Terminal access management method and communication system

The terminal's contract information and interface information are obtained through the source core network element, and the mobile identity cell is dynamically adjusted, which solves the problem of wasting air interface resources during network switching, and achieves more efficient network resource utilization and user experience improvement.

CN120343668AActive Publication Date: 2025-07-18CHINA TELECOM CORP LTD SATELLITE COMMUNICATIONS BRANCH

Patent Information

Application Number
CN202510512596.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-18
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

In the prior art, when switching the network, the terminal needs to have multiple air-interface interactions with the core network elements of the newly accessed network, resulting in serious waste of network air-interface resources and reducing service interaction efficiency.

Method used

Receive the terminal's identity identification through the source core network element, obtain contract information and interface information, dynamically adjust the mobile identity cell, optimize the mobility management process, ensure that the terminal chooses appropriate registration methods between different networks, and reduces unnecessary signaling interactions.

Benefits of technology

It improves network resource utilization efficiency, reduces connection failure rate, optimizes mobility management processes, improves user experience and network security, especially in the scenario of coordinated access between satellite and ground networks, which significantly saves resources and reduces latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343668A_ABST
    Figure CN120343668A_ABST
Patent Text Reader

Abstract

The invention discloses a terminal access management method and a communication system. The method comprises the following steps: a source core network element of a source network receives a first registration request message sent by a terminal, and the first registration request message at least carries a first identity identifier of the terminal; acquiring subscription information of the terminal according to the first identity label; pre-configured interface information is obtained, and the interface information is used for reflecting whether a network interface exists between the source core network element and a target core network element of a target network; and sending a target registration acceptance message to the terminal based on the subscription information and the interface information, the target registration acceptance message at least comprising: a mobile identity cell to indicate the type of a second identity identifier carried in a second registration request message sent when the terminal accesses the target network. According to the method and the device, the technical problem of serious waste of network air interface resources caused by the fact that air interface interaction needs to be carried out between the existing terminal and a core network element of a new access network for many times when the existing terminal switches the network is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication technologies, and in particular, to a terminal access management method and a communication system. Background Art

[0002] In existing communication protocols, when a terminal accesses a new network, it provides GUTI (Global Unique Temporary Identifier, 5G global unique temporary identifier) information or SUCI (Subscription Concealed Identifier, subscription concealed identifier) information during the registration process; the new mobile management module in the new network can identify the information of the original mobile management module in the old network based on the 5G-GUTI, and obtain the SUPI (Subscription Permanent Identifier, global unique subscription permanent identifier) information of the terminal and the terminal context information from the original mobile management module.

[0003] However, if the terminal does not provide SUCI information during the registration process when accessing a new network, or the old mobile management module cannot provide the SUPI information of the terminal to the new mobile management module, or the provided GUTI information is invalid, at this time, the new mobile management module needs to initiate an identity request process to the terminal to obtain the SUCI information of the terminal for subsequent registration processes. This will greatly increase the number of air interface interactions between the terminal and the core network of the new network, occupy a large amount of network air interface resources, and at the same time reduce the service interaction efficiency between the terminal and the core network of the new network.

[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of this application provide a terminal access management method and a communication system, so as to at least solve the technical problem that when an existing terminal switches networks, it needs to perform multiple air interface interactions with the core network elements of the newly accessed network, resulting in serious waste of network air interface resources.

[0006] According to one aspect of the embodiments of the present application, a terminal access management method is provided, including: a source core network element of a source network receives a first registration request message sent by a terminal, and at least the first identity identifier of the terminal is carried in the first registration request message; obtaining the subscription information of the terminal according to the first identity identifier; obtaining pre-configured interface information, where the interface information is used to reflect whether there is a network interface between the source core network element of the source network and the target core network element of the target network; based on the subscription information and the interface information, sending a target registration acceptance message to the terminal, where the target registration acceptance message at least includes: a mobile identity cell, and the mobile identity cell is used to indicate the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network.

[0007] Optionally, the types of the first identity identifier at least include: 5G globally unique temporary identifier, subscription hidden identifier.

[0008] Optionally, the first registration request message further carries an access identifier and a service scenario type, where the access identifier is used to identify the access technology by which the terminal accesses the source network, and the access technology includes one of the following: new radio access, evolved universal terrestrial radio access technology, satellite access technology; the service scenario type is used to indicate the network service type by which the terminal accesses the source network, and the network service type includes one of the following: voice service, data service, satellite communication service.

[0009] Optionally, the types of the source network and the target network include: terrestrial network or satellite network, where when the type of the source network is a terrestrial network, the type of the target network is a satellite network; when the type of the source network is a satellite network, the type of the target network is a terrestrial network or a satellite network.

[0010] Optionally, the source core network element is a source mobility management entity in the source network, and the target core network element is a target mobility management entity in the target network. Among them, sending a target registration acceptance message to the terminal based on the subscription information and interface information includes: when the target network access service is not included in the terminal's subscription information, or when the target network access service is included in the terminal's subscription information and there is a network interface between the source mobility management entity and the target mobility management entity, sending a first target registration acceptance message to the terminal, where the first target registration acceptance message at least includes a first mobile identity cell, and the first mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a 5G globally unique temporary identifier; when the target network access service is included in the terminal's subscription information, but there is no network interface between the source mobility management entity and the target mobility management entity, sending a second target registration acceptance message to the terminal, where the first target registration acceptance message at least includes a second mobile identity cell, and the second mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a subscription hidden identifier.

[0011] Optionally, the mobile identity cell at least includes a target byte for representing the type of the terminal's identity identifier, and the target byte has a total of eight bits, where the first four bits are all 1, the fifth bit is a spare bit, and the last three bits are used to distinguish different types of identity identifiers.

