Communication method and communication apparatus

By receiving messages from terminal devices and obtaining authentication and subscription information and security context information, the problem of service interruption caused by core network element failures or link failures was solved, and the normal operation of terminal devices was realized.

CN120343548BActive Publication Date: 2025-12-30XIAN RUIXIN TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510552126.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-12-30
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

When core network elements or links fail, terminal devices cannot register normally, resulting in service interruption.

Method used

By receiving messages from terminal devices, the roaming status is determined, and a request is sent to the second network element to obtain authentication and subscription information and security context information, ensuring that re-registration and authentication can be performed in the event of network failure.

Benefits of technology

In the event of a core network element failure or a link failure, ensure that the services of the terminal equipment can operate normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343548B_ABST
    Figure CN120343548B_ABST
Patent Text Reader

Abstract

The application provides a communication method and a communication device, and applies to the technical field of communication. The communication method comprises the following steps: a core network element of a daily main plane determines whether a terminal device is roaming, out of roaming, or located in a special area; if it is determined that the terminal device is roaming, out of roaming, or located in a special area, the terminal device is migrated to a core network element of an escape platform, so that the core network element of the escape platform acquires authentication and subscription information and / or security context information of the terminal device, or exports the authentication and subscription information and / or the security context information of the terminal device to the core network element of the escape platform. The embodiment of the application can ensure that the service of the terminal device can normally operate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to communication methods and communication devices. Background Technology

[0002] In communication technology, core network elements can register terminal devices. However, when the primary and backup core network elements fail, or when the related links between the primary and backup core network elements fail, they may be unable to register terminal devices, resulting in the inability of terminal devices to operate normally. Therefore, ensuring the normal operation of terminal devices' services has become one of the urgent problems to be solved. Summary of the Invention

[0003] This application provides a communication method and a communication device, which helps ensure that the services of terminal equipment can operate normally.

[0004] Firstly, this application provides a communication method that can be applied to a first network element. The first network element can be a first network element itself, or a processor, module, chip, chip system, or functional module of the first network element used to implement the method. The method includes: receiving a first message from a terminal device, the first message requesting processing of the terminal device, the first message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device, the first message being used to determine that the terminal device is roaming; and sending a second message to a second network element, the second message requesting registration and / or authentication subscription of the terminal device, the second message including the PLMN of the terminal device and / or the identifier of the terminal device.

[0005] Based on the method described in the first aspect, after receiving a first message from a terminal device, the first network element can determine that the terminal device is roaming based on the first message, and then send a second message to the second network element. Upon receiving the second message, the second network element can register and / or authenticate the terminal device, allowing it to obtain the terminal device's authentication and / or security context information. This way, in the event of a future network failure, such as a failure of the terminal device's home network element or a link failure, the second network element can re-register and / or re-authenticate the terminal device based on the obtained authentication and / or security context information, thus ensuring the normal operation of the terminal device's services. For example, the first and second network elements can be access and mobility management functions (AMF) or mobility management entities (MME), etc.; the terminal device's home network element can be a unified data management (UDM) or a home subscriber server (HSS), etc.

[0006] Secondly, this application provides a communication method that can be applied to a first network element side. The first network element side can be a first network element itself, or a processor, module, chip, chip system, or functional module of the first network element used to implement the method. The method includes: receiving a first message from a terminal device, the first message being used to request processing of the terminal device, the first message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device, the first message being used to determine that the terminal device is roaming; obtaining authentication and subscription information and / or security context information of the terminal device; and sending a third message to a third network element, the third message including the authentication and subscription information and / or security context information of the terminal device.

[0007] Based on the method described in the second aspect, after receiving a first message from a terminal device, the first network element can determine that the terminal device is roaming based on the first message, thereby obtaining the authentication and subscription information and / or security context information of the terminal device, and sending a third message to the third network element to export the obtained authentication and subscription information and / or security context information of the terminal device to the third network element. In this way, in the event of a future network failure, such as a failure of the terminal device's home network element or a failure of the home network element link, the second network element can re-register and / or authenticate the terminal device based on the authentication and subscription information and / or security context information of the terminal device stored in the third network element, thereby helping to ensure the normal operation of the terminal device's services. For example, the first and second network elements can be AMF or MME, etc.; the third network element can be UDM, HSS, or other devices used for data caching (such as a data caching center), etc.; the home network element of the terminal device can be the terminal device's home UDM or HSS, etc.

[0008] In conjunction with the second aspect, in one possible implementation, the specific implementation of obtaining the authentication and subscription information and / or security context information of the terminal device includes: receiving the authentication and subscription information of the terminal device from a fourth network element, wherein the fourth network element is the home network element of the terminal device.

[0009] Thirdly, this application provides a communication method that can be applied to a fourth network element. The fourth network element can be a fourth network element itself, or a processor, module, chip, chip system, or functional module of the fourth network element used to implement the method. The method includes: receiving a fourth message from a first network element, the fourth message being used to request authentication and subscription information of a terminal device, the fourth message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device, the fourth message being used to determine that the terminal device is roaming out, and the fourth network element being the home network element of the terminal device; and sending a fifth message to a third network element, the fifth message including the authentication and subscription information of the terminal device.

[0010] Based on the method described in the third aspect, after receiving the fourth message from the first network element, the fourth network element can determine, according to the fourth message, that the terminal device has roamed out of the province where the fourth network element is located, and then send a fifth message to the third network element to export the authentication and subscription information of the terminal device to the third network element. In this way, in the event of a future network failure, such as a failure of the terminal device's home network element or a failure of the home network element link, the second network element can re-register and / or authenticate the terminal device based on the authentication and subscription information and / or security context information of the terminal device stored in the third network element, thereby helping to ensure the normal operation of the terminal device's services. For example, the first and second network elements can be AMF or MME, etc.; the third network element can be UDM, HSS, or other devices used for data caching (such as a data caching center), etc.; the home network element of the terminal device (i.e., the fourth network element) can be the terminal device's home UDM or HSS, etc.

[0011] Fourthly, this application provides a communication method that can be applied to a fourth network element. The fourth network element can be a fourth network element itself, or a processor, module, chip, chip system, or functional module of the fourth network element used to implement the method. The method includes: receiving a fourth message from a first network element, the fourth message being used to request authentication and subscription information of the terminal device, the fourth message including information about the area where the terminal device is located, the fourth message being used to determine that the area where the terminal device is located is a first area outside the service area of ​​the fourth network element of the terminal device, and the fourth network element being the home network element of the terminal device; and sending a fifth message to a third network element, the fifth message including the authentication and subscription information of the terminal device.

[0012] Based on the method described in the fourth aspect, after receiving the fourth message from the first network element, the fourth network element can determine that the terminal device is located in the first area based on the fourth message, and then send a third message to the third network element to export the authentication and subscription information of the terminal device to the third network element. In this way, in the event of a future network failure, such as a failure of the terminal device's home network element or a link failure between the home network element and the first area, the second network element can re-register and / or authenticate the terminal device based on the authentication and subscription information stored in the third network element, thereby helping to ensure the normal operation of the terminal device's services. For example, the first area can be a pre-determined area prone to service interruption, such as an island area. The first and second network elements can be AMF or MME, etc.; the third network element can be UDM, HSS, or other devices used for data caching (such as a data caching center), etc.; the terminal device's home network element (i.e., the fourth network element) can be the terminal device's home UDM or HSS, etc.

[0013] Fifthly, this application provides a communication method that can be applied to a second network element side. The second network element side can be a second network element itself, or a processor, module, chip, chip system, or functional module of the second network element used to implement the method. The method includes: receiving a second message from a first network element, the second message being used to request registration and / or authentication and subscription for the terminal device, the second message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device; obtaining authentication and subscription information and / or security context information of the terminal device; storing the authentication and subscription information and / or security context information of the terminal device; after the terminal device deregisters, receiving a sixth message from the terminal device, the sixth message being used to request registration and / or authentication and subscription for the terminal device, the sixth message including the PLMN of the terminal device and / or the identifier of the terminal device, the sixth message being used to determine the roaming status of the terminal device and the home network element of the terminal device; and, in the event of a failure of the home network element or a link failure between the home network element and the second network element, registering and / or authenticating and subscribing to the terminal device based on the authentication and subscription information and / or security context information of the terminal device.

[0014] Based on the method described in the fifth aspect, the second network element can obtain and store the authentication and / or security context information of the terminal device after receiving the second message from the first network element. This allows the second network element to re-register and / or authenticate the terminal device based on the stored authentication and / or security context information when the terminal device's home network element fails or the link between the home network element and the second network element fails, thereby ensuring the normal operation of the terminal device's services. For example, the first and second network elements can be AMF or MME, etc.; the terminal device's home network element can be the terminal device's home UDM or HSS, etc.

[0015] In conjunction with the fifth aspect, in one possible implementation, the specific implementation of obtaining the authentication and signing information and / or security context information of the terminal device mentioned above includes: receiving authentication and signing information from the home network element.

[0016] Sixthly, this application provides a communication method that can be applied to a second network element side. The second network element side can be a second network element itself, or a processor, module, chip, chip system, or functional module of the second network element used to implement the method. The method includes: after a terminal device deregisters, receiving a sixth message from the terminal device, the sixth message being used to request registration and / or authentication / signing for the terminal device. The sixth message includes the terminal device's operator mobile network identifier (PLMN), the terminal device's identifier, and / or the area information where the terminal device is located. The sixth message is used to determine the terminal device's home network element and to determine whether the terminal device is located in a first area or is roaming. When the home network element fails or the link between the home network element and the second network element fails, obtaining authentication / signing information and / or security context information of the terminal device from a third network element; and registering and / or authenticating / signing for the terminal device based on the authentication / signing information and / or security context information of the terminal device.

[0017] Based on the method described in the sixth aspect, the third network element stores the authentication and subscription information and / or security context information of the terminal device. Therefore, when the home network element of the terminal device fails or the link between the home network element and the second network element fails, the second network element can obtain the authentication and subscription information and / or security context information of the terminal device from the third network element. Based on this information, the terminal device can be re-registered and / or authenticated, thus ensuring the normal operation of the terminal device's services. For example, the first and second network elements can be AMF or MME, etc.; the third network element can be UDM, HSS, or other devices used for data caching (such as a data caching center), etc.; the home network element of the terminal device can be the terminal device's home UDM or HSS, etc.

[0018] In conjunction with any one of the first to sixth aspects, in one possible implementation, the identifier of the aforementioned terminal device includes one or more of the following: the terminal device's subscription permanent identifier SUPI, the terminal device's subscription hidden identifier SUCI, the terminal device's International Mobile Subscriber Identity (ISMI) segment, or the terminal device's International Mobile Subscriber Number (MSISDN) segment.

[0019] In a seventh aspect, embodiments of this application provide a communication device for executing the method in any possible implementation of any of the first to sixth aspects. The communication device includes a module for executing the method in any possible implementation of any of the first to sixth aspects.

[0020] Eighthly, embodiments of this application provide a communication device including a processing circuit for executing a method in any possible implementation of any of the first to sixth aspects. The processing circuit executes a program, and when the program is executed, the method shown in any possible implementation of the first to sixth aspects is executed.

[0021] In one possible implementation, the communication device further includes a memory for storing the program.

[0022] In one possible implementation, the memory is located outside the aforementioned communication device.

[0023] In one possible implementation, the memory is located within the aforementioned communication device.

[0024] Furthermore, the processing circuitry and memory can be integrated into a single device; that is, the processing circuitry and memory can be combined. For example, the communication device can be a chip.

[0025] In one possible implementation, the communication device further includes a transceiver circuit for receiving information (or inputting information) or sending information (or outputting information).

[0026] Ninthly, embodiments of this application provide a communication device, which includes a processing circuit and a transceiver circuit. The processing circuit can be a logic circuit, and the transceiver circuit can be an interface circuit. The logic circuit and the interface are coupled. The interface circuit is used to input and / or output information, and the logic circuit is used to execute a method of any possible implementation of any of the first to sixth aspects.

