Communication method, device and system
By establishing a direct NAS session between the terminal device and the second network element, the problem of low NAS message transmission efficiency in 5G systems is solved, and more efficient and secure NAS message transmission is achieved, which enhances the flexibility and security of the network architecture.
Patent Information
- Application Number
- CN202410125338.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-27
- Publication Date
- 2025-07-29
AI Technical Summary
In 5G mobile communication system, NAS message transmission efficiency between the terminal device and the core network element is low, and it depends on AMF network element transit, resulting in inflexible network architecture and insufficient security.
After the terminal device establishes a first NAS session with the first network element, it establishes a second NAS session with the second network element, directly transmits NAS messages to avoid transit through the first network element, and activates the security mode through the second NAS session, and generates a key for encryption and integrity protection.
It improves the transmission efficiency of NAS messages, enhances the flexibility and security of the network architecture, prevents messages from being tampered with, and reduces the risk of key theft.
Smart Images

Figure CN120390316A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to communication methods, devices, and systems. Background Art
[0002] In the 5th generation (5G) mobile communication system, information can be transmitted between a terminal device and a core network (CN) network element through non-access stratum (NAS) messages.
[0003] Currently, NAS messages between a terminal device and a core network network element are all transmitted through an access and mobility management function (AMF) network element, that is, the AMF network element transmits the NAS message to the target core network network element of the NAS message. The efficiency of this NAS message transmission method is relatively low. Summary of the Invention
[0004] Embodiments of this application provide communication methods, devices, and systems, which can improve the transmission efficiency of NAS messages.
[0005] Embodiments of this application adopt the following technical solutions:
[0006] In a first aspect, a communication method is provided. This method can be executed by a terminal device, or by a component (such as a processor, a chip, or a chip system, etc.) of the terminal device, or can also be implemented by a logic module or software that can implement all or part of the functions of the terminal device. Hereinafter, taking the terminal device as the execution subject of this method as an example for description, this method includes: The terminal device sends a first request message to a first network element through a first NAS session, and the first NAS session is used to transmit NAS messages between the terminal device and the first network element. Then, the terminal device receives an identifier of a second NAS session, and the second NAS session is used to transmit NAS messages between the terminal device and a second network element. Further, the terminal device can also send a first NAS message to the second network element through the second NAS session according to the identifier of the second NAS session.
[0007] For the first request message, in a possible case, the first request message is used to request a service. In another possible case, the first request message is used to request a service and is also used to request the establishment of a NAS session between the terminal device and the second network element. In another possible case, the first request message is used to request the establishment of a NAS session between the terminal device and the second network element.
[0008] Among them, if the first request message requests a service, the service is provided by a second network element. If the first request message requests the establishment of a NAS session between the terminal device and the second network element (in the case where the above first request message is used to request a service and also used to request the establishment of a NAS session between the terminal device and the second network element, or in the case where the first request message is used to request the establishment of a NAS session between the terminal device and the second network element), the second NAS session is the NAS session actually established between the terminal device and the second network element in response to the request of the first request message.
[0009] Based on the communication method provided in the embodiments of the present application, the terminal device can establish a second NAS session with a second network element when it has already established a first NAS session with a first network element, so that NAS messages between the terminal device and the second network element can be directly transmitted through the second NAS session. Compared with the solution of relaying NAS messages by the first network element, the transmission efficiency of NAS messages is improved. In addition, in this solution, the NAS messages transmitted between the second network element and the terminal device do not depend on the first network element, which can not only match the principle of functional decoupling between network elements, improve the flexibility of the network architecture, but also improve the security of NAS message transmission.
[0010] In a possible implementation manner, when the first request message requests the establishment of a NAS session between the terminal device and the second network element, the first request message includes an identifier of the second NAS session. In this implementation, it can be considered that the first request message requests the establishment of the second NAS session. Optionally, the identifier of the second NAS session included in the first request message can be assigned by the terminal device for the second NAS session.
[0011] Based on this solution, the terminal device can inform the first network element of the identifier of the second NAS session requested to be established through the first request message.
[0012] In a possible implementation manner, the method further includes: the terminal device receives first indication information, and the first indication information is used to instruct the terminal device to activate a security mode for the second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session. Then, the terminal device activates the security mode for the second NAS session according to the first indication information.
[0013] Based on this solution, the terminal device can enable a security mode for the second NAS session to protect NAS messages transmitted through the second NAS session and prevent NAS messages transmitted through the second NAS session from being tampered with.
[0014] In a possible implementation, the method further includes: The terminal device generates a key for a second NAS session according to the root key of the first NAS session and the identifier of the second NAS session. The key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted through the second NAS session, or a key for integrity protecting NAS messages transmitted through the second NAS session.
[0015] Based on this solution, the terminal device can locally generate the key for the second NAS session, avoiding the risk of the key being stolen that may occur when obtaining the key from other devices, and protecting the security of the key.
[0016] In a possible implementation, the terminal device activates a security mode for the second NAS session according to first indication information, including: The terminal device verifies the first indication information by using the key for the second NAS session; wherein, the key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted through the second NAS session, or a key for integrity protecting NAS messages transmitted through the second NAS session. In the case where the verification is passed, the terminal device activates the security mode.
[0017] Based on this solution, the terminal device can activate the security mode after the security verification of the first indication information is passed, further ensuring the security of the second NAS session in the security mode.
[0018] In a possible implementation, the terminal device sends a first request message to a first network element through a first NAS session, including: The terminal device sends a second message to an access network device, and the second message includes the first request message. Optionally, the second message may be a radio resource control (RRC) message. In this implementation, the second message is sent through the radio bearer corresponding to the first NAS session, and / or, the second message includes the identifier of the first NAS session. The radio bearer corresponding to the first NAS session or the identifier of the first NAS session is used for the access network device to determine that the destination network element of the first request message is the first network element, that is, to determine to send the first request message to the first network element. That is to say, after receiving the second message, the access network device can determine to send the first request message to the first network element according to the radio bearer corresponding to the first NAS session and / or the identifier of the first NAS session.
[0019] Based on this solution, when the terminal device sends a message to a destination network element through a NAS session, it can send the radio bearer corresponding to the NAS session, and / or, send the identifier of the NAS session together, so that the access network device responsible for relaying the message can determine the destination network element corresponding to the message, and realize the transmission of the message through the NAS session.
[0020] In a possible implementation, the terminal device sends a first NAS message to a second network element through a second NAS session, including: the terminal device sends a first message to an access network device, and the first message includes the first NAS message. Optionally, the first message may be an RRC message. In this implementation, the first message is sent through a radio bearer corresponding to the second NAS session, and / or the first message includes an identifier of the second NAS session. The radio bearer corresponding to the second NAS session or the identifier of the second NAS session is used for the access network device to determine that the destination network element of the first NAS message is the second network element, that is, to determine to send the first NAS message to the second network element. That is to say, after receiving the first message, the access network device can determine to send the first NAS message to the second network element according to the radio bearer corresponding to the second NAS session and / or the identifier of the second NAS session.
[0021] Based on this solution, when the terminal device sends a NAS message to a destination network element through a NAS session, it can send the identifier of the NAS session through the radio bearer corresponding to the NAS session and / or together, so that the access network device responsible for relaying the message can determine the destination network element corresponding to the message, and realize the transmission of the message through the NAS session.
