indicates that there can be multiple implementation manners for the second service requester. Exemplarily, the second supported group identification can be the identification of the second service requester. Another example is that the second supported group identification can have a corresponding relationship with the identification of the second service requester. The unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester.
[0024] When the unified data management device, such as the UDM network element, registers with the network storage device, such as the NRF network element, it can report the ability to support managing the subscription data of the Internet of Things device (or further report the support for the authentication of active devices or passive devices) and / or the supported range of device identifications (such as the supported field used to indicate the service requester). Thus, the mobility management device can dynamically discover the unified data management device that can manage the subscription data of the terminal device through the network storage device.
[0025] According to the solution of the present application, the core network device can select a UDM network element according to the NRF discovery mechanism, so that the selected UDM supports the execution of the security process for the IoT terminal, avoiding authentication failure and inability to access the network caused by the selected UDM not supporting the security process of the terminal.
[0026] In combination with the first aspect, in some implementation manners of the first aspect, the mobility management device selects an authentication service device according to the first message and the third configuration information. The third configuration information includes the correspondence between the authentication service device information and at least one of the following: the first supported group identifier, the first supported information, and the first supported type information. The authentication service device information includes the identifier and / or address information of the authentication service device. The first supported group identifier corresponds to the first service requester. The authentication service device supports the execution of authentication and / or authorization for the terminal device corresponding to the first service requester. The first supported information indicates whether the authentication service device supports the authentication and / or authorization of IoT devices. The first supported type information indicates the device type for which the authentication service device supports authentication and / or authorization.
[0027] The mobility management device, such as the AMF network element, can locally configure the information of the authentication service device, such as the AUSF network element, that supports the authentication and / or authorization process of the IoT terminal device, which can include the supported group identifier, the supported device type (active terminal and / or passive terminal), etc.
[0028] According to the solution of the present application, by configuring the information for selecting network elements in the mobility management device, such as the AMF network element, the mobility management device is enabled to select other core network devices that support the security process of IoT terminals, eliminating the need for network elements to dynamically execute requests through the NRF and reducing signaling overhead.
[0029] In combination with the first aspect, in some implementation manners of the first aspect, the mobility management device sends a third request message to the unified data management device. The third request message is used to select an authentication service device. The third request message includes at least one of the following: identification information, group identifier, indication information, and device type information. The group identifier is included in the identification information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The mobility management device obtains the third response information from the unified data management device. The third response information includes the identification information and / or address information of the authentication service device. The mobility management device selects the authentication service device according to the first response information.
[0030] In combination with the first aspect, in some implementations of the first aspect, the third response information is determined according to the third request information and the fourth configuration information. The fourth configuration information includes the corresponding relationship between the authentication service device information and at least one of the following: the first supported group identifier, the first supported information, and the first supported type information. The first supported group identifier corresponds to the first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first supported information indicates whether it supports the authentication and / or authorization of Internet of Things devices, and the first supported type information is used to indicate the device type for which the authentication service device supports performing authentication and / or authorization.
[0031] A unified data management device, such as a UDM network element, can locally configure information about an authentication service device, such as an AUSF network element, that supports the authentication and / or authorization process for Internet of Things terminal devices, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0032] According to the solution of this application, by configuring information for selecting network elements in a unified data management device, such as a UDM network element, the mobile management device can select a core network device that supports the security process for Internet of Things terminals through the unified data management device, eliminating the need for network elements to dynamically execute requests through the NRF and reducing signaling overhead.
[0033] In combination with the first aspect, in some implementations of the first aspect, the mobile management device selects a unified data management device according to the first message and the third configuration information. The third configuration information includes the corresponding relationship between the unified data management device information and at least one of the following: the second supported group identifier, the second supported information, and the second supported type information. The second supported group identifier corresponds to the second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices, and the second supported type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0034] A mobile management device, such as an AMF network element, can locally configure information about a unified data management device, such as a UDM network element, that supports the authentication and / or authorization process for Internet of Things terminal devices, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0035] According to the solution of this application, by configuring information for selecting network elements in a mobile management device, such as an AMF network element, the mobile management device can be enabled to select other core network devices that support the security process for Internet of Things terminals, eliminating the need for network elements to dynamically execute requests through the NRF and reducing signaling overhead.
[0036] In combination with the first aspect, in certain implementations of the first aspect, the mobility management device sends a registration request message to the unified data management device. The registration request message includes the identification information of the mobility management device and the identification information and / or address information of the authentication service device. The registration request message indicates the mobility management device and the authentication service device of the service terminal device.
[0037] In combination with the first aspect, in certain implementations of the first aspect, the mobility management device stores the identification information of the authentication service device and / or the identification information of the unified data management device.
[0038] According to the solution of the present application, the mobility management device can provide the information of the authentication service device during registration, so that the unified data management device stores the information of the authentication service device that supports the execution of the security process of the IoT terminal. Thus, in the subsequent case of mobility, the new mobility management device can obtain the information of the authentication service device that supports the execution of the security process through the information stored by the unified data management device, saving signaling overhead.
[0039] In combination with the first aspect, in certain implementations of the first aspect, the mobility management device obtains a sixth request message from the network exposure function. The sixth request message includes network function information, and the network function information includes at least one of the following: the identification information and / or address information of the authentication service device, the unified data management device, the specific network slice authentication and authorization function NSAAF, and the AAA server. The mobility management device selects the authentication service device and / or the unified data management device according to the first message and the sixth request message.
[0040] When the AAA server executes the security process, the mobility management device discovers the address of the AAA Server through the network exposure function, such as the NEF network element.
[0041] In a second aspect, a communication method is provided. The method includes the authentication service device receiving a first authentication request message from the mobility management device. The first authentication request message includes the identification information of the terminal device, and the first authentication request message is used to request to perform authentication and / or authorization on the terminal device. The terminal device accesses the network using the Internet of Things access technology.
[0042] In combination with the second aspect, in certain implementations of the second aspect, the first authentication request message includes device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The authentication service device determines that the terminal device is an Internet of Things device according to the first authentication request message.
[0043] In combination with the second aspect, in some implementation manners of the second aspect, the authentication service device selects a unified data management device according to the first authentication request message. The unified data management device supports authenticating and / or authorizing devices accessing the network by using the Internet of Things access technology. The authentication service device sends a second authentication request message to the unified data management device. The second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0044] In combination with the second aspect, in some implementation manners of the second aspect, the first authentication request message includes terminal device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The second authentication request message includes at least one of the following: identification information, group identification, indication information, and device type information. The group identification is included in the identification information, and the group identification indicates the service requester corresponding to the terminal device.
[0045] In combination with the second aspect, in some implementation manners of the second aspect, the authentication service device sends first configuration information to the network storage device. The first configuration information includes at least one of the following: a first supported group identification, first support information, and first support type information. Among them, the first supported group identification corresponds to a first service requester, and the authentication service device supports authenticating and / or authorizing the terminal device corresponding to the first service requester. The first support information is used to indicate whether the authentication service device supports the authentication and / or authorization of Internet of Things devices, and the first support type information is used to indicate the device type for which the authentication service device supports authentication and / or authorization.
[0046] When the authentication service device, such as an AUSF network element, registers with the network storage device, such as an NRF network element, it can report the ability to support the authentication of Internet of Things devices (or further report the support for the authentication of active or passive devices) and / or the range of supported device identifiers (such as the fields supported for indicating the service requester). Thus, other devices can dynamically discover, through the network storage device, the authentication service device that can support the authentication and / or authorization process of the terminal device.
[0047] In combination with the second aspect, in some implementation manners of the second aspect, the authentication service device sends a fourth request message to the network storage device according to the first authentication request message. The fourth request message is used to request to discover the unified data management device. The fourth request message includes at least one of the following: group identifier, indication information, and device type information. Wherein, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the authentication service device obtains the fourth response information from the network storage device. The fourth response information includes the identification information and / or address information of the unified data device; the authentication service device selects the unified data management device according to the fourth response information.
[0048] In combination with the second aspect, in some implementation manners of the second aspect, the fourth response information is determined according to the fourth request message and the second configuration information of the unified data management device. The second configuration information includes at least one of the following: second supported group identifier, second supported information, and second supported type information. Wherein, the second supported group identifier corresponds to the second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of the Internet of Things device. The second supported type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0049] When the unified data management device, such as the UDM network element, registers with the network storage device, such as the NRF network element, it can report the ability to support managing the subscription data of Internet of Things devices (or further report the authentication for active or passive devices) and / or the range of supported device identifiers (such as the supported field for indicating the service requester). Thus, the authentication service device can dynamically discover the unified data management device that can support managing the subscription data of the terminal device through the network storage device.
[0050] In combination with the second aspect, in some implementation manners of the second aspect, the authentication service device selects the unified data management device according to the first authentication information and the fifth configuration information. The fifth configuration information includes the corresponding relationship between the unified data management device information and at least one of the following: second supported group identifier, second supported information, and second supported type information. Wherein, the second supported group identifier corresponds to the second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of the Internet of Things device. The second supported type information is used to indicate the type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0051] An authentication service device, such as an AUSF network element, can locally configure information about a unified data management device, such as a UDM network element, that supports managing the subscription data of IoT terminal devices. This information may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc.
[0052] In combination with the second aspect, in some implementation manners of the second aspect, the authentication service device obtains a second authentication response message from the unified data management device. The second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of the AAA server.
[0053] In combination with the second aspect, in some implementation manners of the second aspect, the authentication service device sends a fifth request message to the network storage device. The fifth request message is used to request to discover the NSSAAF. The fifth request message includes at least one of the following: a group identifier, an indication information, and device type information. Among them, the group identifier is included in the identification information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The authentication service device obtains a fifth response message from the network storage device. The fifth response message includes identification information and / or address information of the NSSAAF, and identification information and / or address information of the AAA server. The authentication service device selects the NSSAAF according to the fifth response message.
[0054] In combination with the second aspect, in some implementation manners of the second aspect, the fifth response message is determined according to the fifth request message and the sixth configuration information of the NSSAAF. The sixth configuration information includes at least one of the following: a third supported group identifier, a third supported information, and a third supported type information. Among them, the third supported group identifier corresponds to a third service requester. The NSSAAF supports performing authentication and / or authorization on the terminal device corresponding to the third service requester. The third supported information indicates whether the NSSAAF supports the authentication and / or authorization of IoT devices. The third supported type information is used to indicate the device type that the NSSAAF supports for performing authentication and / or authorization.
[0055] In a possible implementation manner, the third supported information indicates that the NSSAAF supports the authentication and / or authorization of IoT devices.
[0056] The authentication and authorization function of a specific network slice can locally configure information that supports the authentication and / or authorization process of IoT terminal devices, which may include supported group identifiers, supported device types (active terminals and / or passive terminals), etc., and send this configuration information to a network storage device, such as an NRF network element, so as to obtain the address of the AAA server through the network storage device, thereby completing the security process of the terminal.
[0057] In combination with the second aspect, in some implementations of the second aspect, the first authentication request message includes specific network slice authentication and authorization function (NSSAAF) information and / or AAA server information. The NSSAAF information indicates the NSSAAF used to perform authentication and / or authorization. The authentication service device sends a third authentication request message to the NSSAAF. The third authentication request message includes at least one of the following: device identifier, indication information, device type information, and AAA server information. Among them, the indication information indicates that the terminal device is an Internet of Things (IoT) device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes the identifier information and / or address information of the AAA server.
[0058] When the access process of the IoT terminal is triggered by the service requester, the network elements involved in the subsequent process can be determined in advance, for example, determined by the Network Exposure Function (NEF). Thus, when the subsequent Access and Mobility Management Function (AMF) receives a registration request (or access request) from the IoT terminal, it can directly select a suitable network element to execute the process according to the network element information provided by the NEF, without requiring the entire 5G Core Network (5GC) to perform enhancements and function upgrades. Only the enhanced NEF needs to perform network element selection, reducing the required new configurations.
[0059] In a third aspect, a communication method is provided. The method includes that a unified data management device receives a second authentication request message from an authentication service device. The second authentication request message includes at least one of the following: identifier information of the terminal device, group identifier, indication information, and device type information. Among them, the group identifier is included in the identifier information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. The unified data management device determines an authentication method according to the second authentication request message, and the authentication method is used to authenticate and / or authorize the terminal device.
[0060] In combination with the third aspect, in some implementations of the third aspect, the unified data management device sends second configuration information to a network storage device. The second configuration information includes at least one of the following: second supported group identifier, second supported information, and second supported type information. Among them, the second supported group identifier corresponds to a second service requester, the unified data management device supports managing the subscription data of the terminal devices corresponding to the second service requester, the second supported information indicates whether the unified data management device supports managing the subscription data of IoT devices, and the second supported type information is used to indicate the device type of the terminal devices corresponding to the subscription data supported by the unified data management device.
[0061] When a unified data management device, such as a UDM network element, registers with a network storage device, such as an NRF network element, it can report the ability to support the authentication of Internet of Things devices (or further report the authentication of active or passive devices) and / or the supported range of device identifiers (e.g., the supported fields for indicating the service requester).
[0062] In combination with the third aspect, in some implementation manners of the third aspect, the unified data management device receives a third request message from the mobile management device. The third request message is used to select an authentication service device. The third request message includes at least one of the following: identification information, group identification, indication information, and device type information. Among them, the group identification is included in the identification information, and the group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. The unified data management device selects an authentication service device according to the third request information and the fourth configuration information. The fourth configuration information includes the corresponding relationship between the authentication service device information and at least one of the following: the first supported group identification, the first supported information, and the first supported type information. Among them, the first supported group identification corresponds to the first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first supported information indicates whether it supports the authentication and / or authorization of Internet of Things devices, and the first supported type information is used to indicate the device type that supports performing authentication and / or authorization. The unified data management device sends a third response message to the mobile management device. The third response message includes the identification information and / or address information of the authentication service device.
[0063] In combination with the third aspect, in some implementation manners of the third aspect, the unified data management device sends a second authentication response message to the authentication service device. The second authentication response message includes at least one of the following: the identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and the identification information and / or address information of the AAA server.
[0064] In combination with the third aspect, in some implementation manners of the third aspect, the unified data management device receives a registration request message from the mobile management device. The registration request message includes the identification information of the mobile management device and the identification information and / or address information of the authentication service device. The registration request message indicates the mobile management device and the authentication service device for serving the terminal device.
[0065] In combination with the third aspect, in some implementation manners of the third aspect, the unified data management device stores the identification information of the authentication service device.
[0066] Fourthly, a communication method is provided. The method includes that a network exposure function receives a service request message from a service requester, where the service request message is used to perform a service operation on at least one terminal device corresponding to the service requester. The network exposure function determines network function information according to the service request message, and the network function corresponding to the network function information is used to perform authentication and / or authorization on the at least one terminal device. The network exposure function sends a sixth request message to a mobility management device, and the sixth request message includes the network function information. The network function information includes the identification information and / or address information of at least one of the following network functions: an authentication service device, a unified data management device, a network slice specific authentication and authorization function (NSSAAF), and an AAA server.
[0067] Fifthly, a communication method is provided. The method includes that a terminal device sends a request message to a reader, the terminal device accesses the network by using Internet of Things access technology, and the request message includes the identification information and / or device type of the terminal device. The device type information indicates that the terminal device is an active terminal or a passive terminal.
[0068] Sixthly, a communication method is provided. The method includes that a reader receives a request message from a terminal device, the terminal device accesses the network by using Internet of Things access technology, and the request message includes the identification information and / or device type of the terminal device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The reader sends a first message to a mobility management device, the first message includes the identification information of the terminal device, the first message indicates the device type of the terminal device, and the first message is used to determine an authentication service device, where the authentication service device supports performing authentication and / or authorization on devices accessing the network by using Internet of Things access technology.
[0069] In a seventh aspect, a communication method is provided. The method includes: a network storage device receiving first configuration information from an authentication service device, where the first configuration information includes at least one of the following: a first supported group identifier, first support information, and first support type information. The first supported group identifier corresponds to a first service requester, and the authentication service device supports performing authentication and / or authorization on a terminal device corresponding to the first service requester. The first support information indicates whether the authentication service device supports authentication and / or authorization of Internet of Things (IoT) devices. The first support type information is used to indicate the type of device for which the authentication service device supports performing authentication and / or authorization; the network storage device receiving a first request message from a mobility management device, where the first request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal; the network storage device discovering the authentication service device based on the first request message and the first configuration information; and the network storage device sending first response information to the mobility management device, where the first response information includes the identification information and / or address information of the authentication service device.
[0070] In combination with the seventh aspect, in some implementation manners of the seventh aspect, the network storage device receives second configuration information from a unified data management device, where the second configuration information includes at least one of the following: a second supported group identifier, second support information, and second support type information. The second supported group identifier indicates support for a corresponding second service requester, and the unified data management device supports managing the subscription data of a terminal device corresponding to the second service requester. The second support information indicates whether it supports managing the subscription data of IoT devices. The second support type information is used to indicate the type of device corresponding to the terminal device for which the unified data management device supports managing subscription data; the network storage device receiving a second request message from the mobility management device, where the second request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal; the network storage device discovering the authentication service device based on the second request message and the second configuration information; and the network storage device sending second response information to the mobility management device, where the second response information includes the identification information and / or address information of the unified data management device.
[0071] In combination with the seventh aspect, in some implementations of the seventh aspect, the network storage device receives second configuration information from the unified data management device. The second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information. The second support group identifier indicates the supported corresponding second service requester. The unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether it supports managing the subscription data of the IoT device. The second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data. The network storage device receives a second request message from the mobility management device. The second request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The network storage device discovers the authentication service device according to the second request message and the second configuration information. The network storage device sends second response information to the mobility management device. The second response information includes the identification information and / or address information of the unified data management device.
[0072] In combination with the seventh aspect, in some implementations of the seventh aspect, the network storage device receives a fourth request message from the authentication service device. The fourth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The network storage device discovers the authentication service device according to the fourth request message and the second configuration information. The network storage device sends fourth response information to the authentication service device. The fourth response information includes the identification information and / or address information of the unified data management device.
[0073] In combination with the seventh aspect, in some implementations of the seventh aspect, the network storage device receives the sixth configuration information from the authentication and authorization function NSSAAF of a specific network slice. The sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information. Among them, the third support group identifier corresponds to a third service requester, and NSSAAF supports performing authentication and / or authorization on the terminal device corresponding to the third service requester. The third support information indicates whether NSSAAF supports the authentication and / or authorization of Internet of Things devices. The third support type information is used to indicate the device type for which NSSAAF supports performing authentication and / or authorization. The network storage device receives a fifth request message from the authentication service device. The fifth request message includes at least one of the following: a group identifier, indication information, and device type information. Among them, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. The network storage device discovers the authentication service device based on the fifth request message and the sixth configuration information. The network storage device sends a fifth response information to the authentication service device. The fifth response information includes the identifier information and / or address information of NSSAAF, and the identifier information and / or address information of the AAA server.
[0074] In an eighth aspect, a communication device is provided. The device includes an interface unit configured to obtain a first message, where the first message includes the identifier information of a terminal device, and the first message indicates the device type of the terminal device. The terminal device accesses the network using Internet of Things access technology. A processing unit is configured to select an authentication service device according to the first message. The authentication service device supports performing authentication and / or authorization on the terminal device accessing the network using Internet of Things access technology. The interface unit is further configured to send a first authentication request message to the authentication service device. The first authentication request message includes the identifier information of the terminal device, and the first authentication request message is used to request performing authentication and / or authorization on the terminal device.
[0075] In combination with the eighth aspect, in some implementations of the eighth aspect, the first message includes device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The mobility management device determines that the terminal device is an Internet of Things device according to the first message. The processing unit is further configured to determine that the terminal device is an Internet of Things device according to the first message, and select an authentication service device that supports performing authentication and / or authorization on Internet of Things devices.
[0076] In combination with the eighth aspect, in some implementations of the eighth aspect, an interface unit is configured to send a first request message to a network storage device according to a first message. The first request message is used to request discovery of an authentication service device. The first request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit is further configured to obtain first response information from the network storage device. The first response information includes identification information and / or address information of the authentication service device. A processing unit is configured to select an authentication service device according to the first response information.