[0027] In a tenth aspect, this application provides a communication system including a communication device for performing the method of the first aspect and a communication device for performing the method of the fifth aspect. Alternatively, it includes a communication device for performing the method of the second aspect and a communication device for performing the method of the sixth aspect. Alternatively, it includes a communication device for performing the method of the third aspect and a communication device for performing the method of the sixth aspect. Alternatively, it includes a communication device for performing the method of the fourth aspect and a communication device for performing the method of the sixth aspect.

[0028] Eleventhly, embodiments of this application provide a computer-readable storage medium for storing a computer program that, when run on a computer, causes the method shown in any possible implementation of any of the first to sixth aspects to be executed.

[0029] In a twelfth aspect, embodiments of this application provide a computer program product that, when run on a computer, causes the method shown in any possible implementation of any of the first to sixth aspects to be executed. Attached Figure Description

[0030] Figure 1 This is a schematic diagram of the architecture of a communication system provided in an embodiment of this application;

[0031] Figure 2 This is a schematic diagram illustrating an application scenario provided in an embodiment of this application;

[0032] Figure 3 This is a schematic diagram of an escape method provided in an embodiment of this application;

[0033] Figure 4 This is a flowchart illustrating a communication method provided in an embodiment of this application;

[0034] Figure 5 This is a schematic diagram of the process before and during a UE's escape, provided in an embodiment of this application;

[0035] Figure 6 This is a flowchart illustrating a communication method provided in an embodiment of this application;

[0036] Figure 7 This is a schematic diagram of the process before and during a UE's escape, provided in an embodiment of this application;

[0037] Figure 8 This is a flowchart illustrating a communication method provided in an embodiment of this application;

[0038] Figure 9 This is a schematic diagram of the process before and during a UE's escape, provided in an embodiment of this application;

[0039] Figure 10 This is a flowchart illustrating a communication method provided in an embodiment of this application;

[0040] Figure 11 This is a schematic diagram of the process before and during a UE's escape, provided in an embodiment of this application;

[0041] Figure 12 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0042] Figure 13 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0043] Figure 14 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation

[0044] To facilitate understanding of the technical solution of this application, the application will be further described below with reference to the accompanying drawings.

[0045] The terms "first" and "second," etc., used in the specification, claims, and drawings of this application are used only to distinguish different objects and not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.

[0046] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0047] In this application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three or more, and "and / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. "Or" indicates that there can be two relationships, such as only A exists and only B exists; when A and B are not mutually exclusive, it can also mean that there are three relationships, such as only A exists, only B exists, and both A and B exist simultaneously. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c".

[0048] In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which can include direct transmission via the air interface or indirect transmission via the air interface from other units or modules. "Receive information from YY" can be understood as the source of the information being YY, which can include direct reception from YY via the air interface or indirect reception from YY via the air interface from other units or modules. "Send" can also be understood as the "output" of a chip interface, and "receive" can also be understood as the "input" of a chip interface. In other words, sending and receiving can occur between devices, such as between a network device and a first terminal device, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.

[0049] In this application, "...when" and "if" both refer to the corresponding processing that will be carried out under certain objective circumstances, and are not limited to a specific time. They do not require a judgment action during implementation, nor do they imply any other limitations.

[0050] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.

[0051] In this application, "instruction" may include: direct instruction, or indirect instruction, or explicit instruction, or implicit instruction.

[0052] In this application, "including" can include: direct inclusion, indirect inclusion, explicit inclusion, or implicit inclusion.

[0053] The prior art may change as the technical solutions evolve, and the technical solutions provided in this application are not limited to the prior art provided.

[0054] It should be noted that different embodiments or some steps (e.g., any one or more steps) in different embodiments of this application can be combined with each other to form new embodiments. It should also be noted that the scope of this application is not limited to including optional steps in a certain embodiment, mandatory steps in a certain embodiment, or both optional and mandatory steps in a certain embodiment.

[0055] It should be noted that, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions between different embodiments are consistent and can be referenced in each other.

[0056] It should be noted that the order of the steps in the embodiments of this application is not limited by this application.

[0057] It should be noted that the order in which different conditions are judged in the embodiments of this application is not limited by this application.

[0058] It should be noted that the terms "after" and "time" in this application do not strictly limit the specific point in time.

[0059] It should be noted that the nouns and terms used in this application are merely examples and may be other names, which are not limited in this application.

[0060] The following describes the communication system involved in the embodiments of this application.

[0061] The technical solutions provided in this application can be applied to various communication systems, such as 5th generation (5G) or new radio (NR) systems, 4th generation (4G) mobile communication systems (such as long term evolution (LTE) systems), wireless local area network (WLAN) systems, satellite communication systems, future communication systems, or integrated systems of multiple systems. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.

[0062] The architecture of the communication system in this embodiment is as follows: Figure 1 As shown, where, Figure 1 The communication system shown includes terminal equipment, a radio access network (RAN), and a core network (CN). Among these:

[0063] Terminal equipment: A terminal device is a device with wireless transceiver capabilities that can communicate with access network equipment in a wireless access network. Terminal equipment can also be referred to as user equipment (UE), access terminal, terminal, subscriber unit, user station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device, etc. In one possible implementation, the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; or it can be deployed on water, including ships; or it can be deployed in the air, such as on airplanes, balloons, or satellites. In another possible implementation, the terminal device can be a handheld device with wireless communication capabilities, vehicle-mounted device, wearable device, sensor, terminal in the Internet of Things, terminal in the Internet of Vehicles, drone, 5G network, or any form of terminal device in future networks, etc., and this application embodiment does not limit this. In another possible implementation, the terminal device can also be a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in autonomous driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in a smart city, or a wireless terminal in a smart home, etc.

[0064] Radio Access Network: This includes at least one access network device, similar to a base station in a traditional network. Deployed close to the terminal equipment, it is responsible for forwarding control signals and user data between the terminal equipment and the core network. Specifically, the access network device can implement radio link maintenance, radio resource management, and some mobility management functions. For example, in radio link maintenance, it is responsible for maintaining the radio link with the terminal equipment and for protocol conversion of radio link data and IP data quality control; in radio resource management, it is responsible for establishing and releasing radio links, scheduling and allocating radio resources; and in mobility management, it is responsible for configuring terminal equipment to measure and evaluate radio link commands and making cell handover decisions. For instance, the access network device may include next-generation evolved node B (ng-eNB) or next-generation node B (gNB) in a 5G system, without specific limitations. Alternatively, access network equipment may also include access points (APs) in WLANs, broadband remote access servers (BRAS), relay stations, communication equipment in future public land mobile networks (PLMNs), and communication equipment in NTN networks.

[0065] Core Network: This includes at least one core network element. The core network element is responsible for maintaining the mobile network's subscription data, managing the mobile network's functions, and providing UE with functions such as session management, mobility management, policy management, and security authentication. When a terminal device attaches, it provides network access authentication; when the terminal device makes a service request, it allocates network resources to the terminal device; when the terminal device moves, it updates network resources for the terminal device; when the terminal device is idle, it provides a fast recovery mechanism; when the terminal device detaches, it releases network resources for the terminal device; and when the terminal device has service data, it provides data routing functions, such as forwarding uplink data to the data network; or receiving downlink data from the data network and forwarding it to the radio access network, thereby sending it to the terminal device.

[0066] For example, in a 4G mobile communication system, core network elements include, but are not limited to, one or more of the following: the network element responsible for access control, security control, and signaling coordination is the mobile management entity (MME); the network element that serves as the local mobile management anchor point is the serving gateway (S-GW); the network element that serves as the anchor point for handover to external data networks and is responsible for Internet Protocol (IP) address allocation is the packet data network (PDN) gateway (P-GW); the network element that stores authentication and subscription information of terminal devices is the home subscriber server (HSS); and the network element responsible for policy and charging functions is called the policy and charging rule function (PCRF), etc.

[0067] For example, in a 5G mobile communication system, core network elements include, but are not limited to, one or more of the following: network elements that serve as interfaces to the data network and are responsible for user plane data forwarding are called user plane functions (UPF); network elements responsible for access control and mobility management functions are called access and mobility management functions (AMF); network elements responsible for session management and the execution of control policies are called session management functions (SMF); network elements responsible for managing authentication and subscription information of terminal devices are called unified data management (UDM); and network elements responsible for billing and policy control functions are called policy and charging functions (PCF), etc.

[0068] It should be noted that the above descriptions of each core network element are merely illustrative examples. Each core network element may have other names in other network architectures, and the embodiments of this application do not limit this.

[0069] The following describes the relevant terminology used in the embodiments of this application:

[0070] I. Dual-plane large area

[0071] A dual-plane region, also known as a dual-data center site (DC) region, refers to a region that deploys multiple functionally identical but independent network element nodes. These independent network element nodes serve as backups for each other to achieve redundancy and load balancing. A region is a logical partition covering a large geographical area, with a geographical area larger than that of a province; for example, a region typically includes one or more provinces. For instance, a dual-plane region can refer to a region deploying at least two core network elements with identical functions, such as at least two UDM network elements, including a primary UDM network element and a backup UDM network element. The primary UDM network element is the one that is used daily. Optionally, the backup UDM network element can also be used daily to reduce the processing load on the primary UDM network element. Alternatively, the backup UDM network element can be inactive daily, but activated when the primary UDM fails or the link connecting to the primary UDM fails.

[0072] II. Main Plane and Escape Plane

[0073] The primary plane refers to the main communication plane used daily, including the primary communication paths and the communication equipment along those paths. The escape plane refers to the communication plane that provides emergency escape routes in the event of a failure in the primary plane, ensuring continued service operation. The escape plane includes escape communication paths and the communication equipment along those paths. For example, the communication equipment in the escape plane may include access network equipment and / or core network elements, but is not limited to these. Optionally, if the primary plane is dual-plane, the escape plane can ensure continued service operation after both planes fail.

[0074] III. UE Network Access Processing Flow

[0075] After powering on, the UE needs to go through the following processing steps to implement its relevant services: Generally, the UE first needs to initiate a registration request to the network, thereby triggering the network to detect the UE and obtain the UE's authentication and subscription information, and then authenticate and subscribe to the UE. For example, the UE's authentication and subscription information includes, but is not limited to, the UE's identifier, authentication algorithm, and / or subscription data. Optionally, if the UE authentication is successful, security context information can also be generated for the UE. For example, the UE's security context information includes the key generated during the UE authentication process, security algorithm, and / or security parameters. The UE's security context information can be used to ensure the legitimacy of the UE and the network's mutual identity verification, thereby ensuring the security of information transmission in subsequent communication between the two parties.

[0076] The following uses a 5G mobile communication system as an example to introduce the application scenarios of the embodiments of this application:

[0077] like Figure 2As shown, this application scenario includes a first UE and a second UE. The first UE is located in a first area, and the second UE moves from a second area to the first area. The UDM in the first area stores the authentication and subscription information of the first UE, and the UDM in the second area stores the authentication and subscription information of the second UE.

[0078] When a first UE accesses a first area, it may initiate a registration and / or authentication / signing request to the AMF in the first area. The AMF in the first area obtains the authentication / signing information of the first UE from the UDM in the first area to complete the registration and / or authentication / signing of the first UE. Optionally, the AMF in the first area may also obtain the security context information of the first UE generated during the registration and / or authentication / signing process.

[0079] When a second UE accesses the first area, it can initiate a registration and / or authentication / signing request to the AMF in the first area. The AMF in the first area obtains the authentication / signing information of the second UE from the UDM in the second area to complete the registration and / or authentication / signing of the second UE. Optionally, the AMF in the first area can also obtain the security context information of the second UE generated during the registration and / or authentication / signing process.

[0080] Optionally, the first UE can be a local UE of the first region or the first UE can be located in the first region; the second UE can be a local UE of the second region or the second UE can be located in the second region.

[0081] Optionally, the movement of the second UE from the second region to the first region constitutes international roaming (domestic roaming). For example, if the first region is the service area of ​​one country and the second region is the service area of ​​another country, then the movement of the second UE from the second region to the first region can be understood as the second UE roaming domestically. The second UE is a roaming-in UE in the first region and a roaming-out UE in the second region.