[0022] In a possible implementation, the first request message includes first information, and the first information is used to select a second network element from network elements providing services.
[0023] Based on this solution, a second network element suitable for establishing a second NAS session can be selected from network elements providing services based on the first information.
[0024] In a possible implementation, the method further includes: the terminal device receives second information from the access network device, and the second information is used to configure one or more radio bearers corresponding to the second NAS session. The terminal device sends a first NAS message to the second network element through the second NAS session, including: the terminal device sends the first NAS message to the second network element through the radio bearer corresponding to the second NAS session.
[0025] Based on this solution, a corresponding radio bearer can be configured for the second NAS session, and the terminal device can send a NAS message through the radio bearer corresponding to the second NAS session. Correspondingly, the access network device can determine the NAS session corresponding to the NAS message through the radio bearer receiving the NAS message.
[0026] In a possible implementation, the second NAS session includes one or more Quality of Service (QoS) flows. The terminal device sends a first NAS message to a second network element through the second NAS session, including: the terminal device sends the first NAS message to the second network element through a radio bearer corresponding to the first QoS flow. Among them, the first NAS message corresponds to the first QoS flow, and the one or more QoS flows include the first QoS flow.
[0027] Based on this solution, by configuring corresponding radio bearers for the QoS flows included in the second NAS session, the NAS messages transmitted through the second NAS session can be split and transmitted through different radio bearers based on the corresponding QoS flows, preventing message blocking that may be caused by all the NAS messages transmitted through the second NAS session being mixed and transmitted in the same channel.
[0028] In a possible implementation, the method further includes: the terminal device receives a mapping rule, and the mapping rule includes the correspondence between the first NAS message and the first QoS flow. The terminal device receives third information from an access network device, and the third information is used to configure the radio bearer corresponding to the first QoS flow.
[0029] Based on this solution, the terminal device can determine which QoS flow the NAS message to be sent corresponds to based on the mapping rule, and further determine the radio bearer corresponding to the QoS flow according to the third information.
[0030] In a second aspect, a communication method is provided. This method can be executed by a first network element, or by components of the first network element (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can implement all or part of the functions of the first network element. The following takes the first network element as the execution subject of this method for illustration. The method includes: the first network element receives a first request message from a terminal device through a first NAS session, where the first NAS session is an NAS session established between the terminal device and the first network element and is used to transmit NAS messages between the terminal device and the first network element. The first network element triggers the establishment of a second NAS session, and the second NAS session is used to transmit NAS messages between the terminal device and a second network element.
[0031] For the first request message, in a possible case, the first request message is used to request a service. In another possible case, the first request message is used to request a service and is also used to request the establishment of an NAS session between the terminal device and the second network element. In another possible case, the first request message is used to request the establishment of an NAS session between the terminal device and the second network element.
[0032] Among them, if the first request message requests a service, the service is provided by a second network element. If the first request message requests the establishment of a NAS session between the terminal device and the second network element (in the case where the above first request message is used to request a service and also used to request the establishment of a NAS session between the terminal device and the second network element, or in the case where the first request message is used to request the establishment of a NAS session between the terminal device and the second network element), the second NAS session is the NAS session actually established between the terminal device and the second network element in response to the request of the first request message.
[0033] Based on the communication method provided in the embodiments of the present application, the terminal device can establish a second NAS session with the second network element when it has already established a first NAS session with the first network element, so that NAS messages between the terminal device and the second network element can be directly transmitted through the second NAS session. Compared with the solution of relaying NAS messages by the first network element, the transmission efficiency of NAS messages is improved. In addition, in this solution, the NAS messages transmitted between the second network element and the terminal device do not depend on the first network element, which can not only match the principle of functional decoupling between network elements, improve the flexibility of the network architecture, but also improve the security of NAS message transmission.
[0034] In a possible implementation manner, the method further includes: the first network element sends an identifier of the second NAS session to the second network element. Among them, optionally, the identifier of the second NAS session can be assigned by the terminal device for the second NAS session, or can be assigned by the first network element for the second NAS session. In a possible implementation manner, the method further includes: the first network element determines whether to allow the establishment of a NAS session between the terminal device and the second network element according to the subscription information of the terminal device. The first network element triggers the establishment of the second NAS session, including: when the subscription information of the terminal device indicates that the establishment of a NAS session between the terminal device and the second network element is allowed, the first network element triggers the establishment of the second NAS session.
[0035] Based on this solution, the first network element can decide whether to allow the establishment of the second NAS session according to the subscription information of the terminal device. That is to say, the first network element can authorize the establishment of the second NAS session according to the subscription information of the terminal device to prevent unauthorized NAS sessions from causing insecure impacts on the system.
[0036] Optionally, the subscription information of the terminal device indicating that the establishment of a NAS session between the terminal device and the second network element is allowed includes: the subscription information of the terminal device indicating that it is allowed to create a NAS session between the terminal device and the second network element for the service requested by the first request message.
[0037] Based on this solution, the first network element can determine whether to establish a second NAS session for the service requested by the first request message according to the subscription information of the terminal device.
[0038] In a possible implementation, the method further includes: a first network element sending a fifth request message to a second network element, where the fifth request message is used to request a service. The first network element receives fourth information from the second network element, and the fourth information is used to indicate the establishment of a second NAS session. The first network element triggers the establishment of the second NAS session, including: the first network element triggering the establishment of the second NAS session according to the fourth information.
[0039] Based on this solution, the second network element can decide to establish a second NAS session, and the first network element can trigger the establishment of the second NAS session under the indication of the second network element.
[0040] In a possible implementation, the method further includes: the first network element selecting a second network element from the network elements providing services according to first information; where the first request message includes the first information, or the subscription information of the terminal device includes the first information.
[0041] Based on this solution, the first network element can select, according to the first information, a network element suitable for establishing a second NAS session with the terminal device from the network elements that can provide services as the second network element.
[0042] In a possible implementation, the first network element triggering the establishment of the second NAS session includes: the first network element sending a second request message to the second network element, where the second request message is used to request the establishment of the second NAS session.
[0043] Based on this solution, the first network element can trigger the establishment of the second NAS session by sending a request message to the second network element.
[0044] In a possible implementation, the second request message includes the root key of the second NAS session, and the root key of the second NAS session is used to generate the key of the second NAS session. The key of the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted through the second NAS session, or a key for integrity protection of NAS messages transmitted through the second NAS session.
[0045] Based on this solution, the NAS messages transmitted through the second NAS session can be securely protected through the key of the second NAS session, and the NAS messages transmitted through the second NAS session can be prevented from being tampered with.
[0046] In a possible implementation, the method further includes: the first network element generating the root key of the second NAS session according to the root key of the first NAS session and the identifier of the second NAS session.
[0047] This solution provides a method for generating the root key of the second NAS session.
[0048] In a possible implementation, the second request message further includes the security capability information of the terminal device. The security capability information is used to indicate one or more encryption algorithms supported by the terminal device, and / or one or more integrity protection algorithms supported by the terminal device. The security capability information is used to determine the security algorithm corresponding to the second NAS session. The security algorithm includes at least one of the following algorithms: an encryption algorithm for encrypting the NAS messages transmitted through the second NAS session, or an integrity protection algorithm for performing integrity protection on the NAS messages transmitted through the second NAS session.