[0077] In combination with the eighth aspect, in some implementations of the eighth aspect, the first response information is determined according to the first request message and first configuration information of the authentication service device. The first configuration information includes at least one of the following: a first supported group identifier, first support information, and first supported type information. The first supported group identifier corresponds to a first service requester. The authentication service device supports performing authentication and / or authorization on a terminal device corresponding to the first service requester. The first support information indicates whether authentication and / or authorization of Internet of Things devices is supported. The first supported type information is used to indicate the device type for which the authentication service device supports performing authentication and / or authorization.
[0078] In combination with the eighth aspect, in some implementations of the eighth aspect, an interface unit is configured to send a second request message to a network storage device. The second request message is used to request discovery of a unified data management device. The second request message includes at least one of the following: identification information, a group identifier, indication information, and device type information. The group identifier is included in the identification information. The group identifier indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit is configured to obtain a second response message from the network storage device. The second response information includes identification information and / or address information of the unified data management device. A processing unit is configured to select a unified data management device according to the second response message.
[0079] In combination with the eighth aspect, in some implementations of the eighth aspect, the second response information is determined according to the second request information and the second configuration information of the unified data management device. The second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information. The second support group identifier indicates the supported corresponding second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether it supports managing the subscription data of the IoT device. The second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0080] In combination with the eighth aspect, in some implementations of the eighth aspect, the processing unit is configured to select an authentication service device according to the first message and the third configuration information. The third configuration information includes the corresponding relationship between the authentication service device information and at least one of the following: a first support group identifier, first support information, and first support type information. The authentication service device information includes the identifier and / or address information of the authentication service device. The first support group identifier corresponds to the first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first support information indicates whether it supports the authentication and / or authorization of the IoT device. The first support type information is used to indicate the device type for which the authentication service device supports performing authentication and / or authorization.
[0081] In combination with the eighth aspect, in some implementations of the eighth aspect, the interface unit is configured to send a third request message to the unified data management device. The third request message is used to select an authentication service device. The third request message includes at least one of the following: identification information, group identifier, indication information, and device type information. The group identifier is included in the identification information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit is further configured to obtain the third response information from the unified data management device. The third response information includes the identification information and / or address information of the authentication service device. The processing unit is configured to determine the authentication service device according to the third response information.
[0082] In combination with the eighth aspect, in some implementations of the eighth aspect, the third response information is determined according to the third request information and the fourth configuration information, and the fourth configuration information includes the correspondence between the authentication service device information and at least one of the following: the first supported group identifier, the first supported information, and the first supported type information. The first supported group identifier corresponds to the first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first supported information indicates whether it supports the authentication and / or authorization of Internet of Things devices, and the first supported type information is used to indicate the device type for which the authentication service device supports performing authentication and / or authorization.
[0083] In combination with the eighth aspect, in some implementations of the eighth aspect, the processing unit is configured to determine the unified data management device according to the first message and the third configuration information. The third configuration information includes the correspondence between the unified data management device information and at least one of the following: the second supported group identifier, the second supported information, and the second supported type information. The second supported group identifier corresponds to the second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices, and the second supported type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0084] In combination with the eighth aspect, in some implementations of the eighth aspect, the interface unit is configured to send a registration request message to the unified data management device. The registration request message includes the identification information of the mobility management device and the identification information and / or address information of the authentication service device, and the registration request message indicates the mobility management device and the authentication service device for the serving terminal device.
[0085] In combination with the eighth aspect, in some implementations of the eighth aspect, the apparatus further includes a storage unit configured to store the identification information of the authentication service device and / or the identification information of the unified data management device.
[0086] In combination with the eighth aspect, in some implementations of the eighth aspect, the interface unit is configured to obtain a sixth request message from the network exposure function. The sixth request message includes network function information, and the network function information includes the identification information and / or address information of at least one of the following devices: the authentication service device, the unified data management device, the specific network slice authentication and authorization function NSAAF, and the AAA server. The processing unit is configured to select the authentication service device and / or the unified data management device according to the first message and the sixth request message.
[0087] In a ninth aspect, a communication device is provided. The device includes an interface unit configured to receive a first authentication request message from a mobility management device. The first authentication request message includes identification information of a terminal device, and is used to request authentication and / or authorization of the terminal device. The terminal device accesses the network using Internet of Things (IoT) access technology.
[0088] In combination with the ninth aspect, in some implementations of the ninth aspect, the first authentication request message includes device type information and / or indication information. The device type information indicates whether the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an IoT device. A processing unit is configured to determine that the terminal device is an IoT device based on the first authentication request message.
[0089] In combination with the ninth aspect, in some implementations of the ninth aspect, a processing unit is configured to select a unified data management device based on the first authentication request message. The unified data management device supports authentication and / or authorization of devices accessing the network using IoT access technology. The interface unit is configured to send a second authentication request message to the unified data management device. The second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0090] In combination with the ninth aspect, in some implementations of the ninth aspect, the first authentication request message includes terminal device type information and / or indication information. The device type information indicates whether the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an IoT device. The second authentication request message includes at least one of the following: identification information, group identification, indication information, and device type information. The group identification is included in the identification information and indicates the service requester corresponding to the terminal device.
[0091] In combination with the ninth aspect, in some implementations of the ninth aspect, the interface unit is configured to send first configuration information to a network storage device. The first configuration information includes at least one of the following: a first supported group identification, first support information, and first support type information. The first supported group identification corresponds to a first service requester, and the authentication service device supports authentication and / or authorization of the terminal device corresponding to the first service requester. The first support information indicates whether it supports authentication and / or authorization of IoT devices, and the first support type information is used to indicate the device type for which the authentication service device supports authentication and / or authorization.
[0092] In combination with the ninth aspect, in some implementations of the ninth aspect, an interface unit is configured to send a fourth request message to a network storage device according to a first authentication request message. The fourth request message is used to request to discover a unified data management device. The fourth request message includes at least one of the following: a group identifier, an indication information, and a device type information. Wherein, the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit is further configured to obtain fourth response information from the network storage device. The fourth response information includes identification information and / or address information of the unified data device. A processing unit is configured to determine the unified data management device according to the fourth response information.
[0093] In combination with the ninth aspect, in some implementations of the ninth aspect, the fourth response information is determined according to the fourth request message and second configuration information of the unified data management device. The second configuration information includes at least one of the following: a second supported group identifier, a second supported information, and a second supported type information. Wherein, the second supported group identifier corresponds to a second service requester, and the unified data management device supports managing subscription data of terminal devices corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of terminal devices corresponding to which the unified data management device supports managing subscription data.
[0094] In combination with the ninth aspect, in some implementations of the ninth aspect, a processing unit is configured to determine the unified data management device according to the first authentication information and fifth configuration information. The fifth configuration information includes the correspondence between the unified data management device information and at least one of the following: a second supported group identifier, a second supported information, and a second supported type information. Wherein, the second supported group identifier corresponds to a second service requester, and the unified data management device supports managing subscription data of terminal devices corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of terminal devices corresponding to which the unified data management device supports managing subscription data.
[0095] In combination with the ninth aspect, in some implementations of the ninth aspect, an interface unit is configured to obtain a second authentication response message from the unified data management device. The second authentication response message includes at least one of the following: identification information and / or address information of an authentication and authorization function NSSAAF of a specific network slice, and identification information and / or address information of an AAA server.
[0096] In combination with the ninth aspect, in some implementations of the ninth aspect, an interface unit is configured to send a fifth request message to a network storage device. The fifth request message is used to request to discover the NSSAAF. The fifth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier is included in the identification information, and the group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit is further configured to obtain fifth response information from the network storage device. The fifth response information includes the identification information and / or address information of the NSSAAF, and the identification information and / or address information of the AAA server. A processing unit is configured to determine the NSSAAF according to the fifth response information.
[0097] In combination with the ninth aspect, in some implementations of the ninth aspect, the fifth response information is determined according to the fifth request message and the sixth configuration information of the NSSAAF. The sixth configuration information includes at least one of the following: a third supported group identifier, third supported information, and third supported type information. The third supported group identifier corresponds to a third service requester, and the NSSAAF supports performing authentication and / or authorization on the terminal device corresponding to the third service requester. The third supported information indicates whether the NSSAAF supports the authentication and / or authorization of Internet of Things devices. The third supported type information is used to indicate the device type for which the NSSAAF supports performing authentication and / or authorization.
[0098] In combination with the ninth aspect, in some implementations of the ninth aspect, the first authentication request message includes specific network slice authentication and authorization function (NSSAAF) information and / or AAA server information. The NSSAAF information indicates the NSSAAF used to perform authentication and / or authorization. An interface unit is configured to send a third authentication request message to the NSSAAF. The third authentication request message includes at least one of the following: a device identifier, indication information, device type information, and AAA server information. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The AAA server information includes the identification information and / or address information of the AAA server.
[0099] In a tenth aspect, a communication device is provided. The device includes an interface unit configured to receive a second authentication request message from an authentication service device. The second authentication request message includes at least one of the following: identification information of a terminal device, a group identification, indication information, and device type information. The group identification is included in the identification information, and the group identification indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit is configured to determine an authentication method according to the second authentication request message, and the authentication method is used to authenticate and / or authorize the terminal device.
[0100] In combination with the tenth aspect, in some implementation manners of the tenth aspect, the interface unit is configured to send second configuration information to a network storage device. The second configuration information includes at least one of the following: a second supported group identification, second supported information, and second supported type information. The second supported group identification corresponds to a second service requester, and the unified data management device supports managing subscription data of terminal devices corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of terminal devices corresponding to which the unified data management device supports managing subscription data.
[0101] In combination with the tenth aspect, in some implementation manners of the tenth aspect, the interface unit is configured to receive a third request message from a mobility management device. The third request message is used to select an authentication service device. The third request message includes at least one of the following: identification information, a group identification, indication information, and device type information. The group identification is included in the identification information, and the group identification indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The processing unit is configured to select an authentication service device according to the third request information and fourth configuration information. The fourth configuration information includes a corresponding relationship between authentication service device information and at least one of the following: a first supported group identification, first supported information, and first supported type information. The first supported group identification corresponds to a first service requester, and the authentication service device supports performing authentication and / or authorization on terminal devices corresponding to the first service requester. The first supported information indicates whether it supports authentication and / or authorization of Internet of Things devices. The first supported type information is used to indicate the device type for which the authentication service device supports performing authentication and / or authorization. The interface unit is configured to send third response information to the mobility management device. The third response information includes identification information and / or address information of the authentication service device.
[0102] In combination with the tenth aspect, in some implementations of the tenth aspect, an interface unit is configured to send a second authentication response message to an authentication service device, where the second authentication response message includes at least one of the following: identification information and / or address information of an authentication and authorization function NSSAAF of a specific network slice, and / or identification information and / or address information of an AAA server.
[0103] In combination with the tenth aspect, in some implementations of the tenth aspect, an interface unit is configured to receive a registration request message from a mobility management device. The registration request message includes identification information of the mobility management device and identification information and / or address information of the authentication service device, and the registration request message indicates the mobility management device and the authentication service device that serve the terminal device.
[0104] In combination with the tenth aspect, in some implementations of the tenth aspect, the apparatus further includes a storage unit configured to store identification information of the authentication service device.
[0105] The eleventh aspect provides a communication apparatus, which includes an interface unit configured to receive a service request message from a service requester. The service request message is used to perform a service operation on at least one terminal device corresponding to the service requester. The network exposure function determines network function information according to the service request message, and the network function corresponding to the network function information is used to perform authentication and / or authorization on at least one terminal device; the interface unit is further configured to send the service request message to a mobility management device, where the service request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: an authentication service device, a unified data management device, a specific network slice authentication and authorization function NSSAAF, and an AAA server.
[0106] The twelfth aspect provides a communication apparatus, which includes an interface unit configured to send a request message to a reader. The terminal device accesses the network using Internet of Things access technology, and the request message includes identification information and / or device type of the terminal device. The device type information indicates that the terminal device is an active terminal or a passive terminal.
[0107] The thirteenth aspect provides a communication apparatus, which includes an interface unit configured to receive a request message from a terminal device. The terminal device accesses the network using Internet of Things access technology, and the request message includes identification information and / or device type of the terminal device. The device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit is further configured to send a first message to a mobility management device, where the first message includes identification information of the terminal device, the first message indicates the device type of the terminal device, and the first message is used to determine an authentication service device that supports authentication and / or authorization of devices accessing the network using Internet of Things access technology.
[0108] In a fourteenth aspect, a communication device is provided. The device includes an interface unit configured to receive first configuration information from an authentication service device. The first configuration information includes at least one of the following: a first supported group identifier, first support information, and first support type information. The first supported group identifier corresponds to a first service requester, and the authentication service device supports performing authentication and / or authorization on a terminal device corresponding to the first service requester. The first support information indicates whether authentication and / or authorization of Internet of Things (IoT) devices is supported. The first support type information is used to indicate the type of device for which the authentication service device supports performing authentication and / or authorization. The interface unit is further configured to receive a first request message from a mobility management device. The first request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit is configured to discover the authentication service device based on the first request message and the first configuration information. The interface unit is configured to send a first response information to the mobility management device. The first response information includes the identification information and / or address information of the authentication service device.
[0109] In combination with the fourteenth aspect, in some implementations of the fourteenth aspect, the interface unit is configured to receive second configuration information from a unified data management device. The second configuration information includes at least one of the following: a second supported group identifier, second support information, and second support type information. The second supported group identifier corresponds to a second service requester, and the unified data management device supports managing the subscription data of a terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of IoT devices. The second support type information is used to indicate the type of device corresponding to the terminal device for which the unified data management device supports managing the subscription data. The interface unit is further configured to receive a second request message from the mobility management device. The second request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The processing unit is configured to discover the authentication service device based on the second request message and the second configuration information. The interface unit is configured to send a second response information to the mobility management device. The second response information includes the identification information and / or address information of the unified data management device.
[0110] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, an interface unit is configured to receive second configuration information from a unified data management device. The second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information. The second support group identifier corresponds to a second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data. The interface unit is further configured to receive a second request message from a mobility management device. The second request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit is configured to discover an authentication service device based on the second request message and the second configuration information. The interface unit is configured to send second response information to the mobility management device. The second response information includes the identification information and / or address information of the unified data management device.
[0111] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, an interface unit is configured to receive a fourth request message from an authentication service device. The fourth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit is configured to discover an authentication service device based on the fourth request message and the second configuration information. The interface unit is configured to send fourth response information to the authentication service device. The fourth response information includes the identification information and / or address information of the unified data management device.
[0112] In combination with the fourteenth aspect, in certain implementations of the fourteenth aspect, an interface unit is configured to receive sixth configuration information from an authentication and authorization function NSSAAF of a specific network slice. The sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information. The third support group identifier corresponds to a third service requester, and the NSSAAF supports performing authentication and / or authorization on a terminal device corresponding to the third service requester. The third support information indicates whether the NSSAAF supports authentication and / or authorization of Internet of Things devices. The third support type information is used to indicate the type of device for which the NSSAAF supports performing authentication and / or authorization. The interface unit is further configured to receive a fifth request message from an authentication service device. The fifth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit is configured to discover the authentication service device based on the fifth request message and the sixth configuration information. The interface unit is configured to send a fifth response information to the authentication service device. The fifth response information includes identification information and / or address information of the NSSAAF, and identification information and / or address information of an AAA server.
[0113] The fifteenth aspect provides a communication device, which may be a core network device or a terminal device, or a component of a core network device or a terminal device (such as a processor, a chip, or a chip system), or a logical node, a logical module, or software that can implement all or part of the functions of a core network device or a terminal device. The device has the functions of implementing the above first aspect to the seventh aspect and various possible implementation manners. The function may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0114] In a possible design, the device includes: an interface unit, which may be at least one of a transceiver, a receiver, and a transmitter, and the interface unit may include a radio frequency circuit or an antenna. Optionally, the device further includes a processing unit, which may be a processor. Optionally, the device further includes a storage unit, which may be a memory, for example. When the storage unit is included, the storage unit is configured to store programs or instructions. The processing unit is connected to the storage unit, and the processing unit may execute the programs, instructions, or instructions from other sources stored in the storage unit to enable the device to execute the communication methods of the above first aspect to the seventh aspect and various possible implementation manners.
[0115] In another possible design, when the device is a chip, the chip includes: an interface unit and a processing unit. The interface unit can be, for example, an input / output interface, a pin, or a circuit on the chip. The processing unit can be, for example, a processor. The processing unit can execute instructions to enable the chip in the network device to execute the above-mentioned first aspect, second aspect, fourth aspect, and fifth aspect and various possible implementation methods. Optionally, the processing unit can execute the instructions in the storage unit, and the storage unit can be a storage module in the chip, such as a register, a cache, etc. The storage unit can also be located inside the communication device but outside the chip, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0116] In a sixteenth aspect, a communication system is provided, and the communication system includes the communication devices provided in the above-mentioned eighth aspect to fourteenth aspect. The communication system can complete the communication methods provided in the above-mentioned first aspect to seventh aspect and any possible implementation manners in the first aspect to seventh aspect.
[0117] In a seventeenth aspect, a computer-readable storage medium is provided, and a computer program is stored on the computer-readable storage medium. When the computer program runs on a computer, it enables the computer to execute the instructions of the methods in the above-mentioned first aspect to seventh aspect or any possible implementation manner in the first aspect to seventh aspect.
[0118] In an eighteenth aspect, a communication device is provided, including: a processor, and the processing unit can execute instructions to enable the methods in the above-mentioned first aspect to seventh aspect or any possible implementation manner in the first aspect to seventh aspect to be executed.
[0119] Among them, the above-mentioned processor can be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the communication methods in the above-mentioned first aspect to fifth aspect.
[0120] In a possible implementation, the communication device further includes a memory for storing the above-mentioned executable instructions. Optionally, the memory and the processor are integrated together.
[0121] In a possible implementation, the communication device further includes a communication interface for inputting and outputting signaling or data.
[0122] In one possible implementation, the communication device is a chip.
[0123] In a nineteenth aspect, a computer program product is provided, which includes computer program code for executing the instructions of the method according to any one of the first aspect to the seventh aspect or any possible implementation manner of the first aspect to the seventh aspect when the computer program code is run.
[0124] In a twentieth aspect, a chip system is provided, including a memory and a processor. The memory is used for storing instructions, and the processor is used for calling and running the instructions from the memory, so that the methods in the first aspect to the seventh aspect and their possible implementation manners are executed.
[0125] Wherein, the chip system may include an input circuit or interface for sending information or data, and an output circuit or interface for receiving information or data.
[0126] Specifically, the beneficial effects of other aspects can refer to the beneficial effects described in the first aspect to the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0127] Figure 1 is a schematic diagram of a communication system applicable to the embodiments of the present application;
[0128] Figure 2 is a schematic diagram of an environmental Internet of Things architecture applicable to the embodiments of the present application;
[0129] Figure 3 is a schematic diagram of a protocol stack supported by an Internet of Things terminal provided by the present application;
[0130] Figure 4 is a schematic diagram of a user hidden identifier structure provided by the present application;
[0131] Figure 5 is a schematic diagram of a process for discovering network elements in the same network provided by the present application;
[0132] Figure 6 is a schematic diagram of a registration process provided by the present application;
[0133] Figure 7 is a schematic diagram of an authentication process provided by the present application;
[0134] Figure 8 is a schematic diagram of a communication method process provided by the embodiments of the present application;
[0135] Figure 9 is another schematic diagram of a communication method process provided by the embodiments of the present application;
[0136] Figure 10It is a schematic flowchart of another communication method provided by an embodiment of the present application;
[0137] Figure 11 It is a schematic flowchart of another communication method provided by an embodiment of the present application;
[0138] Figure 12 It is a schematic block diagram of a communication device provided by an embodiment of the present application;
[0139] Figure 13 It is a schematic block diagram of another communication device provided by an embodiment of the present application. Detailed implementation manners
[0140] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.
[0141] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Global System of Mobile Communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE Frequency Division Duplex (FDD) system, LTE Time Division Duplex (TDD), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, Fifth Generation (5G), Sixth Generation (6G) system or New Radio (NR), and other future communication systems, etc.
[0142] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings.
[0143] Figure 1 It is a schematic diagram of a communication system. As Figure 1As shown in the figure, the network includes an access and mobility management function (AMF), a network exposure function (NEF), a network repository function (NRF), a unified data management (UDM), a radio access network (RAN) device, a policy control function (PCF), a user equipment (UE), a policy control function (PCF), a user plane function (UPF), a data network (DN), an authentication server function (AUSF), a network slice selection function (NSSF), an authentication, authorization, and accounting server (AAA Server), and a network slice-specific and SNPN authentication and authorization function (NSSAAF), and so on.