[0082] Optionally, the movement of the second UE from the second region to the first region constitutes inter-provincial roaming (provincial roaming). For example, the first region is the service area of ​​one province, and the second region is the service area of ​​another province. Alternatively, the first region is a dual-DC (Digital Data Center) region, and the second region is an area outside the dual-DC region, such as... Figure 2 As shown, two UDMs are deployed in the first area: a primary UDM and a backup UDM. Both the primary and backup UDMs can store the authentication and subscription information of local UEs in the first area. Therefore, the movement of a second UE from the second area to the first area can be understood as the second UE saving roaming time. The second UE is a roaming-in UE in the first area and a roaming-out UE in the second area.

[0083] Optionally, the movement of the second UE from the second area to the first area is considered a movement between special areas. For example, the first area is a special area, such as an area prone to failure or where the links between the special area and other areas are limited (i.e., communication is impossible through other links after the link fails), like an island. The second area is a non-special area, such as a non-island land area. In this case, when the first area fails, communication with the second area is impossible. Therefore, the movement of the second UE from the second area to the first area can be understood as the second UE moving from a non-special area to a special area. Optionally, for the first area being a special area, a UDM may not be deployed there. The authentication and subscription information of the local UE in the first area can be stored in a UDM in a non-special area, such as the UDM in the second area. For example, the first area might be an island near the second area. Due to the small coverage area of ​​the first area, to save equipment resources and deployment costs, only the RAN and AMF are deployed in the first area, while the UDM is deployed in the second area. In this way, when a local UE (such as the first UE) in the first area accesses the first area, the AMF in the first area obtains the authentication and subscription information of the first UE from the UDM in the second area to complete the registration and / or authentication and subscription of the first UE.

[0084] against Figure 2 The application scenario shown illustrates that after the first UE and the second UE access the first area, if a fault occurs in the first area, the services running on the first UE and the second UE may be affected. For example, such as... Figure 3 As shown, if the primary UDM in the first area fails, the backup UDM in the first area fails, the link between the AMF and the primary UDM in the first area fails, the link between the AMF and the backup UDM in the first area fails, and / or the link between the AMF in the first area and the UDM in the second area fails, the services running in the first UE and the second UE may be affected.

[0085] In this case, such as Figure 3 As shown, this will trigger the first UE and the second UE to re-register and / or re-authenticate through the AMF and UDM in the escape plane. The escape link corresponding to this process can be found in [reference needed]. Figure 3 That is, the AMF of the escape plane obtains the authentication and signing information of the first UE from the primary UDM and / or backup UDM in the first area to complete the registration and / or authentication and signing of the first UE; the AMF of the escape plane obtains the authentication and signing information of the second UE from the UDM in the second area to complete the registration and / or authentication and signing of the second UE.

[0086] However, if the AMF and UDM of the escape plane do not obtain the authentication and subscription information of the first UE and the second UE, and do not pre-store the authentication and subscription information and / or security context information of the first UE and the second UE, then the first UE and the second UE will also be unable to register and / or authenticate and subscribe through the escape plane, resulting in the inability of the services of the first UE and the second UE to operate normally.

[0087] For example, if the primary UDM in the first area fails, the backup UDM in the first area fails, the link between the AMF in the escape plane and the primary UDM in the first area fails, and / or the link between the AMF in the escape plane and the backup UDM in the first area fails, then the AMF in the escape plane cannot obtain the authentication and subscription information of the first UE from the primary UDM and / or backup UDM in the first area, and consequently the AMF in the escape plane cannot obtain the security context information of the first UE generated based on the registration and / or authentication and subscription of the first UE.

[0088] For example, if the UDM in the second area fails, and / or the link between the AMF in the escape plane and the UDM in the second area fails, the AMF in the escape plane will be unable to obtain the authentication and subscription information of the second UE, and thus the AMF in the escape plane will be unable to obtain the security context information of the second UE generated based on the registration and / or authentication and subscription of the second UE.

[0089] To ensure the normal operation of terminal devices, embodiments of this application propose several communication methods. These communication methods are described below with reference to specific scenarios:

[0090] 1. Roaming Scene

[0091] 1.1 Figure 4 A communication method is shown, which includes steps 401 to 406. Figure 4 The method shown can be applied to the terminal device side, the first network element side, and the second network element side. The terminal device side / first network element side / second network element side can be the terminal device / first network element / second network element, or it can be a processor, module, chip, chip system, or functional module that implements the method.

[0092] Figure 4 Taking the terminal equipment as the executing entity and the first and second network elements as examples, the following is an introduction:

[0093] Step 401: The terminal device sends a first message to the first network element. The first message requests processing of the terminal device. The first message includes the public land mobile network (PLMN) of the terminal device and / or the identifier of the terminal device. The first message is used to determine that the terminal device is roaming.

[0094] Accordingly, the first network element receives the first message.

[0095] In one possible implementation, the first network element may be located in the plane used daily (main plane); for example, the first network element may be an AMF, MME, or a network element that implements AMF or MME functions in a future communication system, which is not limited in this application.

[0096] In one possible implementation, the first message request to the terminal device includes processing the terminal device, specifically: requesting the terminal device to register and / or authenticate and subscribe, or requesting the terminal device to update its registration. This application does not limit the timing of the first message transmission or the operation performed by the first message to request the first network element, and is not limited to the above implementation. For example, when the terminal device accesses the service area of ​​the first network element, the terminal device can send a first message to the first network element, which can be a registration request message. Alternatively, the terminal device can periodically request registration updates from the first network element, sending a first message each time a registration update is requested, which can be a registration update request message.

[0097] In one possible implementation, the PLMN of the terminal device in the first message is the PLMN of the network accessed when the terminal device accesses the service area of ​​the first network element. The PLMN consists of a mobile country code (MCC) and a mobile network code (MNC), with the MNC representing the operator.

[0098] In one possible implementation, the identifier of the terminal device in the first message includes the identifier of the terminal device in its home network and / or the identifier of the terminal device in the service area of ​​the first network element. Examples include, but are not limited to, one or more of the following: the terminal device's subscription permanent identity (SUPI), the terminal device's subscription concealed identifier (SUCI), the terminal device's international mobile subscriber identity (IMSI) range, or the terminal device's mobile station international subscriber directory number (MSISDN) range. The SUPI may consist of the MCC, MNC, and mobile subscriber identification number (MSIN). The SUCI is an encrypted identifier corresponding to the SUPI, such as the SUCI consisting of the MCC, MNC, and encrypted MSIN. The IMSI may consist of the MCC, MNC, and MSIN, and the IMSI range may include the MCC and / or MNC from the ISMI. MSISDN can consist of a country code (CC), a national destination code (NDC), and a subscriber number (SN). MSISDN number ranges can include CC and / or NDC in the MSISDN.

[0099] In this embodiment of the application, the first network element receives the first message, can determine that the terminal device is roaming based on the first message, and then execute the following step 402.

[0100] In one possible implementation, the first network element can determine the terminal device's national identity based on the terminal device's PLMN and / or the terminal device's identifier in the first message.

[0101] For example, the first network element obtains the PLMN of the home network of the terminal device and determines the nationality / roaming status of the terminal device based on the home PLMN and the PLMN of the terminal device in the first message. Alternatively, the first network element obtains the identifier of the network where the first network element is located and determines the nationality / roaming status of the terminal device based on the identifier of the network where the first network is located and the identifier of the terminal device. Or, the first network determines the nationality / roaming status of the terminal device based on the PLMN of the terminal device and the identifier of the terminal device in the first message. This application is not limited to the above examples.

[0102] In another possible implementation, the first network element can determine that the terminal device is not roaming in the national roaming area based on the terminal device PLMN and / or the identifier of the terminal device in the first message; furthermore, the first network element can obtain the identifier of the terminal device's home network element and determine the terminal device's provincial roaming area based on the identifier of the terminal device's home network element.

[0103] For example, the home network element of the terminal device can be a home UDM, HSS, or a network element that implements the home UDM or HSS function in a future communication system. Taking the home UDM as an example, the first network element can obtain the instance identifier (InstanceID) of the home UDM. By comparing the instance ID of the home UDM with the instance ID of the first network element's local UDM, it can determine whether the terminal device is roaming-free.

[0104] Optionally, if the first network element determines, based on the first message, that the terminal device is not roaming (i.e., the terminal device is a local terminal device within the service area of ​​the first network element), the first network element can obtain the authentication and subscription information of the terminal device from the network element corresponding to the first network element that stores the authentication and subscription information of the terminal device locally, and register and / or authenticate and subscribe the terminal device based on the authentication and subscription information of the terminal device. Optionally, the first network element also obtains the security context information of the terminal device generated during the registration and / or authentication and subscription process. Further, optionally, the first network element can instruct the network element corresponding to the first network element that stores the authentication and subscription information of the terminal device locally to automatically export the authentication and subscription information of the terminal device to the third network element (i.e., automatically export the authentication and subscription information of the local user); in this way, the normal operation of the terminal device's services can be ensured based on the authentication and subscription information of the terminal device stored in the third network element.

[0105] In one possible implementation, the network element corresponding to the first network element that stores the authentication and subscription information of the local terminal device can be located in the main plane. For example, the network element corresponding to the first network element that stores the authentication and subscription information of the local terminal device can be a UDM, HSS, or a network element in a future communication system that implements the functions of a UDM or HSS; this application does not limit this.

[0106] In one possible implementation, the primary plane where the first network element resides is dual-plane, so the number of network elements corresponding to the first network element that store the authentication and subscription information of the local terminal device can be at least two. Taking the network element corresponding to the first network element that stores the authentication and subscription information of the local terminal device as a local UDM as an example, the local UDM includes at least a primary UDM and a backup UDM. The specific implementation method for the first network element to obtain the authentication and subscription information of the terminal device from the local UDM includes: the first network element can first try to obtain the authentication and subscription information of the terminal device from the local primary UDM; if the first network element cannot obtain the authentication and subscription information of the terminal device from the local primary UDM, then the first network element can obtain the authentication and subscription information of the terminal device from the local backup UDM.

[0107] In one possible implementation, the third network element can be located in the escape plane. For example, the third network element can be a UDM, HSS, or other devices used for caching data (such as a data caching center); or, the third network element can be a network element that implements UDM or HSS functions in a future communication system, and this application does not limit either of these.

[0108] Step 402: The first network element sends a second message to the second network element. The second message requests the terminal device to register and / or authenticate and sign up. The second message includes the PLMN of the terminal device and / or the identifier of the terminal device.

[0109] Accordingly, the second network element receives the second message.

[0110] In one possible implementation, the second network element may be located in the escape plane. For example, the second network element may be an AMF, an MME, or a network element that implements the functions of an AMF or MME in a future communication system; this application is not limited in this regard.

[0111] In one possible implementation, the second message is either an N1 message or an N2 message. The implementation of the second message, including the terminal device's PLMN and / or the terminal device's identifier, can be referenced from the implementation of the first message and will not be elaborated here.

[0112] Step 403: The second network element obtains the authentication and signing information and / or security context information of the terminal device.

[0113] In one possible implementation, the specific method by which the second network element obtains the authentication and subscription information and / or security context information of the terminal device includes: the second network element determining that the terminal device is roaming based on the second message; obtaining the authentication and subscription information of the terminal device from the home network element of the terminal device, and performing authentication and / or authorization and subscription on the terminal device based on the authentication and subscription information of the terminal device. Optionally, the second network element also generates the security context information of the terminal device generated during the registration and / or authorization and subscription process. The second network element's determination of terminal device roaming can refer to the implementation of the first network element's determination of terminal device roaming, and will not be elaborated here.

[0114] Optionally, if the second network element determines that the terminal device is not roaming, i.e., the terminal device is a local terminal device within the service area of ​​the second network element, the second network element can obtain the authentication and signing information of the terminal device from the network element corresponding to the second network element that stores the authentication and signing information of the terminal device locally, and perform registration and / or authentication and signing on the terminal device based on the authentication and signing information of the terminal device. Optionally, the second network element also obtains the security context information of the terminal device generated during the registration and / or authentication and signing process.