[0049] Based on this solution, the second network element can obtain the security capability information of the terminal device through the second request message, and determine the security algorithm corresponding to the second NAS session based on the security capability information of the terminal device, so as to protect the NAS messages transmitted through the second NAS session.
[0050] In a possible implementation, the method further includes: the first network element receives first indication information from the second network element, and the first indication information is used to indicate that the terminal device activates a security mode for the second NAS session. Among them, the security mode includes one or more of the following: encrypting the NAS messages transmitted through the second NAS session, or performing integrity protection on the NAS messages transmitted through the second NAS session. The first network element sends the first indication information to the terminal device.
[0051] Based on this solution, the terminal device can be instructed through the first indication information to enable the security mode for the second NAS session, protect the NAS messages transmitted through the second NAS session, and prevent the NAS messages transmitted through the second NAS session from being tampered with.
[0052] In a possible implementation, the method further includes: the first network element sends a third request message to the access network device, and the third request message is used to request the establishment of the second NAS session. The third request message includes the identifier of the second NAS session.
[0053] Based on this solution, a direct connection channel can be established between the access network device and the second network element to establish the second NAS session.
[0054] In a possible implementation, the method further includes: the first network element receives second indication information from the second network element, and the second indication information indicates the establishment of the second NAS session. The first network element sends a third request message to the access network device, including: the first network element sends the third request message to the access network device according to the second indication information.
[0055] Based on this solution, the first network element can request the access network device to establish the second NAS session according to the indication of the second network element.
[0056] In a possible implementation, the method further includes: a first network element sending an identifier of a second NAS session to a terminal device.
[0057] In a possible implementation, the second request message includes address information of an access network device and a first identifier. The address information of the access network device is used to send a message to the access network device, and the first identifier is used to indicate the context of the terminal device in the access network device.
[0058] Based on this solution, the address information of the access network device and the first identifier can be sent to a second network element, so that the second network element can send NAS messages through the second NAS session according to the address information of the access network device and the first identifier subsequently.
[0059] In a possible implementation, before the first network element sends a second request message to the second network element, the method further includes: the first network element receiving a first identifier from the access network device.
[0060] Based on this solution, the identifier of the context of the terminal device in the access network device can be assigned by the access network device.
[0061] In a third aspect, a communication method is provided. The method can be executed by a second network element, or by components (such as a processor, a chip, or a chip system, etc.) of the second network element, or can also be implemented by a logic module or software that can implement all or part of the functions of the second network element. The following takes the second network element as the execution subject of the method as an example for illustration. The method includes: the second network element receiving a second request message from the first network element. The second request message is used to request the establishment of a second NAS session, and the second NAS session is used to transmit NAS messages between the terminal device and the second network element. Moreover, there is a first NAS session for transmitting NAS messages between the first network element and the terminal device. Then, the second network element sends a first response message to the first network element for the second request message.
[0062] Based on the communication method provided in the embodiments of the present application, the terminal device can establish a second NAS session with the second network element when it has already established a first NAS session with the first network element, so as to directly transmit NAS messages between the terminal device and the second network element through the second NAS session. Compared with the solution of relaying NAS messages by the first network element, the transmission efficiency of NAS messages is improved. In addition, in this solution, the NAS messages transmitted between the second network element and the terminal device do not depend on the first network element, which can not only match the principle of functional decoupling between network elements, improve the flexibility of the network architecture, but also improve the security of NAS message transmission.
[0063] In a possible implementation, the first response message includes a third request message for requesting the access network device to establish a second NAS session. The third request message includes the address information of the second network element and the identifier of the second NAS session.
[0064] Based on this solution, the second network element can request, via the first network element, the access network device to establish a second NAS session.
[0065] In a possible implementation, the first response message includes second indication information for indicating the access network device to establish a second NAS session. The second indication information is used to trigger the first network element to send a third request message to the access network device, and the third request message is used to request the establishment of the second NAS session.
[0066] Based on this solution, the second network element can instruct the first network element to request the access network device to establish a second NAS session. The first network element can, under the instruction of the second network element, request the access network device to establish a second NAS session.
[0067] In a possible implementation, the method further includes: the second network element sends a third request message to the access network device, where the third request message is used to request the access network device to establish a second NAS session, and the third request message includes the address information of the second network element and the identifier of the second NAS session.
[0068] Based on this solution, the second network element can directly request the access network device to establish a second NAS session.
[0069] In a possible implementation, the second request message includes the address information of the access network device and a first identifier for indicating the context of the terminal device in the access network device. The second network element sending a third request message to the access network device includes: the second network element sending a third request message to the access network device according to the address information of the access network device and the first identifier.
[0070] In a possible implementation, the method further includes: the second network element sends a second response message to the terminal device via the third request message, where the second response message is used to indicate that the second NAS session is successfully established, and the second response message includes the identifier of the second NAS session.
[0071] Based on this solution, the second network element can notify the terminal device that the second NAS session is successfully established via the second response message.
[0072] In a possible implementation, before the second network element receives the second request message from the first network element, the method further includes: the second network element receives a fifth request message from the first network element, where the fifth request message is used to request a service provided by the second network element. The second network element sends fourth information to the first network element according to the fifth request message, and the fourth information is used to indicate the establishment of a second NAS session.
[0073] Based on this solution, the second network element can actively decide to establish a second NAS session according to the service requested by the terminal device, and indicate to the first network element to establish the second NAS session, triggering the establishment of the second NAS session.
[0074] In a possible implementation, the method further includes: the second network element receives a third response message from the access network device, where the third response message includes the address information of the access network device and a second identifier; the second identifier is used to indicate the context of the second NAS session in the access network device.
[0075] Based on this solution, the second network element can obtain the address information of the access network device and the second identifier, so that when sending NAS messages through the second NAS session subsequently, it can directly send NAS messages to the terminal device through the access network device according to the address information of the access network device and the second identifier.
[0076] In a possible implementation, the first response message includes an identifier of the second NAS session.
[0077] In a possible implementation, the method further includes: the second network element sends first indication information to the first network element, where the first indication information is used to indicate that the terminal device activates a security mode for the second NAS session, and the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.
[0078] Alternatively, the method further includes: the second network element sends first indication information to the terminal device through the second NAS session, where the first indication information is used to indicate that the terminal device activates a security mode for the second NAS session; the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.
[0079] Based on this solution, the first indication information can be used to indicate that the terminal device enables the security mode for the second NAS session, protect the NAS messages transmitted through the second NAS session, and prevent the NAS messages transmitted through the second NAS session from being tampered with.
[0080] In a possible implementation, the method further includes: The second network element obtains the key of the second NAS session, and the key of the second NAS session includes at least one of the following keys: the key for encryption, the key for integrity protection. The second network element uses the key of the second NAS session to perform at least one of the following on the first indication information: encryption or integrity protection. The second network element sends the first indication information to the terminal device.
[0081] Based on this solution, the second network element can perform corresponding processing on the first indication information through the key of the second NAS session to verify whether the terminal device receiving the first indication information has the same key of the second NAS session.
[0082] In a possible implementation, the second network element obtains the key of the second NAS session, including: The second network element generates the key of the second NAS session according to the root key of the second NAS session, where the second request message includes the root key of the second NAS session, or the subscription information of the terminal device includes the root key of the second NAS session.
[0083] This solution provides multiple ways to obtain the key of the second NAS session.
