User equipment, core network device and methods therein
The core network device and communication system efficiently authenticate UEs across multiple network slices by reducing authentication checks, addressing the increased time and load associated with auxiliary authentication as the number of slices grows.
Patent Information
- Application Number
- CN202510527504.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2018-09-28
- Filing Date
- 2019-09-25
- Publication Date
- 2025-07-15
AI Technical Summary
As the number of network slices a UE can access increases, the time and processing load for auxiliary authentication (auxiliary authentication) also increases, leading to longer times before the UE can communicate over the network slices.
A core network device and communication system that includes authentication units to perform first and second authentication processes during registration, allowing for efficient authentication of network slices by reducing the number of authentication checks based on a permitted list of network slices.
This approach reduces the time and processing load required for auxiliary authentication, enabling faster and more efficient access to network slices.
Smart Images

Figure CN120321647A_ABST
Abstract
Description
[0001] This application is a divisional application of a Chinese patent application with an application date of September 25, 2019, an application number of 201980063728.X, and an invention title of "Core Network Device, Communication Terminal, Communication System, Authentication Method, and Communication Method". Technical Field
[0002] The present invention relates to a core network device, a communication terminal, a communication system, an authentication method, and a communication method. Background Art
[0003] In the 5th generation (5G) network, providing services by using network slices has been discussed. A network slice is at least one logical network defined on a physical network. A specific network slice may be, for example, a network slice that provides a public safety service. In addition, other network slices may be network slices that guarantee an extremely short delay time, and may be network slices that can accommodate many Internet of Things (IoT) terminals at the same time.
[0004] In addition, in the 5G network, it is also assumed that a communication carrier leases a network slice to a third party having an original subscriber database. In this case, in addition to the authentication of a communication terminal accessing a public land mobile network (PLMN), the authentication of a communication terminal accessing a network slice has also been discussed. The communication terminal accessing the PLMN and the communication terminal accessing the network slice are the same communication terminal. The authentication of a communication terminal accessing the PLMN is, for example, referred to as primary authentication. The authentication of a communication terminal accessing a network slice is, for example, referred to as secondary authentication. Secondary authentication also includes processing for authorizing access to a network slice, and may be referred to as slice-specific secondary authentication and authorization.
[0005] Non-Patent Document 1 describes an outline of primary authentication and secondary authentication being performed on a user equipment (UE) that is a communication terminal. Primary authentication is performed between the UE and a core network device such as an access management function (AMF) entity and an authentication server function (AUSF) entity based on authentication information determined in the 3rd Generation Partnership Project (3GPP). On the other hand, secondary authentication is performed between the UE and an authentication, authorization, and accounting (AAA) server managed by a third party based on authentication information not determined in the 3GPP. The authentication information determined in the 3GPP may be, for example, authentication information used when the UE accesses the PLMN. The authentication information not determined in the 3GPP may be, for example, authentication information managed by a third party. Specifically, the authentication information managed by a third party may be a user ID and password (credentials) being managed in the AAA server.
[0006] In addition, Non-Patent Document 1 describes an outline of authentication processing during PDU session establishment for authenticating access to a network slice when a PDU session is first established in a specific network slice.
[0007] Citation List
[0008] Non-Patent Literature
[0009] [Non-Patent Literature 1]3GPP TS23.740 V0.5.0 (2018-08), Sections 6.3.1 and 6.3.2 Summary of the Invention
[0010] Problems to be Solved by the Invention
[0011] A UE can access multiple network slices. For example, identification information related to multiple network slices that the UE can access is included in the subscriber information of the UE. The network slices that the UE can access can be, for example, network slices previously applied for or subscribed to by the user operating the UE.
[0012] In the case where multiple network slices that the UE can access are included in the subscriber information, secondary authentication is performed for each network slice during the registration process of the UE. Therefore, there is a problem that as the number of network slices included in the subscriber information increases, the time and processing load required for secondary authentication increase, and the time and processing load required until the UE communicates using the network slice increase.
[0013] An object of the present invention is to provide a core network device, a communication terminal, a communication system, an authentication method, and a communication method capable of efficiently performing secondary authentication to be performed for each network slice.
[0014] Solutions to Solve the Problems
[0015] The core network device according to the first aspect of the present invention includes: a first authentication unit configured to perform a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network; a communication unit configured to receive permission list information indicating at least one network slice that can be used by the communication terminal in the serving network; and a second authentication unit configured to perform a second authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slices included in the permission list information during the registration process for registering the communication terminal in the core network.
[0016] The communication terminal according to the second aspect of the present invention includes a communication unit configured to send ability information indicating whether a process associated with a second authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice can be performed to a core network device during a registration process for registering the communication terminal in the core network.
[0017] A communication system according to a third aspect of the present invention includes: a first core network device configured to perform a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network, perform a second authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice during the registration process for registering the communication terminal in the core network, and send information indicating the network slice for performing the second authentication process; and a second core network device configured to receive the information indicating the network slice for performing the second authentication process, determine whether to perform the second authentication process related to the communication terminal when the communication terminal first uses the network slice after the registration process is completed, perform the second authentication process when the second authentication process has not been performed, and not perform the second authentication process when the second authentication process has been performed.
[0018] An authentication method according to a fourth aspect of the present invention includes: performing a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network; receiving permission list information indicating at least one network slice that can be used by the communication terminal in a serving network; and performing a second authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slice included in the permission list information during the registration process for registering the communication terminal in the core network.
[0019] A communication method according to a fifth aspect of the present invention includes: generating capability information indicating whether a process associated with a second authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice can be performed during a registration process for registering the communication terminal in the core network; and sending the capability information to a core network device.
[0020] Advantageous Effects of the Invention
[0021] The present invention can provide a core network device, a communication terminal, a communication system, an authentication method, and a communication method that can efficiently perform secondary authentication to be performed for each network slice. Brief Description of the Drawings
[0022] Figure 1 is a structural diagram of a core network device according to a first exemplary embodiment.
[0023] Figure 2 is a structural diagram of a communication system according to a second exemplary embodiment.
[0024] Figure 3 It is a diagram showing the process of the registration process according to the second exemplary embodiment.
[0025] Figure 4 It is a structural diagram of a communication terminal according to the third exemplary embodiment.
[0026] Figure 5 It is a diagram showing the process of the registration process according to the third exemplary embodiment.
[0027] Figure 6 It is a diagram showing the process of the registration process according to the fourth exemplary embodiment.
[0028] Figure 7 It is a diagram showing the process of the authentication process during PDU session establishment according to the fifth exemplary embodiment.
[0029] Figure 8 It is a diagram showing the process of the authentication process during PDU session establishment according to the fifth exemplary embodiment.
[0030] Figure 9 It is a diagram of a communication terminal and a UE according to each exemplary embodiment.
[0031] Figure 10 It is a structural diagram of a core network device and an AMF according to each exemplary embodiment. Detailed Description of the Invention
[0032] (First Exemplary Embodiment)
[0033] Hereinafter, embodiments of the present invention will be described with reference to the drawings. By using Figure 1 The structural example of the core network device 10 according to the first exemplary embodiment will be described. The core network device 10 may be a computer device operated by a processor that executes a program stored in a memory.
[0034] The core network device 10 includes an authentication unit 11, an authentication unit 12, and a communication unit 13. The authentication unit 11, the authentication unit 12, and the communication unit 13 may be software or modules processed by a processor that executes a program stored in a memory. Optionally, the authentication unit 11, the authentication unit 12, and the communication unit 13 may be hardware such as a circuit or a chip.
[0035] During the registration process of registering a communication terminal in the core network, the authentication unit 11 performs an authentication process to determine whether the communication terminal is a communication terminal permitted to be registered in the core network. The authentication of the communication terminal performed by the authentication unit 11 corresponds to the primary authentication. The communication terminal can be, for example, a cellular phone terminal, a smart phone terminal, or a tablet terminal. Optionally, the communication terminal can be an Internet of Things (IoT) terminal or a machine type communication (MTC) terminal. Optionally, the communication terminal can be a UE, which is a general term used as a communication terminal in 3GPP.