[0115] In one possible implementation, the network element corresponding to the second network element that stores the authentication and subscription information of the local terminal device can be located in the escape plane. For example, the network element corresponding to the second network element that stores the authentication and subscription information of the local terminal device can be a UDM, HSS, or a network element in a future communication system that implements the functions of a UDM or HSS; this application does not limit this.

[0116] Step 404: Authentication and signing information and / or security context information of the second network element storage terminal device.

[0117] Step 405: The terminal device sends a sixth message to the second network element. The sixth message requests registration and / or authentication of the terminal device. The sixth message includes the PLMN of the terminal device and / or the identifier of the terminal device. The sixth message is used to determine the roaming of the terminal device and the network element to which the terminal device belongs.

[0118] Correspondingly, the second network element receives the sixth message.

[0119] In this embodiment, after deregistering, the terminal device sends a sixth message to the second network element. Upon receiving the sixth message, the second network element can determine whether the terminal device is roaming and its home network element based on the sixth message, and then execute step 406 below. The second network element's determination of terminal device roaming can be implemented with reference to step 401, and will not be elaborated here.

[0120] In one possible implementation, the sixth message can be a Registration request message. The sixth message, including the terminal device's PLMN and / or the terminal device's identifier, can be implemented with reference to the first message, and will not be elaborated upon here.

[0121] Optionally, if the second network element determines that the terminal device is not roaming, the second network element registers and / or authenticates the terminal device in the following manner: It obtains the terminal device's authentication and signing information from the network element corresponding to the second network element that stores the terminal device's authentication and signing information locally, or it obtains the terminal device's authentication and signing information and / or security context information locally; it then registers and / or authenticates the terminal device based on the obtained authentication and signing information and / or security context information. Obtaining the terminal device's authentication and signing information from the network element corresponding to the second network element that stores the terminal device's authentication and signing information locally ensures that the second network element obtains the latest authentication and signing information, thereby improving the accuracy of terminal device registration and / or authentication and signing. Obtaining the terminal device's authentication and signing information and / or security context information locally ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services currently running on the terminal device continue to operate.

[0122] Optionally, the terminal device may first attempt to obtain the authentication and signing information of the terminal device from the network element corresponding to the local storage of the terminal device's authentication and signing information. If successful, the terminal device is registered and / or authenticated and signed based on the authentication and signing information of the terminal device, and the security context information of the terminal device generated during the registration and / or authentication and signing process is obtained. If it fails (e.g., the network element corresponding to the local storage of the terminal device's authentication and signing information is faulty, or the link between the second network element and the terminal device is faulty), the terminal device is registered and / or authenticated and signed based on the authentication and signing information and / or security context information of the terminal device obtained locally.

[0123] Optionally, if the terminal device registration and / or authentication agreement is completed, the second network element can store the terminal device's authentication agreement information and / or security context information obtained during this registration and / or authentication agreement process. This provides information for the next registration and / or authentication agreement.

[0124] Step 406: When the home network element fails or the link between the home network element and the second network element fails, the second network element registers and / or authenticates the terminal device based on the terminal device authentication and subscription information and / or security context information.

[0125] In this embodiment, for the identified roaming terminal device, the second network element can register and / or authenticate and sign off on the terminal device according to the following method 1 and / or method 2: Method 1: The second network element obtains the authentication and signing off information of the terminal device from the home network element of the terminal device, and then registers and / or authenticates and signs off on the terminal device based on the authentication and signing off information of the terminal device. Method 2: As can be seen from the above, the authentication and signing off information of the terminal device in the service area of ​​the first network element can be exported to the third network element, or according to step 404 above, the authentication and signing off information and / or security context information of the terminal device in the service area of ​​the first network element can be stored in the second network element. Therefore, the second network element can obtain the authentication and signing off information and / or security context information of the terminal device from the third network element or locally, and register and / or authenticate and sign off on the terminal device.

[0126] In one possible implementation, the second network element can first attempt to register and / or authenticate the terminal device according to method 1 above; if the home network element fails or the link between the home network element and the second network element fails, the terminal device can be registered and / or authenticated according to method 2 above (i.e., step 406 is executed). This ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services running on the terminal device continue to operate.

[0127] In one possible implementation, for method 2, the second network element can first determine whether it stores the authentication and signing information and / or security context information of the terminal device; if the second network element stores the authentication and signing information and / or security context information of the terminal device, the second network element registers and / or authenticates and signs the terminal device based on the stored authentication and signing information and / or security context information of the terminal device; if the second network element does not store the authentication and signing information and / or security context information of the terminal device, the second network element obtains the authentication and signing information of the terminal device from the third network element, and registers and / or authenticates and signs the terminal device based on the obtained authentication and signing information of the terminal device.

[0128] In this embodiment, the roaming terminal device identified by the second network element in step 405 can be either a local terminal device of the first network element or a roaming terminal device identified by the first network element; this application does not limit this. For example, if the terminal device's home location is home location 1, the first network element is a network element of home location 2, and the second network element is a network element of home location 3, then the first network element can determine that the terminal device is roaming and thus execute the implementation methods for roaming terminal devices in steps 401-404 above; similarly, the second network element also determines that the terminal device is roaming and thus executes the implementation methods for roaming terminal devices in steps 405-406 above.

[0129] based on Figure 4In the described embodiment, for a terminal device within the service area of ​​a first network element, the first network element can first identify whether the terminal device is roaming or not. If roaming, the first network element migrates the terminal device to a second network element for registration and / or authentication, allowing the second network element to store the terminal device's authentication and / or security context information after registration and / or authentication. Conversely, if not roaming, the first network element normally registers and / or authenticates the terminal device and exports its authentication information to a third network element. Since both the second and third network elements are located in the escape plane, in the event of a failure in the main plane, all terminal devices within the service area of ​​the first network element can also re-register and / or re-authenticate in the escape plane. This helps ensure the normal operation of services for all terminal devices within the service area of ​​the first network element.

[0130] Optionally, the above Figure 4 In the described embodiments, steps 403-406 following step 402 can be replaced by the following method: After the second network element receives the second message and determines that the terminal device is roaming, the second network element can still obtain the authentication and signing information of the terminal device from the network element corresponding to the second network element that stores the authentication and signing information of the terminal device locally. The network element corresponding to the second network element that stores the authentication and signing information of the terminal device locally obtains the authentication and signing information of the terminal device from the home network element of the terminal device and stores the authentication and signing information of the terminal device. At the same time, the network element corresponding to the second network element that stores the authentication and signing information of the terminal device locally returns the authentication and signing information of the terminal device to the second network element, so that the second network element can register and / or authenticate and sign the terminal device. After a failure occurs in the main plane, the terminal device attempts to register. Since the network element corresponding to the second network element that stores the authentication and signing information of the terminal device locally stores the authentication and signing information of the terminal device, the second network element can still obtain the authentication and signing information of the terminal device, thereby registering and / or authenticating and signing the terminal device again.

[0131] Based on the above Figure 4 The described embodiments, taking a 5G mobile communication system as an example, Figure 5 A schematic diagram illustrating the process before and during UE escape is shown. Specifically, in... Figure 5 In this context, the local AMF is the first network element, the escape AMF is the second network element, the escape UDM / data cache center is the third network element, the remote UDM is the fourth network element, and the local UDM is the network element that stores the authentication and subscription information of the local storage terminal device corresponding to the first network element.

[0132] Step 501: The local AMF receives a registration request from the UE.

[0133] Step 502: The local AMF identifies whether the UE is roaming.

[0134] In this embodiment, if the local AMF identifies that the UE is not roaming, steps 503 to 505 are executed; otherwise, steps 506 to 511 are executed. Steps 501 to 505 can be implemented with reference to step 501, and will not be described in detail here.

[0135] Step 503: The local AMF obtains the UE's authentication and subscription information from the local UDM.

[0136] Step 504: Export the UE's authentication and subscription information from the local UDM to the Escape UDM / Data Cache Center.

[0137] Step 505: The local AMF registers and / or authenticates the UE.

[0138] Step 506: Migrate the UE from the local AMF to the escape AMF.

[0139] Step 506 can be implemented by referring to step 402, and will not be described in detail here.

[0140] Step 507: Escape AMF identifies whether the UE is roaming.

[0141] In this embodiment of the application, if the escape AMF identifies UE roaming, steps 508, 510, and 511 are executed; otherwise, steps 509, 510, and 511 are executed. Steps 507 to 511 can be implemented with reference to steps 403 to 404, and will not be described in detail here.

[0142] Step 508: The Escape AMF obtains the UE's authentication and subscription information from the Escape UDM / Data Cache Center.

[0143] Step 509: The AMF obtains the UE's authentication and signing information from the UDM in another location.

[0144] Step 510: The escape AMF registers and / or authenticates the UE to obtain the UE's security context information.

[0145] Step 511: The escape AMF stores the UE's authentication and subscription information and / or security context information.

[0146] Step 512: The Escape AMF receives a registration request from the UE.

[0147] Step 513: Escape AMF identifies whether the UE is roaming.

[0148] In this embodiment of the application, if the escape AMF identifies that the UE is not roaming, then steps 514 and 516 are executed; otherwise, steps 515 and 516 are executed. Steps 512 to 516 can be implemented with reference to steps 405 to 406, and will not be described in detail here.

[0149] Step 514: The Escape AMF obtains the UE's authentication and subscription information and / or security context information from the Escape UDM / Data Cache Center / Local source.

[0150] Step 515: The escape AMF obtains the UE's authentication and subscription information and / or security context information from the local UDM on the main plane / the external UDM on the main plane / the escape UDM / the data cache center / local.

[0151] Step 516: The Escape AMF registers and / or authenticates the UE.

[0152] 1.2 Figure 6 A communication method is shown, which includes steps 601 to 606. Figure 6 The method shown can be applied to the terminal device side, the first network element side, the second network element side, and the third network element side. The terminal device side / first network element side / second network element side / third network element side can be the terminal device / first network element / second network element / third network element, or it can be a processor, module, chip, chip system, or functional module implementing the method. In this application embodiment, the specific implementation methods of the first network element, second network element, and third network element can refer to the above embodiments, and will not be repeated here.

[0153] Figure 6 Taking the terminal equipment, the first network element, the second network element, and the third network element as examples, the following is an introduction:

[0154] Step 601: The terminal device sends a first message to the first network element. The first message requests processing of the terminal device. The first message includes the PLMN of the terminal device and / or the identifier of the terminal device. The first message is used to determine that the terminal device is roaming.

[0155] Accordingly, the terminal device receives the first message.

[0156] In this embodiment of the application, the first network element receives the first message and can determine that the terminal device is roaming based on the first message, and then executes the following step 602, which can be implemented with reference to the above step 401, and will not be described in detail here.

[0157] Optionally, if the first network element determines, based on the first message, that the terminal device is not roaming (i.e., the terminal device is a local terminal device within the service area of ​​the first network element), the first network element can obtain the authentication and signing information of the terminal device from the network element corresponding to the first network element that stores the authentication and signing information of the terminal device locally, and register and / or authenticate and sign the terminal device based on the authentication and signing information of the terminal device. Optionally, the first network element also obtains the security context information of the terminal device generated during the registration and / or authentication and signing process. Further, optionally, the first network element can instruct the network element corresponding to the first network element that stores the authentication and signing information of the terminal device locally to automatically export the authentication and signing information of the terminal device to the third network element (i.e., automatically export the authentication and signing information of the local user); in this way, the normal operation of the terminal device's services can be ensured based on the authentication and signing information of the terminal device stored in the third network element. The network element corresponding to the first network element that stores the authentication and signing information of the terminal device locally can be implemented with reference to the above embodiments, and will not be elaborated here.

[0158] Optionally, the first network element may also not determine whether the terminal device is roaming, and perform the following steps 602 and 603 for all terminal devices in the service area of ​​the first network element.

[0159] Step 602: The first network element obtains the authentication and signing information and / or security context information of the terminal device.

[0160] In one possible implementation, the first network element obtains the authentication and signing information and / or security context information of the terminal device, specifically by: the first network element obtaining the authentication and signing information of the terminal device from the home network element of the terminal device, and performing authentication and / or authentication signing on the terminal device based on the authentication and signing information of the terminal device. Optionally, the first network element also obtains the security context information of the terminal device generated during the registration and / or authentication signing process. The home network element of the terminal device can be implemented with reference to the above embodiments, and will not be elaborated here.