[0084] In a possible implementation, the method further includes: The second network element obtains the security capability information of the terminal device, and the security capability information is used to indicate one or more encryption algorithms supported by the terminal device, and / or one or more integrity protection algorithms supported by the terminal device. The second network element determines the security algorithm corresponding to the second NAS session according to the security capability information of the terminal device; where the security algorithm includes one or more of the following algorithms: the encryption algorithm for encrypting the NAS message transmitted through the second NAS session, or the integrity protection algorithm for performing integrity protection on the NAS message transmitted through the second NAS session.
[0085] Based on this solution, the second network element can determine the algorithm suitable for performing security protection on the NAS message transmitted through the second NAS session according to the algorithm supported by the terminal device.
[0086] In a possible implementation, the second request message includes the security capability information, and / or the subscription information of the terminal device includes the security capability information.
[0087] In a possible implementation, the second NAS session includes one or more QoS flows, and the method further includes: The second network element sends a mapping rule to the terminal device, and the mapping rule includes the correspondence between the NAS message transmitted through the second NAS session and each QoS flow in the one or more QoS flows.
[0088] Based on this solution, the second network element can send a mapping rule to the terminal device, so that when the terminal device sends a NAS message through the second NAS session, it can determine the QoS flow corresponding to the NAS message.
[0089] In a possible implementation, the second NAS session includes one or more QoS flows, and the method further includes: the second network element sends a fourth request message to the access network device, and the fourth request message is used to request to configure a radio bearer corresponding to each QoS flow in the one or more QoS flows.
[0090] Based on this solution, by configuring a corresponding radio bearer for the QoS flow included in the second NAS session, the NAS message transmitted through the second NAS session can be split and transmitted through different radio bearers based on the corresponding QoS flow, preventing message blocking that may be caused by all NAS messages transmitted through the second NAS session being mixed and transmitted in the same channel.
[0091] In a possible implementation, the method further includes: the second network element sends a second NAS message and identification information of a second QoS flow corresponding to the second NAS message through the second NAS session. The identification information of the second QoS flow is used for the access network device to determine and send the second NAS message to the terminal device through the second NAS session.
[0092] Based on this solution, the second network element can indicate the identification information of the QoS flow corresponding to the NAS message to the access network device, so that the access network device can, based on the identification information of the QoS flow, determine that the QoS flow corresponding to the NAS message is one of the QoS flows included in the second NAS session, and then send the second NAS message to the terminal device through the second NAS session.
[0093] Fourthly, a communication method is provided. This method can be executed by the access network device, or by components of the access network device (such as a processor, a chip, or a chip system, etc.), or can also be implemented by a logic module or software that can implement all or part of the functions of the access network device. The following takes the access network device as the execution entity of this method for illustration. The method includes: the access network device receives a third NAS message from the terminal device. The access network device determines that the third NAS message belongs to a third NAS session, where the third NAS session is a NAS session between the terminal device and the third network element. In other words, the access network device determines that the destination network element of the third NAS message is the third network element. Thus, the access network device sends the third NAS message to the third network element.
[0094] Based on the communication method provided in the embodiments of the present application, after receiving a NAS message from a terminal device, an access network device can distinguish the NAS session corresponding to the received NAS message, so that the NAS message can be transmitted to the correct destination network element, realizing the direct transmission of the NAS message through the NAS session and improving the transmission efficiency of the NAS message.
[0095] In a possible implementation manner, the access network device receives a third NAS message from the terminal device, including: the access network device receives the third NAS message from the terminal device and the identifier of the third NAS session. In this implementation, the access network device determines that the third NAS message belongs to the third NAS session according to the third NAS session to which the third NAS message belongs, including: the access network device determines that the third NAS message belongs to the third NAS session according to the identifier of the third NAS session.
[0096] Optionally, in this implementation, the access network device may determine the destination network element of the third NAS message according to the identifier of the third NAS session and the first correspondence. The first correspondence is used to indicate the correspondence between the identifier of the third NAS session and the destination network element of the third NAS message. For example, the first correspondence may include the correspondence between the identifier of the third NAS session and the information of the destination network element of the third NAS message (such as the identifier information, address information, etc. of the third network element).
[0097] Based on this solution, a method for the access network device to determine the destination network element of the third NAS message is provided: determining based on the identifier of the third NAS session.
[0098] In a possible implementation manner, the access network device determines that the third NAS message belongs to the third NAS session, including: the access network device determines that the third NAS message belongs to the third NAS session according to the radio bearer used to transmit the third NAS message. For example, before receiving the third NAS message, the access network device may configure a corresponding radio bearer for the third NAS session, so that after receiving the third NAS message, the access network device can determine that the third NAS message belongs to the third NAS session according to the radio bearer used to transmit the third NAS message being the radio bearer corresponding to the third NAS session.
[0099] Optionally, in this implementation, the access network device may determine the destination network element of the third NAS message according to the radio bearer used to transmit the third NAS message and the second correspondence; the second correspondence is used to indicate the correspondence between the radio bearer used to transmit the third NAS message and the destination network element of the third NAS message. For example, the second correspondence may include the correspondence between the radio bearer used to transmit the third NAS message, the identifier of the third NAS session, and the information of the destination network element of the third NAS message (such as the identifier information, address information, etc. of the third network element).
[0100] Based on this solution, another way for the access network device to determine the destination network element of the third NAS message is provided: determining based on the radio bearer for transmitting the third NAS message.
[0101] In a possible implementation, the method further includes: the access network device receives a fourth NAS message from a third network element. The access network device determines that the fourth NAS message belongs to a third NAS session. The access network device sends the fourth NAS message and the identifier of the third NAS session to the terminal device, and / or, the access network device sends the fourth NAS message to the terminal device through the radio bearer corresponding to the third NAS session.
[0102] Based on this solution, when the access network device relays and sends the NAS message to the terminal device, it can use the identifier of the NAS session and / or the radio bearer corresponding to the NAS session, so that the terminal device can determine the NAS session corresponding to the NAS message.
[0103] Optionally, in this implementation, the access network device receiving the fourth NAS message from the third network element may include: the access network device receives the fourth NAS message and the identifier of the third NAS session from the third network element. Based on this, the access network device determining that the fourth NAS message belongs to the third NAS session includes: the access network device determines that the fourth NAS message belongs to the third NAS session according to the identifier of the third NAS session.
[0104] Optionally, in this implementation, the access network device receiving the fourth NAS message from the third network element may include: the access network device receives the fourth NAS message and a third identifier from the third network element, where the third identifier is used to indicate the context of the third NAS session in the access network device. Based on this, the access network device determining that the fourth NAS message belongs to the third NAS session includes: the access network device determines that the fourth NAS message belongs to the third NAS session according to the third identifier.
[0105] Based on the communication method provided in the embodiments of this application, after receiving the NAS message from the core network element, the access network device can also determine the NAS session corresponding to the NAS message. Among them, in a possible way, the core network element sends the identifier of the NAS session together with the NAS message to the access network device, and the access network device can directly determine the NAS session corresponding to the NAS message according to the identifier of the NAS session. Another possible way is that the core network element sends the identifier of the context of the NAS session in the access network device together with the NAS message to the access network device, and the access network device can determine the NAS session corresponding to the NAS message according to the context of the NAS session in the access network device.
[0106] In a possible implementation, the method further includes: The access network device receives a fourth NAS message and an identifier of a third NAS session from a third network element, and the access network device sends the fourth NAS message and the identifier of the third NAS session to the terminal device.