[0144] It should be understood that Figure 1 only as a schematic description diagram, the embodiments of the present application do not limit the number and types of network elements (or devices) actually deployed in the network.
[0145] Among them, Figure 1 the main functions of the devices shown are described as follows:
[0146] UE: It can be referred to as user equipment (UE), terminal, access terminal, user unit, user station, mobile station, mobile device, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent or user device. UE can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication function, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal device in a 5G network or terminal device in a future evolved public land mobile network (PLMN) or non-terrestrial networks (NTN), etc. It can also be an end device, logical entity, intelligent device, such as terminal devices like mobile phones and intelligent terminals, or communication devices like servers, gateways, base stations, controllers, or Internet of Things (IoT) devices like tags, passive tags, active tags, semi-active tags, sensors, electricity meters, water meters, etc. It can also be an unmanned aerial vehicle (UAV) with communication function. When the terminal is a passive or semi-active terminal or tag, it can obtain energy to receive or send data. The way to obtain energy can be through radio, solar energy, light energy, wind energy, water energy, thermal energy, kinetic energy, etc. This application does not limit the way for passive or semi-active terminals to obtain energy. This is not limited in the embodiments of this application. It should be noted that the tags involved in this application can be in the form of tags, or in any terminal form.
[0147] It should be understood that UE can be any device that can access the network. UE and the access network device can communicate with each other using a certain air interface technology.
[0148] A radio access network (RAN) device (which can also be referred to as an access network device) corresponds to different access networks in 5G, such as wired access, wireless base station access, and other methods. The RAN devices in this application include, but are not limited to: the next-generation base station (gnodeB, gNB), evolved node B (eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved nodeB, or home node B, HNB), base band unit (BBU), transmitting and receiving point (TRP), transmitting point (TP), mobile switching center, etc. in 5G.
[0149] The operation requester (or also known as the service requester or third party): can be a server or an application function. In the embodiments of this application, the operation requester can be understood as the device that sends operation instructions. For example, the operation requester can be a server, P-IoT server, application function (AF), or other devices that send operation instructions. The operation requester can correspond to a certain type of user, and this type of user can include enterprises, tenants, third parties, or companies, without limitation. Among them, the operation requester corresponding to a certain type of user can be understood as the operation requester belonging to this type of user and being managed by this type of user.
[0150] Unified data management (UDM): can also be referred to as a unified data management network element, unified data management entity, data management device, unified data management device. Among them, the unified data management network element is used to process terminal device identification, access authentication, registration, and mobility management, etc. In a 5G communication system, the unified data management can be UDM or a unified data management device. In future communication systems, the unified data management can also be a UDM network element, or there can be other names, which are not limited in the embodiments of this application. The unified data management device can be a core network device. The unified data management device can be a control plane device.
[0151] Policy Control Function (PCF): It can also be referred to as a policy control network element, a policy control function network element, a policy control device, a policy control function entity, etc. It is mainly responsible for policy control functions such as charging at the session and service flow levels, quality of service (QoS) bandwidth guarantee, mobility management, and UE policy decision-making.
[0152] Session Management Function (SMF): It can also be referred to as a session management device. This device is used to be responsible for the session management of user equipment (including the establishment, modification, and release of sessions), the selection and reselection of user plane function network elements, the allocation of Internet Protocol (IP) addresses for user equipment, QoS control, etc. For example, in 5G, the session management network element can be the Session Management Function (SMF) network element. In future communication systems, such as 6G, the session management network element can still be the SMF network element, or have other names, which are not limited in this application. When the session management network element is the SMF network element, the SMF can provide the Nsmf service.
[0153] Access and Mobility Management Function (AMF): It can also be referred to as an access and mobility management function entity, an access and mobility management device, an access and mobility management network element, an access management device, a mobility management device. It is a type of core network device, mainly used for mobility management and access management, etc. It can be used to implement other functions in the Mobility Management Entity (MME) function except session management, such as lawful interception, or access authorization (or authentication), registration of user equipment, mobility management, tracking area update process, reachability detection, selection of session management network elements, mobile state transition management, etc. For example, in 5G, the access and mobility management network element can be the Access and Mobility Management Function (AMF) network element. In future communication, such as 6G, the access and mobility management network element can still be the AMF network element, or have other names, which are not limited in this application. When the access and mobility management network element is the AMF network element, the AMF can provide the Namf service.
[0154] User Plane Function (UPF): It can also be referred to as a user plane device, a user plane function network element, a user plane network element, or a user plane function entity. It is a type of core network device. This device is responsible for the forwarding and reception of user data in user equipment. It can receive user data from a data network and transmit it to the user equipment through an access network element; the user plane function network element can also receive user data from the user equipment through the access network element and forward it to the data network. The transmission resources and scheduling functions provided for the user equipment in the user plane function network element are managed and controlled by the session management function network element.
[0155] Authentication Server Function (AUSF): It can also be referred to as an authentication server function network element, an authentication server function entity, an authentication service device, or an authentication device. It is mainly used for user authentication and performing authentication, that is, the authentication between the UE and the operator network. After receiving an authentication request initiated by a subscribed user, the authentication server function network element can authenticate and / or authorize the subscribed user through the authentication information and / or authorization information stored in the unified data management network element, or generate the authentication and / or authorization information of the subscribed user through the unified data management network element. The authentication server function network element can feedback the authentication information and / or authorization information to the subscribed user. In a possible implementation, the authentication server function network element can also be co-located with the unified data management network element. In a 5G communication system, the authentication server function network element can be an authentication server function (AUSF) network element. In future communication systems, the unified data management can still be AUSF, or there can be other names, which are not limited in the embodiments of this application.
[0156] Network Repository Function (NRF): It can also be referred to as a network repository device, a network repository function network element, or a network repository function entity. It is mainly used to support the service discovery function. It receives a network element discovery request from a network element function or a Service Communication Proxy (SCP) and can provide feedback on the network element discovery request information. At the same time, the NRF is also responsible for maintaining information about available network functions and the services they support respectively. It can also be understood as a network repository device. Among them, the discovery process is a process in which a required network function (NF) uses the NRF to achieve addressing for a specific NF or a specific service. The NRF provides the IP address, Fully Qualified Domain Name (FQDN), or Uniform Resource Identifier (URI) of the corresponding NF instance or NF service instance. In addition, the NRF can also implement the discovery process across PLMNs by providing a network identifier (such as PLMNID). To achieve the addressing discovery of network element functions, each network element needs to be registered in the NRF, and some network element functions can be registered in the NRF during their first run. The network repository function device can be a core network device.
[0157] Network Exposure Function (NEF): It can also be referred to as a network exposure device, a network exposure function entity, a network exposure function network element, a network capability exposure function entity, a network capability exposure function device, a network capability exposure function network element, a network capability exposure device, etc. It is mainly used to support the exposure of capabilities and events, such as securely exposing services and capabilities provided by 3GPP network functions to the outside.
[0158] User Data Repository (UDR): It can also be referred to as a user data repository entity, a user data repository network element, a user data repository device, etc. It can be understood as the naming of the unified data storage network element in the 5G architecture. Among them, the user data repository mainly includes the following functions: the access function for data types such as subscription data, policy data, and application data.
[0159] Authentication Authorization Accounting Server (AAA server): It can also be called an authentication authorization server, an authentication authorization device, an authentication device, an authentication authorization accounting device, etc. It is a server program that can process user access requests, provide authentication authorization, and account services. The AAA server usually works in coordination with network access control, gateway servers, databases, and user information directories. The network connection server interface that collaborates with the AAA server is "Remote Authentication Dial-In User Service (RADIUS)".
[0160] Network slice-specific and SNPN authentication and authorization function: It is mainly used to support specific network slice authentication and authorization with the AAA server or AAA proxy, and to support accessing the SNPN using credentials from a credentials holder (CH), where the credentials holder uses the AAA server for authentication.
[0161] Among them, as Figure 1 shown, the terminal device accesses the network through the RAN device.
[0162] The terminal device communicates with the AMF through the N1 interface (abbreviated as N1).
[0163] The RAN communicates with the AMF through the N2 interface (abbreviated as N2).
[0164] The RAN communicates with the UPF through the N3 interface (abbreviated as N3).
[0165] The UPF communicates with the UPF through the N9 interface (abbreviated as N9).
[0166] The UPF communicates with the DN through the N6 interface (abbreviated as N6) respectively.
[0167] In addition, Figure 1 the control plane functions such as the AMF, SMF, NEF, NRF, PCF, or UDM shown can also interact using service-based interfaces.
[0168] For example, the service-based interface provided by the AMF can be Namf.
[0169] The service-based interface provided by the NSSF can be Nnssf.
[0170] The service-based interface provided by the UDM can be Nudm.
[0171] The service-based interface provided by NEF can be Nnef.
[0172] The service-based interface provided by NRF can be Nnrf.
[0173] The service-based interface provided by PCF can be Npcf.
[0174] The service-based interface provided by AF can be Naf.
[0175] The service-based interface provided by AUSF can be Nausf.
[0176] The service-based interface provided by NSSAAF can be Nnssaaf.
[0177] The service-based interface provided by SMF can be Nsmf.
[0178] It should be understood that RAN, SMF, PCF, or AF in the embodiments of the present application can also be referred to as a communication device or communication equipment, which can be a general device or a dedicated device, and the present application does not make specific limitations thereto.
[0179] It should also be understood that the above naming is only used to distinguish different functions and does not mean that these devices are respectively independent physical devices. The present application does not limit the specific form of the above devices. For example, they can be integrated in the same physical device or can be different physical devices respectively. In actual deployment, network elements or devices can be co-located. For example, the access and mobility management network element can be co-located with the session management network element; the session management network element can be co-located with the user plane network element. When two network elements are co-located, the interaction between the two network elements provided in the embodiments of the present application becomes an internal operation of the co-located network element or can be omitted.
[0180] It can be understood that the above functions can be either network elements in hardware devices, software functions running on dedicated hardware, or a combination of hardware and software, or virtualized functions instantiated on a platform (such as a cloud platform).
[0181] It should be noted that Figure 1 the naming of each device (such as PCF, AMF, etc.) is only a name, and the name does not limit the function of the device itself. In the 5G network and other future networks, the above devices can also have other names, and the present application does not make specific limitations thereto. For example, in the 6G network, some or all of the above network elements may continue to use the terms in 5G, or may have other naming, etc. A unified description is made here and will not be repeated hereinafter.
[0182] It should be noted that the technical solution of the embodiment of the present application is applicable to 5G networks, and is also applicable to 4G, 6G networks, and future communication networks, etc.
[0183] To better describe the technical solution of the embodiment of the present application, the technical terms related to the technical solution of the embodiment of the present application will be described below.
[0184] 1. Ambient Internet of Things (ambient-IOT)
[0185] The ambient Internet of Things can also be referred to as the ambient power-enabled ambient IoT, or the passive Internet of Things (P-IoT). That is, some network nodes (such as terminals or devices) can be passive, semi-passive, or active. Among them, passive and semi-passive terminals can communicate by reflecting the carrier wave, that is, they need to rely on an external carrier source for communication. Passive terminals can have an energy storage capacitor or not. If they do not have an energy storage capacitor, they need to rely on the external environment to obtain energy for communication, such as radio frequency energy. For semi-passive terminals, they can have a power amplifier, so the communication distance is increased compared with passive terminals. For semi-passive terminals, they usually have an energy storage capacitor and can store energy such as solar energy and wireless power in the capacitor. For active terminals (active devices), they can actively generate a carrier wave (or can be understood as having carrier recovery ability), and they can communicate without relying on an external carrier source, so they can have the ability of active communication. In one possible implementation, they can also have an energy storage capacitor and can obtain energy through solar energy, radio frequency, wind energy, water energy, or tidal energy, etc. The way of obtaining energy is not limited. These nodes do not have or rely on power supply devices such as batteries by themselves, but obtain energy from the environment to support data sensing, transmission, and distributed computing. The nodes (terminals or devices) can also store the obtained energy. In the present application, AmbientIoT can be understood as the ambient Internet of Things.
[0186] The Internet of Things (IoT) architecture for the environment can include terminals (i.e., the above-mentioned nodes or devices), readers, and servers (or application functions, AFs). The terminals can be in the form of tags or any other terminal form, such as sensors, license plates, nameplates, etc., without limitation. The readers can be access network devices, such as base stations, pole stations, small cell base stations, macro base stations, relay points (e.g., integrated access and backhaul nodes, IAB nodes), mobile base stations, etc.; the readers can be terminal devices, such as mobile phones, IoT devices, handheld readers, etc. The reader communicates with the terminal in a non-contact two-way data communication manner via radio frequency, reads and writes the terminal using radio frequency, so as to achieve the purpose of identifying the target and data exchange. There are two working modes. One is that when the terminal enters the effective identification range of the reader, it receives the radio frequency signal sent by the reader and emits the information stored in the chip by virtue of the energy obtained from the induced current (corresponding to passive tags); the other is that the terminal can store some electrical energy through means such as solar energy, so that it can actively send a signal of a certain frequency (this can also be called a semi-passive or semi-active terminal). After the reader receives and decodes the information, it is sent to the central information system for relevant data processing. This technology is widely used in various industries. The following briefly lists two application scenarios:
[0187] (1) Warehouse / Transportation / Materials: Embed or attach passive or semi-passive IoT terminals to goods. When the goods are stored in warehouses, shopping malls, etc. and are in the logistics process, the relevant information of the goods is automatically collected by the reader. Managers can quickly query the goods information in the system, reducing the risk of loss or theft, improving the speed of goods handover, increasing the accuracy rate, and preventing cross-selling and anti-counterfeiting;
[0188] (2) Fixed Asset Management: In some places with large assets or valuable items, such as libraries, art galleries, and museums, a complete management program or strict protection measures are required. When there are abnormal changes in the storage information of books or valuable items, the administrator will be reminded in the system immediately, so as to handle the relevant situation.
[0189] (3) Sensing Data Transmission: The sensor terminal obtains energy from the environment (e.g., obtains solar energy) and can actively generate a carrier to send information. The reader (or base station) receives the signal and sends the sensing information to the server (through the core network).
[0190] The reader interacts with the tag via radio frequency signals or wireless signals. It should be understood that the name of the reader is not limited in this application. The reader can also be named a reading device or other names. That is, it can be understood that the terms "reader" and the name of the reader are interchangeable. The reader here has the functions involved in the reading device in this application. For example, the reader has the function of performing the operations described in this application on the terminal (such as the tag), such as the function of obtaining tag information, inventory operation, read operation, write operation, invalidation operation, or message interaction operation with the tag, etc., and has the function of obtaining charging-related information and / or charging information and sending charging information to the charging function. In one possible implementation, the reader can send instructions from the server or application function to the tag, or the reader can send messages from the tag to the server or application function. In one possible implementation, the reader can obtain the information stored in the specified tag according to the instructions issued by the server. For example, for an inventory operation (or it can be called a stocktaking operation), the reader obtains the identification information of the tag; this identification information can be the unique identification of the tag or the temporary identification of the tag. For example, for a read operation, the reader reads the data in the storage area of the tag. Optionally, in some cases where it is necessary to rewrite the information stored in the tag, the reader can also have a write function. For example, for a write operation, the reader writes the data into the storage area of the tag. In addition, the reader can also perform an invalidation operation on the tag. After the invalidation operation is performed, the tag becomes invalid and cannot be used to perform operations such as obtaining tag information, inventory operation, read operation, message interaction operation with the tag, or write operation. In one possible implementation, the tag being invalid and unable to perform the operation of obtaining tag information can be understood as that after the tag becomes invalid, the reader cannot obtain the tag information of the invalid tag. In another possible implementation, the tag being invalid and unable to perform the message interaction operation with the tag can be understood as that after the tag becomes invalid, the reader cannot interact with the invalid tag.
[0191] In this application, the reading device can be a terminal device, or an access network device, a pole station, an eNodeB, a gNodeB, an integrated access and backhaul (IAB) node, etc. The form of the reader is not limited in this application.
[0192] Figure 2Shows the schematic architecture of the Ambient Internet of Things. In one possible implementation, the core network device (such as the Access and Mobility Management Function (AMF), or a newly added stand-alone core network device, such as the Internet of Things Management Function, Tag Management Function (TMF)) can execute processes related to the Ambient Internet of Things services, such as access management of Internet of Things terminals, security authentication, data transmission, instruction transmission, tag management, etc. In one possible implementation, it can be an enhanced access management device (such as AMF) to execute Internet of Things terminal management. In another possible implementation, newly added functions such as the tag management function, or the Ambient Internet of Things Management Function (AIoTMF) execute Internet of Things terminal management, and this function can be docked with the access network device, which is equivalent to the access network device having an interface with this function, or can interact with the Radio Access Network (RAN) through the AMF. From the perspective of deployment, this function can be co-deployed with the AMF. In this application, the access network device is used as a reader, taking a base station (pole station or macro station) as an example to elaborate, but this application does not limit the device form of the reader. The base station can also be referred to as a Radio Access Network (RAN) device or an access network device.
[0193] When the server operates on the Internet of Things terminal (such as performing inventory, read, write, positioning, inactivation, etc. operations), it can send an operation instruction through the core network. The operation instruction can include, but is not limited to, obtaining Internet of Things terminal information, inventory operation (or called stocktaking operation), read operation, write operation, inactivation operation, and interacting with the Internet of Things terminal information operation. The instruction can include regional location information, identification information of the Internet of Things terminal, etc. The base station sends an access instruction to the Internet of Things terminal. After the Internet of Things terminal randomly accesses successfully, the base station will send an instruction to the Internet of Things terminal (the base station can forward the instruction sent by the core network to the Internet of Things terminal). The Internet of Things terminal obtains or sends corresponding information according to the instruction. For example, when the instruction is an inventory instruction or to perform an inventory operation, the Internet of Things terminal will send the identification information of the Internet of Things terminal; when the instruction is a read instruction or to perform a read operation, the Internet of Things terminal will send the data information stored in the tag storage area; when the instruction is a write instruction or to perform a write operation, the Internet of Things terminal will store the data information to be written into the Internet of Things terminal included in the instruction into the storage area of the Internet of Things terminal. The base station sends (or forwards) the information sent by the Internet of Things terminal to the core network; the core network sends this information to the server.
[0194] The server can send instructions through the control plane channel. As Figure 2As shown, the server sends instructions to the AMF (or other core network devices with management tags or capable of executing tag instructions or supporting passive IoT, such as the Tag Management Function (TMF)). At this time, the server can be an Application Function (AF), an Application Server (AS), or an Ambient IoT Application Function (A-IoT AF or P-IoT AF). In one possible implementation, the P-IoT AF sends instructions to the AMF or TMF through the NEF (as shown in Figure 2 ). Through the above architecture, after the AMF or TMF obtains the instructions, it parses the instructions from the AF, and the AMF or TMF triggers the access network device (such as the RAN) to execute the random access process of the IoT terminal (or tag), and sends instructions to the IoT terminal through the RAN to complete the operation of the IoT terminal.
[0195] The IoT terminal management function (or called the tag management function), for example, the IoT terminal management function can be Figure 2 the TMF of the tag management function, or the IoT terminal management function can be the AmbientIoT Management Function (AIMF). The IoT terminal management function is used to execute the transmission of the service data of the terminal device or to execute the management of the IoT terminal (or tag). For example, when the terminal device is a tag, it can execute the transmission and / or management of the service data of the tag. The naming of the IoT terminal management function (or called the tag management function) in this application is not limited and can be other names. This core network function can be an access management device to execute tag management, such as the Access and Mobility Management Function (AMF); or it can be Figure 2The newly added functions shown are used to perform Internet of Things (IoT) terminal (such as tags) management or execute IoT data transmission, such as IoT management function (IMF) or IoT device management function (IDMF), which can be referred to as ambient IoT management function (AIMF), ambient IoT device management function (AIDMF), passive IoT management function (PIMF), passive IoT device management function (PIDMF), or tag management function (TMF). And this newly added function can be docked with access network devices, and the docking methods include direct docking and indirect docking. Direct docking is equivalent to the access network device having an interface with this function, and indirect docking is to perform signaling or data forwarding through the AMF. The access network device / base station acts as a reader / writer to perform operations on IoT terminals, such as read, write, inventory, positioning, invalidation, etc. In this application, unless otherwise specified, the IoT management function can be interchanged with the IoT management device.