[0036] The core network is a network included in the 5G network. The 5G network includes an access network directly accessed by the communication terminal and a core network that aggregates multiple access networks.
[0037] For example, the registration process can be performed after the communication terminal transitions from the power-off state to the power-on state. Optionally, the registration process can be performed after a predetermined period of time has elapsed since the last registration process. The registration process can be, for example, a registration process determined by 3GPP. Since the communication terminal is registered in the core network, the core network performs mobile management and session management of the communication terminal, etc.
[0038] The communication unit 13 receives permission list information indicating at least one network slice available for use by the communication terminal in the serving network. The serving network is a network that provides communication services to the area where the communication terminal is located. The serving network can be a home public land mobile network (HPLMN) that manages the subscriber information of the communication terminal, and can be a visited PLMN (VPLMN) used as a roaming destination.
[0039] All network slices accessible by the communication terminal are included in the subscriber information of the communication terminal. The network slices available for provision to the communication terminal are different for each serving network. Therefore, the communication terminal may not be able to use all the network slices included in the subscriber information in the currently connected serving network. The network slices included in the permission list information are the network slices included in the subscriber information of the communication terminal that can be used in the serving network. Therefore, the network slices included in the permission list information can be a part of all the network slices included in the subscriber information.
[0040] The communication unit 13 can receive the permission list information from other core network devices configured in the HPLMN, or can receive the permission list information from other core network devices configured in the VPLMN.
[0041] During the registration process of registering the communication terminal in the core network, the authentication unit 12 performs an authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slices included in the permission list information. The authentication performed by the authentication unit 12 corresponds to secondary authentication. When multiple network slices are included in the permission list information, the authentication unit 12 can cooperate with each third party managing each network slice and perform the authentication process of the communication terminal.
[0042] As described above, the authentication unit 12 of the core network device 10 causes the authentication unit to execute the same number of times as the number of network slices included in the permission list information. Here, the number of network slices included in the permission list information is less than the number of network slices included in the subscriber information. Therefore, compared with the case where the authentication process is executed the same number of times as the number of network slices included in the subscriber information, the time required for the authentication process performed by the authentication unit 12 during the registration process for registering the communication terminal in the core network is further shortened.
[0043] In addition, the core network device 10 performs the following authentication method. First, during the registration process for registering the communication terminal in the core network, the core network device 10 performs a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network. Next, the core network device 10 receives permission list information indicating at least one network slice that can be used by the communication terminal in the serving network. Next, during the registration process for registering the communication terminal in the core network, the core network device 10 performs a second authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slices included in the permission list information.
[0044] (Second Exemplary Embodiment)
[0045] Then, by using Figure 2 The structural example of the communication system according to the second exemplary embodiment will be described. Figure 2 The communication system in includes a UE 20, a serving PLMN 30, an HPLMN 40, and a third-party network 50. It is assumed that the UE 20 exists in the area where the serving PLMN 30 provides communication services. The UE 20 corresponds to the communication terminal. The serving PLMN 30 corresponds to the serving network. In Figure 2 In, the serving PLMN 30 may be referred to as a VPLMN. The third-party network 50 may be a network managed by a communication operator different from the communication operator managing the serving PLMN 30 and the communication operator managing the HPLMN 40. The third-party network 50 may be, for example, a network managed by an operator providing application services.
[0046] The serving PLMN 30 includes an Access and Mobility Management Function (AMF) entity 31 (hereinafter referred to as AMF 31), a Visited Session Management Function (V-SMF) entity 32 (hereinafter referred to as V-SMF 32), and a User Plane Function (UPF) entity 33 (hereinafter referred to as UPF 33). The AMF 31 corresponds to the core network device 10 in Figure 1 .
[0047] The HPLMN 40 includes a Unified Data Management (UDM) entity 41 (hereinafter referred to as UDM 41), an Authentication Server Function (AUSF) entity 42 (hereinafter referred to as AUSF 42), a Network Slice Selection Function (NSSF) entity 43 (hereinafter referred to as NSSF 43), a Network Exposure Function (NEF) entity 44 (hereinafter referred to as NEF 44), an H-SMF entity 45 (hereinafter referred to as H-SMF 45), and a UPF entity 46 (hereinafter referred to as UPF 46).
[0048] The third-party network 50 includes an Authentication, Authorization, and Accounting (AAA) server 51.
[0049] The AMF 31 manages access, mobility, etc. related to the UE 20. In addition, the AMF 31 cooperates with the AUSF 42, UDM 41, etc., and performs primary authentication processing related to the UE 20. The V-SMF 32 performs session management related to the UE 20. Session management includes the establishment, change, and deletion of sessions. The UPF 33 routes or transports user plane data between the UE 20 and the UPF 46.
[0050] The UDM 41 manages subscriber information related to the UE 20. Identification information related to multiple network slices that the UE 20 can access is included in the subscriber information. The network slices that the UE 20 can access can be, for example, network slices previously applied for or subscribed to by the user operating the UE 20.
[0051] The AUSF 42 manages authentication information related to the UE 20. The authentication information can be, for example, security keys and authentication algorithms related to the UE 20. The NSSF 43 sends identification information related to the network slices in the serving PLMN 30 that can be used by the UE 20 to the AMF 31. The identification information related to the network slices can be, for example, Network Slice Selection Assistance Information (NSSAI). In addition, the AUSF 42 relays data transmitted between the AAA server 51 configured in the third-party network 50 and the node devices configured in the HPLMN 40.
[0052] The NEF 44 relays data transmitted between the AAA server 51 configured in the third-party network 50 and the node device configured in the HPLMN 40. The H-SMF 45 performs session management related to the UE 20 together with the V-SMF 32. The UPF 46 routes or conveys user plane data between the UPF 33 and the third-party network 50. For example, the UPF 46 can route user plane data between an application server (not shown) configured in the third-party network 50 and the UPF 33.
[0053] The V-SMF 32, UPF 33, H-SMF 45, and UPF 46 constitute a network slice 60. The V-SMF 32, UPF 33, H-SMF 45, and UPF 46 can each be used only for the network slice 60 and can be shared with other network slices. The network slice 60 is a network slice managed by the third-party network 50. In other words, in the case where the UE 20 uses the service provided by the third-party network 50, the UE 20 is connected to the network slice 60.
[0054] The AAA server 51 performs secondary authentication processing related to the UE 20 using the network slice 60.
[0055] In Figure 2 In the structural example, the AUSF 42 and the NEF 44 are configured to relay data transmitted between the AMF 31 and the AAA server 51, but another independent node device (not shown) different from the AUSF 42 and the NEF 44 can be configured to relay data. In addition, the communication system may not include the NEF 44, and the AUSF 42 can be configured to relay data transmitted between the AMF 31 and the AAA server 51. The node device that relays data transmitted between the AMF 31 and the AAA server 51 can be an AAA proxy function (AAA-F).
[0056] Then, the process flow of the registration process related to the UE 20 will be described by using Figure 3 First, the UE 20 sends a registration request message (S11) to the AMF 31. The registration request includes a requested NSSAI. The requested NSSAI is the NSSAI provided from the UE 20 to the serving PLMN 30. In other words, the requested NSSAI is the NSSAI indicating the network slice that the UE 20 expects to use or connect to in the serving PLMN 30. A single network slice selection assistance information (S-NSSAI) is identification information indicating one network slice, and multiple S-NSSAIs can be included in the NSSAI.
[0057] Note that the AMF 31 can obtain the requested NSSAI from a message other than the registration request message (S11). For example, in step S12, the AMF 31 sends a NAS security mode command message to the UE 20, and the UE 20 returns a NAS security mode complete message to the AMF 31 as a response to the NAS security mode command message. In this case, the UE 20 can set the requested NSSAI in the NAS security mode complete message, and the AMF 31 can obtain the requested NSSAI. In addition, for example, before step S12, the AMF 31 can send an identity request message to the UE 20, and the UE 20 can return an identity response message to the AMF 31 as a response to the identity request message. In this case, the UE 20 can set the requested NSSAI in the identity response message, and the AMF 31 can obtain the requested NSSAI.