[0161] Step 603: The first network element sends a third message to the third network element. The third message includes the authentication and subscription information and / or security context information of the terminal device.

[0162] Accordingly, the third network element receives the third message.

[0163] Step 604: The terminal device sends a sixth message to the second network element. The sixth message requests registration and / or authentication of the terminal device. The sixth message includes the PLMN of the terminal device and / or the identifier of the terminal device. The sixth message is used to determine the roaming of the terminal device and the network element to which the terminal device belongs.

[0164] Correspondingly, the second network element receives the sixth message.

[0165] In this embodiment, after deregistering, the terminal device sends a sixth message to the second network element. Upon receiving the sixth message, the second network element can determine whether the terminal device is roaming and its home network element based on the sixth message, and then execute step 605 below. The second network element's determination of the terminal device's roaming and the sixth message can be implemented with reference to the above embodiments, and will not be repeated here.

[0166] Optionally, if the second network element determines that the terminal device is not roaming, the second network element registers and / or authenticates the terminal device in the following manner: It obtains the terminal device's authentication and signing information from the network element corresponding to the second network element that stores the terminal device's authentication and signing information locally, or it obtains the terminal device's authentication and signing information and / or security context information locally; it then registers and / or authenticates the terminal device based on the obtained authentication and signing information and / or security context information. Obtaining the terminal device's authentication and signing information from the network element corresponding to the second network element that stores the terminal device's authentication and signing information locally ensures that the second network element obtains the latest authentication and signing information, thereby improving the accuracy of terminal device registration and / or authentication and signing. Obtaining the terminal device's authentication and signing information and / or security context information locally ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services currently running on the terminal device continue to operate.

[0167] Optionally, the terminal device may first attempt to obtain the authentication and signing information of the terminal device from the network element corresponding to the local storage of the terminal device's authentication and signing information. If successful, the terminal device is registered and / or authenticated and signed based on the authentication and signing information of the terminal device, and the security context information of the terminal device generated during the registration and / or authentication and signing process is obtained. If it fails (e.g., the network element corresponding to the local storage of the terminal device's authentication and signing information is faulty, or the link between the second network element and the terminal device is faulty), the terminal device is registered and / or authenticated and signed based on the authentication and signing information and / or security context information of the terminal device obtained locally.

[0168] Optionally, if the terminal device registration and / or authentication agreement is completed, the second network element can store the terminal device's authentication agreement information and / or security context information obtained during this registration and / or authentication agreement process. This provides information for the next registration and / or authentication agreement.

[0169] Step 605: When the home network element fails or the link between the home network element and the second network element fails, the second network element obtains authentication and subscription information and / or security context information of the terminal device from the third network element.

[0170] Step 606: The second network element registers and / or authenticates the terminal device based on the terminal device's authentication and signing information and / or security context information.

[0171] In this embodiment, for the identified roaming terminal device, the second network element can register and / or authenticate and sign off on the terminal device according to the following methods 3 and / or 4: Method 3: The second network element obtains the authentication and signing off information of the terminal device from the home network element of the terminal device, and then registers and / or authenticates and signs off on the terminal device based on the authentication and signing off information of the terminal device. Method 4: As can be seen from the above, the authentication and signing off information and / or security context information of the terminal device within the service area of ​​the first network element can be exported to the third network element. Therefore, the second network element can obtain the authentication and signing off information and / or security context information of the terminal device from the third network element and register and / or authenticate and sign off on the terminal device.

[0172] In one possible implementation, the second network element can first attempt to register and / or authenticate the terminal device according to method 3 above; if the home network element fails or the link between the home network element and the second network element fails, the terminal device can be registered and / or authenticated according to method 4 above (i.e., steps 605 to 606 are executed). This ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services running on the terminal device continue to operate.

[0173] In this embodiment, the roaming terminal device identified by the second network element in step 604 can be either a local terminal device of the first network element or a roaming terminal device identified by the first network element; this application does not limit this. For example, if the terminal device's home location is home location 1, the first network element is a network element of home location 2, and the second network element is a network element of home location 3, then the first network element can determine that the terminal device is roaming and thus execute the implementation methods for roaming terminal devices in steps 601-603 above; similarly, the second network element also determines that the terminal device is roaming and thus executes the implementation methods for roaming terminal devices in steps 604-606 above.

[0174] Optionally, in this embodiment, in step 601, the first network element may further export the authentication and subscription information and / or security context information of the identified roaming terminal devices, along with the authentication and subscription information of the non-roaming terminal devices, to different network elements in the escape plane. For example, the first network element may export the authentication and subscription information and / or security context information of the identified roaming terminal devices to the data cache center of the escape plane, and export the authentication and subscription information of the non-roaming terminal devices to the UDM network element of the escape plane. This application does not limit this aspect.

[0175] Optionally, in this embodiment, after step 603, if the first network element is not faulty and the link between the first network element and the terminal device is not faulty, then the second network element in steps 604-606 can be replaced by the first network element. That is, the terminal device is still registered and / or authenticated through the network elements of the main plane. This application does not limit this. If the first network element is faulty and / or the link between the first network element and the terminal device is faulty, then steps 604-606 are executed.

[0176] based on Figure 6 In the described embodiment, for terminal devices within the service area of ​​the first network element, regardless of whether the first network element identifies the terminal device as roaming or not, the first network element can normally register and / or authenticate the terminal device. This allows the first network element to export the authentication and / or security context information of the terminal device to the escape plane after registration and / or authentication. Therefore, in the event of a failure in the main plane, all terminal devices within the service area of ​​the first network element can also re-register and / or re-authenticate on the escape plane. This helps ensure the normal operation of services for all terminal devices within the service area of ​​the first network element.

[0177] Based on the above Figure 6 The described embodiments, taking a 5G mobile communication system as an example, Figure 7 A schematic diagram illustrating the process before and during UE escape is shown. Specifically, in... Figure 7 In this context, the local AMF is the first network element, the escape AMF is the second network element, the escape UDM / data cache center is the third network element, the remote UDM is the fourth network element, and the local UDM is the network element that stores the authentication and subscription information of the local storage terminal device corresponding to the first network element.

[0178] Step 701: The local AMF receives a registration request from the UE.

[0179] Step 702: The local AMF identifies whether the UE is roaming.

[0180] In this embodiment of the application, if the local AMF identifies that the UE is not roaming, then steps 703 to 705 are executed; otherwise, steps 706 to 708 are executed. Steps 701 to 705 can be implemented with reference to step 601, and will not be described in detail here.

[0181] Step 703: The local AMF obtains the UE's authentication and subscription information from the local UDM.

[0182] Step 704: Export the UE's authentication and subscription information from the local UDM to the Escape UDM / Data Cache Center.

[0183] Step 705: The local AMF registers and / or authenticates the UE.

[0184] Step 706: The local AMF obtains the UE's authentication and subscription information from the external UDM.

[0185] Step 707: The local AMF registers and / or authenticates the UE to obtain the UE's security context information.

[0186] Steps 706 and 707 can be implemented with reference to step 602, and will not be described in detail here.

[0187] Step 708: Export the UE's authentication and subscription information and / or security context information from the local AMF to the escape UDM / data cache center.

[0188] Step 708 can be implemented by referring to step 603, and will not be described in detail here.

[0189] Step 709: The Escape AMF receives a registration request from the UE.

[0190] Step 710: Escape AMF identifies whether the UE is roaming.

[0191] In this embodiment of the application, if the escape AMF identifies that the UE is not roaming, then steps 711 and 713 are executed; otherwise, steps 712 and 713 are executed. Among them, steps 709 to 713 can be implemented with reference to steps 604 to 606, and will not be described in detail here.

[0192] Step 711: The Escape AMF obtains the UE's authentication and subscription information and / or security context information from the Escape UDM / Data Cache Center / Local.

[0193] Step 712: The escape AMF obtains the UE's authentication and subscription information and / or security context information from the local UDM on the main plane / the external UDM on the main plane / the escape UDM / the data cache center / local.

[0194] Step 713: The Escape AMF registers and / or authenticates the UE.

[0195] 1.3 Figure 8 A communication method is shown, which includes steps 801 to 805. Figure 8The method shown can be applied to the terminal device side, the first network element side, the second network element side, the third network element side, and the fourth network element side. The terminal device side / first network element side / second network element side / third network element side / fourth network element side can be the terminal device / first network element / second network element / third network element / fourth network element, or it can be a processor, module, chip, chip system, or functional module implementing the method. In this application embodiment, the specific implementation of the first network element, second network element, and third network element can be referred to the above embodiments, and will not be repeated here.

[0196] Figure 8 Taking the terminal equipment as the executing entity, and the first network element, second network element, third network element, and fourth network element as examples, the following is an introduction:

[0197] Step 801: The first network element sends a fourth message to the fourth network element. The fourth message requests to obtain the authentication and subscription information of the terminal device. The fourth message includes the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device. The fourth message is used to determine the overflow of the terminal device.

[0198] Accordingly, the fourth network element receives the fourth message.

[0199] In one possible implementation, the fourth network element is the home network element of the terminal device. For example, the fourth network element can be the home UDM, HSS of the terminal device, or a network element that implements the home UDM or HSS function in a future communication system.

[0200] In one possible implementation, before step 801, the terminal device may first send a first message to the first network element. This first message requests processing of the terminal device and includes the terminal device's PLMN and / or its identifier. The first message is used to determine if the terminal device is roaming. This process can be implemented with reference to step 401 above, and will not be elaborated here. Then, the first network element sends a fourth message to the fourth network element. That is, the first network element sends the fourth message to the fourth network element after determining that the terminal device is roaming. Optionally, referring to step 401 above, if the first network element determines that the terminal device is not roaming, the first network element automatically exports the terminal device's authentication and subscription information to the third network element.

[0201] In this embodiment of the application, the fourth network element receives the fourth message, can determine the terminal device overflowing based on the fourth message, and then execute the following step 802.

[0202] In one possible implementation, the fourth network element can determine terminal device overflow based on the terminal device's PLMN and / or the terminal device's identifier in the fourth message. Terminal device overflow means that the fourth network element determines the terminal device belongs to its service area, but the terminal device is currently accessing other service areas.

[0203] In one possible implementation, the PLMN of the terminal device in the fourth message is the PLMN of the network accessed when the terminal device accesses the service area of ​​the first network element.

[0204] In one possible implementation, the identifier of the terminal device in the fourth message includes the identifier of the terminal device in the home network and / or the identifier of the terminal device in the service area of ​​the first network element. Examples include, but are not limited to, one or more of the following: the SUPI of the terminal device, the SUCI of the terminal device, the IMSI segment of the terminal device, or the MSISDN segment of the terminal device.

[0205] Optionally, the fourth message may also include the identifier of the service area of ​​the first network element and / or the identifier of the first network element. The fourth network element can determine the roaming of the terminal device based on the PLMN of the terminal device, the identifier of the terminal device, the identifier of the service area of ​​the first network element and / or the identifier of the first network element.

[0206] Step 802: The fourth network element sends a fifth message to the third network element. The fifth message includes the authentication and signing information of the terminal device.

[0207] Correspondingly, the third network element receives the fifth message.

[0208] In this embodiment, the fourth network element stores the authentication and subscription information of the terminal device. After determining that the terminal device has overrun, the fourth network element can send a fifth message to the third network element, which includes the authentication and subscription information of the terminal device.

[0209] Step 803: The terminal device sends a sixth message to the second network element. The sixth message requests registration and / or authentication of the terminal device. The sixth message includes the PLMN of the terminal device and / or the identifier of the terminal device. The sixth message is used to determine the roaming of the terminal device and the network element to which the terminal device belongs.

[0210] Correspondingly, the second network element receives the sixth message.

[0211] In this embodiment, after deregistering, the terminal device sends a sixth message to the second network element. Upon receiving the sixth message, the second network element can determine whether the terminal device is roaming and its home network element based on the sixth message, and then execute step 804 below. The second network element's determination of terminal device roaming and the sixth message can be implemented with reference to the above embodiments, and will not be repeated here.