[0107] Based on this solution, the access network device can directly forward the fourth NAS message and the identifier of the third NAS session from the third network element to the terminal device.
[0108] Optionally, in this implementation, the access network device can also determine that the fourth NAS message belongs to the third NAS session according to the identifier of the third NAS session.
[0109] In a possible implementation, the method further includes: The access network device receives a third request message for requesting the establishment of a third NAS session, and the third NAS session is used to transmit NAS messages between the terminal device and the third network element. Then, the access network device sends a third response message to the third network element, and the third response message includes the address information of the access network device and a third identifier, and the third identifier is used to indicate the context of the third NAS session in the access network device. Optionally, the third request message may include the identifier of the third NAS session and the address information of the third network element. In this case, the access network device can send the third response message to the third network element according to the address information of the third network element.
[0110] Based on this solution, in order to establish a third NAS session, the access network device can allocate an identifier for the context of the third NAS session (i.e., the third identifier), and send its own address information and the identifier of the context of the third NAS session to the third network element, so as to establish a direct connection channel between the access network device and the third network element.
[0111] In a possible implementation, the method further includes: The access network device receives a fourth request message from a third network element, and the fourth request message is used to request to configure a radio bearer corresponding to each of one or more QoS flows included in the third NAS session. The access network device configures the radio bearer corresponding to each QoS flow according to the fourth request message.
[0112] Based on this solution, the access network device can configure corresponding radio bearers for the QoS flows included in the third NAS session, so that the NAS messages transmitted through the third NAS session can be split and transmitted through different radio bearers based on the corresponding QoS flows, preventing message blocking that may be caused by all the NAS messages transmitted through the third NAS session being mixed and transmitted in the same channel.
[0113] In a possible implementation, the method further includes: The access network device receives a fourth NAS message from a third network element and identification information of a QoS flow corresponding to the fourth NAS message, where one or more QoS flows included in the third NAS session include the QoS flow corresponding to the fourth NAS message. Further, the access network device determines a radio bearer corresponding to the fourth NAS message according to the identification information of the QoS flow corresponding to the fourth NAS message, and sends the fourth NAS message to the terminal device through the radio bearer.
[0114] Based on this solution, if the access network device determines that the QoS flow corresponding to the received downlink NAS message is one of the QoS flows included in the NAS session, the access network device may further send the downlink NAS message to the terminal device through the radio bearer corresponding to the QoS flow according to the correspondence between the configured QoS flow and the radio bearer, so that the terminal device can determine the QoS flow corresponding to the downlink NAS message based on the radio bearer for receiving the downlink NAS message.
[0115] In a fifth aspect, a communication method is provided. This method may be executed by an access network device, or by a component of the access network device (such as a processor, a chip, or a chip system, etc.), or may also be implemented by a logic module or software that can implement all or part of the functions of the access network device. The following takes the access network device as the execution entity of this method as an example for description. The method includes: The access network device receives a fourth request message from a second network element. The fourth request message is used to request to configure a radio bearer corresponding to each QoS flow among one or more QoS flows included in a second NAS session. Wherein, the second NAS session is used to transmit NAS messages between the terminal device and the second network element. Further, the access network device configures a corresponding radio bearer for each QoS flow according to the fourth request message. Then, the access network device sends third information to the terminal device. The third information is used to configure the radio bearer corresponding to each QoS flow.
[0116] Based on this solution, the access network device can configure corresponding radio bearers for the QoS flows included in the second NAS session, so that the NAS messages transmitted through the second NAS session can be split and transmitted through different radio bearers based on the corresponding QoS flows, preventing message blocking that may be caused by all the NAS messages transmitted through the second NAS session being mixed and transmitted in the same channel.
[0117] In a possible implementation, the fourth request message further includes a mapping rule. The mapping rule includes the correspondence between the NAS messages transmitted through the second NAS session and each QoS flow. In this implementation, the method further includes: The access network device sends the mapping rule to the terminal device.
[0118] Based on this solution, the terminal device can determine which QoS flow the NAS message to be sent corresponds to based on the mapping rule, and further determine the radio bearer corresponding to the QoS flow according to the third piece of information.
[0119] In a possible implementation, the method further includes: The access network device receives a first NAS message from the terminal device. After that, the access network device determines that the first NAS message corresponds to a first QoS flow according to the radio bearer used to transmit the first NAS message, and the second NAS session includes the first QoS flow, so as to send the first NAS message and the identification information of the first QoS flow to the second network element.
[0120] Based on this solution, the access network device can determine the QoS flow corresponding to the NAS message and the destination network element of the NAS message according to the radio bearer for receiving the NAS message, and when the terminal device sends the NAS message to the destination network element of the NAS message, it can send the identification information of the QoS flow together; to indicate the QoS flow corresponding to the NAS message.
[0121] In a possible implementation, the method further includes: The access network device receives a first NAS message from the terminal device and the identification information of the first QoS flow corresponding to the first NAS message, where the second NAS session includes the first QoS flow. The access network device sends the first NAS message and the identification information of the first QoS flow to the second network element.
[0122] Based on this solution, if the terminal device sends the identification information of the QoS flow corresponding to the NAS message when sending the NAS message, the access network device can directly determine the session corresponding to the NAS message and the destination network element of the NAS message according to the identification information of the QoS flow corresponding to the NAS message, so as to send the NAS message and the identification information of the QoS flow corresponding to the NAS message to the destination network element of the NAS message.
[0123] In a possible implementation, the method further includes: The access network device receives a second NAS message from the second network element and the identification information of the second QoS flow corresponding to the second NAS message. The access network device determines the radio bearer corresponding to the second QoS flow according to the identification information of the second QoS flow. The access network device sends the second NAS message to the terminal device through the radio bearer corresponding to the second QoS flow.
[0124] Based on this solution, after receiving the downlink NAS message, the access network device can send the NAS message to the terminal device through the radio bearer corresponding to the downlink NAS message, so that the terminal device can determine the QoS flow corresponding to the NAS message according to the radio bearer for receiving the NAS message.
[0125] In a sixth aspect, a communication device is provided for implementing the above various methods. The communication device includes corresponding modules, units, or means for implementing the above methods. The modules, units, or means can be implemented by hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0126] In some possible designs, the communication device may include a transceiver module and a processing module. The transceiver module, which may also be referred to as a transceiver unit, is used to implement the sending and / or receiving functions in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect and any possible implementation manners thereof. The transceiver module may be constituted by a transceiver circuit, a transceiver, a transceiver, or a communication interface. The processing module may be used to implement the processing functions in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect and any possible implementation manners thereof.
[0127] In some possible designs, the transceiver module includes a sending module and a receiving module, which are respectively used to implement the sending and receiving functions in the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect and any possible implementation manners thereof.
[0128] In a seventh aspect, a communication device is provided, including: a processor and a communication interface; the communication interface is used to communicate with modules outside the communication device; the processor is used to execute a computer program or instruction so that the communication device executes the methods in any of the above aspects.
[0129] In an eighth aspect, a communication device is provided, including: at least one processor; the processor is used to execute a computer program or instruction stored in a memory so that the communication device executes the methods in any of the above aspects. In a possible implementation, the memory may be coupled to the processor, or may be independent of the processor. In a possible implementation, the communication device further includes the memory. Optionally, the memory and the processor are integrated together.