[0058] In addition, the AMF 31 can receive a message including the requested NSSAI from any node device other than the UE 20 and can obtain the requested NSSAI. For example, any node device can receive a message including the requested NSSAI sent from the UE 20. In this case, the AMF 31 can obtain the requested NSSAI by receiving the message including the requested NSSAI from any node device.
[0059] Next, in the UE 20, AMF 31, and AUSF 42, a security process (S12) for accessing an existing PLMN is performed. The existing PLMNs are, for example, the serving PLMN 30 and the HPLMN 40. Specifically, in step S12, the primary authentication process related to the UE 20 is performed. For example, the AMF 31 performs the primary authentication process related to the UE 20 by using the authentication information received from the AUSF 42. For example, the authentication information received by the AMF 31 from the AUSF 42 can also be referred to as 3GPP credentials. In other words, the authentication information received by the AMF 31 from the AUSF 42 can be authentication information determined in 3GPP. For example, the 3GPP credentials can include the subscription permanent identifier (SUPI) as the user ID of the UE 20 and the authentication information used when the UE 20 accesses the serving PLMN 30.
[0060] For example, the primary authentication process authenticates the SUPI in the authentication and key agreement (AKA) performed between the AMF 31 and the UE 20. In other words, the AMF 31 authenticates the SUPI indicating the UE 20 in the AKA performed between the UE 20 and the AMF 31. In addition, the primary authentication process may include an authorization process related to the UE 20. For example, the primary authentication process may include the UE 20 authorizing the use of the serving PLMN 30 by the UE 20 by using the subscriber information of the UE 20 obtained from the UDM 41. In other words, the AMF 31 may authorize the UE 20 to use the serving PLMN 30 by using the subscriber information of the UE 20 obtained from the UDM 41. The primary authentication process may be referred to as the primary authentication and primary authorization process.
[0061] Next, the AMF 31 sends a Nudm_SDM_Get message (S13) to the UDM 41. Next, the UDM 41 sends a Nudm_SDM_Get response message (S14) to the AMF 31. The Nudm_SDM_Get response message includes the subscribed S (single)-NSSAI. The S-NSSAI is identification information indicating a network slice. The subscribed S-NSSAI is identification information indicating the network slices included in the subscriber information. Multiple subscribed S-NSSAIs (subscribed S-NSSAIs) may be included in the Nudm_SDM_Get response message.
[0062] Next, the AMF 31 sends a Nnssf_NSSelection_Get message (S15) to the NSSF 43. Next, the NSSF 43 sends a Nnssf_NSSelection_Get response message (S16) to the AMF 31. The Nnssf_NSSelection_Get response message includes the allowed NSSAI. The allowed NSSAI includes the identification information (S-NSSAI) related to the network slices that can be used by the UE 20 in the serving PLMN 30 among the multiple subscribed S-NSSAIs. Multiple S-NSSAIs (S-NSSAIs) may be included in the allowed NSSAI. Here, it is assumed that the number of S-NSSAIs included in the allowed NSSAI is less than the number of multiple subscribed S-NSSAIs included in the Nudm_SDM_Get response message. In other words, it is assumed that the S-NSSAIs included in the allowed NSSAI are a part of the multiple subscribed S-NSSAIs included in the Nudm_SDM_Get response message. For example, the NSSF 43 may obtain the subscribed S-NSSAI related to the UE 20 from the UDM 41 and manage the S-NSSAI indicating the network slices that can be used by the UE 20 in the serving PLMN 30.
[0063] Next, the AMF 31 checks whether to apply the secondary authentication process (S17) in the network slices indicated by each S-NSSAI included in the allowed NSSAI. The AMF 31 can check whether to apply the secondary authentication process in each network slice included in the allowed NSSAI by using a policy server or the like. For example, in a third-party network, there is also a third-party network that includes a policy of not applying the secondary authentication process when using a network slice managed by the third-party network.
[0064] The policy server can manage information related to whether each network slice requests secondary authentication related to the UE 20. In addition, in a node device other than the policy server, information related to whether to request secondary authentication related to the UE 20 can be managed. In this case, the AMF 31 can perform the check in step S17 by using the node device that manages the information related to whether to request secondary authentication related to the UE 20.
[0065] For example, the AMF 31 can perform the check in step S17 by using the UDM 41. In this case, the AMF 31 can receive information related to whether to apply the secondary authentication process in the network slice indicated by the subscribed S-NSSAI from the Nudm_SDM_Get response message (S14). In addition, the AMF 31 can perform the check in step S17 by using the received information.
[0066] Next, in the UE 20, AMF 31, AUSF 42, and AAA server 51, a security process (S18) for accessing the network slice 60 to which the secondary authentication process is applied is performed. Specifically, in step S18, a secondary authentication process related to the UE 20 is performed. For example, in the secondary authentication, authentication information managed by a third party can be used. The authentication information managed by a third party can include the user ID used when the UE 20 uses the network slice 60 and the password managed in the AAA server 51.
[0067] In the secondary authentication process, an authentication process using the Extensible Authentication Protocol (EAP) can be performed. For example, the AMF 31 notifies the UE 20 of the S-NSSAI and sends a request message for requesting the transmission of the user ID and password used in the S-NSSAI. In addition, the AMF 31 sends the user ID and password received from the UE 20 to the AAA server 51 via the AUSF 42. The AAA server 51 can authenticate the user ID related to the UE 20 received from the AUSF 42 (i.e., the UE 20), and further authorize the UE 20 to use the network slice 60 by using the user ID and password received from the UE 20. The secondary authentication process can include authenticating the UE 20 and authorizing the UE 20 to use the network slice 60. Optionally, the secondary authentication process may be referred to as the secondary authentication process and the secondary authorization process.
[0068] In the registration process related to the UE 20, the secondary authentication process is performed for each network slice. In other words, in the registration process, the secondary authentication process is repeated the same number of times as the number of S-NSSAIs in the allowed NSSAI that indicate the network slices to which the secondary authentication process is applied.
[0069] As described above, the number of S-NSSAIs included in the allowed NSSAI is smaller than the number of subscribed S-NSSAIs sent from the UDM 41. In addition, among the network slices indicated by the S-NSSAIs included in the allowed NSSAI, there are also network slices to which the secondary authentication process is not applied. Therefore, the number of network slices to which the secondary authentication process is applied is smaller than the number of network slices indicated by the S-NSSAIs included in the allowed NSSAI. As a result, in Figure 2 the communication system, the number of times of the secondary authentication process performed in the registration process related to the UE 20 is smaller than the number of times of the secondary authentication process when the secondary authentication process is repeated the same number of times as the number of subscribed S-NSSAIs sent from the UDM 41. In this way, compared with the case where the secondary authentication process is repeated the same number of times as the number of subscribed S-NSSAIs, the UE 20, the AMF 31, the AUSF 42, and the AAA server 51 can further reduce the time required for the secondary authentication process in the registration process. In addition, the UE 20, the AMF 31, the AUSF 42, and the AAA server 51 can reduce the processing load required for the secondary authentication process.
[0070] In addition, the process of registering the UE 20 in the core network is performed for each access network. Therefore, the UE 20 can send a registration request message to the AMF 31 via each access network such as 3GPP access and non-3GPP access. 3GPP access is an access network that supports the wireless communication method defined in 3GPP. Non-3GPP access is an access network that supports a wireless communication method different from the wireless communication method defined in 3GPP.
[0071] The AMF 31 receives the registration request message from the UE 20 via either 3GPP access or non-3GPP access and performs secondary authentication. For example, assume that the AMF 31 receives the registration request message via 3GPP access and performs secondary authentication. Here, in the case where the AMF 31 receives the registration request message via non-3GPP access, the secondary authentication in the network slice where the secondary authentication related to the UE 20 has been performed can be not performed and can be omitted. In this way, it is possible to prevent the same UE in the same network slice from being authenticated in an overlapping manner. In this way, compared with the case where the secondary authentication process is not omitted, the time required for the secondary authentication process in the registration process can be reduced, and the processing load required for the secondary authentication process can be reduced. The secondary authentication based on the registration request message received via 3GPP access can also be omitted, the same as the case of performing secondary authentication based on the registration request message received via non-3GPP access.