[0012] Optionally, the method further includes setting the spare bit of the target byte in the mobile identity cell to 0 to obtain a first mobile identity cell; setting the spare bit of the target byte in the mobile identity cell to 1 to obtain a second mobile identity cell.

[0013] According to another aspect of the embodiments of the present application, a terminal access management method is further provided, including: a target core network element in the target network receives a second registration request message sent by the terminal, and the second registration request message at least carries a second identity identifier of the terminal, where the second identity identifier includes: a target 5G globally unique temporary identifier assigned by a source core network element of the source network to the terminal, and a target subscription hidden identifier obtained by encrypting the terminal's globally unique subscription permanent identifier using a preset encryption key; when the second identity identifier is the target 5G globally unique temporary identifier, obtaining the terminal's globally unique subscription permanent identifier information from the source core network element of the source network according to the target 5G globally unique temporary identifier, and performing a registration process according to the globally unique subscription permanent identifier information; when the second identity identifier is the target subscription hidden identifier, performing a registration process according to the target subscription hidden identifier.

[0014] Optionally, the source core network element is a source mobility management entity in the source network. Among them, the globally unique subscription permanent identifier information of the terminal is obtained from the source core network element according to the target 5G globally unique temporary identifier, including: parsing the target 5G globally unique temporary identifier to obtain the identification information of the source mobility management entity and the public land mobile network identification information; sending a terminal context transfer request message to the source mobility management entity according to the identification information of the source mobility management entity and the public land mobile network identification information; receiving a terminal context transfer response message fed back by the source mobility management entity, where the terminal context transfer response message carries the context information of the terminal, and the context information at least includes the globally unique subscription permanent identifier information of the terminal.

[0015] According to another aspect of the embodiments of the present application, a communication system is further provided. The communication system at least includes: a terminal, a source core network element of the source network, and a target core network element of the target network. Among them, the terminal is used to send a first registration request message to the source core network element, and the first registration request message at least carries the first identity identifier of the terminal; sending a second registration request message to the target core network element block, and the second registration request message at least carries the second identity identifier of the terminal; the source core network element is used to execute the above terminal access management method; the target core network element is used to execute the above terminal access management method.

[0016] According to another aspect of the embodiments of the present application, a network device is further provided. The electronic device includes: a memory and a processor. Among them, a computer program is stored in the memory, and the processor is configured to execute the above terminal access management method through the computer program.

[0017] In the embodiments of the present application, the source mobility management entity dynamically adjusts the mobile identity cell based on the subscription information and interface configuration information of the terminal, so as to optimize the mobility management process. Thereby, not only can the flexibility and self-adaptability of the system architecture be improved; it can also ensure that when the terminal moves between different types of networks, it can select the most appropriate registration method, reducing the connection failure rate caused by improper use of identifiers. Furthermore, it solves the technical problem that due to the need for multiple radio interface interactions between the existing terminal and the core network element of the newly accessed network when switching networks, the radio interface resources of the network are seriously wasted. Description of the Drawings

[0018] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:

[0019] Figure 1 It is a schematic structural diagram of a 5G-GUTI in the related art;

[0020] Figure 2 is a schematic structural diagram of an optional communication system according to an embodiment of the present application;

[0021] Figure 3 is a schematic flowchart of an optional terminal access management according to an embodiment of the present application;

[0022] Figure 4 is a schematic flowchart of an optional process for obtaining terminal subscription information according to an embodiment of the present application;

[0023] Figure 5 is another schematic flowchart of an optional process for obtaining terminal subscription information according to an embodiment of the present application;

[0024] Figure 6 is another schematic flowchart of an optional terminal access management according to an embodiment of the present application;

[0025] Figure 7 is a schematic flowchart of an optional terminal access according to an embodiment of the present application;

[0026] Figure 8 is another schematic flowchart of an optional terminal access according to an embodiment of the present application;

[0027] Figure 9 is a schematic structural diagram of an optional network device according to an embodiment of the present application. Detailed implementation manners

[0028] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0029] It should be noted that the terms "first", "second", etc. in the specification, claims and drawings of the present application are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0030] To better understand the embodiments of the present application, the following is a translation and explanation of some nouns or terms that appear in the description process of the embodiments of the present application:

[0031] 5G-GUTI (Global Unique Temprrty Identifier, 5G Global Unique Temporary Identifier): It is a key identifier of the user equipment (UE) in the 5G (NR) mobile communication network. Generally, when receiving a registration request message of the initial registration or mobile registration update type from the terminal, the mobility management module (such as AMF or MME) will send a new 5G-GUTI to the terminal in the registration acceptance message; when receiving a registration request message of the periodic registration update type from the terminal, the mobility management module will send a new 5G-GUTI to the terminal in the registration acceptance message; when receiving a service request message from the terminal (triggered by the network, that is, the terminal's response to the network paging message), the mobility management module will cause the terminal configuration update program to send a new 5G-GUTI to the terminal. In addition, the structure of the 5G-GUTI is as Figure 1 shown, where the 5G-GUTI includes 80 bits and consists of the following parts:

[0032] (1) PLMN ID (Public Land Mobile Network Identifier, Public Land Mobile Network Identification): It consists of 12-bit MCC (Mobile Country Code, Mobile Country Code) and 12-bit MNC (Mobile Network Code, Mobile Network Code). Among them, the MCC is assigned by the ITU (International Telecommunication Union) and is used to uniquely identify the country where the PLMN where the UE is currently registered is located; the MNC is assigned by the national regulatory agency and is used to uniquely identify the mobile network operator in the PLMN;

[0033] (2) AMF (Access and Mobility Management Function Identifier, Access and Mobility Management Function Identification) ID: It consists of 8-bit AMF Region ID (i.e., the region identifier where the AMF is located), 10-bit AMF SetID (i.e., the set identifier of the AMFs belonging to the same region), and 6-bit AMF Pointer (i.e., identifying which AMF is in the AMF set), and is used to track and manage the UE in the core network;

[0034] (3) 5G-TMSI (5G Temporary Mobile Subscriber Identity): It is a temporary identifier assigned when a UE registers with a specific AMF, used to uniquely identify the UE within the AMF coverage area to enhance privacy protection. It occupies 32 bits.