[0130] In the fifth to eighth aspects, the communication device may be the terminal device in the first aspect above, or any implementation manner in the first aspect, or a device including the above terminal device, or a device included in the above terminal device, such as a chip. Alternatively, the communication device may be the first network element in the second aspect above, or any implementation manner in the second aspect, or a device including the above first network element, or a device included in the above first network element, such as a chip. Alternatively, the communication device may be the second network element in the third aspect above, or any implementation manner in the third aspect, or a device including the above second network element, or a device included in the above second network element, such as a chip. Alternatively, the communication device may be the access network device in the fourth aspect above, or any implementation manner in the fourth aspect, or the fifth aspect, or any implementation manner in the fifth aspect, or a device including the above access network device, or a device included in the above access network device, such as a chip or a chip system.
[0131] In a ninth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program or instruction. When it runs on a communication device, the communication device can execute the method in any of the above aspects or any of its implementation manners.
[0132] In a tenth aspect, a computer program product including instructions is provided. When it runs on a communication device, the communication device can execute the method in any of the above aspects or any of its implementation manners.
[0133] In an eleventh aspect, a communication device (for example, the communication device may be a chip or a chip system) is provided. The communication device includes a processor for implementing the functions involved in any of the above aspects or any of its implementation manners.
[0134] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.
[0135] In some possible designs, when the device is a chip system, it may be composed of chips, or may also include chips and other discrete devices.
[0136] It can be understood that when the communication device provided in any of the sixth to eighth aspects is a chip, the above-mentioned sending action / function can be understood as output, and the above-mentioned receiving action / function can be understood as input.
[0137] Among them, for the technical effects brought by any implementation manner in the sixth to eleventh aspects, reference can be made to the technical effects brought by the corresponding implementation manners in the first to fifth aspects, which will not be elaborated here.
[0138] Among them, it should be noted that various possible implementation manners of any one of the above aspects can be combined on the premise that the solutions do not conflict with each other.
[0139] In a twelfth aspect, a communication system is provided, and the communication system includes a first network element and a second network element. Among them, the first network element is used to execute the method of the second aspect or any implementation manner of the second aspect. The second network element is used to execute the method of the third aspect or any implementation manner of the third aspect.
[0140] In some possible designs, the communication system further includes a terminal device, and the terminal device is further used to execute the method of the first aspect or any implementation manner of the first aspect.
[0141] In some possible designs, the communication system further includes an access network device, and the access network device is used to execute the fourth aspect, or any implementation manner of the fourth aspect, or the fifth aspect, or any implementation manner of the fifth aspect. Description of the Drawings
[0142] Figure 1 It is a schematic diagram of the current NAS message transmission mechanism;
[0143] Figure 2 It is a schematic diagram of the architecture of the communication system applicable to the embodiments of the present application;
[0144] Figure 3 It is an interaction schematic diagram of a communication method provided by the embodiments of the present application;
[0145] Figure 4 It is a schematic diagram of an exemplary process of a communication method provided by the embodiments of the present application;
[0146] Figure 5 It is an interaction schematic diagram of another communication method provided by the embodiments of the present application;
[0147] Figure 6 It is an interaction schematic diagram of yet another communication method provided by the embodiments of the present application;
[0148] Figure 7 It is a schematic diagram of the structure of a communication device provided by the embodiments of the present application;
[0149] Figure 8 It is a schematic diagram of the structure of another communication device provided by the embodiments of the present application. Detailed Embodiments
[0150] To facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction to the related technologies of the present application is given as follows.
[0151] 1. NAS Message Transmission Mechanism in 5G:
[0152] 5G introduces a service-based architecture in the core network control plane. The communication between network functions in the service-based control plane, such as between the AMF network element and the session management function (SMF) network element, is based on service-based interfaces. Based on service-based interfaces, each core network control plane network element can communicate directly. However, the interfaces between the terminal device or the access network (AN) device and the core network are still non-service-based interfaces. Among them, the terminal device communicates with the AMF network element through the N1 interface, and the access network device communicates with the AMF network element through the N2 interface. Currently, NAS messages between the terminal device and the core network element, and messages between the access network device and the core network element (which can be called N2 messages) all need to be transmitted through the AMF network element.
[0153] NAS messages include different types. Between the terminal device and the AMF network element, the NAS message for mobility management (MM) can be called NAS-MM (NAS for mobility management). Between the terminal device and the SMF network element, the NAS message for session management (SM) can be called NAS-SM (NAS for session management) message. Short messages (SMS) are transmitted between the terminal device and the short message service function (SMSF) network element through NAS messages. Policy information (policy) of the terminal device is transmitted between the terminal device and the policy control function (PCF) network element through NAS messages.
[0154] Exemplarily, the current NAS message transmission mechanism is as Figure 1As shown in the figure. NAS messages are transmitted between the terminal device and the AMF network element through the NAS protocol. Among the NAS messages sent by the terminal device to the AMF network element, it can not only include the messages sent to the AMF network element (such as NAS-MM messages), but also include the messages whose destination network element is other network elements. For example, NAS-SM messages sent to the SMF network element, SMS sent to the SMSF network element, information related to the policy of the terminal device sent to the PCF network element, and information related to location services (LCS) sent to the location management function (LMF). The terminal device transmits the NAS message to the AMF network element. After receiving the NAS message, the AMF network element forwards the information that needs to be sent to other network elements included in the NAS message to the corresponding network element through the interface with the corresponding network element. For example, the AMF network element sends the NAS-MM message in the NAS message to the SMF network element through the N11 / Nsmf interface. The AMF network element sends the SMS in the NAS message to the SMSF network element through the N20 / Nsmf interface. The AMF network element sends the information related to the policy of the terminal device in the NAS message to the PCF network element through the N15 / Npcf interface. The AMF network element sends the information related to LCS in the NAS message to the LMF network element through the NL1 / Nlmf interface.
[0155] Similarly, the N2 messages between the access network device and the core network element also need to be relayed by the AMF network element. Exemplarily, the N2 message between the access network device and the SMF network element, that is, the N2 SM (N2 session management) message, needs to be transmitted through the AMF network element.
[0156] However, this way of transmitting both NAS messages and N2 messages by the AMF network element has the following problems. On the one hand, this way makes other network elements in the core network dependent on the AMF network element, which does not match the principle of functional decoupling between network elements in the service-based architecture. For example, when adding new N2 message and / or NAS message types, this way still requires the AMF network element to be enhanced accordingly. On the other hand, the deployment location of the AMF network element is usually relatively high. When the target core network element (such as the SMF / LMF network element) of the N2 / NAS message is deployed at the edge, forwarding the N2 / NAS message by the AMF network element will result in message detours and cannot meet the requirements of some low-latency scenarios. In addition, there is also a requirement in some scenarios that the message does not leave the campus. When the AMF network element is deployed in the operator's network, while the access network device, SMF / LMF and other network elements are deployed in the campus, if the message is forwarded by the AMF network element, it cannot meet the requirement that the message does not leave the campus, which may bring security risks.
[0157] Based on the above problems, the embodiments of the present application provide a communication method, apparatus, and system, which can improve the transmission efficiency of NAS messages, and can also improve the flexibility of the network architecture and the security of NAS message transmission.