[0072] In addition, in the case where the secondary authentication related to the S-NSSAI of the UE 20 fails, the AMF 31 can replace the S-NSSAI provided to the UE 20 in the allowed N-SSAI in the case of successful secondary authentication with another S-NSSAI, and can provide the S-NSSAI to the UE 20. For example, the replaced S-NSSAI can be the default S-NSSAI. In addition, the replaced S-NSSAI can be provided with an identifier indicating that the S-NSSAI has been replaced and an identifier indicating the S-NSSAI before replacement. The UE 20 recognizes that access to the network slice indicated by the replaced S-NSSAI is authorized. In this way, the AMF 31 can prevent the situation where the UE 20 cannot access any network slice. In other words, the AMF 31 can guide the UE 20 that cannot be authenticated so that the UE 20 accesses a specific network slice.
[0073] (Third Exemplary Embodiment)
[0074] Then, by using Figure 4To illustrate the structural example of the communication terminal 70 according to the third exemplary embodiment. The communication terminal 70 may be a computer device operated by a processor that executes a program stored in a memory. In addition, the core network device 10 described in the first exemplary embodiment serves as a core network device that communicates with the communication terminal 70.
[0075] The communication terminal 70 includes a control unit 71 and a communication unit 72. The control unit 71 and the communication unit 72 may be software or modules processed by a processor that executes a program stored in a memory. Alternatively, the control unit 71 and the communication unit 72 may be hardware such as a circuit or a chip.
[0076] During the registration process for registering the communication terminal 70 in the core network, the control unit 71 generates capability information indicating whether it is possible to perform a process associated with the authentication process for determining whether the communication terminal 70 is a communication terminal permitted to use a network slice.
[0077] The authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice corresponds to a secondary authentication process. The process associated with the authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice includes processes such as the communication terminal 70 receiving a message sent from the core network device 10 in the secondary authentication process. In addition, the process associated with the authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice includes processes such as reading parameters set for the received message. In addition, the process associated with the authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice includes processes such as sending a message to the core network device 10 or responding to the core network device 10 to continue the secondary authentication process normally.
[0078] The communication unit 72 sends the capability information generated in the control unit 71 to the core network device 10.
[0079] The core network device 10 determines whether the capability information received from the communication terminal 70 indicates that the communication terminal 70 can perform a process associated with the secondary authentication process. When the core network device 10 determines that the communication terminal 70 can perform a process associated with the secondary authentication process, the core network device 10 performs a secondary authentication process related to the communication terminal 70 during the registration process for registering the communication terminal 70 in the core network. When the core network device 10 does not receive the capability information from the communication terminal 70, the core network device 10 may determine that the communication terminal 70 cannot perform a process associated with the secondary authentication process.
[0080] For example, when the core network device 10 performs the secondary authentication process on a communication terminal that cannot perform the process associated with the secondary authentication, the core network device 10 cannot receive the information required for the secondary authentication process from the communication terminal. In other words, even if the secondary authentication will fail, the core network device 10 wastes the time related to the secondary authentication process.
[0081] On the other hand, the communication terminal 70 according to the third exemplary embodiment can send the core network device 10 the capability information indicating whether the process associated with the secondary process can be performed. In addition, during the registration process for registering the communication terminal 70 in the core network, the core network device 10 does not perform the secondary authentication process related to the communication terminal 70 that is determined to be unable to perform the process associated with the secondary process, and continues the process by considering whether the secondary authentication process is successful or failed. In this way, the time and processing load related to the secondary authentication process can be reduced.
[0082] For the communication terminal 70 determined to be unable to perform the process associated with the secondary process, the core network device 10 can determine whether the secondary authentication process is regarded as successful or failed for each network slice. For example, a certain S-NSSAI can be regarded as successful, while other S-NSSAIs can be regarded as failed.
[0083] In addition, the communication terminal 70 performs the communication method following the indication. First, during the registration process for registering the communication terminal in the core network, the communication terminal 70 generates the capability information indicating whether the process associated with the second authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slice can be performed. Then, the communication terminal 70 sends the capability information to the core network device.
[0084] Then, it will be described by using Figure 5 the process flow of the registration process related to the UE 80. The UE 80 corresponds to the communication terminal 70. First, the UE 80 sends a registration request message (S21) to the AMF 31. The registration request includes the requested NSSAI and the UE capability. The UE capability corresponds to the capability information indicating whether the UE 80 can perform the process associated with the secondary authentication process. The UE capability can be represented by the security capability or other manifestations.
[0085] Note that the AMF 31 can obtain the requested NSSAI and / or UE capabilities from messages other than the registration request message (S21). For example, in step S22, when the AMF 31 sends a NAS security mode command message to the UE 80, the UE 80 returns a NAS security mode complete message to the AMF 31 as a response to the NAS security mode command message. In this case, the UE 80 can set the requested NSSAI and / or UE capabilities in the NAS security mode complete message, and the AMF 31 can obtain the requested NSSAI and / or UE capabilities. Additionally, for example, before step S22, when the AMF 31 sends an identity request message to the UE 80, the UE 80 can return an identity response message to the AMF 31 as a response to the identity request message. In this case, the UE 80 can set the requested NSSAI and / or UE capabilities in the identity response message, and the AMF 31 can obtain the requested NSSAI and / or UE capabilities.
[0086] Furthermore, the AMF 31 can receive a message including the requested NSSAI and / or UE capabilities from any node device other than the UE 80, and can obtain the requested NSSAI and / or UE capabilities. For example, any node device can receive a message sent from the UE 80 that includes the requested NSSAI and / or UE capabilities. In this case, the AMF 31 can obtain the requested NSSAI and / or UE capabilities by receiving the message including the requested NSSAI and / or UE capabilities from any node device that has received the message.
[0087] Steps S22 to S27 are the same as steps S12 to S17 in Figure 3 and thus the detailed description thereof will be omitted.
[0088] Next, when the predetermined requirements are met, the AMF 31 performs the secondary authentication in step S28, and when the predetermined requirements are not met, the AMF 31 does not perform the secondary authentication in step S28. When the predetermined requirements are met, it can be indicated that the processing associated with the secondary authentication process can be performed, and the network slice to which the requested connection belongs is the network slice to which the secondary authentication is applied. When the predetermined requirements are not met, it may not be indicated that the processing associated with the secondary authentication process can be performed, or the network slice to which the requested connection belongs is not the network slice to which the secondary authentication is applied.
[0089] The AMF 31 that does not perform the secondary authentication can indicate that the authentication process using EAP is not performed. For example, the AMF 31 that does not perform the secondary authentication can indicate that a request message for requesting the user ID and password used in the network slice indicated by the S-NSSAI has not been sent from the AMF 31 to the UE 80.
[0090] In addition, the AMF 31 that does not perform secondary authentication may instruct the AMF 31 to return a registration rejection message including a specific cause code in response to a registration request message (S21). The specific cause code may be referred to as a specific 5GMM cause value. For example, the specific cause code may mean that the AMF 31 does not perform secondary authentication, or may mean that the AMF 31 determines that the UE 80 cannot perform the process associated with the secondary authentication process.
[0091] In addition, in the case of receiving a registration rejection message including such a specific cause code, the UE 80 may change the S-NSSAI included in the requested NSSAI and send a registration request message (S21). For example, the changed S-NSSAI may be a default S-NSSAI. Optionally, the UE 80 may select another PLMN different from the PLMN to which the registration request message is sent, change the PLMN, and send a registration request message (S21).
[0092] Figure 5 It is shown that in step S27, the AMF 31 checks whether the secondary authentication process is applied to the network slice indicated by each S-NSSAI included in the allowed NSSAI, but is not limited thereto. For example, the AMF 31 may check whether the secondary authentication process is applied to the network slice indicated by each subscribed S-NSSAI among the multiple subscribed S-NSSAIs received in step S24.