[0035] SUCI (Subscription Concealed Identifier): It is the unique permanent identifier of the UE. Usually, to avoid transmitting this identifier in plain text, this identifier can be hidden through encryption. Among them, the encrypted value is called SUPI (Subscription Permanent Identifier). The encryption is performed by the UE during registration, and a new SUCI is generated each time to prevent tracking of the UE, while the decryption is performed by the Unified Data Management (UDM) network function in the packet core.

[0036] Base Station: Generally refers to the device used to provide wireless communication services, responsible for communicating with mobile devices through radio signals in a cellular network, and managing the connection and data transmission of user equipment. Base stations are mainly used in 2G, 3G, and 4G networks. It should be noted that in the 4G LTE (Long Term Evolution) network, the base station is usually called eNodeB (evolved Node B).

[0037] gNB (Next Generation Node B): It is the radio access device in the 5G network, equivalent to the eNodeB in 4G. The gNB supports the 5G NR (New Radio) interface and can provide higher bandwidth, lower latency, and more reliable connections.

[0038] Embodiment 1

[0039] First, according to the embodiments of the present application, a communication system is provided. Figure 2 It is a schematic structural diagram of an optional communication system 20 provided according to the embodiments of the present application, as Figure 2As shown in the figure. The communication system 20 at least includes: a terminal 21, a source core network element 22 of the source network, and a target core network element 23 of the target network. Among them, the types of the source network and the target network include: a terrestrial network or a satellite network. When the type of the source network is a terrestrial network, the type of the target network is a satellite network; when the type of the source network is a satellite network, the type of the target network is a terrestrial network or a satellite network. In addition, the source core network element 22 and the target core network element 23 can be mobility management entities in the network, such as an Access and Mobility Management Function (AMF) network element in a 5G network and a Mobility Management Entity (MME) network element in a 4G LTE network.

[0040] Specifically, the above-mentioned terminal 21 can send a first registration request message to the source core network element 22 (i.e., the source mobility management entity). Among them, the first registration request message at least carries a first identity identifier of the terminal 21. The source core network element 22 can receive the first registration request message and execute the following terminal access management method to reduce the network air interface resources when the terminal 21 accesses the target network.

[0041] The following will describe the specific steps of the source core network element 22 (using the "source mobility management entity" throughout the description of the method) in executing the terminal access management method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0042] Figure 3 is a flowchart of a terminal access management method provided according to an embodiment of the present application. As Figure 3 shown, the method includes the following steps:

[0043] Step S302: Receive a first registration request message sent by the terminal.

[0044] In the technical solution provided in the above step S302, the first registration request message at least carries a first identity identifier of the terminal, so that the source network can identify and process the registration request of the terminal, and the types of the first identity identifier at least include: 5G globally unique temporary identifier (hereinafter all use the abbreviation "5G-GUTI"), subscription hidden identifier (hereinafter all use the abbreviation "SUCI") or other types of identity identifiers (such as international mobile subscriber identity IMSI), etc. Among them:

[0045] When the terminal does not have a valid 5G-GUTI when it initially registers or roams to the source network, it can carry the SUCI in the first registration request message for the source network to authenticate and register the terminal. Among them, the SUCI is converted into the SUPI by the authentication server function network element of the source network, enabling the source mobility management entity (AMF or MME) of the source network to perform subsequent operations, such as obtaining the subscription information and context information of the UE.

[0046] When the terminal carries a 5G-GUTI in the first registration request message, it indicates that the terminal has interacted with the source network, and this 5G-GUTI is a temporary and globally unique identifier assigned by the source network to the terminal. It can assist the source mobility management entity (AMF or MME) in the source network to quickly identify the terminal, thereby reducing the authentication process and restoring the terminal's information from the stored context to handle services more efficiently.

[0047] In addition, the first registration request message sent by the terminal may also include: access identifier, service scenario type, where:

[0048] The access identifier indicates the technology through which the terminal accesses the source network to initiate the first registration request message. This is crucial when establishing the initial connection between the terminal and the source network because different access types may require different processing procedures and network functions. Among them, the access technologies include but are not limited to: (5G) New Radio (NR) access, Evolved Universal Terrestrial Radio (E-UTRA) access technology, satellite access technology, non-3GPP (3rd Generation Partnership Project) access technology (such as Wi-Fi, Bluetooth, or wired network, etc.), Single Network Slice Selection Assistance Information (S-NSSAI) technology, etc. It should be noted that the access identifier can appear in the form of TAI (Tracking Area Identity), which is an identifier used to indicate the current tracking area where the terminal is located, or more specifically in the satellite scenario, it may contain parameters unique to the satellite network for the network side to identify.

[0049] The service scenario type indicates the network service type for the terminal to access the source network element, which is crucial for network management resources and selecting appropriate network slices. Among them, the network service types include but are not limited to: voice services (such as Voice over LTE (VoLTE) in 4G networks and Voice over New Radio (VoNR) in 5G networks), data services, satellite communication services, dedicated network services (such as enterprise networks, private networks), etc.

[0050] Step S304: Obtain the subscription information of the terminal according to the first identity identifier.

[0051] In the technical solution provided in the above step S304, according to the different types of identity identifiers, the above acquisition process can be divided into the following two cases:

[0052] Case 1: The type of the first identity identifier is SUCI. In this case, the process of obtaining the subscription information of the terminal is as Figure 4 shown, which includes the following steps:

[0053] The first step: The source mobility management entity resolves the SUCI to obtain the hidden SUPI, encryption information, and Home Network Identifier (HNI), where HNI includes MCC and MNC, that is, PLMN ID; and based on the resolved PLMN ID, query the Network Slice Selection Function (NSSF) or select the AUSF network element through other mechanisms, such as pre-configured mapping.