[0196] 2. Schematic diagram of the IoT terminal protocol stack
[0197] As Figure 3 shown, in a possible implementation, the protocol stack supported by the IoT terminal can be a control plane protocol stack. For example, it can include a non-access stratum (NAS) protocol for the interaction between the terminal and the core network, a radio resource control (RRC) protocol for the interaction with access network devices such as the RAN, and MAC and PHY are the protocol stacks of the link layer and the physical layer respectively, which are used to transmit data.
[0198] 3. Subscription permanent identifier (SUPI) and subscription concealed identifier (SUCI)
[0199] The identifiers of the terminal device defined by 3GPP mainly include the Subscriber Permanent Identifier (SUPI), the Subscriber Concealed Identifier (SUCI), the generic public subscription identifier (GPSI), the globally unique temporary identity (GUTI), the 5G-GUTI, the 5G temporary mobile subscriber identity (5G-TMSI), the 5G System temporary mobile subscriber identity (5G-S-TMSI), the international mobile equipment identity (IMEI), the international mobile subscriber identity (IMSI), etc.
[0200] SUPI is the globally unique permanent identifier of the terminal device. It can include:
[0201] (1) The international mobile subscriber identity (IMSI).
[0202] (2) The format of the network-specific identifier (NSI) will adopt the format of the network access identifier (NAI), such as username@realm.
[0203] (3) The global cable identifier (GCI) and the operator identifier of the 5GC operator, adopting the NAI format; this situation is used to support the Fixed Network-Broadband Residential Gateway (FN-BRG).
[0204] (4) The global line identifier (GLI) and the operator identifier of the 5GC operator adopt the NAI format; this situation is used to support the fixed network-cable residential gateway (FN-CRG) and the 5G-cable residential gateway (5G-CRG).
[0205] For the SUPI that contains the NSI, it will adopt the format of the network access identifier (NAI), such as username@realm. Among them, the realm part is the same as the realm part in the NSI.
[0206] SUCI can be understood as the encrypted SUPI. As Figure 4 shown, the SUCI can include the following parts:
[0207] (1) SUPI Type: This parameter contains a value from 0 to 7. It is used to identify the type of the SUPI corresponding to the SUCI encrypted; the types of SUPI are defined as follows:
[0208] 0: IMSI;
[0209] 1: Network Specific Identifier (NSI);
[0210] 2: Global Line Identifier (GLI);
[0211] 3: Global Cable Identifier (GCI);
[0212] 4 to 7: Reserved for future use.
[0213] Which type of SUPI is specifically used is related to the service type initiated by the terminal. For example, if the terminal has been shut down for a long time, restarted and initiates an initial registration, then the SUPI type at this time is 0 (IMSI).
[0214] 2) Home Network Identifier: It is used to identify the home network of the subscribed user; when the SUPI type is IMSI, the HNI contains two parts: the Mobile Country Code (MCC) and the Mobile Network Code (MNC). When the SUPI type is NSI, GLI or GCI, the Home Network Identifier (HNI) contains a variable-length string.
[0215] When the SUPI type is NSI, GLI, or GCI, the home network identifier is a variable-length string that represents a domain name.
[0216] 3) Routing Indicator: It is assigned by the home network operator and allows, in combination with the HNI, to send network signaling carrying the SUCI to the AUSF or UDM to serve the subscribed user.
[0217] 4) Protection Scheme Identifier: It is used to identify the null-scheme or non-null scheme; the non-null scheme is defined by the home public land mobile network (HPLMN).
[0218] 5) Home Network Public Key Identifier: If the null protection scheme is adopted, this value is also set to 0.
[0219] 6) Scheme Output: It contains a variable-length string, depending on the protection scheme adopted.
[0220] From the structure of the SUCI, it can be seen that the SUCI itself can contain the identification information of the UE's home network. The role of this identification information is that when the UE executes the registration process, the AMF in the serving public land mobile network (PLMN) serving the UE will, according to the home network identifier in the SUCI, select the AUSF or UDM network element in that home network to perform the security authentication process for the UE. The reason is that only the UE's home network has the UE's subscribed data, so it is necessary to select the AUSF and UDM in the home network to perform the security authentication process for the UE.
[0221] Figure 5 It is a schematic diagram of the process by which an NF discovers network elements in the same network through the NRF. As Figure 5 shown, the specific steps are as follows:
[0222] S201, the Network Function Service Consumer will send a Network Function Discovery Request message (Nnrf_NFDiscover_Request) to the NRF.
[0223] S202, the NRF will authorize the request message sent in step S201.
[0224] S203, if the NF is found, the response message will include one or more network function instances (NF instances), network function types (NF types), network function instance identifiers (NF instance IDs), fully qualified domain names (FQDNs) or IP addresses of the network functions. If the NF is not found, the reason for failure will be reported, such as 404 not found, indicating that the requested NF cannot be found in the NRF.
[0225] 4. UE Registration
[0226] Figure 6 is a schematic diagram of the UE registration process. The specific content is as Figure 6 shown.
[0227] S301, the RAN receives the registration request information from the UE.
[0228] It should be understood that when the UE needs to register to the network, the UE sends the registration request information, which includes the registration type and the identification information of the terminal device. Exemplarily, the identification information of the UE may include one or more of the following information: globally unique temporary identity (GUTI), SUCI, and permanent equipment identifier (PEI).
[0229] S302, the RAN performs the selection of the AMF.
[0230] It should be understood that after receiving the registration request information from the UE, the RAN will select a suitable AMF and send the UE's registration request information to the AMF.
[0231] S303, the AMF receives the registration request information.
[0232] S304, the AMF performs the selection of the AUSF.
[0233] Specifically, the AMF selects a suitable AUSF for authentication and other security processes. The method for the AMF to select the AUSF refers to the AUSF selection method in the above text. The UE, AMF, AUSF, and UDM interact to complete authentication and other security processes; for 3GPP UEs, this authentication process is a two-way authentication between the UE and the network.
[0234] S305, perform authentication or security processes.
[0235] It should be understood that the execution process of the above authentication or security process involves the interaction of the UE, AMF, AUSF, and UDM.
[0236] S306, obtain the subscription data of the UE.
[0237] After the mutual authentication between the UE and the core network element is successful, the AMF can interact with the UDM to obtain the subscription data of the terminal device.
[0238] S307, the AMF sends N2 information to the RAN.
[0239] It should be understood that the N2 information sent by the AMF to the RAN includes non-access stratum (NAS) information, and the NAS information includes registration acceptance information.
[0240] S308, the RAN sends the registration acceptance information to the UE.
[0241] After the RAN receives the registration acceptance information sent by the AMF, it forwards the registration acceptance information to the UE. Thus, the UE completes the registration process.
[0242] Since the IoT terminal is a low-power and low-complexity terminal device, a specific authentication process or authentication algorithm needs to be adopted.
[0243] Based on the above problems, the present application provides a communication method. According to the solution of the present application, the IoT terminal can be enabled to access the core network to execute the security authentication process, improving the communication reliability.
[0244] Figure 7 This is a communication method 400 provided by the present application. This method is described by taking the authentication service device as the AUSF and the mobility management device as the AMF as examples. In a possible implementation, in the present application, the mobility management device can be replaced by a functional device for executing IoT device management or service processing, such as a tag management function (TMF), an ambient IoT function (AIoTF), an ambient IoT management function (AIoTMF), etc. The device name does not limit the function of the device itself. In future communication systems, some or all of the above network elements may continue to use these names, or there may be other names, which are uniformly described here. This method may include the following steps:
[0245] S401, the AMF obtains the first message.
[0246] The first message includes the identification information of the terminal device, the first message indicates the device type of the terminal device, and the terminal device accesses the network using IoT access technology.
[0247] In a possible embodiment, the Internet of Things may specifically be the Ambient Internet of Things (such as ambientiot), the Ambient Power - enabled Internet of Things (such as ambientpower - enablediot), or the Passive Internet of Things (such as passiveiot).
[0248] In a possible embodiment, the first message includes device type information, and the device type information indicates that the terminal device is an Internet of Things device, an Ambient Internet of Things device, an Ambient Power - enabled Internet of Things device, or a Passive Internet of Things device.
[0249] In a possible embodiment, the first message includes device type information, and the device type information indicates that the terminal device is an active terminal or a passive terminal.
[0250] In a possible embodiment, the first message may include indication information. The indication information indicates that the terminal device is an Internet of Things device, or the indication information indicates that the terminal device accesses the network using Internet of Things access technology, or indicates that the terminal device is a device corresponding to an Internet of Things service. Exemplarily, the Internet of Things service may be understood as an Ambient Internet of Things service (such as ambientiotservice), an Ambient Power - enabled Internet of Things service (such as ambientpower - enablediotservice), or a Passive Internet of Things service (such as passiveiotservice). In a possible implementation manner, the indication information may be access technology type information (such as radioaccesstechnologytype, RAT type).
[0251] S402, the AMF selects an AUSF according to the first message.
[0252] This step may further include: the AMF determines that the terminal device is an Internet of Things device according to the first message.
[0253] In a possible implementation manner, the AMF can indicate that the terminal device is an Internet of Things device through the format, structure, etc. of the terminal device identifier (such as device ID).
[0254] In another possible implementation manner, the AMF determines that the terminal device is an Internet of Things device through the device type information in the first message. Further, it can also determine that the terminal device is an active device or a passive device. For example, the AMF can determine whether the terminal device is an active device or a passive device according to the identification information. Also for example, the AMF can determine whether the terminal device is an active device or a passive device according to the subscription data or configuration information.
[0255] In another possible implementation, the AMF determines that the terminal device is an Internet of Things device based on the indication information in the first message. For example, the AMF may determine that the terminal device is an Internet of Things device according to the access technology type information in the first message, or determine that the terminal device uses an Internet of Things access technology.
[0256] S403. The AMF sends a first authentication request message to the AUSF.
[0257] The first authentication request message includes the identification information of the terminal device, and the first authentication request message is used to request to perform authentication and / or authorization on the terminal device.
[0258] The first authentication request message includes the identification information of the terminal device.
[0259] In a possible embodiment, the first authentication request message may include indication information, where the indication information indicates that the terminal device is an Internet of Things device, or the indication information indicates that the terminal device accesses the network using an Internet of Things access technology, or the indication information indicates that the terminal device is a terminal device corresponding to an Internet of Things service.
[0260] S404. The AUSF performs authentication and / or authorization on the terminal device according to the first message.
[0261] Figure 8 This is a communication method 500 provided by the present application. This method is described by taking the authentication service device as the AUSF, the network storage device as the NRF, the mobility management device as the AMF, and the unified data management device as the UDM as examples. The device names do not limit the functions of the devices themselves. The devices can be understood as corresponding functions. Without special instructions, the two can be interchanged. In future communication systems, some or all of the above network elements may continue to use these names, or there may be other names. This is explained uniformly here, and the same will not be repeated in the subsequent methods 600-800. This method may include the following steps:
[0262] S501. The AUSF sends first configuration information (such as a profile or an NF profile) to the NRF.
[0263] The first configuration information includes at least one of the following: a first support group identifier, first support information, and first support type information. Among them, the first support group identifier indicates the first service requester. The first support group identifier may also be expressed as the first group identifier. The first group identifier indicates the supported service requester. Alternatively, the first group identifier may represent that the AUSF supports performing authentication and / or authorization on the Internet of Things devices of the service requester corresponding to the first group identifier. Alternatively, the first group identifier may represent that the AUSF supports performing authentication and / or authorization on the Internet of Things devices corresponding to the first group identifier. The first support information indicates whether it supports the authentication and / or authorization of Internet of Things devices. Alternatively, the first support information indicates support for the authentication and / or authorization of Internet of Things devices. The first support type information may also be expressed as the first type information. The first type information is used to indicate the device type for which authentication and / or authorization is supported. Alternatively, the first type information may represent that the AUSF supports performing authentication and / or authorization on the device type indicated by the first type information.
[0264] Exemplarily, the first configuration information may include one or more of the following information: network function type (NF type), identification information (such as NF instance ID), fully qualified domain name (FQDN) of the network function, IP address, network identifier (such as PLMN ID or PLMN ID + NID); among them, the network function type may be indicated as the authentication service function (such as AUSF); the identification information may be the identifier of the authentication service function, the FQDN is the FQDN of the authentication service function, the IP address is the IP address of the authentication service function; the network identifier may be used to indicate the network where the authentication service function is located or the network to which it belongs / serves.
[0265] In a possible implementation manner, the first configuration information may include indication information (the indication information indicates support for Ambient IoT), one or more supported Owner IDs, and supported device types (such as active terminals and / or passive terminals).
[0266] The indication information may be used to indicate support for the authentication or authorization of Ambient IoT terminals, or may be used to indicate the authentication / authorization algorithm or process for Ambient IoT terminals.
[0267] One or more supported Owner IDs (i.e., the first support group identifier) represent support for performing the authentication / authorization process on one or more terminals (Internet of Things terminals) corresponding to the one or more Owner IDs.
[0268] The owner ID can be replaced with a group identifier or an identifier information indicating the service requestor. The identifier information indicating the service requestor can be a service requestor identifier, a user identifier (User ID), an enterprise identifier (enterprise ID), a third-party identifier (the third party ID), or an owner ID. The service requestor identifier, the user identifier, the enterprise identifier, the third-party identifier, or the owner ID is an implementation manner of the identifier information indicating the service requestor. In practical applications, the identifier of the service requestor can be indicated by other identifiers. The operation requestor, which can be referred to as the service requestor or the third party, can be a server, an application function, or other devices indicating the execution of operation instructions. In the embodiments of the present application, the operation requestor can be understood as the device sending the operation instruction. For example, the operation requestor can be a server / Ambient IoT server / Passive IoT server / AF / other devices sending operation instructions. The operation requestor can correspond to a certain type of user, and this type of user can include enterprises, tenants, third parties, or companies. The present application does not limit this. Among them, the operation requestor corresponding to a certain type of user can be understood as that the operation requestor belongs to this type of user and is managed by this type of user.
[0269] The supported device types (such as active terminals and / or passive terminals, or one or more of device types A / B / C) can be used to indicate the types of terminals that support the execution of authentication and / or authorization; or, the supported device types (such as active terminals and / or passive terminals, or one or more of device types A / B / C) can be used to indicate the support for performing authentication and / or authorization on this type of terminal; or, the supported device types (such as active terminals and / or passive terminals, or one or more of device types A / B / C) can be used to indicate the support for the authentication / authorization algorithm process corresponding to this type of terminal.
[0270] In a possible implementation manner, the AUSF sends the above first configuration information through Nnrf_NFManagement_NFRegister Request or Nnrf_NFManagement_NFUpdate Request.
[0271] S502, the NRF sends result indication information (such as Nnrf_NFManagement_NFRegisterResponse or Nnrf_NFManagement_NFUpdate Response) to the AUSF.
[0272] Exemplarily, when the NRF successfully obtains the first configuration information, it can send result indication information indicating success to the AUSF.
[0273] In S503, the UDM sends second configuration information (such as a profile or an NF profile) to the NRF.
[0274] Different from step S501, the network function type NF type is the NF type indicated as the UDM, and the provided information is the identification information of the UDM, the fully qualified domain name FQDN of the network function, the IP address, and the network identification (such as a PLMN ID or a PLMNID+NID) instead of the relevant information of the AUSF. Among them, the network function type can be indicated as unified data management (such as UDM); the identification information can be the identification of the unified data management, the FQDN is the FQDN of the unified data management, and the IP address is the IP address of the unified data management; the network identification can be used to indicate the network where the unified data management is located or the network to which it belongs / serves.
[0275] The second configuration information includes at least one of the following: a second support group identification, second support information, and second support type information. Among them, the second support group identification indicates the second service requester, and the second support group identification can also be expressed as the second group identification. The second group identification indicates the service requester supported by the UDM, or the second group identification can represent that the UDM supports managing the subscription data of the Internet of Things devices of the service requester corresponding to the second group identification, or the second group identification can represent that the UDM supports the subscription data of the Internet of Things devices corresponding to the second group identification; the second support information indicates whether the UDM supports the authentication and / or authorization of Internet of Things devices; the second support type information can also be expressed as the second type information. The second type information is used to indicate the device type that supports authentication and / or authorization, or the first type information can represent that the AUSF supports performing authentication and / or authorization on the device type indicated by the second type information.
[0276] The message for providing information can refer to step S501.
[0277] In S504, the NRF sends result indication information to the UDM.
[0278] The message for providing the result indication information can refer to step S502.
[0279] In S505, after the terminal device successfully initiates random access, it sends a second message (such as a registration request message) to the reader (such as the RAN).
[0280] In a possible implementation, the Internet of Things terminal sends an AS message (access stratum access layer message) to the reader / writer, and the second message (such as a registration request message) is included in the AS message, that is, the second message (such as a registration request message) is a NAS message.
[0281] In a possible implementation, the second message may include a device identifier (such as a device ID) and device type information, such as device type information indicating an active terminal (such as an active device) or a passive terminal (such as a passive device); wherein, an active terminal may represent that the terminal supports active communication and / or energy storage; a passive terminal may represent that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Wherein, device A may represent that the terminal does not support energy storage and / or does not support active communication; device B may represent that the terminal supports energy storage and / or does not support active communication; device C may represent that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication may be understood as supporting carrier generation or supporting carrier recovery. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring dependence on an external excitation source or an external carrier source for communication. In a possible implementation, the device type information is indicated as a first type of device or a second type of device. Wherein, the first type of device does not support active communication, or the first type of device needs to rely on an external carrier to perform uplink data transmission; the second type of device supports active communication, or the second type of device does not need to rely on an external carrier to perform uplink data transmission. Exemplarily, supporting active communication may be understood as supporting carrier generation or supporting carrier recovery.
[0282] S506, the reader (such as RAN) selects an AMF.
[0283] RAN determines that the device sending the registration request message is an IoT terminal and selects a suitable AMF.
[0284] Exemplarily, if RAN can determine that the IoT terminal accesses using the access technology type of Ambient IoT, it selects an AMF that supports Ambient IoT.
[0285] S507, RAN sends a first message to the AMF.
[0286] The first message may include a second message. The first message includes the identification information of the terminal device (for example, the first message includes a second message, and the second message includes the identification information of the terminal device), and the first message indicates the device type of the terminal device.
[0287] In a possible embodiment, the RAN may send information indicating an IoT terminal (or Internet of Things terminal) or indicating Ambient IoT to the AMF (i.e., the indication message is included in the first message); in another possible implementation, the RAN may send information indicating the access technology type of Ambient IoT to the AMF. This information can be used by the AMF to determine that the terminal is an IoT terminal (or Internet of Things terminal) and select an AUSF that supports the authentication / authorization of the terminal. Alternatively, the AMF may determine that the terminal is an IoT terminal based on the information sent by the RAN and select an AUSF that supports the authentication / authorization of the terminal.
[0288] S508, the AMF sends a first request message (such as Nnrf_NFDiscovery Request) to the NRF.
[0289] The AMF determines that the terminal device is an Ambient IoT device based on the first message and selects an AUSF that supports the authentication / authorization of the Ambient IoT device. The ways for the AMF to determine that the terminal device is an Ambient IoT device are as follows:
[0290] Way 1: According to the Ambient IoT indication information or access technology type sent by the RAN, that is, the indication information in the first message (step S507).
[0291] Way 2: Determine it as an Ambient IoT device according to the device type sent by the IoT terminal. Exemplarily, the device type can be specifically an active device or a passive device, or the device type can be device A, device B or device C. Among them, device A can represent that the terminal does not support energy storage and / or does not support active communication; device B can represent that the terminal supports energy storage and / or does not support active communication; device C can represent that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication can be understood as supporting carrier generation or supporting carrier recovery. In another possible implementation, not supporting active communication can be understood as supporting passive communication, or it can be understood as relying on an external excitation source or an external carrier source for communication. In a possible implementation, the device type information is indicated as a first type of device or a second type of device. Among them, the first type of device does not support active communication, or the first type of device needs to rely on an external carrier to perform uplink data transmission; the second type of device supports active communication, or the second type of device does not need to rely on an external carrier to perform uplink data transmission. Exemplarily, supporting active communication can be understood as supporting carrier generation or supporting carrier recovery. Exemplarily, the identification information and device type information in the first message.