[0093] As described above, the UE 80 according to the third exemplary embodiment may send the UE capability indicating whether the process associated with the secondary authentication process can be performed to the AMF 31. In this way, the AMF 31 performs secondary authentication on the UE 80 only when the UE 80 can perform the process associated with the secondary authentication process. As a result, in the case where the UE 80 cannot perform the process associated with the secondary authentication, the time and processing load associated with the secondary authentication process can be reduced.
[0094] (Fourth Exemplary Embodiment)
[0095] Then, the process flow of the registration process related to the UE 90 will be described by using Figure 6 It is assumed that the UE 90 has the same structure as the Figure 4 communication terminal 70 shown.
[0096] First, the UE 90 sends a registration request message (S31) to the AMF 31. The registration request includes information related to a preferred network slice of the network slice to which the UE 90 accesses immediately after the registration process is completed. The preferred network slice may be referred to as a network slice with high urgency. The preferred network slice may be one, or may be two or more. For example, in the case where multiple S-NSSAIs are included in the requested NSSAI, the requested NSSAI may include an S-NSSAI indicating the preferred network slice and an S-NSSAI indicating a network slice that is not a preferred network slice. Immediately after the registration process is completed may be, for example, a timing before a predetermined period of time has elapsed after the registration process is completed.
[0097] Steps S32 to S37 are the same as steps S22 to S27 in Figure 5 and thus their detailed descriptions will be omitted.
[0098] Next, the AMF 31 performs secondary authentication on network slices that meet predetermined requirements, and does not perform secondary authentication on network slices that do not meet the predetermined requirements (S38).
[0099] For example, the AMF 31 performs secondary authentication on a network slice that is a preferred network slice and a network slice to which secondary authentication is applied in step S38. In this case, the AMF 31 does not perform secondary authentication on a network slice that is not a preferred network slice and is a network slice to which secondary authentication is applied in step S38. In other words, the AMF 31 does not perform secondary authentication in the registration process on a network slice that is not a preferred network slice and is a network slice to which secondary authentication is applied.
[0100] Secondary authentication for a network slice that is not a preferred network slice and is a network slice to which secondary authentication is applied may be performed when the UE 90 first accesses the network slice. In other words, secondary authentication for a network slice that is not a preferred network slice and is a network slice to which secondary authentication is applied may be performed when a PDU session is established between the UE 90 and the network slice.
[0101] In addition, as Figure 5 described, in the case where the UE 90 sends UE capabilities and information related to the preferred network slice to the AMF 31, the AMF 31 may perform secondary authentication according to the following requirements. For example, in the case where the UE 90 can perform processing associated with secondary authentication, the AMF 31 may perform secondary authentication on a network slice that is a preferred network slice and to which secondary authentication is applied. In other words, in the case where the UE 90 cannot perform processing associated with secondary authentication, the AMF 31 may not perform secondary authentication related to the UE 90 on a network slice that is a preferred network slice and to which secondary authentication is applied.
[0102] As described above, the UE 90 according to the fourth exemplary embodiment may send information indicating a preferred network slice to the AMF 31. In this way, the AMF 31 may perform secondary authentication only for the preferred network slice without performing secondary authentication for all network slices related to the network slice determined to have applied secondary authentication in step S37. As a result, compared with the case where the AMF 31 performs secondary authentication for all network slices, when the AMF 31 performs secondary authentication only for the preferred network slice, the time related to secondary authentication can be reduced, and the processing load related to the secondary authentication process can also be reduced.
[0103] (Fifth Exemplary Embodiment)
[0104] Then, the process flow of the authentication process during PDU session establishment according to the fifth exemplary embodiment will be described by using Figure 7 . In Figure 7 , the process flow in the communication system described in Figure 2 will be described. When the secondary authentication process in the registration process and the authentication process during PDU session establishment are performed independently, the following problems occur.
[0105] The authentication process during PDU session establishment is initiated by the SMF. At this time, when the SMF does not recognize that the secondary authentication process of the UE in a specific network slice has been performed in the registration process, the SMF performs the secondary authentication process of the UE in the specific network slice during PDU session establishment. Therefore, the problem of overlapping secondary authentication processes during the registration process and PDU session establishment occurs.
[0106] Therefore, in the fifth exemplary embodiment, the AMF 31 notifies the V-SMF 32 or H-SMF 45 of information related to the network slice for which secondary authentication has been performed. In this way, the overlapping secondary authentication process during the registration process and PDU session establishment is avoided.
[0107] First, the UE 20 sends a NAS message (S41) including a PDU session establishment request to the AMF 31. The PDU session establishment request includes an S-NSSAI indicating that the network slice is the connection destination.
[0108] Next, the AMF 31 selects the V-SMF 32 and sends an Nsmf_PDUSession_CreateSMContext request (S42) to the V-SMF 32. An Nsmf_PDUSession_UpdateSMContext request may be sent instead of the Nsmf_PDUSession_CreateSMContext request.
[0109] The Nsmf_PDUSession_CreateSMContext request includes the subscription permanent identifier (SUPI) of the UE 20, the S-NSSAI, and a flag indicating that the authentication process of the UE 20 in the network slice indicated by the S-NSSAI has been performed. The S-NSSAI is the S-NSSAI included in the message received in step S41. The AMF 31 includes the flag in the Nsmf_PDUSession_CreateSMContext request and thus notifies the V-SMF 32 that the secondary authentication of the UE 20 in a specific network slice has been performed.
[0110] Next, the V-SMF 32 sends an Nsmf_PDUSession_CreateSMContext response to the AMF 31 as a response to the Nsmf_PDUSession_CreateSMContext request (S43).
[0111] Next, the V-SMF 32 sends the Nsmf_PDUSession_CreateSMContext request received in step S42 to the H-SMF 45 (S44). The H-SMF 45 can determine whether the secondary authentication process of the UE 20 in the network slice indicated by the S-NSSAI has been performed by receiving the Nsmf_PDUSession_CreateSMContext request.
[0112] Next, the H-SMF 45 obtains subscriber data corresponding to the SUPI included in the Nsmf_PDUSession_CreateSMContext request from the UDM 41 (S45).
[0113] Next, in the case where the flag is not included in the Nsmf_PDUSession_CreateSMContext request, the H-SMF 45 starts the EAP authentication to perform the secondary authentication process related to the UE 20 (S46). On the other hand, in the case where the flag is included in the Nsmf_PDUSession_CreateSMContext request, the H-SMF 45 determines that the authentication process related to the UE 20 has been performed and does not start the EAP authentication in step S46.
[0114] Then, it will be described by using Figure 8 to illustrate the process of the authentication process during PDU session establishment according to the fifth exemplary embodiment, which is different from that in Figure 7 .
[0115] First, an N4 session is established between the V-SMF 32 and the UPF 33 (S51). Next, the V-SMF 32 sends an authentication / authorization request to the AAA server 51 via the UPF 33 (S52). Next, the AAA server 51 sends an authentication / authorization response to the V-SMF 32 via the UPF 33 (S53). Next, the V-SMF 32 sends a Namf_Communication_N1N2Message transfer including the authentication message sent from the AAA server 51 to the AMF 31 (S54).
[0116] Next, the AMF 31 sends a response as a response to the Namf_Communication_N1N2Message transfer to the V-SMF 32 (S55). The AMF 31 includes in this response a flag indicating that the secondary authentication process of the UE 20 in the network slice to which the UE 20 needs to connect has been performed.
[0117] Next, the AMF 31 sends an NAS SM transfer including an authentication message to the UE 20 (S56). Next, the UE 20 sends an NAS SM transfer including an authentication message to the AMF 31 (S57). Next, the AMF 31 sends an Nsmf_PDUSession_UpdateSMContext including an authentication message to the V-SMF 32 (S58). Next, the V-SMF 32 sends a response to the AMF 31 (S59).