[0054] The second step: The source mobility management entity sends an authentication request message to the selected AUSF network element, where the authentication request message includes identity information (such as relevant information in the resolved SUPI or 5G-GUTI) and necessary authentication parameters.

[0055] The third step: The AUSF network element decrypts the SUCI using the key Kausf to extract the SUPI and relevant authentication parameters; obtains the authentication data of the terminal from the data management module (such as the Unified Data Management (UMD) network element in 5G networks and the Home Subscriber Server (HSS) network element in 4G networks) based on the SUPI, including the authentication key Ki and user identifier; generates a random number RAND and an authentication token AUTN, and calculates the expected response XRES through a preset security algorithm using the authentication key Ki and the random number RAND; combines parameters such as the random number RAND, the authentication token AUTN, and the expected response XRES into an authentication vector.

[0056] Step 4: The AUSF network element sends an authentication response message carrying the authentication vector to the source mobility management entity, where the authentication vector includes a random number RAND, an authentication token AUTN, and an expected response XRES;

[0057] Step 5: The source mobility management entity sends an authentication challenge carrying the authentication vector to the terminal;

[0058] Step 6: The terminal uses its own key Ki and the received random number RAND to generate an authentication response RES;

[0059] Step 7: The terminal sends the authentication response RES to the source mobility management entity;

[0060] Step 8: The source mobility management entity compares the authentication response RES with the expected response XRES to obtain an authentication result. Among them, if the authentication response RES matches the expected response XRES, it means that the authentication is successful; otherwise, it means that the authentication fails;

[0061] Step 9: In the case where the authentication result is successful authentication, the source mobility management entity interacts with the data management module to obtain the subscription information of the terminal, including: service plan (such as satellite access service), network permissions, QoS (Quality of Service) configuration, etc.

[0062] Case 1: The type of the first identity identifier is 5G-GUTI. In this case, the process of obtaining the subscription information of the terminal is as Figure 5 shown, and it includes the following steps:

[0063] Step 1: The source mobility management entity sends an Identity Request message to the terminal;

[0064] Step 2: Receive the Identity Reponse message fed back by the terminal, where the identity response message carries the SUCI of the terminal;

[0065] Step 3: The source mobility management entity directly parses the 5G-GUTI to obtain the PLMN ID (Public Land Mobile Network Identifier), AMF Region ID, AMF Set ID, and AMF Pointer; and based on the parsed PLMN ID, query the NSSF (Network Slice Selection Function) or select the AUSF network element through other mechanisms, such as pre-configured mapping;

[0066] Step 4: The source mobility management entity sends an authentication request message to the selected AUSF network element. The authentication request message includes identity information (such as relevant information in the parsed SUPI or 5G-GUTI) and necessary authentication parameters.

[0067] Step 5: The AUSF network element decrypts the SUCI using the key Kausf, extracts the SUPI and relevant authentication parameters; obtains the authentication data of the terminal from the data management module (such as the unified data management UMD network element in the 5G network and the home subscriber server HSS network element in the 4G network) based on the SUPI, including the authentication key Ki and the user identifier; generates a random number RAND and an authentication token AUTN, and uses the authentication key Ki and the random number RAND to calculate the expected response XRES through a preset security algorithm; combines parameters such as the random number RAND, the authentication token AUTN, and the expected response XRES into an authentication vector.

[0068] Step 6: The AUSF network element sends an authentication response message carrying the authentication vector to the source mobility management entity. The authentication vector includes the random number RAND, the authentication token AUTN, and the expected response XRES.

[0069] Step 7: The source mobility management entity sends an authentication challenge carrying the authentication vector to the terminal.

[0070] Step 8: The terminal generates an authentication response RES using its own encryption key Ki and the received random number RAND.

[0071] Step 9: The terminal sends the authentication response RES to the source mobility management entity.

[0072] Step 10: The source mobility management entity compares the authentication response RES with the expected response XRES to obtain an authentication result. If the authentication response RES matches the expected response XRES, it indicates successful authentication; otherwise, it indicates failed authentication.

[0073] Step 11: In the case of successful authentication, the source mobility management entity interacts with the data management module to obtain the subscription information of the terminal.

[0074] It should be noted that in Step 9 and Step 11 above, the interaction between the source mobility management entity and the data management module to obtain the subscription information of the terminal is the content disclosed in the existing protocol. Therefore, the embodiments of the present application do not specifically describe this interaction process. Figure 4 in Step 9 and Figure 5 in Step 11, the interaction between the source mobility management entity and the data management module to obtain the subscription information of the terminal is the content disclosed in the existing protocol. Therefore, the embodiments of the present application do not specifically describe this interaction process.

[0075] Step S306, obtain the pre-configured interface information.

[0076] In the technical solution provided in step S306 above, the interface information is used to reflect whether there is a network interface between the source mobility management entity and the target mobility management entity of the target network. This information enables the source mobility management entity to determine whether it can directly communicate with the target mobility management entity of the target network, and whether it can seamlessly handle the handover or redirection of the terminal from the source network to the target network.

[0077] Step S308: Based on the subscription information and the interface information, send a target registration acceptance message to the terminal.

[0078] In the technical solution provided in step S308 above, the target registration acceptance message at least includes: a Mobility Identity Information Element, which is used to indicate the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network.

[0079] Specifically, the Mobility Identity Information Element defines different formats for representing the mobility identity identifier, including but not limited to GUTI (5G Globally Unique Temporary Identifier) and SUCI (Subscription Concealed Identifier), etc. Its specific structure is shown in Table 1 below.