[0292] Method 3: Based on the identification information (device ID) sent by the IoT terminal.
[0293] In a possible implementation, the format, structure, etc. of the device ID can be indicated as an Ambient IoT device.
[0294] In another possible implementation, the device ID includes identification information indicating the service requester (such as the group identification owner ID), and the AMF selects the AUSF based on the owner ID. The group identification indicates the service requester. The group identification can be the identification of the service requester, or the group identification can have a corresponding relationship with the identification of the service requester.
[0295] In another possible implementation, the device ID includes information indicating the device type of the IoT terminal. For example, the device ID includes a field indicating an active device or a passive device.
[0296] The first request message includes at least one of the following: group identification, indication information, and device type information. Among them, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. Among them, the group identification can indicate the service requester, or the group identification can represent that the selected AUSF needs to support the authentication and / or authorization of the IoT device corresponding to the service requester of the group identification, or the group identification can represent that the selected AUSF needs to support the authentication and / or authorization of the IoT device corresponding to the group identification; the indication information indicates that the selected AUSF needs to support the authentication and / or authorization of the IoT device; or the indication information indicates that the selected AUSF needs to support the authentication / authorization algorithm process of the IoT device. An active terminal can represent that the terminal supports active communication and / or energy storage; a passive terminal can represent that the terminal does not support active communication. Or, the device type information is indicated as device A, device B, or device C. Among them, device A can represent that the terminal does not support energy storage and / or does not support active communication; device B can represent that the terminal supports energy storage and / or does not support active communication; device C can represent that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication can be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation, not supporting active communication can be understood as supporting passive communication, or can be understood as requiring dependence on an external excitation source or an external carrier source for communication.
[0297] In one possible implementation, in the present application, the passive terminal can be interchanged with a passive device, a terminal of the first type, device A, or device B; in another possible implementation, in the present application, the active terminal can be interchanged with an active device, a terminal of the second type, or device C.
[0298] In one possible implementation, the first request message is determined according to the first message; alternatively, the AMF can determine the first request message according to the first message. Exemplarily, the first request message may include one or more of the following information: NF type information indicating an AUSF, Owner ID, information indicating Ambient IoT, device type (for example, it may specifically be an active device / passive device); so that the NRF selects an AUSF according to this information.
[0299] S509. The NRF sends the first response information to the AMF.
[0300] The first response information includes AUSF information. In one possible implementation, the AUSF supports performing authentication and / or authorization on the terminal device corresponding to the service requestor indicated by the group identifier in the first request message, or the AUSF supports performing authentication and / or authorization on the terminal device indicated as an Internet of Things device by the indication information in the first request message, or the AUSF supports performing authentication and / or authorization on the terminal device indicated as an active terminal or a passive terminal by the device type information in the first request message.
[0301] Exemplarily, it may be AUSF identification information (AUSF instance ID), FQDN, IP address, etc.
[0302] S510. The AMF sends a first authentication request message to the AUSF fed back in step S509.
[0303] The first authentication request message includes a device identifier (device ID).
[0304] In a possible embodiment, the first authentication request message may include information indicating Ambient IoT and / or device type information. The information indicating Ambient IoT may be a displayed indication information, such as AmbientIoT Indication / Indicator, or may be indicated as Ambient IoT by the message name / message type (e.g., Nausf_AmbientIoT_Authentication Request). The device type information may be the displayed device type information, such as an Internet of Things device (Ambient IoT device), an active terminal (e.g., Active device), a passive terminal (e.g., passive device). Among them, the active terminal may characterize that the terminal supports active communication and / or energy storage; the passive terminal may characterize that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Among them, device A may characterize that the terminal does not support energy storage and / or does not support active communication; device B may characterize that the terminal supports energy storage and / or does not support active communication; device C may characterize that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication may be understood as supporting generating a carrier or supporting recovering a carrier. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring dependence on an external excitation source or an external carrier source for communication.
[0305] In a possible embodiment, it may be indicated by some fields in the Device ID.
[0306] In a possible embodiment, the AMF may send the owner ID to the AUSF, or the AUSF may obtain the owner ID according to the device ID.
[0307] In another possible embodiment, the AMF may determine the device type according to the field indicating the device type in the device ID, and send the device type information to the AUSF.
[0308] S511, the AUSF sends a second request message (e.g., Nnrf_NFDiscovery Request) to the NRF.
[0309] The second request message includes at least one of the following: identification information, group identification, indication information, and device type information. Among them, the group identification is included in the identification information. The group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. Among them, the group identification can indicate the service requester, or the group identification can represent that the selected UDM needs to support authenticating and / or authorizing the Internet of Things devices of the service requester corresponding to the group identification, and also needs to support managing the subscription data of the Internet of Things devices of the service requester corresponding to the group identification. Or the group identification can represent that the selected UDM needs to support authenticating and / or authorizing the Internet of Things devices corresponding to the group identification, and also needs to support managing the subscription data of the Internet of Things devices corresponding to the group identification. The indication information indicates that the selected UDM needs to support authenticating and / or authorizing the Internet of Things devices, and / or needs to support managing the subscription data of the Internet of Things devices; or the indication information indicates that the selected UDM needs to support the authentication / authorization algorithm process of the Internet of Things devices, and / or needs to support the process of managing the subscription data of the Internet of Things devices.
[0310] An active terminal can represent that the terminal supports active communication and / or energy storage; a passive terminal can represent that the terminal does not support active communication. Or the device type information indicates device A, device B, or device C. Among them, device A can represent that the terminal does not support energy storage and / or does not support active communication; device B can represent that the terminal supports energy storage and / or does not support active communication; device C can represent that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication can be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation, not supporting active communication can be understood as supporting passive communication, or can be understood as needing to rely on an external excitation source or an external carrier source for communication.
[0311] Exemplarily, the second request message may include one or more of the following information: NFtype information indicating UDM, Owner ID, information indicating Ambient IoT, device type (for example, it can be specifically activedevice / passive device), so that the NRF selects the UDM according to this information.
[0312] The AUSF determines that it is an Ambient IoT device and selects a UDM that supports authenticating / authorizing Ambient IoT devices. The ways for the AUSF to determine that it is an Ambient IoT device are:
[0313] Method 1: Determine it as an IoT device according to the Ambient IoT indication information sent by the AMF, or the access type or device type information of the access technology (step S510). Among them, the device type can specifically be an active device (such as an active device) or a passive device (such as a passive device).
[0314] Method 2: According to the device ID sent by the IoT terminal.
[0315] In a possible implementation, the format, structure, etc. of the device ID can be indicated as an Ambient IoT device.
[0316] In another possible implementation, the device ID includes identification information indicating the service requester (such as the owner ID), and the AUSF selects the UDM according to the owner ID.
[0317] In another possible implementation, the device ID includes information indicating the device type of the IoT terminal. For example, the device ID includes a field indicating an active device or a passive device.
[0318] The AUSF can obtain one or more of the following information according to the above several implementation methods: Ambient IoT access technology type / device, device type of active / passive device, Owner ID, etc.
[0319] S512, the NRF sends a second response message to the AUSF.
[0320] The second response message includes UDM information. In a possible implementation, the UDM supports performing authentication and / or authorization on the terminal device corresponding to the service requester indicated by the group ID in the second request message, or the UDM supports performing authentication and / or authorization on the terminal device indicated as an IoT device by the indication information in the second request message, or the UDM supports performing authentication and / or authorization on the terminal device whose device type information in the second request message indicates an active terminal or a passive terminal. In another possible implementation, the UDM supports managing the subscription data of the terminal device corresponding to the service requester indicated by the group ID in the second request message, or the UDM supports managing the subscription data of the terminal device indicated as an IoT device by the indication information in the second request message, or the UDM supports managing the subscription data of the terminal device whose device type information in the second request message indicates an active terminal or a passive terminal.
[0321] Exemplarily, UDM identification information (UDM instance ID), FQDN, IP address, etc.;
[0322] S513, the AUSF sends a second authentication request message (such as Nudm_UEAuthentication_Get Request) to the UDM determined in step S512.
[0323] The second authentication request message is used to determine the authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0324] The second authentication message may include device identification (Device ID), Owner ID, Ambient IoT indication information, device type, etc.
[0325] S514, the UDM may obtain the subscribed data according to the device identification and determine the authentication method according to the subscribed data.
[0326] In a possible implementation, the subscribed data stored by the UDM is not at the device granularity, that is, it may be at the service requestor granularity (that is, obtain the subscribed data according to the owner ID), or at the service type (or access technology type) granularity, that is, obtain the subscribed data according to the indication information of Ambient IoT; or at the device type granularity, that is, obtain the subscribed data according to the active / passive device.
[0327] The subscribed data may also be at the granularity of a combination of the above several types of information. For example, it is at the granularity of the service requestor and the device type to obtain the subscribed data. For example, under the same service requestor, the authentication methods or key information corresponding to different device types are different, and the authentication methods, keys, etc. of terminals of the same device type are the same. Exemplarily, the subscribed data may be context (mutually replaceable).
[0328] S515, execute the security authentication process between the network and the IoT terminal.
[0329] In a possible implementation, the authentication process may be executed between the terminal device, AMF, AUSF, and UDM.
[0330] S516, the AMF sends a request message to the NRF.
[0331] After the IoT terminal authentication is successful, the AMF needs to register itself with the UDM as the AMF serving the IoT terminal.
[0332] The AMF discovers the UDM through the NRF; the discovery method is as in step S511, except that the network function sending the request is the AMF, and the device ID can be the decrypted Device ID, which will not be elaborated here.
[0333] S517, the NRF sends UDM information supporting this capability to the AMF, such as UDM identification information (UDM instance ID), FQDN, IP address, etc.
[0334] S518, the AMF registers itself with the UDM as the AMF serving this IoT terminal.
[0335] The AMF provides the UDM with a globally unique AMF identifier (GUAMI).
[0336] In a possible embodiment, the AMF can send AUSF information to the UDM so that the UDM stores the AUSF information supporting the execution of the security process of this IoT terminal. Thus, in the subsequent case of mobility, the new AMF can obtain the AUSF information supporting the execution of this security process through the information stored by the UDM.
[0337] S519, the AMF sends a registration acceptance message to the IoT terminal.
[0338] This message can include a temporary identifier (5G globally unique temporary identity, 5G-GUTI) assigned by the AMF.
[0339] In a possible embodiment, method 500 may further include:
[0340] S520, the AMF can store the selected AUSF and UDM information in the context so that when a new AMF serves the IoT terminal later, the information can be sent to the target AMF through the context migration or context transmission process, enabling the target AMF to select the AUSF and UDM based on this information without having to re-execute the above NRF discovery process, saving signaling overhead.
[0341] In the execution of network element selection and network element configuration information in method 500, capability information, service requestor information, or device type information corresponding to the IoT device is added, etc., so that the selected network element is for indicating the security process of this terminal.
[0342] According to the solution of the present application, the core network device can select network elements such as AUSF and UDM according to the NRF discovery mechanism, so that the selected AUSF and UDM support the execution of the security process for the IoT terminal, avoiding the situation where the selected AUSF or UDM does not support the security process of the terminal, resulting in authentication failure and inability to access the network.
[0343] Figure 9 This is a communication method 600 provided by the present application. The method may include the following steps:
[0344] S6001, the AMF obtains third configuration information, where the third configuration information includes the correspondence between authentication service device information and at least one of the following: a first support group identifier, a first support information, and a first support type information. The first support group identifier indicates a first service requester, and the first support group identifier may also be expressed as a first group identifier. The first group identifier indicates the supported service requester. Alternatively, the first group identifier may represent that the AUSF supports the execution of authentication and / or authorization for the IoT device corresponding to the first group identifier. Alternatively, the first group identifier may represent that the AUSF supports the execution of authentication and / or authorization for the IoT device corresponding to the first group identifier. The first support information indicates whether it supports the authentication and / or authorization of the IoT device, or the first support information indicates the support for the authentication and / or authorization of the IoT device. The first support type information may also be expressed as a first type information, and the first type information is used to indicate the device type that supports the execution of authentication and / or authorization. Alternatively, the first type information may represent that the AUSF supports the execution of authentication and / or authorization for the device type indicated by the first type information.
[0345] Exemplarily, the AMF is configured with the correspondence between one or more of the following information and the AUSF information: (1) information indicating the service requester (such as owner ID); (2) support for Ambient IoT device authentication; (3) supported device types, such as active / passive devices. The AUSF information may include an AUSF identifier (such as AUSF instanceID), an FQDN, or an IP address.
[0346] In a possible embodiment, the AMF is further configured with the correspondence between one or more of the following information and the UDM information: (1) information indicating the service requester (such as owner ID); (2) support for Ambient IoT device authentication; (3) supported device types, such as active / passive devices. The UDM information may include a UDM identifier (such as UDM instance ID), an FQDN, or an IP address.
[0347] The AUSF obtains the fifth configuration information, where the fifth configuration information includes the correspondence between the unified data management device information and at least one of the following: the second support group identifier, the second support information, and the second support type information. The second support group identifier indicates the second service requester, and the second support group identifier may also be expressed as the second group identifier. The second group identifier indicates the service requester supported by the UDM. Alternatively, the second group identifier may represent that the UDM supports managing the subscription data of the Internet of Things devices of the service requester corresponding to the second group identifier. Alternatively, the second group identifier may represent that the UDM supports the subscription data of the Internet of Things devices corresponding to the second group identifier. The second support information indicates whether the UDM supports the authentication and / or authorization of Internet of Things devices. The second support type information may also be expressed as the second type information. The second type information is used to indicate the device type that supports authentication and / or authorization. Alternatively, the first type information may represent that the AUSF supports performing authentication and / or authorization on the device type indicated by the second type information.
[0348] Exemplarily, the AUSF may be configured with the correspondence between one or more of the following information and the UDM information: (1) information indicating the service requester (such as the owner ID); (2) supporting the authentication of Ambient IoT devices; (3) the supported device types, such as active / passive devices. The UDM information may include the UDM identifier (such as the UDM instance ID), FQDN, or IP address.
[0349] The UDM obtains the fourth configuration information, where the fourth configuration information includes the correspondence between the authentication service device information and at least one of the following: the first support group identifier, the first support information, and the first support type information. The first support group identifier indicates the first service requester, and the first support group identifier may also be expressed as the first group identifier. The first group identifier indicates the supported service requester. Alternatively, the first group identifier may represent that the AUSF supports performing authentication and / or authorization on the Internet of Things devices of the service requester corresponding to the first group identifier. Alternatively, the first group identifier may represent that the AUSF supports performing authentication and / or authorization on the Internet of Things devices corresponding to the first group identifier. The first support information indicates whether it supports the authentication and / or authorization of Internet of Things devices. Alternatively, the first support information indicates supporting the authentication and / or authorization of Internet of Things devices. The first support type information may also be expressed as the first type information. The first type information is used to indicate the device type that supports authentication and / or authorization. Alternatively, the first type information may represent that the AUSF supports performing authentication and / or authorization on the device type indicated by the first type information.
[0350] Exemplarily, the UDM may be configured with the correspondence relationship between one or more of the following information and the AUSF information or the UDM information: (1) information indicating the service requester (e.g., owner ID); (2) support for Ambient IoT device authentication; (3) supported device types, such as active / passive devices.
[0351] In a possible implementation manner, the correspondence relationship configured by the UDM is at a non-terminal device granularity. It can be used for the subsequent AMF to obtain information such as AUSF information when requesting subscription data or configuration information from the UDM (see the description in step 604).
[0352] S601, after the terminal device successfully initiates random access, it sends a registration request message to the RAN.
[0353] S602, the RAN determines that the device sending the message is an IoT terminal and selects a suitable AMF.
[0354] S603, the RAN sends the registration request message from the IoT terminal to the AMF.
[0355] The above steps can refer to the description of S505 - S507 in method 500 and will not be elaborated here.
[0356] S604, the AMF determines that it is an Ambient IoT device and selects an AUSF that supports Ambient IoT device authentication / authorization.
[0357] The manner in which the AMF determines that it is an Ambient IoT device can refer to the description in S508.
[0358] In a possible implementation manner, the AMF selects the AUSF according to the third configuration information (as described in step S6001).
[0359] Exemplarily, the AMF selects the AUSF according to the information indicating the service requester (e.g., owner ID) in the identification information of the terminal device (e.g., device ID) and the correspondence relationship in the third configuration information; or selects the AUSF according to information such as the device type, Ambient IoT access technology type, etc. and the correspondence relationship. The AUSF supports performing authentication and / or authorization on the terminal device corresponding to the service requester indicated by the group identification, or the AUSF supports performing authentication and / or authorization on the terminal device indicated by the indication information as an IoT device, or the AUSF supports performing authentication and / or authorization on the terminal device whose device type information indicates an active terminal or a passive terminal.
[0360] In another possible implementation, the AMF obtains a suitable AUSF from the UDM by interacting with the UDM. The AMF sends a third request message to the UDM. The third request message is used to select an authentication service device. The third request message includes at least one of the following: identification information, group identification, indication information, and device type information. Among them, the group identification is included in the identification information. The group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. Among them, the group identification can indicate the service requester, or the group identification can represent that the selected AUSF needs to support authenticating and / or authorizing the Internet of Things devices of the service requester corresponding to the group identification, or the group identification can represent that the selected AUSF needs to support authenticating and / or authorizing the Internet of Things devices corresponding to the group identification; the indication information indicates that the selected AUSF needs to support authenticating and / or authorizing Internet of Things devices; or, the indication information indicates that the selected AUSF needs to support the authentication / authorization algorithm process of Internet of Things devices. An active terminal can represent that the terminal supports active communication and / or energy storage; a passive terminal can represent that the terminal does not support active communication. Or, the device type information indicates device A, device B, or device C. Among them, device A can represent that the terminal does not support energy storage and / or does not support active communication; device B can represent that the terminal supports energy storage and / or does not support active communication; device C can represent that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication can be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation, not supporting active communication can be understood as supporting passive communication, or can be understood as needing to rely on an external excitation source or an external carrier source for communication.
[0361] Exemplarily, the AMF sends a request message to the UDM, which includes one or more of Device ID (or information indicating the service requester, such as owner ID), Ambient IoT indication information, and device type (such as it can be specifically an active device / passive device). The UDM selects a suitable AUSF according to the fourth configuration information (such as exemplified in step S6001) and the request message sent by the AMF, and sends the AUSF information (such as AUSF identification, FQDN, IP address, etc.) to the AMF.
[0362] S605, the AMF sends a first authentication request message (such as Nausf_UEAuthentication_Authentication Request) to the selected AUSF.
[0363] The first authentication request message includes a device identifier (device ID).
[0364] In a possible embodiment, the first authentication request message may include information indicating Ambient IoT and / or device type information. The information indicating Ambient IoT may be a displayed indication information, such as AmbientIoT Indication / Indicator, or may be indicated as Ambient IoT by the message name / message type (e.g., Nausf_AmbientIoT_Authentication Request). The device type information may be the displayed device type information, such as an Internet of Things device (Ambient IoT device), an active terminal (e.g., Active device), a passive terminal (e.g., passive device). Among them, the active terminal may characterize that the terminal supports active communication and / or energy storage; the passive terminal may characterize that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Among them, device A may characterize that the terminal does not support energy storage and / or does not support active communication; device B may characterize that the terminal supports energy storage and / or does not support active communication; device C may characterize that the terminal supports energy storage and / or active communication. In a possible implementation manner, supporting active communication may be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation manner, not supporting active communication may be understood as supporting passive communication, or may be understood as requiring dependence on an external excitation source or an external carrier source for communication.
[0365] In a possible embodiment, the AMF may send the owner ID to the AUSF, or the AUSF may obtain the owner ID according to the device ID.
[0366] In another possible implementation manner, the AMF may determine the device type according to the field indicating the device type in the device ID and send the device type information to the AUSF.
[0367] S606. The AUSF determines that it is an Ambient IoT device and selects a UDM that supports the authentication / authorization of Ambient IoT devices or a UDM that supports managing the subscription data of Internet of Things devices.
[0368] The manner in which the AUSF determines that it is an Ambient IoT device may refer to the description in S511 and will not be elaborated here.