[0118] Here, in the case where the V-SMF 32 has not received the flag indicating that the secondary authentication process of the UE 20 has been performed in step S55, the V-SMF 32 sends an authentication / authorization request to the AAA server 51 via the UPF 33 (S60). The authentication / authorization request includes an authentication message. After the AAA server 51 performs the authentication process of the UE 20 in a specific network slice, the AAA server 51 sends an authentication / authorization response to the V-SMF 32 via the UPF 33 (S61).
[0119] In step S55, in the case where the V-SMF 32 has received the flag indicating that the secondary authentication process of the UE 20 in the network slice to which the UE 20 needs to connect has been performed, the processing after step S60 is not performed.
[0120] In Figure 8In [description], the processing of including a flag in the response of step S55 is described, but the flag may be included in Nsmf_PDUSession_UpdateSMContext in step S58. Optionally, the AMF 31 may send the flag to the V-SMF 32 or H-SMF 45 independently of the PDU session establishment processing after the registration processing instead of during the PDU session establishment. In this case, the V-SMF 32 or H-SMF 45 may not perform and may omit the processing after S52.
[0121] As described above, the AMF 31 may notify the V-SMF 32 or H-SMF 45 of information related to the performed secondary authentication processing. As a result, it is possible to avoid performing the secondary authentication processing in an overlapping manner during the registration processing and the PDU session establishment. In this way, the time related to the secondary authentication can be reduced, and the processing load related to the secondary authentication processing can also be reduced.
[0122] Note that the present invention is not limited to the above-described exemplary embodiments, and appropriate modifications can be made without departing from the scope of the present invention.
[0123] Then, the structural examples of the core network device 10, AMF 31, SMF, communication terminal 70, UE 20, UE 80, and UE 90 described in the above-described multiple exemplary embodiments will be described below.
[0124] Figure 9 is a block diagram showing the structural examples of the communication terminal 70, UE 20, UE 80, and UE 90. The radio frequency (RF) transceiver 1101 performs analog RF signal processing for communicating with the base station. The analog RF signal processing performed by the RF transceiver 1101 includes upconversion, downconversion, and amplification. The RF transceiver 1101 is coupled to the antenna 1102 and the baseband processor 1103. In other words, the RF transceiver 1101 receives modulated symbol data (or OFDM symbol data) from the baseband processor 1103, generates a transmission RF signal, and supplies the transmission RF signal to the antenna 1102. In addition, the RF transceiver 1101 generates a baseband received signal based on the received RF signal received by the antenna 1102 and supplies the baseband received signal to the baseband processor 1103.
[0125] The baseband processor 1103 performs digital baseband signal processing (data plane processing) and control plane processing for wireless communication. The digital baseband signal processing includes (a) data compression / decompression, (b) segmentation / cascading of data, and (c) generation / decomposition of a transmission format (transmission frame). In addition, the digital baseband signal processing includes (d) transmission path encoding / decoding, (e) modulation (symbol mapping) / demodulation, and (f) generation of OFDM symbol data (baseband OFDM signal) by inverse fast Fourier transform (IFFT), etc. On the other hand, the control plane processing includes communication management of layer 1 (e.g., transmission power control), layer 2 (e.g., radio resource management and hybrid automatic repeat request (HARQ) processing), and layer 3 (e.g., attachment, mobility, and signaling related to call management).
[0126] For example, in the case of LTE and 5G, the digital baseband signal processing of the baseband processor 1103 may include signal processing of the packet data convergence protocol (PDCP) layer, radio link control (RLC) layer, MAC layer, and physical layer. In addition, the control plane processing of the baseband processor 1103 may include processing of the non-access stratum (NAS) protocol, RRC protocol, and MAC CE.
[0127] The baseband processor 1103 may include a modulation / demodulation processor (e.g., a digital signal processor (DSP)) that performs digital baseband signal processing and a protocol stack processor (e.g., a central processing unit (CPU) or a microprocessing unit (MPU)) that performs control plane processing. In this case, the protocol stack processor that performs control plane processing may be common with the application processor 1104 described later.
[0128] The application processor 1104 is also referred to as a CPU, MPU, microprocessor, or processor core. The application processor 1104 may include multiple processors (multiple processor cores). The application processor 1104 implements various functions of the communication terminals 70, UE 20, UE 80, and UE 90 by executing a system software program (operating system (OS)) read from the memory 1106 or a memory not shown. Alternatively, the application processor 1104 implements various functions of the communication terminals 70, UE 20, UE 80, and UE 90 by executing various application programs read from the memory 1106 or a memory not shown. The application programs may be, for example, a call application, a web browser, a mail program, a camera operation application, or a music reproduction application.
[0129] In some installations, such as Figure 9As indicated by the dashed line (1105) in [the figure], the baseband processor 1103 and the application processor 1104 can be integrated on a single chip. In other words, the baseband processor 1103 and the application processor 1104 can be installed as a system-on-chip (SoC) device 1105. The SoC device can also be referred to as a system large-scale integration (LSI) or a chipset.
[0130] The memory 1106 is a volatile memory, a non-volatile memory, or a combination of a volatile memory and a non-volatile memory. The memory 1106 can include a plurality of physically independent memory devices. The volatile memory is, for example, a static random access memory (SRAM), a dynamic RAM (DRAM), or a combination of SRAM and DRAM. The non-volatile memory is a mask read-only memory (MROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, a hard disk drive, or any combination of MROM, EEPROM, flash memory, and hard disk drive. For example, the memory 1106 can include an external memory device accessible from the baseband processor 1103, the application processor 1104, and the SoC 1105. The memory 1106 can include a built-in memory device integrated in the baseband processor 1103, the application processor 1104, or the SoC 1105. In addition, the memory 1106 can include the memory in a universal integrated circuit card (UICC).
[0131] The memory 1106 can store software modules (computer programs) including command groups and data for performing the processing of the communication terminals 70, UEs 20, 80, and 90 illustrated in the above-described multiple exemplary embodiments. In some installations, the baseband processor 1103 or the application processor 1104 can be configured to perform the processing illustrated in the above-described exemplary embodiments by reading the software modules from the memory 1106 and executing the software modules.
[0132] Figure 10 is a block diagram showing a structural example of the core network device 10, the AMF 31, and the SMF. Refer to Figure 10 , the core network device 10, the AMF 31, and the SMF include a network interface 1201, a processor 1202, and a memory 1203. The network interface 1201 is used to communicate with other network node devices constituting the communication system. The network interface 1201 can, for example, include a network interface card (NIC) conforming to the IEEE 802.3 series.
[0133] The processor 1202 performs the processing of the core network device 10, the AMF 31, and the SMF described by using the sequence diagrams and flowcharts in the above exemplary embodiments by reading software (computer program) from the memory 1203 and executing the software. The processor 1202 may be, for example, a microprocessor, a microprocessing unit (MPU), or a central processing unit (CPU). The processor 1202 may include a plurality of processors.
[0134] The memory 1203 is composed of a combination of a volatile memory and a non-volatile memory. The memory 1203 may include a memory configured away from the processor 1202. In this case, the processor 1202 may access the memory 1203 via an I / O interface (not shown).
[0135] In Figure 10 the example, the memory 1203 is used to store a group of software modules. The processor 1202 may perform the processing of the core network device 10, the AMF 31, and the SMF described in the above exemplary embodiments by reading the group of software modules from the memory 1203 and executing the group of software modules.
[0136] As described by using Figure 10 each processor included in the core network device 10, the AMF 31, and the SMF executes one or more programs including a command group for causing a computer to perform the algorithms described by using the drawings.
[0137] In the above example, programs are stored by using various types of non-transitory computer-readable media, and the programs may be supplied to a computer. Non-transitory computer-readable media include various types of tangible storage media. Examples of non-transitory computer-readable media include magnetic recording media, magneto-optical recording media (e.g., optical disks), CD-ROM (read-only memory), CD-R, CD-R / W, and semiconductor memories. The magnetic recording media may be, for example, floppy disks, magnetic tapes, and hard disk drives. The semiconductor memories may be, for example, mask ROM, programmable ROM (PROM), erasable PROM (EPROM), flash ROM, and random access memory (RAM). In addition, programs may be supplied to a computer by various types of transitory computer-readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable media may supply programs to a computer via a wired communication path such as wires and optical fibers or a wireless communication path.