[0080] Table 1

[0081]

[0082] As can be seen from Table 1 above, the Mobility Identity Information Element contains a target byte (i.e., octet 4) for representing the type of the identity identifier of the terminal, and octet 4 includes eight bits. Among them, the first four bits are all 1, the fifth bit is a spare bit (i.e., 0spare), and the last three bits are used to distinguish different types of identity identifiers.

[0083] Therefore, in the technical solution provided in step S308 above, depending on the different subscription information and interface information, the source mobility management entity can divide the feedback of the target registration acceptance message into the following three cases. Among them, the formats of the Mobility Identity Information Element corresponding to different cases are different, specifically as follows:

[0084] Case 1: The subscription information of the terminal does not include the target network access service.

[0085] In this case, the source mobility management entity may send a first target registration acceptance message to the terminal. The first target registration acceptance message at least includes a first mobile identity cell, and the first mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a 5G globally unique temporary identifier.

[0086] Case 2: The subscribed information of the terminal includes the target network access service and there is a network interface between the source mobility management entity and the target mobility management entity.

[0087] In this case, the source mobility management entity may send a first target registration acceptance message to the terminal. The first target registration acceptance message at least includes a first mobile identity cell, and the first mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a 5G globally unique temporary identifier.

[0088] Among them, in the above two cases, the source mobility management entity may set the spare bit position of the target byte in the mobile identity cell to 0 (that is, keep 0spare as "0") to obtain the first mobile identity cell.

[0089] Case 3: The subscribed information of the terminal includes the target network access service, but there is no network interface between the source mobility management entity and the target mobility management entity.

[0090] In this case, the source mobility management entity may send a second target registration acceptance message to the terminal. The first target registration acceptance message at least includes a second mobile identity cell, and the second mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a subscription hidden identifier.

[0091] Among them, in the above case, the source mobility management entity may set the spare bit position of the target byte in the mobile identity cell to 1 (that is, set 0spare to "1") to obtain the second mobile identity cell.

[0092] In the technical solution provided in the above step S308, the source mobility management entity may determine which type of identity identifier the terminal should carry when sending the second registration request message to the target network according to the subscribed information and the interface information, and indicate the determination result through the mobile identity cell. Furthermore, the source mobility management entity feeds back the target registration acceptance message carrying the mobile identity cell to the terminal. This can ensure that the identity authentication and registration process between the terminal and the target network is carried out based on the indication of the source mobility management entity, thus avoiding unnecessary signaling interactions, saving satellite resources, and improving the network efficiency and user experience in different access scenarios.

[0093] Based on the solution defined in the above steps S302 to S308, it can be known that in the embodiment of the present application, the source mobility management entity dynamically adjusts the mobile identity cell carried in the registration acceptance message based on the subscription information of the terminal and the interface configuration. On the one hand, it can improve the flexibility and self-adaptability of the network architecture; on the other hand, it can also optimize the mobility management process to ensure that when the terminal moves between different types of networks, it can select the most appropriate registration method, reducing the connection failure rate caused by improper use of identifiers. Especially when the terminal switches between the terrestrial network and the satellite network, or between different satellite networks, this access mechanism can achieve higher resource utilization efficiency and user service quality.

[0094] Furthermore, the above terminal 21 can also send a second registration request message to the target core network element 23 (i.e., the target mobility management entity), where the second registration request message carries at least the second identity identifier of the terminal 21. The target core network element 23 can receive the second registration request message and execute the following terminal access management method to reduce the network air interface resources when the terminal 21 accesses the target network.

[0095] The following will describe the specific steps of the target core network element 23 (using "target mobility management entity" throughout the description of the method) in executing the terminal access management method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0096] Figure 6 is a flowchart of a terminal access management method provided according to an embodiment of the present application, as Figure 6 shown, the method includes the following steps:

[0097] Step S602, receiving a second registration request message sent by the terminal.

[0098] In the technical solution provided in the above step S602, the second registration request message carries at least the second identity identifier of the terminal, and the second identity identifier includes: the target 5G globally unique temporary identifier assigned by the source core network element of the source network to the terminal, and the target subscription hidden identifier obtained by encrypting the globally unique subscription permanent identifier of the terminal using a preset encryption key, and the encryption key is the encryption key negotiated during the authentication process between the terminal and the target core network element.

[0099] Step S604: When the second identity identifier is the target 5G globally unique temporary identifier, obtain the globally unique subscription permanent identifier information of the terminal from the source core network element of the source network based on the target 5G globally unique temporary identifier, and authenticate and register the terminal based on the globally unique subscription permanent identifier information.

[0100] In the technical solution provided in the above step S604, since the terminal uses the target 5G-GUTI for the registration request, that is to say, the subscribed information of the terminal includes the target network access service, and there is an interface between the source core network element and the target core network element (that is, these two core network elements can exchange the context information of the terminal with each other). At this time, when the terminal switches to the target network, the target core network element can identify which source core network element assigned it according to the target 5G-GUTI, and ask the source core network element about the globally unique subscription permanent identifier information of the terminal, and perform subsequent authentication processes, subscribed information acquisition and other registration processes on the terminal based on the globally unique subscription permanent identifier information.

[0101] Specifically, in the technical solution provided in the above step S604, the target core network element can obtain the globally unique subscription permanent identifier information of the terminal according to the following steps, including:

[0102] The first step: Parse the target 5G globally unique temporary identifier to obtain the identification information of the source core network element (such as AMF ID, etc.) and the public land mobile network identification information PLMN ID;

[0103] The second step: Send a terminal context transfer request message to the source core network element based on the identification information of the source core network element and the public land mobile network identification information;

[0104] The third step: Receive the terminal context transfer response message fed back by the source mobility management entity. The terminal context transfer response message carries the context information of the terminal, and the context information includes at least the globally unique subscription permanent identifier information of the terminal;

[0105] It should be noted that in the case where the source network is a terrestrial network and the target network is a satellite network, the target core network element can interact with the source core network element through the N14 interface.