[0369] The AUSF can obtain one or more of the following information in the above - mentioned several ways: the Ambient IoT access technology type / device, the device type of active / passive device, the Owner ID, etc. The AUSF selects the UDM according to the fifth configuration information; for example, the AUSF selects the UDM according to the information indicating the service requester in the device ID (such as the owner ID) and the corresponding relationship in the fifth configuration information; or selects the UDM according to information such as the device type, the Ambient IoT access technology type, etc. and the corresponding relationship.
[0370] S607, the AUSF sends a second authentication request message (such as Nudm_UEAuthentication_Get Request) to the UDM determined in step S606.
[0371] The second authentication message may include at least one of the following: device identifier (Device ID), Owner ID, Ambient IoT indication information, device type, etc.
[0372] S608, the UDM can obtain the subscription data according to the device identifier and determine the authentication method according to the subscription data.
[0373] In another possible implementation, the subscription data stored in the UDM is not at the device granularity, that is, it may be at the service requester granularity (that is, obtain the subscription data according to the owner ID), or at the service type (or access technology type) granularity, that is, obtain the subscription data according to the indication information of Ambient IoT; or at the device type granularity, that is, obtain the subscription data according to active / passive device; the subscription data can also be at the granularity of a combination of the above - mentioned several kinds of information, for example, at the granularity of the service requester and the device type to obtain the subscription data, for example, under the same service requester, the authentication methods or key information corresponding to different device types are different, and the authentication methods, keys, etc. of terminals of the same device type are the same. Exemplarily, the subscription data can be context (mutually replaceable).
[0374] S609, execute the security authentication process between the network and the IoT terminal.
[0375] In one possible implementation, the authentication process can be executed among the Ambient IoT device, AMF, AUSF, and UDM.
[0376] S610, the AMF discovers the UDM according to the third configuration information.
[0377] After the authentication of the IoT terminal is successful, the AMF needs to register itself with the UDM as the AMF serving the IoT terminal; the discovery method is as in step S604.
[0378] S611. The AMF registers itself with the UDM as the AMF serving the IoT terminal.
[0379] The AMF provides the GUAMI to the UDM. Optionally, the AUSF information can be provided to enable the UDM to store the AUSF information supporting the execution of the IoT terminal security process, so that in the subsequent mobility scenario, the new AMF can obtain the AUSF information supporting the execution of the security process through the information stored by the UDM.
[0380] S612. The AMF sends a registration acceptance message to the IoT terminal.
[0381] The message may include a temporary identifier (5G globally unique temporary identity, 5G-GUTI) assigned by the AMF.
[0382] In a possible embodiment, method 600 may further include:
[0383] S613. The AMF may store the selected AUSF and UDM information in the context, so that when a new AMF serves the IoT terminal later, the information can be sent to the target AMF through the context migration or context transmission process, enabling the target AMF to select the AUSF and UDM based on this information without having to re-execute the above NRF discovery process, saving signaling overhead.
[0384] According to the solution of the present application, the AMF, AUSF, and UDM are respectively configured with information for selecting network elements, enabling the network element to select other core network devices supporting the Ambient IoT terminal security process, so that the network elements do not need to dynamically execute requests through the NRF, reducing signaling overhead.
[0385] Figure 10 This is a communication method 700 provided by the present application. The method may include the following steps:
[0386] S7001, the AUSF obtains the sixth configuration information, where the sixth configuration information includes at least one of the following: a third support group identifier, third support information, and third support type information. Among them, the third support group identifier indicates the third service requester, and the third support group identifier may also be expressed as the third group identifier. The third group identifier indicates the supported service requester. Alternatively, the third group identifier may represent that the NSSAAF supports performing authentication and / or authorization on the Internet of Things devices of the service requester corresponding to the third group identifier. Alternatively, the third group identifier may represent that the NSSAAF supports performing authentication and / or authorization on the Internet of Things devices corresponding to the third group identifier. The third support information refers to whether the NSSAAF supports the authentication and / or authorization of Internet of Things devices. The third support type information may also be expressed as the third type information. The third type information is used to indicate the device type for which authentication and / or authorization is supported. Alternatively, the third type information may represent that the NSSAAF supports performing authentication and / or authorization on the device type indicated by the third type information.
[0387] Exemplarily, the AUSF is configured with the corresponding relationships of two or more of the following pieces of information: (1) information indicating the service requester (such as owner ID); (2) AAA server information (such as domain name or address); (3) NSSAAF information (such as identifier, FQDN, or IP address). Among them, the AAA server information may include the AAA server identifier, FQDN, or IP address; the NSSAAF information may include the NSSAAF identifier, FQDN, or IP address. Among them, the NSSAAF may be the NSSAAF that supports interacting with the AAA server or the NSSAAF that supports interacting with the specific AAA server.
[0388] The UDM is configured with the corresponding relationships of two or more of the following pieces of information: (1) information indicating the service requester (such as owner ID); (2) AAA server information (such as domain name or address); (3) NSSAAF information (such as identifier, FQDN, or IP address). Among them, the AAA server information may include the AAA server identifier, FQDN, or IP address; the NSSAAF information may include the NSSAAF identifier, FQDN, or IP address. Among them, the NSSAAF may be the NSSAAF that supports interacting with the AAA server or the NSSAAF that supports interacting with the specific AAA server.
[0389] The NSSAAF can be configured with the corresponding relationships of two or more of the following information: (1) information indicating the service requester (e.g., owner ID); (2) AAA server information (e.g., domain name or address); (3) NSSAAF information (e.g., identifier, FQDN, or IP address). Among them, the AAA server information can include the AAA server identifier, FQDN, or IP address.
[0390] S702, the NSSAAF sends the sixth configuration information (e.g., Nnrf_NFManagement_NFRegisterRequest or Nnrf_NFManagement_NFUpdate Request) to the NRF.
[0391] The sixth configuration information can include one or more of the following information: network function type (networkfunction type, NF type), identification information (e.g., NF instance ID), FQDN, IP address, network identification (e.g., PLMN ID or PLMN ID + NID). Among them, the network function type can be indicated as the authentication and authorization function for a specific network slice (e.g., NSSAAF); the identification information can be the identifier of the NSSAAF, the FQDN is the FQDN of the NSSAAF, and the IP address is the IP address of the NSSAAF; the network identification can be used to indicate the network where the NSSAAF is located or the network to which it belongs / serves.
[0392] In a possible implementation, the sixth configuration information can include information indicating support for Ambient IoT, one or more supported Owner IDs, supported device types (e.g., passive device and / or activedevice), and AAA server information.
[0393] The information indicating support for Ambient IoT can be used to indicate support for the authentication or authorization of Ambient IoT terminals, or can be used to indicate the authentication / authorization algorithm or process for Ambient IoT terminals.
[0394] One or more supported Owner IDs represent support for executing the authentication / authorization process of one or more terminals (IoT terminals) corresponding to the one or more Owner IDs; among them, the owner ID can be replaced with: identification information indicating the service requester.
[0395] The AAA server information includes the AAA server identifier, domain name (e.g., FQDN), or IP address.
[0396] In S703, the NRF sends result indication information (such as Nnrf_NFManagement_NFRegisterResponse or Nnrf_NFManagement_NFUpdate Response) to the NSSAAF.
[0397] Exemplarily, when the NRF successfully obtains the information, it can send result indication information indicating success to the NSSAAF.
[0398] In S704, after the terminal device successfully initiates random access, it sends a registration request message to the RAN.
[0399] In S705, the RAN determines that the device sending the message is an IoT terminal and selects a suitable AMF.
[0400] In S706, the RAN sends the registration request message from the IoT terminal to the AMF.
[0401] In S707, the AMF determines that it is an Ambient IoT device and selects an AUSF that supports Ambient IoT device authentication / authorization.
[0402] In S708, the AMF sends a first authentication request message to the selected AUSF.
[0403] In S709, the AUSF determines that it is an Ambient IoT device and selects a UDM that supports Ambient IoT device authentication / authorization.
[0404] In S710, the AUSF sends a second authentication request message to the UDM determined in step S709.
[0405] In S711, the UDM can obtain the subscribed data according to the device identifier and determine the authentication method according to the subscribed data.
[0406] The above steps can refer to steps S601 - 608 in method 600 and will not be elaborated here.
[0407] In S712, the UDM sends a second authentication response message (such as Nudm_UEAuthentication_GetResponse) to the AUSF.
[0408] The second authentication response message may include the device identifier (such as the decrypted identifier), indication information for authentication performed by the AAA server; optionally, it may include NSSAAF information (such as which NSSAAFs can interact with this AAA server) and AAA server information.
[0409] S713. The AUSF discovers the NSSAAF through the NRF, and the AUSF sends a fifth request message (such as Nnrf_NFDiscovery Request) to the NRF.
[0410] In a possible implementation, if the response message sent by the UDM in step S712 does not include the NSSAAF information, the AUSF discovers the NSSAAF through the NRF. The authentication service device sends a fifth request message to the network storage device. The fifth request message is used to request the discovery of the NSSAAF. The fifth request message is determined according to the first authentication request message. The fifth request message includes at least one of the following: group identifier, indication information, and device type information. Among them, the group identifier is included in the identification information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. Among them, the group identifier can indicate the service requester, or the group identifier can represent that the selected NSSAAF needs to support the authentication and / or authorization of the Internet of Things devices of the service requester corresponding to the group identifier, or the group identifier can represent that the selected AUSF needs to support the authentication and / or authorization of the Internet of Things devices corresponding to the group identifier; the indication information indicates that the selected NSSAAF needs to support the authentication and / or authorization of the Internet of Things devices; or, the indication information indicates that the selected NSSAAF needs to support the authentication / authorization algorithm process of the Internet of Things devices. An active terminal can represent that the terminal supports active communication and / or energy storage; a passive terminal can represent that the terminal does not support active communication. Alternatively, the device type information indicates device A, device B, or device C. Among them, device A can represent that the terminal does not support energy storage and / or does not support active communication; device B can represent that the terminal supports energy storage and / or does not support active communication; device C can represent that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication can be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation, not supporting active communication can be understood as supporting passive communication, or can be understood as requiring dependence on an external excitation source or an external carrier source for communication.
[0411] Exemplarily, the AUSF sends a fifth request message to the NRF. The fifth request message may include one or more of the following information: NF type information indicating NSSAAF, Owner ID, information indicating Ambient IoT, device type (such as specifically active device / passive device); so that the NRF selects the NSSAAF according to this information.
[0412] S714, the NRF sends the fifth response message to the AUSF.
[0413] The fifth response message includes at least one of the following: NSSAAF information, AAA server information, etc.; where the NSSAAF information may include an NSSAAF identifier (such as an NSSAAF Instance ID), FQDN, IP address; the AAA server information may include an AAA server identifier, FQDN, IP address, etc. In a possible implementation, the NSSAAF supports performing authentication and / or authorization on the terminal device corresponding to the service requester indicated by the group identifier in the fifth request message, or the NSSAAF supports performing authentication and / or authorization on the terminal device indicated as an Internet of Things device by the indication information in the fifth request message, or the NSSAAF supports performing authentication and / or authorization on the terminal device indicated as an active terminal or a passive terminal by the device type information in the fifth request message.
[0414] In another possible implementation, if the response message sent by the UDM in step S712 includes NSSAAF information, the AUSF can interact with the NSSAAF based on this information (i.e., steps S713 and S714 may not be executed).
[0415] S715, the AUSF sends a third authentication request message (such as NSSAAF_AIWF_AuthenticationRequest) to the NSSAAF.
[0416] In a possible embodiment, the third authentication request message may include a device identifier (such as a decrypted device ID), Ambient IoT indication information, device type (such as passive / active device); optionally, it may include AAA server information.
[0417] In a possible embodiment, the AAA server address may be from the second authentication response message sent by the UDM in step S712; it may also be configured in the AUSF, i.e., the information configured in step S7001; the AUSF determines the corresponding AAA server address based on the NSSAAF information or the owner ID information.
[0418] In another possible embodiment, it may be from the fifth response message sent by the NRF; the AUSF sends the AAA server information to the NSSAAF.
[0419] S716, the NSSAAF determines the AAA server address.
[0420] In a possible implementation, if the AUSF does not send the AAA server information to the NSSAAF, the NSSAAF can determine the AAA server according to the sixth configuration information.
[0421] In another possible implementation, if the AUSF sends the AAA server information to the NSSAAF in step S715, the NSSAAF can determine the AAA server information according to the information from the AUSF.
[0422] S717, execute the security authentication process between the network and the IoT terminal.
[0423] In a possible implementation, the authentication process can be executed among the Ambient IoT device, AMF, AUSF, NSSAAF, and AAA server.
[0424] S718, after the IoT terminal is authenticated successfully, the AMF needs to register itself with the UDM as the AMF serving the IoT terminal.
[0425] The AMF discovers the UDM according to the configuration information; the discovery method can be through local configuration (such as step S606 in method 600) or through NRF discovery (such as steps S516 and S517 in method 500).
[0426] S719, the AMF registers itself with the UDM as the AMF serving the IoT terminal.
[0427] The AMF provides the GUAMI to the UDM. Optionally, it can provide the AUSF information so that the UDM stores the AUSF information supporting the execution of the IoT terminal security process. Thus, in subsequent mobility situations, the new AMF can obtain the AUSF information supporting the execution of this security process through the information stored by the UDM.
[0428] S720, the AMF sends a registration acceptance message to the IoT terminal.
[0429] The message can include a temporary identifier assigned by the AMF (such as 5G globally unique temporary identity, 5G-GUTI); optionally, the AMF can store the selected AUSF and UDM information in the context so that when a new AMF serves the IoT terminal later, it can send this information to the target AMF through the context migration or context transmission process, enabling the target AMF to select the AUSF and UDM according to this information without having to re-execute the above NRF discovery process, saving signaling overhead.
[0430] When the IoT terminal cannot adopt the identification format of username@realm, it can obtain the address of the AAA server according to the configuration information or through the NRF, so as to complete the security process of the terminal.
[0431] According to the solution of the present application, the AAA server information can be configured on network elements such as AUSF, UDM, NSSAAF, and NRF, so that when the IoT terminal adopts a new ID identification, it can interact with the AAA server to complete the security process of the IoT terminal.
[0432] Figure 11 This is a communication method 800 provided by the present application. The method may include the following steps:
[0433] S801, the AUSF may send the first configuration information to the NRF according to steps S501 and S502 in method 500.
[0434] S802, the UDM may send the second configuration information to the NRF according to steps S503 and S504 in method 500.
[0435] S803, the NSSAAF may send the sixth configuration information to the NRF according to steps S702 and S703 of method 700.
[0436] S804, the NEF performs configuration.
[0437] In a possible embodiment, the NEF may be configured with the correspondence between two or more of the following information: (1) AF information (which can be understood as the service requester); (2) Device ID; (3) Owner ID (or information indicating the service requester); (4) AMF information; (5) AUSF information; (6) UDM information; (7) NSSAAF information; (8) AAA server information.
[0438] Among them, the AF information may include an AF identifier, an AF domain name (such as the FQDN of the AF), and AF address information (such as an IP address); the AMF information may include an AMF identifier, an AMF domain name (such as the FQDN of the AMF), and AMF address information (such as an IP address); the AUSF information may include an AUSF identifier, an AUSF domain name (such as the FQDN of the AUSF), and AUSF address information (such as an IP address); the UDM information may include a UDM identifier, a UDM domain name (such as the FQDN of the UDM), and UDM address information (such as an IP address); the NSSAAF information may include an NSSAAF identifier, an NSSAAF domain name (such as the FQDN of the NSSAAF), and NSSAAF address information (such as an IP address); the AAA server information may include a AAA server identifier, a AAA server domain name (such as the FQDN of the AAA server), and AAA server address information (such as an IP address).
[0439] S805, the service requester (such as the AF) sends a service request message (such as Nnef_AmbientIoT_Service Request) to the NEF.
[0440] The service request message may include AF information (such as an AF identifier, an AF address, or an AF FQDN), a service type (such as inventory, read, write, inactivation, or positioning, etc.), location information (which can be used to determine that a reader (such as the RAN) performs a service operation), a Device ID (range) (an optional parameter, if not carried, it may represent that for a specific range, service operations are performed on all IoT terminals belonging to the service requester), and AAA server information (an optional parameter, which can be carried when the AAA server performs a security process).
[0441] S806, the NEF performs network function (NF) selection according to the service request sent by the AF.
[0442] In a possible implementation, the NEF performs one or more NF selections. Exemplarily, the NEF may select the AUSF and UDM corresponding to the AF (service requester) according to the information configured in step S804; if the AAA server needs to perform a security process, the NEF may select the NSSAAF and / or the AAA server. If the NEF does not configure the configuration information in step S804, the NEF may discover the NF through the NRF in the following steps S807 and S808.
[0443] S807, the NEF sends a request message to the NRF.
[0444] The request message is used to request to discover at least one network function corresponding to the service requester, and the network function is used to perform service operations on at least one terminal device.
[0445] The request message may include the types of one or more NFs to be discovered, such as one or more of NSSAAF, AUSF, and UDM; the request message may include the Device ID (range), Ambient IoT indication information, device type (such as passive / active device); so that the NRF sends the NF corresponding to the service request to the NEF. Among them, the type of NF may indicate the type of network element that needs to perform service operations on the terminal device; the Device ID indicates the terminal device that performs service operations; the Ambient IoT indication information indicates that the selected NF needs to support the authentication and / or authorization of IoT devices; or, the indication information indicates that the selected NF needs to support the authentication / authorization algorithm process of IoT devices. An active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Among them, device A may indicate that the terminal does not support energy storage and / or does not support active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; device C may indicate that the terminal supports energy storage and / or active communication. In one possible implementation, supporting active communication may be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or may be understood as needing to rely on an external excitation source or an external carrier source for communication.
[0446] In another possible implementation, when the NEF needs to discover multiple NFs, the NEF may separately execute step S807 and step S808 multiple times to discover different types of NFs respectively.
[0447] S808, the NRF sends the corresponding NF information to the NEF according to the request message.
[0448] The NF information may include the identifier, FQDN, or IP address of the NF.
[0449] In a possible implementation, the NF message may include a network function type (NF type), identification information (such as an NF instance ID), the fully qualified domain name (FQDN) of the network function, an IP address, and a network identifier (such as a PLMN ID or a PLMN ID + NID). Exemplarily, the network function type may be indicated as an authentication service function (such as an AUSF); the identification information may be the identifier of the authentication service function, the FQDN may be the FQDN of the authentication service function, and the IP address may be the IP address of the authentication service function; the network identifier may be used to indicate the network where the authentication service function is located or the network to which it belongs / serves. Again exemplarily, the network function type may be indicated as a unified data management function (such as a UDM); the identification information may be the identifier of the unified data management function, the FQDN may be the FQDN of the unified data management function, and the IP address may be the IP address of the unified data management function; the network identifier may be used to indicate the network where the unified data management function is located or the network to which it belongs / serves. Again exemplarily, the network function type may be indicated as an authentication and authorization function for a specific network slice (such as an NSSAAF); the identification information may be the identifier of the NSSAAF, the FQDN may be the FQDN of the NSSAAF, and the IP address may be the IP address of the NSSAAF; the network identifier may be used to indicate the network where the NSSAAF is located or the network to which it belongs / serves.
[0450] S809. The NEF sends a sixth request message to the AMF.
[0451] The sixth request message includes network function information, and the network function information includes the identification information and / or address information of at least one of the following network functions: an authentication service device, a unified data management device, an authentication and authorization function for a specific network slice NSSAAF, and an AAA server.
[0452] In a possible implementation, the NEF determines the corresponding AMF according to the location information; the service request message sent to the AMF may include AF information, a service type, and location information; optionally, it may include the NF information discovered by the NEF in steps S806 - S808, such as one or more of AUSF information, UDM information, NSSAAF information, and AAA server information, so that the AMF does not need to perform NF selection after the subsequent IoT terminal accesses, but is pre - selected by the NEF.