[0138] The user equipment (UE) (or including a mobile station, a mobile terminal, a mobile device, or a wireless device, etc.) in this specification is an entity connected to a network via a wireless interface.
[0139] The UE in this specification is not limited to dedicated communication devices and can be any device as follows (including the communication functions described in this specification as those of the UE).
[0140] Each of the terms "user equipment (UE) (as used in 3GPP)", "mobile station", "mobile terminal", "mobile device", and "wireless terminal" is intended to be generally synonymous with each other and can be an independent mobile station such as a terminal, cellular phone, smart phone, tablet computer, cellular IoT terminal, and IoT device, etc.
[0141] Note that it can be understood that the terms "UE" and "wireless terminal" also include devices that are stationary for a long time.
[0142] In addition, the UE can be, for example, a production facility, manufacturing facility, and / or energy-related machine (e.g., boiler, engine, turbine, solar panel, wind turbine, hydroelectric generator, thermal power generator, nuclear power generator, storage battery, nuclear power system, nuclear power-related equipment, heavy electrical equipment, pumps including vacuum pumps, etc., compressor, fan, hair dryer, hydraulic equipment, pneumatic equipment, metalworking machine, manipulator, robot, robot application system, tool, die, roller, conveying device, lifting device, freight device, textile machine, sewing machine, printer, printing-related machine, paper-making machine, chemical machine, mining machine, mining-related machine, construction machine, construction-related machine, agricultural machine and / or implement, forestry machine and / or implement, fishery machine and / or implement, safety and / or environmental protection implement, tractor, bearing, precision bearing, chain, gear, power transmission device, lubrication device, valve, pipe fitting, and / or application system of any of the above devices or machines).
[0143] In addition, the UE can be, for example, a transportation device (e.g., vehicle, automobile, two-wheeled vehicle, bicycle, train, bus, bicycle cart, rickshaw, ship and other water transportation tools, airplane, rocket, satellite, drone, and balloon, etc.).
[0144] In addition, the UE can be, for example, an information and communication device (e.g., electronic computer and related devices, communication devices and related devices, and electronic components, etc.).
[0145] In addition, the UE can be, for example, a refrigerator, refrigerator application products and devices, commercial and service equipment, vending machine, self-service machine, office machines and devices, household electrical and electronic machinery and equipment (e.g., voice equipment, speaker, radio, video equipment, television, multifunctional microwave oven, rice cooker, coffee maker, dishwasher, dryer, fan, ventilation fan and related products, and vacuum cleaner, etc.).
[0146] In addition, the UE may be, for example, an electronic application system or an electronic application device (e.g., an X-ray device, a particle accelerator device, a radioactive substance application device, an acoustic wave application device, an electromagnetic application device, and an electric power application device, etc.).
[0147] In addition, the UE may be, for example, a light bulb, lighting, a weighing machine, an analysis device, a testing machine, and a measuring machine (e.g., a smoke alarm, a human alarm sensor, a motion sensor, and a wireless tag, etc.), a watch or a clock, a physical and chemical machine, an optical machine, a medical device and / or a medical system, a weapon, tableware or a hand tool, etc.
[0148] In addition, the UE may be, for example, a personal digital assistant or a device including a wireless communication function (e.g., an electronic device (such as a personal computer and an electronic measuring instrument, etc.) to which a wireless card and a wireless module, etc. are attached or inserted).
[0149] In addition, the UE may be, for example, a device or a part of the device that provides the following applications, services, and solutions in the "Internet of Things (IoT)" using wired and wireless communication technologies.
[0150] IoT devices (or things) include appropriate electronic devices, software, sensors, and network connections, etc. that enable data collection and data exchange between devices and with other communication devices.
[0151] In addition, the IoT device may be an automated device that follows software instructions stored in an internal memory.
[0152] In addition, the IoT device may operate without human supervision or processing.
[0153] In addition, the IoT device may be a device that is equipped for a long time and / or remains inactive for a long time.
[0154] In addition, the IoT device may be installed as a part of a stationary device. The IoT device may be embedded in a non-stationary device (such as a vehicle, etc.), or may be attached to animals and people to be monitored / tracked.
[0155] It can be understood that IoT technology can be installed on any communication device that can be connected to a communication network, and the communication network sends and receives data independently of human input or software commands stored in a memory.
[0156] It can be understood that the IoT device may be referred to as a machine type communication (MTC) device, a machine-to-machine (M2M) communication device, or a narrowband IoT (NB-IoT) UE.
[0157] In addition, it can be understood that the UE may support one or more IoT or MTC applications.
[0158] Some examples of MTC applications are listed in the following table (Source: Appendix B of 3GPP TS22.368 V13.2.0 (January 13, 2017), the content of which is incorporated herein by reference). This list is not exhaustive and indicates MTC applications, for example.
[0159]
[0160]
[0161] Applications, services, and solutions can be, for example, mobile virtual network operator (MVNO) services / systems, disaster prevention wireless services / systems, private wireless telephone (private branch exchange (PBX)) services / systems, PHS / digital cordless telephone services / systems, point of sale (POS) systems, advertising delivery services / systems, multicast (multimedia broadcast and multicast services (MBMS)) services / systems, vehicle-to-everything (V2X: vehicle-to-vehicle communication and road-to-vehicle and pedestrian-to-vehicle communication) services / systems, train mobile wireless services / systems, location information-related services / systems, disaster / emergency wireless community services / systems, Internet of Things (IoT) services / systems, communication services / systems, video distribution services / systems, femtocell application services / systems, LTE voice (VoLTE) services / systems, wireless tag services / systems, billing services / systems, radio-on-demand services / systems, roaming services / systems, user behavior monitoring services / systems, communication operator / communication NW selection services / systems, function restriction services / systems, proof of concept (PoC) services / systems, terminal-specific personal information management services / systems, terminal-specific display and video services / systems, terminal-specific non-communication services / systems, and ad hoc NW / delay tolerant network (DTN) services / systems, etc.
[0162] Note that the categories of UEs described above are merely application examples of the technical ideas and exemplary embodiments described in this specification. The present invention is not limited to these examples, and of course, those skilled in the art can make various modifications.
[0163] Although the invention of this application has been described with exemplary embodiments, the invention of this application is not limited to the above exemplary embodiments. Various modifications understandable to those skilled in the art can be made to the structure and details of the invention of this application within the scope of the present invention.
[0164] This application is based on and claims the benefit of the priority of Japanese Patent Application No. 2018-185420 filed on September 28, 2018, the entire disclosure of which is incorporated herein by reference.
[0165] Part or all of the above exemplary embodiments can also be as described in the following supplementary explanations, but are not limited thereto.
[0166] (Supplementary Explanation 1)
[0167] A core network device, comprising:
[0168] A first authentication component, configured to perform a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network;
[0169] A communication component, configured to receive permission list information indicating at least one network slice that can be used by the communication terminal in the serving network; and
[0170] A second authentication component, configured to perform a second authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slices included in the permission list information during a registration process for registering the communication terminal in the core network.
[0171] (Supplementary Explanation 2)
[0172] The core network device according to Supplementary Explanation 1, wherein, in the case where a plurality of the network slices are included in the permission list information, the second authentication component is configured to determine whether it is necessary to perform the second authentication process in each network slice and perform the second authentication process for each network slice that requires the second authentication process.
[0173] (Supplementary Explanation 3)
[0174] The core network device according to Supplementary Explanation 1 or 2, wherein the communication component is configured to send identification information related to the communication terminal used when the communication terminal uses the network slice to an authentication server associated with the network slice.
[0175] (Supplementary Explanation 4)
[0176] The core network device according to Supplementary Explanation 3, wherein the communication component is configured to obtain identification information related to the communication terminal from the communication terminal for each network slice included in the permission list information.