[0106] Specifically, Figure 7 is a flowchart of a terminal access according to an embodiment of the present application. As Figure 7 shown, when the second identity identifier in the second registration request message is the target 5G-GUTI, the following interactions can occur between the terminal and the target network to implement the terminal access process, including:

[0107] Step 1: The terminal sends a second Registration Request message to the network access module, and the second Registration Request message carries at least the target 5G-GUTI assigned by the source mobility management entity to the terminal. Among them, if the target network is a satellite network, the network access module is a Ground Station (also known as an earth station); if the target network is a terrestrial network, the network access module can be a base station or a gNB.

[0108] Step 2: The network access module selects a target mobility management entity and forwards the second Registration Request message to the selected target mobility management entity.

[0109] Step 3: The target mobility management entity parses the target 5G-GUTI to obtain the identification information of the source mobility management entity and the PLMN ID information.

[0110] Step 4: The target mobility management entity sends a UE context transfer request (such as Namf_Communciation_UE Context Transfer Request) message to the source core network element based on the identification information of the source mobility management entity and the PLMN ID information.

[0111] Step 5: The source mobility management entity sends a UE context transfer response (such as Namf_Communciation_UE Context Transfer Response) message to the target mobility management entity. Among them, the UE context transfer response message carries at least the context information of the terminal, and the context information includes but is not limited to: SUPI information, subscription information, etc.

[0112] Step 6: The target mobility management entity selects a suitable AUSF network element based on the context information (i.e., subscription information) to authenticate the terminal.

[0113] Step 7: In the case of successful authentication, the target mobility management entity sends a registration status update context (such as Namf_Communication Registration Status Update) message to the source mobility management entity.

[0114] Step 8: The target mobility management entity conducts an identity authentication interaction with the terminal, that is, the target mobility management entity sends an Identity Request message to the terminal and receives the Identity Response message fed back by the terminal.

[0115] Step 9: The target mobility management entity sends a terminal context management registration (such as Nudm_UE communication Management Registration) message to the data management module;

[0116] Step 10: The data management module interacts with the source mobility management entity to cancel the subscription information related to the terminal at the source mobility management entity. Among them, the data management module sends a communication management deregistration notification (such as Nudm_UE communication Management Deregistration Notify) message to the source mobility management entity and receives a data management module subscription cancellation (such as Nudm_SDM Unsubscribe) message fed back by the source mobility management entity;

[0117] Step 1: The target mobility management entity sends a corresponding second registration acceptance (RegistrationAccept) message to the terminal.

[0118] It should be noted that there are other communication interaction processes between Steps 6 and 11. Since these processes are all disclosed in the 3GPP protocol and are not the key content of the embodiments of this application, the description of this part of the content is omitted in the above processes.

[0119] Therefore, compared with the existing terminal access method, in the entire interaction process of the terminal switching from the source network to the target network according to the access management method provided by the embodiments of this application, Steps 4-6 (that is, the process of obtaining the terminal context and SUPI from the source core network element based on the target 5G-GUTI) are added, and there is no need to perform an additional identity request process (that is, the process of re-obtaining the SUCI from the terminal). Especially in the scenario of satellite and terrestrial network collaborative access, doing so has the following technical advantages, including:

[0120] (1) By optimizing the signaling interaction process, the number of signaling interactions between the terminal and the target core network element is reduced, directly saving the occupancy of the target network air interface resources and reducing the network load in the target network access scenario.

[0121] (2) By optimizing the signaling interaction process, the terminal registration process is simplified, the waiting time of the UE during the handover process is reduced, and the user experience is improved.

[0122] (3) The target core network element can directly obtain the SUPI of the terminal from the source core network element, so that the identity identifier SUPI of the terminal does not need to be transmitted in the air interface either, reducing the risk of transmitting sensitive information in the air interface, enhancing user privacy protection, and improving the overall security of the network.

[0123] (4) The target core network element can directly obtain the terminal's context information from the source core network element, including network slice allocation and policy information, which helps to maintain service continuity during handover, especially for services that require maintaining network slice continuity.

[0124] Step S606: When the second identity identifier is the target subscription hidden identifier, perform authentication processing on the terminal according to the target subscription hidden identifier.

[0125] In the technical solution provided in the above step S606, since the terminal uses the target SUCI for the registration request, that is to say, the subscribed information of the terminal includes the target network access service, and there is no interface between the source core network element and the target core network element (that is, these two core network elements cannot communicate with each other about the terminal's context information). At this time, when the terminal switches to the target network, the target core network element can directly perform subsequent authentication processes, subscribed information acquisition, and other registration processes according to the target SUCI.

[0126] Specifically, Figure 8 is an optional terminal access flowchart according to an embodiment of the present application. As Figure 8 shown, when the second identity identifier in the second registration request message is the target SUCI, the following interactions can occur between the terminal and the target network to implement the terminal access process, including:

[0127] The first step: The terminal sends a second registration request (Registration Request) message to the network access module, and the second registration request message carries at least the target SUCI assigned by the source mobility management entity to the terminal. Among them, if the target network is a satellite network, the network access module is a ground station (also known as an earth station), and if the target network is a terrestrial network, the network access module can be a base station or a gNB;

[0128] The second step: The network access module selects a target mobility management entity and forwards the second registration request message to the selected target mobility management entity;

[0129] The third step: The target mobility management entity parses the target SUCI to obtain the hidden SUPI, encryption information, and Home Network Identifier (HNI), where HNI includes MCC and MNC, that is, the PLMN ID;