[0453] In a possible implementation, if the function that supports the execution environment for Internet of Things (IoT) service transmission is used to perform service processing (such as processing service request messages / information from a service requester, performing processes related to the IoT service in the execution environment, performing functions such as access management, security authentication, data transmission, instruction transmission, or IoT terminal management for IoT terminals), the NEF can select this network function, and this network function sends a request message to the AMF. In a possible implementation, this function can interface with the access network device, which is equivalent to the access network device having an interface with this function, or it can interact with the RAN through the AMF. From a deployment perspective, this function can be co-deployed with the AMF. If this function can directly interface with the RAN, step 810 can be replaced by this function sending information indicating to trigger the random access of IoT terminals to the reader (RAN).
[0454] S810, the AMF sends information indicating to trigger the random access of IoT terminals to the reader (RAN).
[0455] For example, send random access indication information to the RAN through an N2 message to trigger the RAN to initiate the random access process for IoT terminals; optionally, it can include information indicating the scope of IoT terminals participating in the random access, such as a MASK. The MASK indicates the identification range of IoT terminals that need to participate in the random access process (which can be understood as the prefix of the identification, and terminals that match this identification prefix need to participate in the random access process).
[0456] S811, the IoT terminal initiates the random access process;
[0457] S812, when the IoT terminal successfully initiates random access, it sends a registration request message to the RAN.
[0458] In a possible implementation, the IoT terminal sends an AS message (access stratum message) to the reader / writer, and this AS message includes this registration request message, that is, this registration request message is a NAS message.
[0459] In a possible implementation, the registration request message can include a device identifier (such as a device ID) and device type information, such as device type information indicating an active device or a passive device. The RAN sends the registration request message from the IoT terminal to the AMF.
[0460] S813, the AMF sends a first authentication request message (such as Nausf_UEAuthentication_Authentication Request) to the selected AUSF.
[0461] The AMF selects an AUSF that supports the authentication / authorization of Ambient IoT devices.
[0462] In a possible implementation, if the AMF receives AUSF information from the NEF in step S809, the AMF selects the AUSF based on this information.
[0463] The first authentication request message includes a device identifier (device ID); optionally, it may include information indicating Ambient IoT and / or device type information; the information indicating Ambient IoT may be an explicit indication information, such as Ambient IoT Indication / Indicator, or it may be indicated as Ambient IoT through the message name / message type (e.g., Nausf_AmbientIoT_Authentication Request). The device type information may be explicit device type information, such as an Internet of Things device (Ambient IoT device), an active terminal (e.g., Active device), a passive terminal (e.g., passive device). Among them, an active terminal may indicate that the terminal supports active communication and / or energy storage; a passive terminal may indicate that the terminal does not support active communication. Alternatively, the device type information is indicated as device A, device B, or device C. Among them, device A may indicate that the terminal does not support energy storage and / or does not support active communication; device B may indicate that the terminal supports energy storage and / or does not support active communication; device C may indicate that the terminal supports energy storage and / or active communication. In a possible implementation, supporting active communication may be understood as supporting generating a carrier or supporting restoring a carrier. In another possible implementation, not supporting active communication may be understood as supporting passive communication, or it may be understood as requiring dependence on an external excitation source or an external carrier source for communication.
[0464] In another possible implementation, the AMF may determine the device type based on the field in the device ID that indicates the device type, and send the device type information to the AUSF. In another possible implementation, if the AMF receives one or more of the UDM, NSSAFF, and AAA server information from the NEF in step S809, the AMF may send one or more of the UDM, NSSAFF, and AAA server information to the AUSF.
[0465] S814, the AUSF sends a second authentication request message.
[0466] In a possible implementation, if in step S813, the AUSF does not receive the NSSAAF information (for example, the security process is executed by the AUSF / UDM), then when the AUSF determines to be an Ambient IoT device, it selects a UDM that supports the authentication / authorization of Ambient IoT devices.
[0467] In a possible embodiment, the AUSF can discover the UDM through the NRF (for example, steps S511 and S512 of method 500), or the AUSF selects the UDM according to the configuration information (as described in step S6001 of method 600); for example, the AUSF selects the UDM according to the information indicating the service requester in the device ID (such as the owner ID) and the corresponding relationship in the configuration information; or selects the UDM according to information such as the device type and the Ambient IoT access technology type and the corresponding relationship.
[0468] When the AUSF sends a second authentication request message to the UDM, it can include one or more of the information such as the Device ID, Ambient IoT indication information, and device type.
[0469] In another possible implementation, if the AUSF receives the NSSAAF information from the AMF (for example, the security process is executed by the AAA server), then the AUSF can directly interact with the NSSAAF to send an authentication request message (such as Nnssaaf_AIWF_Authentication Request), without interacting with the UDM. When the AUSF receives the AAA server information from the AMF, the AUSF can send the AAA server information to the NSSAAF.
[0470] S815, determine the AAA server address.
[0471] If step S814 is to execute sending an authentication request message from the AUSF to the NSSAAF, then the NSSAAF can obtain the address information of the AAA server, and the obtaining methods can be:
[0472] Method 1: Receive the AAA server information from the AUSF in step S814.
[0473] Method 2: The configured AAA server information in method 700.
[0474] S816, execute the security authentication process between the network and the IoT terminal.
[0475] In a possible implementation, the authentication process can be executed among the Ambient IoT device, AMF, AUSF, NSSAAF, and AAA server (if the AAA server is required to execute this security process).
[0476] In another possible implementation, the authentication process can be executed among the Ambient IoT device, AMF, AUSF, and UDM.
[0477] S817, the AMF selects the UDM.
[0478] After the authentication of the IoT terminal is successful, the AMF needs to register itself with the UDM as the AMF serving this IoT terminal; the AMF discovers the UDM according to the third configuration information.
[0479] S818, the AMF registers itself with the UDM as the AMF serving this IoT terminal.
[0480] The AMF provides the GUAMI to the UDM. Optionally, it can provide the AUSF information, so that the UDM stores the AUSF information that supports the execution of the security process of this IoT terminal. Thus, in the subsequent mobility scenario, the new AMF can obtain the AUSF information that supports the execution of this security process through the information stored by the UDM.
[0481] S819, the AMF sends a registration acceptance message to the IoT terminal. The message can include a temporary identifier (such as 5G globally unique temporary identity, 5G-GUTI) assigned by the AMF. Optionally, the AMF can store the selected AUSF and UDM information in the context, so that when a new AMF serves the IoT terminal subsequently, this information can be sent to the target AMF through the context migration or context transmission process, enabling the target AMF to select the AUSF and UDM based on this information without having to re-execute the above NRF discovery process, saving signaling overhead.
[0482] S820, the AMF can send information (such as identifiers, stored data, etc.) from one or more IoT terminals to the NEF.
[0483] In a possible embodiment, it is sent through the Namf_AmbientIoT_service response message.
[0484] S821, the NEF sends the information (such as identifiers, stored data, etc.) of the IoT terminal to the AF (service requester).
[0485] In a possible embodiment, it is sent through the Nnef_AmbientIoT_Service response message.
[0486] When the access process of the IoT terminal is triggered by the service requester, the network elements involved in the subsequent process can be determined in advance, for example, determined by the NEF. Thus, when the subsequent AMF receives a registration request (or access request) from the IoT terminal, it can directly select a suitable network element to execute the process according to the network element information provided by the NEF, so that it is not necessary to enhance and upgrade the functions of the entire 5GC, and only the NEF needs to be enhanced to perform network element selection, reducing the required new configurations.
[0487] According to the solution of this application, the core network is enabled to optimize and adapt the NF selection for the access process of the IoT terminal, and the core network device is enabled to select a suitable NF to execute the security process according to the service request or the characteristics and capabilities of the IoT terminal.
[0488] It should be understood that in various embodiments of this application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application; any order arrangement that can implement the functions of each step should be within the protection scope of this application.
[0489] It should be understood that the above embodiments can be implemented separately or in combination according to the functions and internal logics of the steps among the embodiments.
[0490] According to the foregoing method, Figure 12 FIG. 900 is a schematic diagram of a communication device provided for an embodiment of this application.
[0491] As Figure 12 shown, the device 900 may include modules or units corresponding one by one to the methods / operations / steps / actions described in methods 500 to 800. The module or unit may be a hardware circuit, software, or a combination of a hardware circuit and software. In a possible implementation manner, the device may include an interface unit 910 and a processing unit 920.
[0492] In a possible design, the device 900 may correspond to the mobility management device in the above embodiments.
[0493] In a possible embodiment, the device 900 includes an interface unit 910 configured to obtain a first message, where the first message includes identification information of a terminal device, the first message indicates the device type of the terminal device, and the terminal device accesses the network using Internet of Things (IoT) access technology; a processing unit 920 configured to select an authentication service device according to the first message, where the authentication service device supports authenticating and / or authorizing devices accessing the network using IoT access technology; and the interface unit 910 is further configured to send a first authentication request message to the authentication service device, where the first authentication request message includes the identification information of the terminal device, and the first authentication request message is used to request to perform authentication and / or authorization on the terminal device.
[0494] In a possible implementation, the first message includes device type information and / or indication information, where the device type information indicates that the terminal device is an active terminal or a passive terminal, the indication information indicates that the terminal device is an IoT device, and the mobility management device determines that the terminal device is an IoT device according to the first message; the processing unit 920 is further configured to determine that the terminal device is an IoT device according to the first message and select an authentication service device that supports authenticating and / or authorizing IoT devices.
[0495] In a possible implementation, the interface unit 910 is configured to send a first request message to a network storage device according to the first message, where the first request message is used to request to discover an authentication service device, and the first request message includes at least one of the following: a group identifier, indication information, and device type information, where the group identifier indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an IoT device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the interface unit 910 is further configured to obtain first response information from the network storage device, where the first response information includes the identification information and / or address information of the authentication service device; and the processing unit 920 is configured to select an authentication service device according to the first response information.
[0496] In a possible implementation, the first response information is determined according to the first request message and first configuration information of the authentication service device, where the first configuration information includes at least one of the following: a first supported group identifier, first support information, and first support type information, where the first supported group identifier corresponds to a first service requester, the authentication service device supports authenticating and / or authorizing terminal devices corresponding to the first service requester, the first support information indicates whether it supports authenticating and / or authorizing IoT devices, and the first support type information is used to indicate the device type that the authentication service device supports for authentication and / or authorization.
[0497] In a possible implementation, the interface unit 910 is configured to send a second request message to the network storage device. The second request message is used to request discovery of the unified data management device. The second request message includes at least one of the following: identification information, group identification, indication information, and device type information. Among them, the group identification is included in the identification information. The group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit 910 is configured to obtain a second response message from the network storage device. The second response information includes the identification information and / or address information of the unified data management device. The processing unit 920 is configured to determine the unified data management device according to the second response message.
[0498] In a possible implementation, the second response information is determined according to the second request information and the second configuration information of the unified data management device. The second configuration information includes at least one of the following: second supported group identification, second supported information, and second supported type information. Among them, the second supported group identification indicates support for the corresponding second service requester. The unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether it supports managing the subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of the terminal device corresponding to the subscription data management supported by the unified data management device.
[0499] In a possible implementation, the processing unit 920 is configured to select an authentication service device according to the first message and the third configuration information. The third configuration information includes the corresponding relationship between the authentication service device information and at least one of the following: first supported group identification, first supported information, and first supported type information. The first supported group identification corresponds to the first service requester. The authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first supported information indicates whether it supports authentication and / or authorization of Internet of Things devices. The first supported type information is used to indicate the device type of the terminal device for which the authentication service device supports performing authentication and / or authorization.
[0500] In a possible implementation, an interface unit 910 is configured to send a third request message to a unified data management device. The third request message is used to select an authentication service device and includes at least one of the following: identification information, group identification, indication information, and device type information. The group identification is included in the identification information, and the group identification indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit 910 is further configured to obtain third response information from the unified data management device. The third response information includes the identification information and / or address information of the authentication service device. A processing unit 920 is configured to select an authentication service device according to the third response information.
[0501] In a possible implementation, the third response information is determined according to the third request information and fourth configuration information. The fourth configuration information includes the correspondence between authentication service device information and at least one of the following: first supported group identification, first supported information, and first supported type information. The second supported group identification corresponds to a second service requester. The unified data management device supports managing the subscription data of the terminal devices corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of the terminal devices corresponding to the unified data management device that supports managing subscription data.
[0502] In a possible implementation, a processing unit 920 is configured to determine a unified data management device according to a first message and third configuration information. The third configuration information includes the correspondence between unified data management device information and at least one of the following: second supported group identification, second supported information, and second supported type information. The second supported group identification corresponds to a second service requester. The unified data management device supports managing the subscription data of the terminal devices corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of the terminal devices corresponding to the unified data management device that supports managing subscription data.
[0503] In a possible implementation, an interface unit 910 is configured to send a registration request message to a unified data management device. The registration request message includes the identification information of a mobility management device and the identification information and / or address information of an authentication service device. The registration request message indicates the mobility management device and the authentication service device for servicing the terminal device.
[0504] In a possible implementation, the apparatus 900 may further include a storage unit 930 configured to store the identification information of the authentication service device and / or the identification information of the unified data management device.
[0505] In a possible implementation, an interface unit 910 is configured to obtain a sixth request message from a network exposure function. The sixth request message includes network function information, and the network function information includes at least one of the following: identification information and / or address information of a device: an authentication service device, a unified data management device, a specific network slice authentication and authorization function NSAAF, and an AAA server. A processing unit 920 is configured to select an authentication service device and / or a unified data management device according to a first message and the sixth request message.
[0506] In a possible implementation, a first authentication request message includes device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The processing unit 920 is configured to determine that the terminal device is an Internet of Things device according to the first authentication request message.
[0507] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the mobility management device in the foregoing method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0508] In a possible design, the device 900 may correspond to the authentication service device in the foregoing embodiments.
[0509] In a possible embodiment, the device 900 includes an interface unit 910 configured to receive a first authentication request message from a mobility management device. The first authentication request message includes identification information of a terminal device. The first authentication request message is used to request to perform authentication and / or authorization on the terminal device. The terminal device accesses the network using Internet of Things access technology.
[0510] In a possible implementation, a processing unit 920 is configured to determine a unified data management device according to the first authentication request message. The unified data management device supports authentication and / or authorization of devices accessing the network using Internet of Things access technology. An interface unit 910 is configured to send a second authentication request message to the unified data management device. The second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
[0511] In a possible implementation, the first authentication request message includes terminal device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The second authentication request message includes at least one of the following: identification information, group identification, indication information, and device type information. The group identification is included in the identification information, and the group identification indicates a service requester corresponding to the terminal device.
[0512] In a possible implementation, the interface unit 910 is configured to send first configuration information to the network storage device. The first configuration information includes at least one of the following: a first supported group identifier, first support information, and first support type information. The first supported group identifier corresponds to a first service requester, and the authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first support information indicates whether it supports authentication and / or authorization of Internet of Things devices, and the first support type information is used to indicate the device type for which the authentication service device supports performing authentication and / or authorization.
[0513] In a possible implementation, the interface unit 910 is configured to send a fourth request message to the network storage device according to the first authentication request message. The fourth request message is used to request discovery of a unified data management device. The fourth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal. The interface unit 910 is further configured to obtain fourth response information from the network storage device. The fourth response information includes the identification information and / or address information of the unified data device. The processing unit 920 is configured to determine the unified data management device according to the fourth response information.
[0514] In a possible implementation, the fourth response information is determined according to the fourth request message and the second configuration information of the unified data management device. The second configuration information includes at least one of the following: a second supported group identifier, second support information, and second support type information. The second supported group identifier corresponds to a second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices, and the second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0515] In a possible implementation, the processing unit 920 is configured to determine the unified data management device according to the first authentication information and the fifth configuration information. The fifth configuration information includes the correspondence between the unified data management device information and at least one of the following: a second supported group identifier, second support information, and second support type information. The second supported group identifier corresponds to a second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices, and the second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing the subscription data.
[0516] In a possible implementation, the interface unit 910 is configured to obtain a second authentication response message from the unified data management device. The second authentication response message includes at least one of the following: identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and / or identification information and / or address information of the AAA server.
[0517] In a possible implementation, the interface unit 910 is configured to send a fifth request message to the network storage device. The fifth request message is used to request to discover the NSSAAF. The fifth request message includes at least one of the following: group identification, indication information, and device type information. The group identification is included in the identification information, and the group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates whether the terminal device is an active terminal or a passive terminal. The interface unit 910 is further configured to obtain a fifth response message from the network storage device. The fifth response message includes identification information and / or address information of the NSSAAF, and / or identification information and / or address information of the AAA server. The processing unit 920 is configured to determine the NSSAAF according to the fifth response message.
[0518] In a possible implementation, the fifth response message is determined according to the fifth request message and the sixth configuration information of the NSSAAF. The sixth configuration information includes at least one of the following: the third supported group identification, the third supported information, and the third supported type information. The third supported group identification corresponds to the third service requester, and the NSSAAF supports performing authentication and / or authorization on the terminal device corresponding to the third service requester. The third supported information indicates whether the NSSAAF supports authentication and / or authorization of Internet of Things devices. The third supported type information is used to indicate the device type for which the NSSAAF supports performing authentication and / or authorization.
[0519] In a possible implementation, the first authentication request message includes specific network slice authentication and authorization function NSSAAF information and / or AAA server information. The NSSAAF information indicates the NSSAAF used to perform authentication and / or authorization. The interface unit 910 is configured to send a third authentication request message to the NSSAAF. The third authentication request message includes at least one of the following: device identification, indication information, device type information, and AAA server information. The indication information indicates that the terminal device is an Internet of Things device, the device type information indicates whether the terminal device is an active terminal or a passive terminal, and the AAA server information includes identification information and / or address information of the AAA server.
[0520] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the authentication service device in the above method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0521] In a possible design, the device 900 may correspond to the unified data management device in the above embodiments.
[0522] In a possible embodiment, the device 900 includes an interface unit 910, configured to receive a second authentication request message from an authentication service device, where the second authentication request message includes at least one of the following: identification information of a terminal device, a group identification, indication information, and device type information, where the group identification is included in the identification information, the group identification indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; and a processing unit 920, configured to determine an authentication method according to the second authentication request message, where the authentication method is used to authenticate and / or authorize the terminal device.
[0523] In a possible implementation, the interface unit 910 is configured to send second configuration information to a network storage device, where the second configuration information includes at least one of the following: a second supported group identification, second supported information, and second supported type information, where the second supported group identification corresponds to a second service requester, and the unified data management device supports managing subscription data of terminal devices corresponding to the second service requester, the second supported information indicates whether the unified data management device supports managing subscription data of Internet of Things devices, and the second supported type information is used to indicate a device type corresponding to a terminal device for which the unified data management device supports managing subscription data.
[0524] In a possible implementation, the interface unit 910 is configured to receive a third request message from a mobility management device, where the third request message is used to select an authentication service device, and the third request message includes at least one of the following: identification information, a group identification, indication information, and device type information, where the group identification is included in the identification information, the group identification indicates a service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the processing unit 920 is configured to select an authentication service device according to the third request information and fourth configuration information, where the fourth configuration information includes a corresponding relationship between authentication service device information and at least one of the following: a first supported group identification, first supported information, and first supported type information, where the first supported group identification corresponds to a first service requester, the authentication service device supports performing authentication and / or authorization on terminal devices corresponding to the first service requester, the first supported information indicates whether it supports authentication and / or authorization of Internet of Things devices, and the first supported type information is used to indicate a device type for which the authentication service device supports performing authentication and / or authorization; and the interface unit 910 is configured to send third response information to the mobility management device, where the third response information includes identification information and / or address information of the authentication service device.
[0525] In a possible implementation, the interface unit 910 is configured to send a second authentication response message to an authentication service device, where the second authentication response message includes at least one of the following: identification information and / or address information of an authentication and authorization function NSSAAF for a specific network slice, and / or identification information and / or address information of an AAA server.
[0526] In a possible implementation, the interface unit 910 is configured to receive a registration request message from a mobility management device, where the registration request message includes identification information of the mobility management device and identification information and / or address information of the authentication service device, and the registration request message indicates the mobility management device and the authentication service device serving the terminal device.
[0527] In a possible implementation, the apparatus 900 includes a storage unit 930 configured to store identification information of the authentication service device.
[0528] The interface unit 910 in the communication apparatus 900 performs the receiving and sending operations performed by the unified data management device in the above method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0529] In a possible design, the apparatus 900 may correspond to the network exposure function device in the above embodiments.