[0158] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the present application, unless otherwise specified, " / " means that the objects associated before and after are an "or" relationship. For example, A / B may represent A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. These three situations, where A and B may be singular or plural. Also, in the description of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression below refers to any combination of these items, including any combination of a single item (item) or a plurality of items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c may be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily limit to be different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.
[0159] In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information (such as the first indication information or the second indication information below) is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to use the arrangement order of each piece of information pre-agreed (such as stipulated by a protocol) to implement the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, it is also possible to identify the common parts of each piece of information and indicate them uniformly to reduce the indication overhead caused by separately indicating the same information.
[0160] In addition, the specific indication method can also be various existing indication methods, such as, but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above description, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0161] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending times of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present application. Among them, the sending periods and / or sending times of these sub-information can be predefined, such as predefined according to a protocol, or can be configured by the sending device by sending configuration information to the receiving device.
[0162] In the embodiments of the present application, "pre-defined", "predefined", "pre-configured", or "pre-configured" can be implemented by pre-saving corresponding codes, tables, or other means that can be used to indicate relevant information in a device. For example, it can be burned into the device when the device leaves the factory. The embodiments of the present application do not limit the specific implementation manner thereof. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or integrated in an encoder, a decoder, a processor, or a communication device. The one or more memories can also be partially separately provided and partially integrated in a decoder, a processor, or a communication device. The type of the memory can be any form of storage medium, and the embodiments of the present application do not limit this.
[0163] The "protocol" involved in the embodiments of the present application can refer to a protocol family in the communication field, a standard protocol with a frame structure similar to that of a protocol family, or a relevant protocol applied to a future communication system. The embodiments of the present application do not make specific limitations thereto.
[0164] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if", and "if" all mean that the device will perform corresponding processing under a certain objective situation, which does not limit time, and does not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.
[0165] The technical solutions provided by the present application can be used in various communication systems. The communication system can be a 3rd generation partnership project (3GPP) communication system. For example, a 5th generation (5G) mobile communication system, a long term evolution (LTE) system, a 5G mobile communication system and its evolved system, a non-terrestrial network (NTN), a multiple-input multiple-output (MIMO) system, a vehicle to everything (V2X) system, a system of hybrid networking of LTE and new radio (NR), or a device-to-device (D2D) system, a machine-to-machine (M2M) communication system, an internet of things (IoT), or an evolved system for the future, such as a 6th generation (6G) mobile communication system, etc. In addition, the term "system" can be interchanged with "network".
[0166] It should be noted that the network architecture and service scenarios described in the embodiments of this application are for more clearly explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those of ordinary skill in the art can know that with the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of this application are equally applicable to similar technical problems.
[0167] Figure 2 FIG. is a schematic diagram of an architecture of a possible and non-limiting communication system applicable to the embodiments of this application. As Figure 2 shown, the communication system 10 includes at least one access network device 100 and at least one terminal device 101 ( Figure 2 illustrated by taking one access network device and one terminal device as an example). The communication system 10 further includes core network elements: a first network element 102 and at least one second network element 103 ( Figure 2 illustrated by taking one second network element as an example).
[0168] Among them, the terminal device 101 can be connected to the access network device 100 in a wireless manner. The access network device 100 can be connected to the first network element 102 and the second network element 103 in a wired or wireless manner. The first network element 102 and the second network element 103 can be connected to each other in a wired or wireless manner.
[0169] Optionally, the communication system 10 may further include other network elements or devices not shown, such as wireless relay devices and / or wireless backhaul devices, etc. The embodiments of this application do not make specific limitations on this.
[0170] In the communication system 10, a NAS session (which can be called a first NAS session) can be established between the first network element and the terminal device. After the first network element and the terminal device establish the first NAS session, the terminal device can further establish a NAS session (which can be called a second NAS session) with the second network element based on the technical solution provided by this application. Thus, NAS messages can be transmitted between the terminal device and the second network element through the second NAS session without the first network element relaying the NAS messages.
[0171] The specific implementation and technical effects of the technical solution provided by this application will be described in detail in the subsequent method embodiments and will not be elaborated here.
[0172] In the embodiments of the present application, no specific restrictions are imposed on the first network element or the second network element. Exemplarily, the first network element may be an AMF network element in a 5G system or a network element in a 6G system. Among them, if the first network element is an AMF network element, a first NAS session is established between the terminal device and the first network element, which is equivalent to the terminal device communicating with the first network element through the N1 interface. The second network element may be any network element different from the first network element. For example, it may be an SMF network element, a PCF network element, an SMSF network element, or an LMF network element in a 5G system, or it may also be a network element in a 6G system, such as an artificial intelligent (AI) proxy network element. Among them, it can be understood that if the second network element is not an AMF network element, establishing a second NAS session between the terminal device and the second network element can be considered as the terminal device communicating with the second network element through a new interface.
[0173] The access network device in the embodiments of the present application refers to a RAN node (or device) that connects a terminal device to a wireless network. In some network architectures, the access network device may be a base station. Currently, some examples of access network devices are: the next generation node B (gNB), transmission reception point (TRP), evolved node B (eNodeB / eNB), radio network controller (RNC), node B (NB), base station controller (BSC), base transceiver station (BTS), home evolved node B, or home node B (HNB), base band unit (BBU), or wireless fidelity (Wifi) access point (AP), etc.
[0174] In addition, in a network structure, multiple access network devices cooperate to assist a terminal device in achieving wireless access, and different access network devices respectively implement some functions of a base station. For example, the access network device may be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU may be separately provided, or may also be included in the same network element, such as a baseband unit (BBU). The RU may be included in a radio frequency device or a radio frequency unit, such as included in a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0175] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (openRAN, O-RAN or ORAN), the CU may also be referred to as an O-CU (open CU), the DU may also be referred to as an O-DU, the CU-CP may also be referred to as an O-CU-CP, the CU-UP may also be referred to as an O-CU-UP, and the RU may also be referred to as an O-RU. For the convenience of description, in this application, the CU, CU-CP, CU-UP, DU, and RU are used as examples for description. Any one of the CU (or CU-CP, CU-UP), DU, and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0176] All or part of the functions of the access network device in this application may also be implemented by a software function running on hardware, or by a virtualized function instantiated on a platform (such as a cloud platform). The access network device in this application may also be a logical node, a logical module, or software that can implement all or part of the functions of the access network device.
[0177] The terminal device in the embodiments of this application can also be referred to as a terminal, user equipment (UE), mobile station (MS), mobile terminal, etc., which is a device with wireless transceiver functions. The terminal device can be widely applied to various scenarios, such as V2X, machine-type communication (MTC), IoT, virtual reality (VR), augmented reality (AR), industrial control, self-driving, remote medical surgery, smart grid, smart home, smart office, smart bracelet, smart city, etc. Currently, some examples of terminal devices are: mobile phones, tablets, computers with wireless transceiver functions, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiments of this application do not limit the device form of the terminal device.
[0178] The core network element in the embodiments of this application refers to the device in the core network that provides service support for the terminal device, such as the AMF network element, SMF network element, etc., which are not listed one by one here. The functions of these core network elements can specifically refer to the existing protocols and will not be elaborated here.
[0179] In the embodiments of this application, a network element can also be referred to as an entity or a functional entity. For example, the first network element can also be referred to as the first entity or the first functional entity.
[0180] Next, in combination with Figure 2 , the communication method provided by the embodiments of this application will be further described.