[0130] The fourth step: The source mobility management entity selects an appropriate AUSF network element according to the PLMN ID to authenticate the terminal;

[0131] Step 5: When the authentication is successful, the target mobility management entity sends a registration status update context (such as Namf_Communication Registration Status Update) message to the source mobility management entity;

[0132] Step 6: The target mobility management entity performs an authentication interaction with the terminal, that is, the target mobility management entity sends an Identity Request message to the terminal and receives an Identity Response message fed back by the terminal;

[0133] Step 7: The target mobility management entity sends a terminal context management registration (such as Nudm_UE communication Management Registration) message to the data management module;

[0134] Step 8: The data management module interacts with the source mobility management entity to cancel the subscription information related to the terminal in the source mobility management entity. Among them, the data management module sends a communication management deregistration notification (such as Nudm_UE communication Management Deregistration Notify) message to the source mobility management entity and receives a data management module subscription cancellation (such as Nudm_SDM Unsubscribe) message fed back by the source mobility management entity;

[0135] Step 9: The target mobility management entity sends a corresponding second registration acceptance (RegistrationAccept) message to the terminal.

[0136] It should be noted that there are other communication interaction processes between Steps 4 and 9. Since these processes are all disclosed in the 3GPP protocol and are not the key content of the embodiments of this application, the description of this part of the content is omitted in the above process.

[0137] Therefore, compared with the existing terminal access method, in the entire interaction process of the terminal switching from the source network to the target network according to the access management method provided by the embodiments of this application, there is no need to perform an additional identity request process (that is, the process of re-obtaining the SUCI from the terminal). Especially in the scenario of satellite and terrestrial network collaborative access, doing so has the following technical advantages, including:

[0138] (1) The terminal uses the SUCI for registration, which can enhance user privacy protection and avoid potential privacy leakage risks.

[0139] (2) The terminal does not need to send additional identification information or respond to the IdentityRequest request from the new core network element, thereby reducing the signaling interaction over the air interface, greatly saving network bandwidth and reducing network latency.

[0140] (3) Avoiding the target core network element from initiating an additional identity request process for the terminal shortens the time for the terminal to complete registration, reduces the latency for the user to wait for access to the satellite network, and improves the user experience.

[0141] In summary, through the terminal access management methods respectively executed by the source core network element and the target core network element in the communication system 10 of the present application, not only the utilization efficiency of network resources is improved, the energy consumption of the terminal is reduced, but also the mobility management process is simplified, the user experience is improved, and at the same time, the user privacy protection is strengthened, realizing the intelligent optimization of mobility management in the satellite-terrestrial integrated network.

[0142] Embodiment 2

[0143] According to an embodiment of the present application, there is also provided a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the terminal access management methods respectively applied to the source core network element side and the target core network element side in Embodiment 1.

[0144] According to an embodiment of the present application, there is also provided a non-volatile storage medium, which includes a stored computer program. The device where the non-volatile storage medium is located executes the terminal access management methods respectively applied to the source core network element side and the target core network element side in Embodiment 1 by running the computer program.

[0145] According to an embodiment of the present application, there is also provided a processor, which is used to run a computer program. When the computer program runs, it executes the terminal access management methods respectively applied to the source core network element side and the target core network element side in Embodiment 1.

[0146] According to an embodiment of the present application, there is also provided an electronic device, which includes: a memory and a processor. The memory stores a computer program, and the processor is configured to execute the terminal access management methods respectively applied to the source core network element side and the target core network element side in Embodiment 1 through the computer program.

[0147] Optionally, when the computer program runs, it implements the following steps: The source core network element of the source network receives a first registration request message sent by the terminal, where the first registration request message carries at least a first identity identifier of the terminal; obtains the subscription information of the terminal according to the first identity identifier; obtains the pre-configured interface information, where the interface information is used to reflect whether there is a network interface between the source core network element of the source network and the target core network element of the target network; based on the subscription information and the interface information, sends a target registration acceptance message to the terminal, where the target registration acceptance message includes at least: a mobile identity cell, and the mobile identity cell is used to indicate the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network.

[0148] Optionally, when the computer program runs, it implements the following steps: The target core network element of the target network receives a second registration request message sent by the terminal, where the second registration request message carries at least a second identity identifier of the terminal, and the second identity identifier includes: a target 5G globally unique temporary identifier assigned by the source core network element of the source network to the terminal, and a target subscription hidden identifier obtained by encrypting the globally unique subscription permanent identifier of the terminal using a preset encryption key; when the second identity identifier is the target 5G globally unique temporary identifier, obtains the globally unique subscription permanent identifier information of the terminal from the source core network element of the source network according to the target 5G globally unique temporary identifier, and executes the registration process according to the globally unique subscription permanent identifier information; when the second identity identifier is the target subscription hidden identifier, executes the registration process according to the target subscription hidden identifier.

[0149] As an optional implementation manner, the above network device may exist in the form of a mobile terminal, a computer terminal, or a similar computing device. Figure 9 The hardware structure block diagram of a network device for implementing the terminal access management method is shown. As Figure 9 shown, the network device 90 may include one or more (shown as 902a, 902b,..., 902n in the figure) processors 902 (the processor 902 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 904 for storing data, and a transmission device 906 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 9 the structure shown is only schematic and does not limit the structure of the above network device. For example, the network device 90 may further include more or fewer components than Figure 9 shown, or have a structure different from Figure 9The different configurations shown.

[0150] It should be noted that one or more of the above-mentioned processors 902 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the network device 90. As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0151] The memory 904 can be used to store software programs and modules of application software, such as the program instructions / data storage devices corresponding to the terminal access management method in the embodiments of the present application. The processor 902 executes various functional applications and data processing by running the software programs and modules stored in the memory 904, that is, implements the vulnerability detection method of the above-mentioned application program. The memory 904 can include high-speed random access memory, and can also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 904 can further include a memory remotely set relative to the processor 902, and these remote memories can be connected to the network device 90 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.