[0177] (Supplementary Explanation 5)
[0178] The core network device according to any one of Supplementary Descriptions 1 to 4, wherein, when the second authentication component is configured to perform the second authentication process during the registration process in which the communication terminal registers the communication terminal in the core network via the first access network, the second authentication component is configured to omit the second authentication process during the registration process in which the communication terminal registers the communication terminal in the core network via the second access network.
[0179] (Supplementary Description 6)
[0180] The core network device according to any one of Supplementary Descriptions 1 to 5, wherein, when the second authentication component is configured to determine that the communication terminal is not a communication terminal permitted to use the network slice included in the permission list information, the second authentication component is configured to notify the communication terminal of identification information related to a predetermined network slice.
[0181] (Supplementary Description 7)
[0182] A core network device, comprising:
[0183] A communication component, configured to receive, during a registration process for registering a communication terminal in a core network, a registration request message from the communication terminal, the registration request message including information indicating whether the communication terminal supports slice-specific authentication and authorization; and
[0184] An authentication component, configured to perform processing related to the slice-specific authentication and authorization when the information indicates that the communication terminal supports slice-specific authentication and authorization.
[0185] (Supplementary Description 8)
[0186] The core network device according to Supplementary Description 7, wherein the authentication component is configured not to perform processing related to the slice-specific authentication and authorization when the information indicates that the communication terminal does not support slice-specific authentication and authorization.
[0187] (Supplementary Description 9)
[0188] The core network device according to Supplementary Description 7 or 8, wherein, when the authentication component is configured not to perform processing related to the slice-specific authentication and authorization, the communication component is configured to send a registration rejection message including a specific cause code to the communication terminal in response to the registration request message.
[0189] (Supplementary Description 10)
[0190] A communication terminal, comprising:
[0191] A communication component for sending a registration request message including information indicating whether a communication terminal supports slice-specific authentication and authorization to a core network device.
[0192] (Supplementary Note 11)
[0193] The communication terminal according to Supplementary Note 10, wherein, when the communication terminal does not support the slice-specific authentication and authorization, the core network device receiving the registration request message does not perform processing related to the slice-specific authentication and authorization.
[0194] (Supplementary Note 12)
[0195] The communication terminal according to Supplementary Note 10 or 11, wherein, when the core network device is configured not to perform processing related to the slice-specific authentication and authorization, the communication component is configured to receive a registration rejection message including a specific cause code from the core network device in response to the registration request message.
[0196] (Supplementary Note 13)
[0197] A core network device, comprising:
[0198] A first authentication component for performing a first authentication process to determine whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network;
[0199] A communication component for receiving information related to a plurality of network slices desired to be used and information related to a network slice preferentially used among the plurality of network slices from the communication terminal; and
[0200] A second authentication component for performing a second authentication process to determine whether the communication terminal is a communication terminal permitted to use the preferentially used network slice during the registration process for registering the communication terminal in the core network.
[0201] (Supplementary Note 14)
[0202] The core network device according to Supplementary Note 13, wherein the second authentication component is configured to perform the second authentication process when the communication terminal first uses a network slice for which the second authentication process has not been performed after the registration process is completed.
[0203] (Supplementary Note 15)
[0204] A communication terminal, comprising:
[0205] A communication component, configured to send information related to a plurality of network slices expected to be used and information related to a network slice preferentially used among the plurality of network slices to a core network device during a registration process for registering a communication terminal in the core network.
[0206] (Supplementary Note 16)
[0207] The communication terminal according to Supplementary Note 15, wherein the communication component is configured to include information related to the network slice preferentially used and information related to a network slice different from the network slice preferentially used in a registration request message, and send the registration request message.
[0208] (Supplementary Note 17)
[0209] A communication system, comprising:
[0210] A first core network device, configured to perform a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network, perform a second authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice during the registration process for registering the communication terminal in the core network, and send information indicating the network slice for which the second authentication process is to be performed; and
[0211] A second core network device, configured to receive the information indicating the network slice for which the second authentication process is to be performed, determine whether to perform the second authentication process related to the communication terminal when the communication terminal first uses the network slice after the registration process is completed, perform the second authentication process when the second authentication process has not been performed, and not perform the second authentication process when the second authentication process has been performed.
[0212] (Supplementary Note 18)
[0213] The communication system according to Supplementary Note 17, wherein the first core network device sends the information indicating the network slice for which the second authentication process is to be performed during a PDU session establishment process.
[0214] (Supplementary Note 19)
[0215] An authentication method in a core network device, the authentication method comprising:
[0216] Performing a first authentication process for determining whether the communication terminal is a communication terminal permitted to be registered in the core network during a registration process for registering the communication terminal in the core network;
[0217] Receive permission list information indicating at least one network slice that can be used by the communication terminal in the service network; and
[0218] During the registration process for registering the communication terminal in the core network, perform a second authentication process for determining whether the communication terminal is a communication terminal permitted to use the network slices included in the permission list information.
[0219] (Supplementary Note 20)
[0220] A communication method in a communication terminal, the communication method comprising:
[0221] During the registration process for registering a communication terminal in a core network, generate capability information indicating whether a process associated with a second authentication process for determining whether the communication terminal is a communication terminal permitted to use a network slice can be performed; and
[0222] Send the capability information to a core network device.
[0223] List of reference numerals
[0224] 10 Core network device
[0225] 11 Authentication unit
[0226] 12 Authentication unit
[0227] 13 Communication unit
[0228] 20 UE
[0229] 30 Serving PLMN
[0230] 31 AMF
[0231] 32 V-SMF
[0232] 33 UPF
[0233] 40 HPLMN
[0234] 41 UDM
[0235] 42 AUSF
[0236] 43 NSSF
[0237] 44 NEF
[0238] 45 H-SMF
[0239] 46 UPF
[0240] 50 Third-party network
[0241] 51 AAA Server
[0242] 60 Network Slice
[0243] 70 Communication Terminal
[0244] 71 Control Unit
[0245] 72 Communication Unit
[0246] 80 UE
[0247] 90 UE
Claims
1. A method in a user equipment (UE), the method comprising: Sending a registration request message to a core network device operating as an Access Management Function (AMF), the registration request message including a Request Network Slice Selection Assistance Information (Request NSSAI) and information indicating whether the UE supports slice-specific authentication and authorization.
2. The method according to claim 1, further comprising: Receiving, from the core network device, a rejection message including a cause value, based on the Request NSSAI for a network slice for which slice-specific authentication and authorization is not indicated.
3. A method in a core network device operating as an Access Management Function (AMF), the method comprising: Receiving a registration request message from a user equipment (UE), the registration request message including a Request Network Slice Selection Assistance Information (Request NSSAI) and information indicating whether the UE supports slice-specific authentication and authorization, Wherein, based on the information indicating that the UE supports the slice-specific authentication and authorization, triggering a process related to the slice-specific authentication and authorization, and Wherein, based on the information indicating that the UE does not support the slice-specific authentication and authorization, not triggering a process related to the slice-specific authentication and authorization.
4. The method according to claim 3, further comprising: Sending, to the UE, a rejection message including a cause value, based on the Request NSSAI for a network slice for which slice-specific authentication and authorization is not indicated.
5. A user equipment (UE) comprising: A sending component for sending a registration request message to a core network device operating as an Access Management Function (AMF), the registration request message including a Request Network Slice Selection Assistance Information (Request NSSAI) and information indicating whether the UE supports slice-specific authentication and authorization.
6. A core network device operating as an Access Management Function (AMF) comprising: A receiving component for receiving a registration request message from a user equipment (UE), the registration request message including a Request Network Slice Selection Assistance Information (Request NSSAI) and information indicating whether the UE supports slice-specific authentication and authorization, Wherein, based on the information indicating that the UE supports the slice-specific authentication and authorization, triggering a process related to the slice-specific authentication and authorization, and Wherein, based on the information indicating that the UE does not support the slice-specific authentication and authorization, not triggering a process related to the slice-specific authentication and authorization.
Citation Information
Patent Citations
Circulating body driving device, image forming apparatus, circulating body position adjustment method, and circulating body position adjustment program
JP2018185420A