[0212] Optionally, if the second network element determines that the terminal device is not roaming, the second network element registers and / or authenticates the terminal device in the following manner: It obtains the terminal device's authentication and signing information from the network element corresponding to the second network element that stores the terminal device's authentication and signing information locally, or it obtains the terminal device's authentication and signing information and / or security context information locally; it then registers and / or authenticates the terminal device based on the obtained authentication and signing information and / or security context information. Obtaining the terminal device's authentication and signing information from the network element corresponding to the second network element that stores the terminal device's authentication and signing information locally ensures that the second network element obtains the latest authentication and signing information, thereby improving the accuracy of terminal device registration and / or authentication and signing. Obtaining the terminal device's authentication and signing information and / or security context information locally ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services currently running on the terminal device continue to operate.

[0213] Optionally, the terminal device may first attempt to obtain the authentication and signing information of the terminal device from the network element corresponding to the local storage of the terminal device's authentication and signing information. If successful, the terminal device is registered and / or authenticated and signed based on the authentication and signing information of the terminal device, and the security context information of the terminal device generated during the registration and / or authentication and signing process is obtained. If it fails (e.g., the network element corresponding to the local storage of the terminal device's authentication and signing information is faulty, or the link between the second network element and the terminal device is faulty), the terminal device is registered and / or authenticated and signed based on the authentication and signing information and / or security context information of the terminal device obtained locally.

[0214] Optionally, if the terminal device registration and / or authentication agreement is completed, the second network element can store the terminal device's authentication agreement information and / or security context information obtained during this registration and / or authentication agreement process. This provides information for the next registration and / or authentication agreement.

[0215] Step 804: When the home network element fails or the link between the home network element and the second network element fails, the second network element obtains authentication and subscription information and / or security context information of the terminal device from the third network element.

[0216] Step 805: The second network element registers and / or authenticates the terminal device based on the terminal device's authentication and signing information and / or security context information.

[0217] In this embodiment, for the identified roaming terminal device, the second network element can register and / or authenticate and sign off on the terminal device according to the following methods 3 and / or 4: Method 3: The second network element obtains the authentication and signing off information of the terminal device from the home network element of the terminal device, and then registers and / or authenticates and signs off on the terminal device based on the authentication and signing off information of the terminal device. Method 4: As can be seen from the above, the authentication and signing off information and / or security context information of the terminal device within the service area of ​​the first network element can be exported to the third network element. Therefore, the second network element can obtain the authentication and signing off information and / or security context information of the terminal device from the third network element and register and / or authenticate and sign off on the terminal device.

[0218] In one possible implementation, the second network element can first attempt to register and / or authenticate the terminal device according to method 3 above; if the home network element fails or the link between the home network element and the second network element fails, the terminal device can be registered and / or authenticated according to method 4 above (i.e., steps 804 to 805 are executed). This ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services running on the terminal device continue to operate.

[0219] In this embodiment, the roaming terminal device identified by the second network element in step 803 can be either a local terminal device of the first network element or a roaming terminal device identified by the first network element; this application does not limit this. For example, if the terminal device's home location is home location 1, the first network element is a network element of home location 2, and the second network element is a network element of home location 3, then the first network element can determine that the terminal device is roaming and thus execute steps 801 and 802 as described above. Similarly, the second network element also determines that the terminal device is roaming and thus executes the implementation methods for roaming terminal devices in steps 803-805 as described above.

[0220] Optionally, in this embodiment, the network elements exported by the first network element in step 801 for non-roaming terminal devices and by the fourth network element in step 802 for roaming terminal devices may be different. This application does not limit this.

[0221] Optionally, in this embodiment, after step 802, if the first network element is not faulty and the link between the first network element and the terminal device is not faulty, then the second network element in steps 803-805 can be replaced by the first network element. That is, the terminal device is still registered and / or authenticated through the network elements of the main plane. This application does not limit this. If the first network element is faulty and / or the link between the first network element and the terminal device is faulty, then steps 804-805 are executed.

[0222] based on Figure 8In the described embodiment, for a terminal device within the service area of ​​a first network element, the first network element can first identify whether the terminal device is roaming or not. If roaming, the terminal device's home network element (i.e., the fourth network element) determines whether the terminal device is roaming out. If roaming out, the fourth network element exports the terminal device's authentication and subscription information to the third network element. Conversely, if not roaming, the first network element normally registers and / or authenticates the terminal device, allowing it to export the terminal device's authentication and subscription information to the third network element after registration and / or authentication. Since the third network element is located in the escape plane, all terminal devices within the service area of ​​the first network element can also re-register and / or re-authenticate in the escape plane when the main plane fails. This helps ensure the normal operation of services for all terminal devices within the service area of ​​the first network element.

[0223] Based on the above Figure 8 The described embodiments, taking a 5G mobile communication system as an example, Figure 9 A schematic diagram illustrating the process before and during UE escape is shown. Specifically, in... Figure 9 In this context, the local AMF is the first network element, the escape AMF is the second network element, the escape UDM / data cache center is the third network element, the remote UDM is the fourth network element, and the local UDM is the network element that stores the authentication and subscription information of the local storage terminal device corresponding to the first network element.

[0224] Step 901: The local AMF receives a registration request from the UE.

[0225] Step 902: The local AMF identifies whether the UE is roaming.

[0226] In this embodiment, if the local AMF identifies that the UE is not roaming, steps 903 to 905 are executed; otherwise, steps 906 to 909 are executed. Steps 901 to 907 and 909 can be implemented with reference to step 801, and will not be described in detail here.

[0227] Step 903: The local AMF obtains the UE's authentication and subscription information from the local UDM.

[0228] Step 904: Export the UE's authentication and subscription information from the local UDM to the Escape UDM / Data Cache Center.

[0229] Step 905: The local AMF registers and / or authenticates the UE.

[0230] Step 906: The local AMF obtains the UE's authentication and subscription information from the external UDM.

[0231] Step 907: The external UDM determines the UE overflow.

[0232] Step 908: Export the UE's authentication and subscription information from the external UDM to the escape UDM / data cache center.

[0233] Step 908 can be implemented by referring to step 802, and will not be described in detail here.

[0234] Step 909: The local AMF registers and / or authenticates the UE to obtain the UE's security context information.

[0235] Step 910: The Escape AMF receives a registration request from the UE.

[0236] Step 911: Escape AMF identifies whether the UE is roaming.

[0237] In this embodiment of the application, if the escape AMF identifies that the UE is not roaming, then steps 912 and 914 are executed; otherwise, steps 913 and 914 are executed. Steps 910 to 914 can be implemented with reference to steps 804 to 805, and will not be described in detail here.

[0238] Step 912: The Escape AMF obtains the UE's authentication and subscription information and / or security context information from the Escape UDM / Data Cache Center / Local source.

[0239] Step 913: The escape AMF obtains the UE's authentication and subscription information and / or security context information from the local UDM on the main plane / the external UDM on the main plane / the escape UDM / the data cache center / local.

[0240] Step 914: The Escape AMF registers and / or authenticates the UE.

[0241] 2. Special Area Scenarios

[0242] In this embodiment, the special area refers to an area prone to failure, and / or an area with a relatively simple link between the special area and other areas (i.e., after the link fails, communication cannot be carried out through other links). For example, the special area is an island area.

[0243] Figure 10 A communication method is shown, which includes steps 1001 to 1005. Figure 10 The method shown can be applied to the terminal device side, the first network element side, the second network element side, the third network element side, and the fourth network element side. The terminal device side / first network element side / second network element side / third network element side / fourth network element side can be the terminal device / first network element / second network element / third network element / fourth network element, or it can be a processor, module, chip, chip system, or functional module implementing the method. In the embodiments of this application, the first network element, second network element, third network element, and fourth network element can be implemented with reference to the above embodiments, and will not be repeated here.

[0244] Figure 10 Taking the terminal equipment as the executing entity, and the first network element, second network element, third network element, and fourth network element as examples, the following is an introduction:

[0245] Step 1001: The first network element sends a fourth message to the fourth network element. The fourth message includes information about the area where the terminal device is located. The fourth message is used to determine that the area where the terminal device is located is a first area outside the service area of ​​the fourth network element.

[0246] Accordingly, the fourth network element receives the fourth message.

[0247] In this embodiment, the fourth network element is the home network element of the terminal device. The specific implementation can be referred to the above embodiment, and will not be repeated here.

[0248] In one possible implementation, before step 1001, the terminal device may first send a seventh message to the first network element, requesting processing of the terminal device. The seventh message includes information about the area where the terminal device is located. Then, the first network element sends a fourth message to the fourth network element. The specific implementation of the seventh message requesting processing of the terminal device can be referred to in the above embodiments, specifically the implementation of the first message requesting processing of the terminal device, which will not be elaborated here.

[0249] In one possible implementation, the area information of the terminal device includes, but is not limited to, one or more of the following: tracing area ID (TAI), location area ID (LAI), or cell global identifier (CGI).

[0250] In this embodiment, when the fourth network element receives the fourth message, it can determine that the area where the terminal device is located is a first area outside the service area of ​​the fourth network element based on the information about the area where the terminal device is located in the fourth message. Then, step 1002 can be executed. The first area can be a predefined special area; for example, it can be predefined by protocol specification or instruction from other network elements, but this application does not limit this.

[0251] Optionally, if the fourth network element determines that the region where the terminal device is located is its service area based on the information about the terminal device's location in the fourth message, then the fourth network element can automatically export the terminal device's authentication and subscription information to the third network element. In this way, the normal operation of the terminal device's services can be ensured based on the authentication and subscription information of the terminal device stored in the third network element.

[0252] Step 1002: The fourth network element sends a fifth message to the third network element. The fifth message includes the authentication and signing information of the terminal device.

[0253] Correspondingly, the third network element receives the fifth message.

[0254] In this embodiment, the fourth network element stores the authentication and subscription information of the terminal device. After determining that the terminal device is located in the first area, the fourth network element can send a fifth message to the third network element, which includes the authentication and subscription information of the terminal device.

[0255] Step 1003: The terminal device sends a sixth message to the second network element. The sixth message requests registration and / or authentication of the terminal device. The sixth message includes the area information where the terminal device is located. The sixth message is used to determine the network element to which the terminal device belongs and to determine that the terminal device is located in the first area.

[0256] Correspondingly, the second network element receives the sixth message.

[0257] In this embodiment, after deregistering, the terminal device sends a sixth message to the second network element. Upon receiving the sixth message, the second network element can determine that the terminal device is located in the first area, and also determines the network element to which the terminal device belongs. Then, step 1004 is executed. The second network element's determination that the terminal device is located in the first area can be implemented with reference to step 1001, and will not be elaborated here.

[0258] Step 1004: When the home network element fails or the link between the home network element and the second network element fails, the second network element obtains the authentication and subscription information of the terminal device from the third network element.

[0259] Step 1005: The second network element registers and / or authenticates / signs the terminal device based on the authentication and signing information of the terminal device.

[0260] In this embodiment, for the identified terminal device located in the second area, the second network element can register and / or authenticate the terminal device according to the following methods 5 and / or 6: Method 5: The second network element obtains the authentication and signing information of the terminal device from the home network element of the terminal device, and then registers and / or authenticates the terminal device based on the authentication and signing information. Method 6: As can be seen from the above, the authentication and signing information of the terminal device located in the first area can be exported to the third network element. Therefore, the second network element can obtain the authentication and signing information of the terminal device from the third network element and register and / or authenticate the terminal device.

[0261] In one possible implementation, the second network element can first attempt to register and / or authenticate the terminal device according to method 5 above; if the home network element fails or the link between the home network element and the second network element fails, the terminal device can be registered and / or authenticated according to method 6 above (i.e., steps 1004 to 1005 are executed). This ensures that the terminal device can be registered and / or authenticated, thereby ensuring that the services running on the terminal device continue to operate.