[0152] The transmission device 906 is used to receive or send data via a network. Specific examples of the above-mentioned network can include the wireless network provided by the communication provider of the network device 90. In one instance, the transmission device 906 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 906 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0153] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables users to interact with the user interface of the network device 90.

[0154] The above-mentioned serial numbers of the embodiments are only for description and do not represent the advantages or disadvantages of the embodiments.

[0155] In the above embodiments of the present application, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0156] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.

[0157] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0158] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0159] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.

[0160] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A terminal access management method, characterized in that, including: A source core network element of a source network receives a first registration request message sent by the terminal, and at least the first identity identifier of the terminal is carried in the first registration request message; obtain the subscription information of the terminal according to the first identity identifier; obtain pre-configured interface information, where the interface information is used to reflect whether there is a network interface between the source core network element of the source network and the target core network element of the target network; Based on the subscription information and the interface information, send a target registration acceptance message to the terminal, where the target registration acceptance message at least includes: a mobile identity cell, and the mobile identity cell is used to indicate the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network.

2. The method according to claim 1, wherein The types of the first identity identifier at least include: 5G globally unique temporary identifier, subscription hidden identifier.

3. The method according to claim 1, wherein The first registration request message also carries an access identifier and a service scenario type, where the access identifier is used to identify the access technology by which the terminal accesses the source network, and the access technology includes one of the following: New Radio access, evolved universal terrestrial radio access technology, satellite access technology; the service scenario type is used to indicate the network service type by which the terminal accesses the source network, and the network service type includes one of the following: voice service, data service, satellite communication service.

4. The method according to claim 1, characterized in that, The types of the source network and the target network include: terrestrial network or satellite network, where when the type of the source network is a terrestrial network, the type of the target network is a satellite network; when the type of the source network is a satellite network, the type of the target network is a terrestrial network or a satellite network.

5. The method according to claim 4, wherein The source core network element is a source mobility management entity in the source network, and the target core network element is a target mobility management entity in the target network. Among them, sending a target registration acceptance message to the terminal based on the subscription information and the interface information includes: when the target network access service is not included in the subscription information of the terminal, or when the target network access service is included in the subscription information of the terminal and there is a network interface between the source mobility management entity and the target mobility management entity, send a first target registration acceptance message to the terminal, where the first target registration acceptance message at least includes a first mobile identity cell, and the first mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a 5G globally unique temporary identifier; When the target network access service is included in the subscription information of the terminal, but there is no network interface between the source mobility management entity and the target mobility management entity, a second target registration acceptance message is sent to the terminal. The first target registration acceptance message at least includes a second mobile identity cell, and the second mobile identity cell is used to indicate that the type of the second identity identifier carried in the second registration request message sent when the terminal accesses the target network is a subscription hidden identifier.

6. The method according to claim 1, wherein The mobile identity cell at least includes target bytes for representing the type of the identity identifier of the terminal, and the target bytes are eight bits in total. Among them, the first four bits are all 1, the fifth bit is a spare bit, and the last three bits are used to distinguish different types of identity identifiers.

7. The method according to claim 5, wherein The method further includes: Setting the spare bit of the target byte in the mobile identity cell to 0 to obtain the first mobile identity cell; Setting the spare bit of the target byte in the mobile identity cell to 1 to obtain the second mobile identity cell.

8. A terminal access management method, characterized in that, It includes: The target core network element of the target network receives the second registration request message sent by the terminal. The second registration request message at least carries the second identity identifier of the terminal. The second identity identifier includes: the target 5G globally unique temporary identifier assigned by the source core network element of the source network to the terminal, and the target subscription hidden identifier obtained by encrypting the globally unique subscription permanent identifier of the terminal with a preset encryption key; When the second identity identifier is the target 5G globally unique temporary identifier, the globally unique subscription permanent identifier information of the terminal is obtained from the source core network element of the source network according to the target 5G globally unique temporary identifier, and the registration process is executed according to the globally unique subscription permanent identifier information; When the second identity identifier is the target subscription hidden identifier, the registration process is executed according to the target subscription hidden identifier.

9. The method according to claim 8, wherein The source core network element is the source mobility management entity in the source network. Among them, obtaining the globally unique subscription permanent identifier information of the terminal from the source core network element according to the target 5G globally unique temporary identifier includes: Parsing the target 5G globally unique temporary identifier to obtain the identification information of the source mobility management entity and the public land mobile network identification information; According to the identification information of the source mobility management entity and the public land mobile network identification information, a terminal context transfer request message is sent to the source mobility management entity; Receiving the terminal context transfer response message fed back by the source mobility management entity. The terminal context transfer response message carries the context information of the terminal, and the context information at least includes the globally unique subscription permanent identifier information of the terminal.

10. A communication system, characterized in that, The communication system at least includes: a terminal, a source core network element of the source network, and a target core network element of the target network. Among them, The terminal is configured to send a first registration request message to the source core network element, where the first registration request message carries at least a first identity identifier of the terminal; and send a second registration request message to the target core network element block, where the second registration request message carries at least a second identity identifier of the terminal. The source core network element is configured to execute the terminal access management method according to any one of claims 1 to 7. The target core network element is configured to execute the terminal access management method according to any one of claims 8 to 9.

11. A network device, characterized in that, Comprising: A memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the terminal access management method according to any one of claims 1 to 9 through the computer program.

Citation Information

Patent Citations

  • Registration method and communication device

    CN111866858A

  • Support of service continuity for home-routed PDU session when there is no n14 interface between source network and target network

    EP4224930A1

  • Dual access / steer capability information for network and devices dual access / steer service

    US20250088950A1

Cited By

  • Network access method, device, equipment, medium and program product

    CN121568087A