[0530] In a possible embodiment, the apparatus 900 includes an interface unit 910 configured to receive a service request message from a service requester, where the service request message is used to perform a service operation on at least one terminal device corresponding to the service requester, and the network exposure function determines network function information according to the service request message, and the network function corresponding to the network function information is used to perform authentication and / or authorization on at least one terminal device; the interface unit 910 is further configured to send the service request message to a mobility management device, where the service request message includes network function information, and the network function information includes identification information and / or address information of at least one of the following network functions: an authentication service device, a unified data management device, a specific network slice authentication and authorization function NSSAAF, and an AAA server.
[0531] In a possible design, the apparatus 900 may correspond to the terminal device in the above embodiments.
[0532] In a possible embodiment, the apparatus 900 includes an interface unit 910 configured to send a registration request message to a reader, where the terminal device accesses the network using Internet of Things access technology, and the registration request message includes identification information and / or device type of the terminal device, and the device type information indicates that the terminal device is an active terminal or a passive terminal.
[0533] In a possible design, the device 900 may correspond to the reader / writer device in the above embodiments.
[0534] In a possible embodiment, the device 900 includes an interface unit 910, configured to receive a registration request message from a terminal device. The terminal device accesses the network using Internet of Things (IoT) access technology. The registration request message includes identification information and / or device type of the terminal device. The device type information indicates whether the terminal device is an active terminal or a passive terminal. The interface unit 910 is further configured to send a first message to a mobility management device. The first message includes the identification information of the terminal device. The first message indicates the device type of the terminal device. The first message is used to determine an authentication service device, which supports authenticating and / or authorizing devices that access the network using IoT access technology.
[0535] In a possible design, the device 900 may correspond to the network storage device in the above embodiments.
[0536] In a possible embodiment, the device 900 includes an interface unit 910, configured to receive first configuration information from an authentication service device. The first configuration information includes at least one of the following: a first supported group identifier, first support information, and first support type information. The first supported group identifier corresponds to a first service requester. The authentication service device supports authenticating and / or authorizing terminal devices corresponding to the first service requester. The first support information indicates whether it supports authenticating and / or authorizing IoT devices. The first support type information is used to indicate the device type for which the authentication service device supports authentication and / or authorization. The interface unit 910 is further configured to receive a first request message from a mobility management device. The first request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an IoT device. The device type information indicates whether the terminal device is an active terminal or a passive terminal. A processing unit 920 is configured to discover the authentication service device based on the first request message and the first configuration information. The interface unit 910 is configured to send first response information to the mobility management device. The first response information includes the identification information and / or address information of the authentication service device.
[0537] In a possible implementation, an interface unit 910 is configured to receive second configuration information from a unified data management device. The second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information. The second support group identifier corresponds to a second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second support type information is used to indicate the device type of the terminal device corresponding to the unified data management device that supports managing subscription data. The interface unit 910 is further configured to receive a second request message from a mobile management device. The second request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit 920 is configured to discover an authentication service device according to the second request message and the second configuration information. The interface unit 910 is configured to send second response information to the mobile management device. The second response information includes the identification information and / or address information of the unified data management device.
[0538] In a possible implementation, an interface unit 910 is configured to receive second configuration information from a unified data management device. The second configuration information includes at least one of the following: a second support group identifier, second support information, and second support type information. The second support group identifier corresponds to a second service requester, and the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second support type information is used to indicate the device type of the terminal device corresponding to the unified data management device that supports managing subscription data. The interface unit 910 is further configured to receive a second request message from a mobile management device. The second request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. A processing unit 920 is configured to discover an authentication service device according to the second request message and the second configuration information. The interface unit 910 is configured to send second response information to the mobile management device. The second response information includes the identification information and / or address information of the unified data management device.
[0539] In a possible implementation, the interface unit 910 is configured to receive a fourth request message from an authentication service device. The fourth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The processing unit 920 is configured to discover the authentication service device according to the fourth request message and the second configuration information. The interface unit 910 is configured to send a fourth response message to the authentication service device. The fourth response message includes identification information and / or address information of the unified data management device.
[0540] In a possible implementation, the interface unit 910 is configured to receive sixth configuration information from an authentication and authorization function NSSAAF of a specific network slice. The sixth configuration information includes at least one of the following: a third supported group identifier, third supported information, and third supported type information. The third supported group identifier indicates a service requester supported by the NSSAAF. The third supported information corresponds to a third service requester. The NSSAAF supports performing authentication and / or authorization on a terminal device corresponding to the third service requester. The third supported type information is used to indicate the device type for which the NSSAAF supports performing authentication and / or authorization. The interface unit 910 is further configured to receive a fifth request message from the authentication service device. The fifth request message includes at least one of the following: a group identifier, indication information, and device type information. The group identifier indicates a service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal. The processing unit 920 is configured to discover the authentication service device according to the fifth request message and the sixth configuration information. The interface unit 910 is configured to send a fifth response message to the authentication service device. The fifth response message includes identification information and / or address information of the NSSAAF, and identification information and / or address information of an AAA server.
[0541] The interface unit 910 in the communication device 900 performs the receiving and sending operations performed by the network storage device in the foregoing method embodiments, and the processing unit 920 performs operations other than the receiving and sending operations.
[0542] According to the foregoing method, Figure 13 FIG. 11 is a schematic diagram of a communication device 1000 provided in an embodiment of the present application.
[0543] The device 1000 may include a processor 1010 (i.e., an example of a processing unit). In a possible implementation, the device 1000 further includes a memory 1020. The memory 1020 is used to store instructions, and the processor 1010 is used to execute the instructions stored in the memory 1020, so that the device 1000 implements the steps performed by the communication device in Methods 500 - 800.
[0544] In a possible implementation, the device 1000 may further include an interface 1030 (i.e., an example of an interface unit module). Further, the processor 1010, the memory 1020, and the interface 1030 may communicate with each other through an internal connection path to transmit control and / or data signals. The memory 1020 is used to store a computer program, and the processor 1010 may be used to call and run the computer program from the memory 1020 to control the interface 1030 to receive signals or send signals. The memory 1020 may be integrated in the processor 1010 or may be separately provided from the processor 1010.
[0545] In a possible implementation manner, if the communication device 1000 is a communication equipment, the interface 1030 is a receiver or a transmitter. Among them, the receiver and the transmitter may be the same or different physical entities. When they are the same physical entity, they may be collectively referred to as a transceiver.
[0546] In a possible implementation manner, if the communication device 1000 is a chip or a circuit, the interface 1030 is an input interface or the interface 1030 is an output interface.
[0547] As an implementation manner, the function of the interface 1030 may be considered to be implemented by a transceiver circuit or a dedicated chip for transceiver. The processor 1010 may be considered to be implemented by a dedicated processing chip, a processing circuit, a processor, or a general-purpose chip.
[0548] As another implementation manner, a general computer may be considered to be used to implement the communication device provided in the embodiments of the present application. That is, the program codes for implementing the functions of the processor 1010 and the interface 1030 are stored in the memory 1020, and the general-purpose processor implements the functions of the processor 1010 and the interface 1030 by executing the codes in the memory 1020.
[0549] For the concepts, explanations, detailed descriptions, and other steps related to the technical solutions provided in the embodiments of the present application involved in the device 1000, please refer to the descriptions of these contents in the foregoing methods or other embodiments, and details are not described herein.
[0550] The embodiments of the present application further provide a computer-readable storage medium, on which computer instructions for implementing the methods performed by various devices in the foregoing method embodiments are stored.
[0551] For example, when the computer program is executed by a computer, the computer can implement the methods executed by various devices in the foregoing method embodiments.
[0552] An embodiment of the present application further provides a computer program product containing instructions, and when the instructions are executed by a computer, the computer implements the methods executed by various devices in the foregoing method embodiments.
[0553] An embodiment of the present application further provides a communication system, and the communication system includes various devices in the foregoing embodiments.
[0554] For the explanations and beneficial effects of the relevant content in any of the foregoing devices, reference may be made to the corresponding method embodiments provided above, and details are not described herein again.
[0555] It should be understood that in the embodiments of the present application, the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0556] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0557] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more sets of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as digital versatile discs (DVDs)), or semiconductor media. The semiconductor media can be a solid-state drive.
[0558] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after.
[0559] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0560] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here. In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.
[0561] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, the functional units in each embodiment of this application can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The foregoing storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks, or optical discs.
[0562] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.
Claims
1. A communication method, characterized in that, Including: The mobility management device obtains a first message, where the first message includes the identification information of the terminal device, the first message indicates the device type of the terminal device, and the terminal device accesses the network using the Internet of Things access technology; The mobility management device selects an authentication service device according to the first message, and the authentication service device supports authenticating and / or authorizing a terminal device accessing the network using the Internet of Things access technology; The mobility management device sends a first authentication request message to the authentication service device, where the first authentication request message includes the identification information of the terminal device, and the first authentication request message is used to request to perform authentication and / or authorization on the terminal device.
2. The method according to claim 1, characterized in that, The first message includes device type information and / or indication information, where the device type information indicates that the terminal device is an active terminal or a passive terminal, and the indication information indicates that the terminal device is an Internet of Things device. The mobility management device selecting an authentication service device according to the first message includes: The mobility management device determines that the terminal device is an Internet of Things device according to the first message, and selects an authentication service device that supports authenticating and / or authorizing the Internet of Things device.
3. The method according to claim 1 or 2, characterized in that, Selecting an authentication service device according to the first message includes: The mobility management device sends a first request message to the network storage device according to the first message, where the first request message is used to request to discover an authentication service device, and the first request message includes at least one of the following: group identification, indication information, and device type information, where The group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The mobility management device obtains first response information from the network storage device, where the first response information includes the identification information and / or address information of the authentication service device; The mobility management device selects the authentication service device according to the first response information.
4. The method according to any one of claims 1 - 3, characterized in that, The method further includes: The mobility management device sends a second request message to the network storage device, where the second request message is used to request to discover a unified data management device, and the second request message includes at least one of the following: identification information, group identification, indication information, and device type information, where The group identification is included in the identification information, the group identification indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The mobility management device obtains a second response message from the network storage device, where the second response information includes the identification information and / or address information of the unified data management device; The mobility management device selects the unified data management device according to the second response message.
5. The method according to claim 1 or 2, characterized in that, Selecting an authentication service device according to the first message includes: The mobile management device selects an authentication service device according to the first message and the third configuration information. The third configuration information includes the correspondence between the authentication service device information and at least one of the following: the first support group identifier, the first support information, and the first support type information. Among them, the authentication service device information includes the identifier and / or address information of the authentication service device. The first support group identifier corresponds to the first service requester. The authentication service device supports performing authentication and / or authorization on the terminal device corresponding to the first service requester. The first support information indicates whether it supports the authentication and / or authorization of Internet of Things devices. The first support type information indicates the device type for which the authentication service device supports performing authentication and / or authorization.
6. The method according to claim 1 or 2, characterized in that, Selecting an authentication service device according to the first message includes: The mobile management device sends a third request message to the unified data management device. The third request message is used to select an authentication service device. The third request message includes at least one of the following: identifier information, group identifier, indication information, and device type information. Among them, the group identifier is included in the identifier information. The group identifier indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal; The mobile management device obtains third response information from the unified data management device. The third response information includes the identifier information and / or address information of the authentication service device; The mobile management device selects the authentication service device according to the third response information.
7. The method according to claim 5 or 6, characterized in that, The method further includes: The mobile management device selects a unified data management device according to the first message and the third configuration information. The third configuration information includes the correspondence between the unified data management device information and at least one of the following: the second support group identifier, the second support information, and the second support type information. Among them, the second support group identifier corresponds to the second service requester. The unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second support information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second support type information is used to indicate the device type corresponding to the terminal device for which the unified data management device supports managing subscription data.
8. The method according to claim 4 or 7, characterized in that, The method further includes: The mobile management device sends a registration request message to the unified data management device. The registration request message includes the identifier information of the mobile management device and the identifier information and / or address information of the authentication service device. The registration request message indicates the mobile management device and the authentication service device serving the terminal device.
9. The method according to any one of claims 4 - 8, characterized in that, The method further includes: The mobile management device stores the identifier information of the authentication service device and / or the identifier information of the unified data management device.
10. The method according to claim 1 or 2, characterized in that, Selecting an authentication service device according to the first message includes: The mobile management device obtains a sixth request message from the network exposure function. The sixth request message includes network function information, and the network function information includes at least one of the following: identification information and / or address information of devices: an authentication service device, a unified data management device, a specific network slice authentication and authorization function NSAAF, and an AAA server; The mobile management device selects the authentication service device and / or the unified data management device according to the first message and the sixth request message.
11. A communication method, characterized in that, Including: The authentication service device receives a first authentication request message from the mobile management device. The first authentication request message includes identification information of the terminal device. The first authentication request message is used to request to perform authentication and / or authorization on the terminal device. The terminal device accesses the network using Internet of Things access technology.
12. The method according to claim 11, characterized in that, The first authentication request message includes device type information and / or indication information. The device type information indicates that the terminal device is an active terminal or a passive terminal. The indication information indicates that the terminal device is an Internet of Things device. The method further includes: The authentication service device selects the terminal device as an Internet of Things device according to the first authentication request message.
13. The method according to claim 11 or 12, characterized in that, The method includes: The authentication service device selects a unified data management device according to the first authentication request message. The unified data management device supports authentication and / or authorization of devices accessing the network using the Internet of Things access technology; The authentication service device sends a second authentication request message to the unified data management device. The second authentication request message is used to determine an authentication method, and the authentication method is used to authenticate and / or authorize the terminal device.
14. The method according to claim 13, characterized in that, The second authentication request message includes at least one of the following: identification information of the terminal device, a group identification, the indication information, and the device type information. The group identification is included in the identification information. The group identification indicates the service requester corresponding to the terminal device. The indication information indicates that the terminal device is an Internet of Things device. The device type information indicates that the terminal device is an active terminal or a passive terminal.
15. The method according to any one of claims 11 - 14, characterized in that, The method further includes: The authentication service device sends first configuration information to the network storage device. The first configuration information includes at least one of the following: a first supported group identification, first support information, and first support type information, where The first supported group identification corresponds to a first service requester. The authentication service device supports authentication and / or authorization of terminal devices corresponding to the first service requester. The first support information is used to indicate whether the authentication service device supports authentication and / or authorization of Internet of Things devices. The first support type information is used to indicate the device type for which the authentication service device supports authentication and / or authorization.
16. The method according to any one of claims 13 - 15, characterized in that, The authentication service device selects a unified data management device according to the first authentication request message, including: The authentication service device sends a fourth request message to the network storage device according to the first authentication request message. The fourth request message is used to request to discover a unified data management device. The fourth request message includes at least one of the following: a group identifier, indication information, and device type information. Among them, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the authentication service device obtains fourth response information from the network storage device. The fourth response information includes the identification information and / or address information of the unified data device; the authentication service device selects a unified data management device according to the fourth response information.
17. The method according to any one of claims 13 - 15, characterized in that, The authentication service device selects a unified data management device according to the first authentication request message, including: the authentication service device selects a unified data management device according to the first authentication information and fifth configuration information. The fifth configuration information includes the correspondence between the unified data management device information and at least one of the following: a second supported group identifier, second supported information, and second supported type information. Among them, the second supported group identifier corresponds to a second service requester. The unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester. The second supported information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices. The second supported type information is used to indicate the device type of the terminal device corresponding to the unified data management device that supports managing subscription data; 18. The method according to claim 17, characterized in that, The method further includes: the authentication service device obtains a second authentication response message from the unified data management device. The second authentication response message includes at least one of the following: the identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, the identification information and / or address information of an AAA server; 19. The method according to claim 11, characterized in that, The method further includes: the authentication service device sends a fifth request message to the network storage device. The fifth request message is used to request to discover NSSAAF. The fifth request message includes at least one of the following: a group identifier, indication information, and device type information. Among them, the group identifier is included in the identification information. The group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; the authentication service device obtains fifth response information from the network storage device. The fifth response information includes at least one of the following: the identification information and / or address information of NSSAAF, the identification information and / or address information of an AAA server; the authentication service device selects NSSAAF according to the fifth response information.
20. The method according to claim 11, characterized in that, The first authentication request message includes specific network slice authentication and authorization function (NSSAAF) information and / or AAA server information, and the NSSAAF information indicates the NSSAAF used to perform authentication and / or authorization; the method includes: The authentication service device sends a third authentication request message to the NSSAAF, and the third authentication request message includes at least one of the following: device identifier, indication information, device type information, and the AAA server information, where the indication information indicates that the terminal device is an Internet of Things device, the device type information indicates that the terminal device is an active terminal or a passive terminal, and the AAA server information includes the identifier information and / or address information of the AAA server.
21. A communication method, characterized in that, including: The unified data management device receives a second authentication request message from the authentication service device, and the second authentication request message includes at least one of the following: the identifier information of the terminal device, the group identifier, the indication information, and the device type information, where the group identifier is included in the identifier information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The unified data management device determines an authentication method according to the second authentication request message, and the authentication method is used to authenticate and / or authorize the terminal device.
22. The method according to claim 21, characterized in that, The method further includes: the unified data management device sends second configuration information to the network storage device, and the second configuration information includes at least one of the following: the second supported group identifier, the second supported information, and the second supported type information, where the second supported group identifier corresponds to a second service requester, the unified data management device supports managing the subscription data of the terminal device corresponding to the second service requester, the second supported information indicates whether the unified data management device supports managing the subscription data of Internet of Things devices, and the second supported type information is used to indicate the device type of the terminal device corresponding to the unified data management device that supports managing the subscription data.
23. The method according to claim 21 or 22, characterized in that, The method further includes: The unified data management device receives a third request message from the mobility management device, and the third request message is used to select the authentication service device. The third request message includes at least one of the following: identifier information, group identifier, indication information, and device type information, where the group identifier is included in the identifier information, the group identifier indicates the service requester corresponding to the terminal device, the indication information indicates that the terminal device is an Internet of Things device, and the device type information indicates that the terminal device is an active terminal or a passive terminal; The unified data management device selects an authentication service device according to the third request information and the fourth configuration information. The fourth configuration information includes the corresponding relationship between the authentication service device information and at least one of the following: a first supported group identifier, first supported information, and first supported type information. Among them, the first supported group identifier corresponds to a first service requester, and the authentication service device supports performing authentication and / or authorization indication support for the service requester corresponding to the first service requester. The first supported information indicates whether it supports the authentication and / or authorization of Internet of Things devices, and the first supported type information is used to indicate the device type that supports performing authentication and / or authorization. The unified data management device sends third response information to the mobility management device. The third response information includes the identification information and / or address information of the authentication service device.
24. The method according to claim 21 or 22, characterized in that, The method further includes: The unified data management device sends a second authentication response message to the authentication service device. The second authentication response message includes at least one of the following: the identification information and / or address information of the authentication and authorization function NSSAAF of a specific network slice, and the identification information and / or address information of the AAA server.
25. The method according to any one of claims 21 - 24, characterized in that, The method further includes: The unified data management device receives a registration request message from the mobility management device. The registration request message includes the identification information of the mobility management device and the identification information and / or address information of the authentication service device. The registration request message indicates the mobility management device and the authentication service device serving the terminal device.
26. The method according to claim 25, characterized in that, The method further includes: The unified data management device stores the identification information of the authentication service device.
27. A communication method, characterized in that, Including: The network exposure function receives a service request message from a service requester. The service request message is used to perform a service operation on at least one terminal device corresponding to the service requester. The network exposure function determines network function information according to the service request message. The network function corresponding to the network function information is used to perform authentication and / or authorization on the at least one terminal device. The network exposure function sends a sixth request message to the mobility management device. The sixth request message includes the network function information. The network function information includes the identification information and / or address information of at least one of the following network functions: an authentication service device, a unified data management device, a specific network slice authentication and authorization function NSSAAF, and an AAA server.
28. A communication device, characterized in that, Including: A processor, which is used to execute a program or instruction, so that the device executes the method according to any one of claims 1 to 10, or so that the device executes the method according to any one of claims 11 to 20, or so that the device executes the method according to any one of claims 21 to 26, or so that the device executes the method according to claim 27.
29. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program runs on a computer, the computer is caused to execute the method described in any one of claims 1 to 10, or the method described in any one of claims 11 to 20, or the method described in any one of claims 21 to 26, or the method described in claim 27.
Citation Information
Cited By
Communication method, and apparatus
WO2025124169A1