[0262] Optionally, in this embodiment, after step 1002, if the first network element is not faulty and the link between the first network element and the terminal device is not faulty, then the second network element in steps 1003-1005 can be replaced by the first network element. That is, the terminal device is still registered and / or authenticated through the network elements of the main plane. This application does not limit this. If the first network element is faulty and / or the link between the first network element and the terminal device is faulty, then steps 1004-1005 are executed.

[0263] based on Figure 10 In the described embodiment, for a terminal device in a first area (special area), a first network element can first identify that the terminal device is located in the first area; then, the first network element sends a request to a fourth network element, so that the fourth network element can identify that the terminal device is located in the first area and export the authentication and subscription information of the terminal device to a third network element. Since the third network element is located in the escape plane, when the main plane fails, especially when the first area in the main plane fails, the terminal device in the first area can also re-register and / or re-authenticate and subscribe in the escape plane. This helps to ensure that the services of the terminal devices in the first area can operate normally.

[0264] Based on the above Figure 11 The described embodiments, taking a 5G mobile communication system as an example, Figure 11 A schematic diagram illustrating the process before and during UE escape is shown. Specifically, in... Figure 11 In this context, the local AMF is the first network element mentioned above, the escape AMF is the second network element mentioned above, the escape UDM / data cache center is the third network element mentioned above, and the foreign UDM is the fourth network element mentioned above. The foreign UDM is located outside the first region, or the first region where the UE is located is not within the service area of ​​the foreign UDM.

[0265] Step 1101: The local AMF receives a registration request from the UE.

[0266] Step 1102: The local AMF determines that the UE is located in the first region.

[0267] Step 1103: The local AMF obtains the UE's authentication and subscription information from the external UDM.

[0268] Step 1104: The external UDM determines that the UE is located in the first region.

[0269] Steps 1101 to 1104 can be implemented with reference to step 1001, and will not be described in detail here.

[0270] Step 1105: Export the UE's authentication and subscription information from the external UDM to the escape UDM / data cache center.

[0271] Step 1105 can be implemented by referring to step 1002, and will not be described in detail here.

[0272] Step 1106: The local AMF registers and / or authenticates the UE.

[0273] Step 1107: The Escape AMF receives a registration request from the UE.

[0274] Step 1108: Escape AMF determines that the UE is located in the first area.

[0275] Step 1109: The Escape AMF obtains the UE's authentication and subscription information and / or security context information from the external UDM / Escape UDM / Data Cache Center on the main plane.

[0276] Step 1110: The Escape AMF registers and / or authenticates the UE.

[0277] Steps 1106 to 1110 can be implemented by referring to steps 1003 to 1005, and will not be repeated here.

[0278] Optionally, the above embodiments can be implemented individually or in combination in specific applications, and this application does not limit this. Furthermore, in the embodiments of this application, the information exported from the home network element of the terminal device to the third network element is not limited to the authentication and subscription information of the terminal device.

[0279] The following describes the communication device provided in the embodiments of this application.

[0280] This application divides the communication device into functional modules according to the above-described method embodiments. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated modules can be implemented in hardware or as software functional modules. It should be noted that the module division in this application is illustrative and represents only one logical functional division; other division methods may be used in actual implementation. The following will combine... Figures 12 to 14 The communication device of the present application embodiment is described in detail.

[0281] Figure 12This is a schematic diagram of the structure of a communication device provided in an embodiment of this application, such as... Figure 12 As shown, the communication device includes a processing module 1201 and a communication module 1202. The communication module 1202 can implement corresponding communication functions, and the processing module 1201 is used to implement corresponding processing functions. For example, the communication module 1202 can also be an interface, a communication interface, etc.

[0282] In this embodiment, the communication device can be used to perform the actions performed on the first network element side / fourth network element side in the method embodiment described above. In this case, the first network element side / fourth network element side can be the first network element / fourth network element itself or a chip or functional module configurable within the first network element / fourth network element. The communication module 1202 is used to perform transmit / receive related operations on the first network element side / fourth network element side in the method embodiment described above, and the processing module 1201 is used to perform processing related operations on the first network element / fourth network element in the method embodiment described above.

[0283] In some embodiments, when the actions performed by the first network element are executed as described above: the communication module 1202 is configured to receive a first message from the terminal device, the first message being a request for processing of the terminal device, the first message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device, the first message being used to determine that the terminal device is roaming; and to send a second message to the second network element, the second message being a request for registration and / or authentication subscription of the terminal device, the second message including the PLMN of the terminal device and / or the identifier of the terminal device. The processing module 1201 is configured to process the first message.

[0284] In some embodiments, when the actions performed by the first network element are executed as described above: the communication module 1202 is configured to receive a first message from the terminal device, the first message being used to request processing of the terminal device, the first message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device, the first message being used to determine that the terminal device is roaming; obtain the authentication and subscription information and / or security context information of the terminal device; and send a third message to the third network element, the third message including the authentication and subscription information and / or security context information of the terminal device. The processing module 1201 is configured to process the first message.

[0285] In some embodiments, when the actions performed by the fourth network element are executed as described above: the communication module 1202 is configured to receive a fourth message from the first network element, the fourth message being used to request the authentication and subscription information of the terminal device, the fourth message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device, the fourth message being used to determine that the terminal device is roaming, and the fourth network element being the home network element of the terminal device; and to send a fifth message to the third network element, the fifth message including the authentication and subscription information of the terminal device. The processing module 1201 is configured to process the fourth message.

[0286] In some embodiments, when the actions performed by the fourth network element are executed as described above: the communication module 1202 is configured to receive a fourth message from the first network element, the fourth message being used to request the authentication and subscription information of the terminal device, the fourth message including information about the area where the terminal device is located, the fourth message being used to determine that the area where the terminal device is located is a first area outside the service area of ​​the fourth network element of the terminal device, and the fourth network element is the home network element of the terminal device; and to send a fifth message to the third network element, the fifth message including the authentication and subscription information of the terminal device. The processing module 1201 is configured to process the fourth message.

[0287] In this embodiment, the communication device can be used to perform actions performed on the second network element side in the method embodiment described above. In this case, the second network element side can be the second network element itself or a chip or functional module configurable within the second network element. The communication module 1202 is used to perform transmit / receive related operations on the second network element side in the method embodiment described above, and the processing module 1201 is used to perform processing related operations on the second network element side in the method embodiment described above.

[0288] In some embodiments, the communication module 1202 is configured to receive a second message from a first network element, the second message being used to request registration and / or authentication and subscription for the terminal device, the second message including the operator mobile network identifier (PLMN) of the terminal device and / or the identifier of the terminal device; obtain authentication and subscription information and / or security context information of the terminal device; the processing module 1201 is configured to store the authentication and subscription information and / or security context information of the terminal device; after the terminal device deregisters, the communication module 1202 is further configured to receive a sixth message from the terminal device, the sixth message being used to request registration and / or authentication and subscription for the terminal device, the sixth message including the PLMN of the terminal device and / or the identifier of the terminal device, the sixth message being used to determine the roaming status of the terminal device and the home network element of the terminal device; when the home network element fails or the link between the home network element and the second network element fails, the processing module 1201 is further configured to register and / or authenticate and subscribe for the terminal device based on the authentication and subscription information and / or security context information of the terminal device.

[0289] In some embodiments, the communication module 1202 is configured to receive a sixth message from the terminal device after the terminal device has deregistered. The sixth message is used to request registration and / or authentication and subscription for the terminal device. The sixth message includes the operator mobile network identifier (PLMN) of the terminal device, the identifier of the terminal device, and / or the area information where the terminal device is located. The sixth message is used to determine the home network element of the terminal device and to determine whether the terminal device is located in a first area or is roaming. The processing module 1201 is configured to obtain authentication and subscription information and / or security context information of the terminal device from a third network element when the home network element fails or the link between the home network element and the second network element fails. Based on the authentication and subscription information and / or security context information of the terminal device, the processing module 1201 is configured to register and / or authenticate and subscribe for the terminal device.

[0290] Optionally, in the above embodiments, the communication device may further include a storage module, which can be used to store instructions and / or data. The processing module 1201 can read the instructions and / or data in the storage module so that the communication device can implement the aforementioned method embodiments.

[0291] The specific descriptions of the communication module and the processing module are merely examples. For the specific functions or execution steps of the communication module and the processing module, please refer to the above method embodiments, which will not be detailed here.

[0292] The communication device according to the embodiments of this application has been described above. The following describes the possible product forms of the communication device. Any device possessing the above-described... Figure 12 Any form of the communication device described herein falls within the protection scope of the embodiments of this application. The following description is merely illustrative and does not limit the product form of the communication device in the embodiments of this application to this extent.

[0293] In one possible implementation, Figure 12In the communication device shown, the processing module 1201 can be one or more processing circuits, and the communication module 1202 can be a communication circuit, or the communication module 1202 can also be a transmitting module and / or a receiving module. The transmitting module can be a transmitting circuit, and the receiving module can be a receiving circuit. The transmitting module and the receiving module are integrated into one device, such as a communication circuit. In the embodiments of this application, the processing circuit and the communication circuit can be coupled, etc. The connection method of the processing circuit and the communication circuit is not limited in the embodiments of this application. In the process of performing the above method, the process of sending information in the above method can be the process of the processing circuit outputting the above information. When outputting the above information, the processing circuit outputs the above information to the communication circuit so that the communication circuit can transmit (or output). After the above information is output by the processing circuit, it may need to undergo other processing before reaching the communication circuit. Similarly, the process of receiving information in the above method can be the process of the processing circuit receiving the input above information. When the processing circuit receives the input information, the communication circuit receives the above information and inputs it into the processing circuit. Furthermore, after the communication circuit receives the above information, the above information may need to undergo other processing before being input into the processing circuit.

[0294] Figure 13 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Figure 13 As shown, the communication device 130 includes one or more processing circuits 1320 and communication circuits 1310.

[0295] In some embodiments of this application, the communication device can be used to perform the steps, methods, or functions performed on the first network element side / fourth network element side as described above. For example, the processing circuit 1320 can be used to perform, for example... Figure 12 The functions or steps implemented by the processing module 1201 shown can be executed by the communication circuit 1310, such as... Figure 12 The functions or steps implemented by the communication module 1202 shown are illustrated. For detailed descriptions of the processing circuit 1320 and the communication circuit 1310, please refer to [link / reference needed]. Figure 12 Alternatively, the method embodiments shown above will not be described in detail here.

[0296] In other embodiments of this application, the communication device is used to perform the steps, methods, or functions performed on the second network element side as described above. For example, the processing circuit 1320 can be used to perform, for example... Figure 12 The functions or steps implemented by the processing module 1201 shown can be executed by the communication circuit 1310, such as... Figure 12 The functions or steps implemented by the communication module 1202 shown are illustrated. For detailed descriptions of the processing circuit 1320 and the communication circuit 1310, please refer to [link / reference needed]. Figure 12 Alternatively, the method embodiments shown above will not be described in detail here.

[0297] For example, the processing circuitry may be one or more processors, or all or part of the circuitry within one or more processors. The communication circuitry may be a transceiver, an input / output circuit, or an interface circuit, etc.

[0298] For example, in Figure 13 In various implementations of the communication device shown, the communication circuitry may include a receiver for performing a receiving function (or operation) and a transmitter for performing a transmitting function (or operation). The communication circuitry is also used for communicating with other devices / communication devices via a transmission medium.

[0299] Optionally, the communication device 130 may further include one or more memories 1330 for storing program instructions and / or data. The memories 1330 are coupled to the processing circuitry 1320. The coupling in this embodiment is an indirect coupling or communication connection between communication devices, units, or modules, and can be electrical, mechanical, or other forms, used for information exchange between the communication devices, units, or modules. The processing circuitry 1320 may operate in conjunction with the memories 1330. The processing circuitry 1320 may execute the program instructions stored in the memories 1330. Optionally, at least one of the aforementioned memories may be included in the processing circuitry.

[0300] This application embodiment does not limit the specific connection medium between the communication circuit 1310, processing circuit 1320, and memory 1330. This application embodiment... Figure 13 The memory 1330, processing circuit 1320, and communication circuit 1310 are connected via a bus 1340. Figure 13 The connections between other components are shown in bold and are for illustrative purposes only, not as limiting information. The bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 13 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0301] In the embodiments of this application, the processing circuit may be a general-purpose processing circuit, a digital signal processing circuit, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., and can implement or execute the various methods, steps, and logic block diagrams in the embodiments of this application. The general-purpose processing circuit may be a microprocessor circuit or any conventional processing circuit, etc. The steps of the methods in conjunction with the embodiments of this application can be directly manifested as the execution of the hardware processing circuit, or the execution of the steps by combining hardware and software modules in the processing circuit, etc.

[0302] In this application embodiment, the memory may include, but is not limited to, non-volatile memory such as hard disk drive (HDD) or solid-state drive (SSD), random access memory (RAM), erasable programmable read-only memory (EPROM), read-only memory (ROM), or compact disc read-only memory (CD-ROM), etc. Memory is any storage medium capable of carrying or storing program code in the form of instructions or data structures, and capable of being read and / or written by a computer (such as the communication device shown in this application), but is not limited to these. The memory in this application embodiment may also be a circuit or any other communication device capable of implementing storage functions, used to store program instructions and / or data.

[0303] For example, the processing circuit 1320 is mainly used to process communication protocols and communication data, control the entire communication device, execute software programs, and process the data of the software programs. The memory 1330 is mainly used to store software programs and data. The communication circuit 1310 may include a control circuit and an antenna. The control circuit is mainly used for the conversion between baseband signals and radio frequency signals, and for processing radio frequency signals. The antenna is mainly used for transmitting and receiving radio frequency signals in the form of electromagnetic waves. Input / output communication devices, such as touch screens, displays, and keyboards, are mainly used to receive user input data and output data to the user.

[0304] When the communication device is powered on, the processing circuit 1320 can read the software program in the memory 1330, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be transmitted wirelessly, the processing circuit 1320 performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit then performs RF processing on the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processing circuit 1320. The processing circuit 1320 converts the baseband signal into data and processes the data.

[0305] In another implementation, the radio frequency circuit and antenna can be set up independently of the processing circuit that performs baseband processing. For example, in a distributed scenario, the radio frequency circuit and antenna can be arranged in a remote manner, independent of the communication device.

[0306] The communication device shown in the embodiments of this application may also have a higher... Figure 13Other components, etc., are not limited in this application embodiment. The methods performed by the processing circuit and communication circuit shown above are merely examples, and the specific steps performed by the processing circuit and communication circuit can be referred to the methods described above.

[0307] In another possible implementation Figure 12 In the communication device shown, the processing module 1201 can be one or more logic circuits, and the communication module 1202 can be an input / output interface, or a communication interface, or an interface circuit, or an interface, etc. Alternatively, the communication module 1202 may also include a transmitting module and / or a receiving module. The transmitting module may include an output interface, and the receiving module may include an input interface. The transmitting module and the receiving module are integrated into one module, such as an input / output interface.

[0308] Figure 14 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Figure 14 As shown, Figure 14 The communication device shown includes logic circuit 1401 and interface circuit 1402. That is, the processing module 1201 can be implemented using logic circuit 1401, and the communication module 1202 can be implemented using interface circuit 1402. The logic circuit 1401 can be a chip, processing circuit, integrated circuit, or system-on-chip (SoC) chip, etc., and the interface circuit 1402 can be a communication interface, input / output interface, pins, etc. For example, Figure 14 The communication device can be a chip, which includes logic circuit 1401 and interface circuit 1402.

[0309] In this embodiment, the logic circuit and the interface can also be coupled to each other. The specific connection method between the logic circuit and the interface is not limited in this embodiment. For example, the logic circuit 1401 can be used to perform... Figure 12 The interface circuit 1402 can be used to execute the functions or steps implemented by the processing module 1201 shown. Figure 12 The communication module 1202 shown illustrates the functions or steps implemented by this module. For detailed descriptions of the logic circuit 1401 and interface circuit 1402, please refer to [link / reference needed]. Figure 12 Alternatively, the method embodiments shown above will not be described in detail here.

[0310] The communication device shown in the embodiments of this application can implement the method provided in the embodiments of this application in hardware form, or it can implement the method provided in the embodiments of this application in software form, etc., and the embodiments of this application do not limit it in this way.

[0311] This application also provides a communication system, which includes a first network element side / fourth network element side and a second network element side. The first network element side / fourth network element side and the second network element side can be used to execute the methods in any of the foregoing embodiments.

[0312] In addition, this application also provides a computer program for implementing the operations and / or processes performed by various communication devices in the method provided in this application.

[0313] This application also provides a computer-readable storage medium storing computer code that, when executed on a computer, causes the computer to perform the operations and / or processes performed by various communication devices in the methods provided in this application.

[0314] This application also provides a computer program product comprising computer code or a computer program that, when run on a computer, causes the operations and / or processes performed by various entities in the method provided in this application to be executed.

[0315] In the embodiments provided in this application, it should be understood that the disclosed systems, communication devices, and methods can be implemented in other ways. For example, the communication device embodiments described above are merely illustrative. For instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, communication devices, or modules, or may be electrical, mechanical, or other forms of connection.

[0316] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the technical effects of the solutions provided in the embodiments of this application.

[0317] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0318] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0319] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method characterized by comprising: Applied to the first network element side, the method comprises: Receiving a first message from a terminal device, the first message being used for requesting processing of the terminal device, the first message comprising a PLMN (Public Land Mobile Network) of the terminal device and / or an identity of the terminal device; In a case where it is determined according to the first message that the terminal device is roaming, sending a second message to a second network element, the second message being used for instructing the second network element to acquire and store authentication subscription information and / or security context information of the terminal device, so that the second network element registers and / or authenticates and subscribes the terminal device based on the stored authentication subscription information and / or security context information of the terminal device in a case where it is determined that the terminal device is roaming and a home network element of the terminal device fails or a link between the home network element and the second network element fails; the second message comprising the PLMN of the terminal device and / or the identity of the terminal device; The first network element side is located in a main plane, and the second network element is located in an escape plane.

2. A communication method characterized by comprising: Applied to the first network element side, the method comprises: Receiving a first message from a terminal device, the first message being used for requesting processing of the terminal device, the first message comprising a PLMN (Public Land Mobile Network) of the terminal device and / or an identity of the terminal device; In a case where it is determined according to the first message that the terminal device is roaming, acquiring authentication subscription information and / or security context information of the terminal device, and sending a third message to a third network element, the third message comprising the authentication subscription information and / or the security context information of the terminal device, so that the second network element registers and / or authenticates and subscribes the terminal device based on the authentication subscription information and / or the security context information of the terminal device received by the third network element in a case where it is determined that the terminal device is roaming and a home network element of the terminal device fails or a link between the home network element and the second network element fails; The first network element side is located in a main plane, and the second network element and the third network element are located in an escape plane.

3. The method of claim 2, wherein, The acquiring of the authentication subscription information and / or the security context information of the terminal device comprises: Receiving authentication subscription information of the terminal device from a fourth network element, the fourth network element being a home network element of the terminal device.

4. A communication method characterized by comprising: Applied to the fourth network element side, the method comprises: Receiving a fourth message from a first network element, the fourth message being used for requesting acquisition of authentication subscription information of a terminal device, the fourth message comprising a PLMN (Public Land Mobile Network) of the terminal device and / or an identity of the terminal device, the fourth network element being a home network element of the terminal device; The fourth network element side is located in an escape plane. In a case where it is determined according to the fourth message that the terminal device is out of roaming, a fifth message is sent to a third network element, the fifth message comprising authentication and subscription information of the terminal device, so that the second network element registers and / or authenticates and subscribes the terminal device based on the authentication and subscription information of the terminal device received by the third network element in a case where it is determined that the terminal device is roaming and the fourth network element side fails or a link between the fourth network element side and the second network element fails. The first network element and the fourth network element side are located in a main plane, and the third network element and the second network element are located in an escape plane.

5. A communication method characterized by comprising: The method applied to the fourth network element side comprises: receiving a fourth message from a first network element, the fourth message being used to request authentication and subscription information of a terminal device, the fourth message comprising information of an area where the terminal device is located; In a case where it is determined according to the fourth message that the area where the terminal device is located is a first area outside a service area of the fourth network element, a fifth message is sent to a third network element, the fifth message comprising authentication and subscription information of the terminal device, so that the second network element registers and / or authenticates and subscribes the terminal device based on the authentication and subscription information of the terminal device received by the third network element in a case where it is determined that the terminal device is located in the first area and the fourth network element side fails or a link between the fourth network element side and the second network element fails. The first network element and the fourth network element side are located in a main plane, and the third network element and the second network element are located in an escape plane.

6. A communication method characterized by comprising: The method applied to the second network element side comprises: receiving a second message from a first network element, the second message being used to indicate that the second network element acquires and stores authentication and subscription information and / or security context information of a terminal device, the second message comprising a public land mobile network (PLMN) of the terminal device and / or an identifier of the terminal device; acquiring authentication and subscription information and / or security context information of the terminal device in a case where it is determined according to the second message that the terminal device is roaming; storing the authentication and subscription information and / or the security context information of the terminal device; after the terminal device is deregistered, receiving a sixth message from the terminal device, the sixth message being used to request registration and / or authentication and subscription of the terminal device, the sixth message comprising the PLMN of the terminal device and / or the identifier of the terminal device; registering and / or authenticating and subscribing the terminal device based on the stored authentication and subscription information and / or security context information of the terminal device in a case where it is determined according to the sixth message that the terminal device is roaming and a home network element of the terminal device fails or a link between the home network element and the second network element fails. The first network element and the home network element are located in a main plane, and the second network element side is located in an escape plane.

7. The method of claim 6, wherein, The acquiring authentication and subscription information and / or security context information of the terminal device comprises: receiving authentication and subscription information of the terminal device from the home network element.

8. A communication method characterized by comprising: The method applied to the second network element side comprises: After the terminal device deregisters, a sixth message is received from the terminal device, the sixth message being used to request registration and / or authentication and subscription of the terminal device, the sixth message including a Public Land Mobile Network (PLMN) identity of the terminal device, an identity of the terminal device, and / or area information in which the terminal device is located, the sixth message being used to determine a home network element of the terminal device; In a case where it is determined according to the sixth message that the terminal device is located in the first area or the terminal device is roaming, and it is determined according to the sixth message that the home network element of the terminal device is faulty or a link between the home network element and the second network element is faulty, authentication and subscription information and / or security context information of the terminal device from a third network element are acquired; The terminal device is registered and / or authenticated and subscribed based on the authentication and subscription information and / or the security context information of the terminal device; The authentication and subscription information and / or the security context information of the terminal device from the third network element are sent by the first network element to the third network element in a case where it is determined by the first network element that the terminal device is roaming before the terminal device deregisters. The authentication and subscription information of the terminal device from the third network element are sent by the home network element to the third network element in a case where it is determined by the home network element that the terminal device is out of roaming or the area in which the terminal device is located is the first area before the terminal device deregisters. The first network element and the home network element are located in a main plane, and the second network element side and the third network element are located in an escape plane.

9. The method according to any one of claims 1-8, characterized in that, The identity of the terminal device includes one or more of the following: a Subscription Permanent Identifier (SUPI) of the terminal device, a Subscription Concealed Identifier (SUCI) of the terminal device, an International Mobile Subscriber Identity (IMSI) number segment of the terminal device, or a Mobile Subscriber International ISDN (MSISDN) number segment of the terminal device.

10. A communications device, characterized by The apparatus includes a module or unit for performing the method of any one of claims 1-9.

11. A communications device, characterized by The communication apparatus includes at least one processor; wherein the at least one processor is configured to cause the communication apparatus to perform the method of any one of claims 1-9.

12. A computer-readable storage medium, characterized in that, The storage medium has stored therein a computer program or instructions, and when the computer program or instructions are executed, the method of any one of claims 1-9 is performed.

Citation Information

Patent Citations

  • Roaming service registration method, device and system

    CN116095663A

  • Communication roaming method, system and device and storage medium

    CN117729526A

  • Roaming service opening method and system

    CN117793694A