[0181] It should be noted that the names of the messages between the network elements or the names of the parameters in the messages in the following embodiments of this application are only examples. In specific implementations, other names can also be used, and the embodiments of this application do not make specific limitations on this.
[0182] It can be understood that in the embodiments of this application, each network element can execute some or all of the steps in the embodiments of this application. These steps or operations are only examples, and the embodiments of this application can also execute other operations or various deformations of the operations. In addition, each step can be executed in a different order presented in the embodiments of this application, and it is possible not to execute all the operations in the embodiments of this application.
[0183] As shown Figure 3 in the figure, a communication method provided by an embodiment of the present application is shown. Figure 3 In Figure 3 , the terminal device and the first network element are taken as an example of the execution entities of the interaction schematic to illustrate the method, but the present application does not limit the execution entities of the interaction schematic. For example, Figure 3 the first network element in Figure 3 can also be a module applied to the first network element, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the first network element; Figure 3 the second network element in Figure 3 can also be a module applied to the first network element, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the second network element; Figure 3 the terminal device in Figure 3 can also be a module applied to the terminal device, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the terminal device.
[0184] As shown Figure 3 in the figure, the communication method includes steps S301 - S303:
[0185] S301. The terminal device sends a first request message to the first network element through a first NAS session, and the first request message is used to request a service. Correspondingly, the first network element receives the first request message. Among them, the service requested by the first request message is provided by the second network element, and the first NAS session is used to transmit NAS messages between the terminal device and the first network element.
[0186] S302. The first network element triggers the establishment of a second NAS session. Among them, the second NAS session is used to transmit NAS messages between the terminal device and the second network element.
[0187] S303. A second NAS session is established between the second network element and the terminal device.
[0188] It can be understood that the first NAS session is an exemplary name of the NAS session established between the first network element and the terminal device in the embodiment of the present application. Similarly, the second NAS session is an exemplary name of the NAS session established between the second network element and the terminal device. In specific implementation, it can also be other names, and the embodiment of the present application does not make specific limitations in this regard. For example, the first NAS session can also be called the NAS main session, and the second NAS session can also be called the NAS sub - session.
[0189] Based on the communication method provided in the embodiment of the present application, the terminal device can establish a second NAS session with the second network element after having established a first NAS session with the first network element. Compared with the solution in which the NAS message is relayed by the first network element, the transmission efficiency of the NAS message is improved. In addition, in this solution, the NAS message transmitted between the second network element and the terminal device does not depend on the first network element. It can not only match the principle of functional decoupling between network elements and improve the flexibility of the network architecture, but also improve the security of NAS message transmission. For example, when the first network element is deployed in the operator network and the second network element and the access network equipment are deployed in the park, the present solution is used to transmit the NAS message between the terminal device and the second network element. This can meet the requirement that the message does not leave the park, and improves the security of the NAS message compared to the solution in which the NAS message is relayed by the first network element.
[0190] The following is an introduction to S301-S303 respectively.
[0191] In S301, the first request message is transmitted via the first NAS session. That is, before the terminal device sends the first request message, a first NAS session is established between the terminal device and the first network element.
[0192] The first NAS session established between the terminal device and the first network element can be understood as a communication connection established between the terminal device and the access network device, such as a radio resource control (RRC) connection, and a communication connection established between the access network device and the first network element, such as a signaling connection, so that the access network device forwards NAS messages between the terminal device and the first network element.
[0193] The establishment of the first NAS session is described below.
[0194] Optionally, the establishment of the first NAS session may be triggered by a first NAS session establishment request message sent by the terminal device to the first network element.
[0195] Optionally, after triggering the establishment of the first NAS session, the first network element may determine whether to allow the establishment of the first NAS session. For example, the first network element may authenticate and authorize the terminal device (for example, authentication and authorization may be performed based on the contract information of the terminal device) to determine whether to allow the terminal device to establish the first NAS session.
[0196] Optionally, during the establishment of the first NAS session, the first network element may enable the security of the first NAS session. Among them, the method for enabling the security of the first NAS session can refer to the process related to the NAS security mode between the AMF network element (corresponding to the first network element) and the terminal device in the prior art, such as the NAS security mode command.
[0197] In a possible case, the establishment process of the first NAS session can refer to the existing registration process, such as the registration process in the 5G system. In other words, the terminal device can initiate the establishment of the first NAS session through the registration process. In this case, the registration request message sent by the terminal device is equivalent to the first NAS session establishment request message and can request the establishment of the first NAS session. Among them, the specific registration process can refer to the existing standard protocol and will not be elaborated here.
[0198] Optionally, the first NAS session can be identified by identification information (hereinafter referred to as the identifier of the first NAS session). In a possible implementation, the identifier of the first NAS session can be assigned by the terminal device, and the terminal device sends the identifier of the first NAS session to the first network element. For example, the terminal device can carry the identifier of the first NAS session in the first NAS session establishment request message. In another possible implementation, the identifier of the first NAS session can be assigned by the first network element, and the first network element sends the identifier of the first NAS session to the terminal device. For example, the first network element can carry the identifier of the first NAS session in the response message to the first NAS session establishment request message and send it to the terminal device.
[0199] Furthermore, the first network element may send the correspondence between the identifier of the first NAS session and the information of the first network element to the access network device. The access network device may save the received correspondence in the context of the terminal device for subsequent forwarding of NAS messages between the first network element and the terminal device (i.e., messages that need to be transmitted through the first NAS session). The specific implementation of the access network device forwarding NAS messages between the first network element and the terminal device through the correspondence will be introduced later and will not be elaborated here for the time being.
[0200] Among them, the information of the first network element may include the address information of the first network element, such as the fully qualified domain name (FQDN) or the internet protocol (IP) address of the first network element, and the identification information indicating the context of the first NAS session in the first network element, such as a string.
[0201] Exemplarily, if the interface between the access network device and the first network element is a service-based interface, the information of the first network element may be a uniform resource locator (URL), the hostname of the URL is the FQDN or IP address of the first network element, and the URL includes identification information indicating the context of the first NAS session in the first network element. If the interface between the access network device and the first network element is based on the stream control transmission protocol (SCTP), the information of the first network element may include the address information of the first network element (such as the IP address) and an identifier indicating the context of the first NAS session in the first network element, such as the next generation application protocol (NGAP) user equipment identifier (NGAP UEID) assigned by the first network element. In the above example, the identification information indicating the context of the first NAS session in the first network element may also be the identification information of the terminal device. For example, it is a temporary identifier assigned by the first network element to the terminal device.
[0202] Optionally, the access network device may configure a corresponding radio bearer (RB) for the first NAS session. Among them, the first NAS session may correspond to one or more radio bearers. In a possible implementation, the access network device may allocate corresponding identification information (hereinafter referred to as RB identification) for each radio bearer corresponding to the first NAS session. For example, the RB identification may be a media access control (MAC) layer channel identifier (MAC channel ID).
[0203] Optionally, the access network device may also send information for configuring the radio bearer corresponding to the first NAS session to the terminal device. After receiving the information, the terminal device may send NAS messages through the radio bearer corresponding to the first NAS session when sending NAS messages to the first network element subsequently.
[0204] Optionally, if the access network device also obtains the correspondence between the identifier of the first NAS session and the information of the first network element, the access network device may save the correspondence between the identifier of the first NAS session, the information of the first network element, and the radio bearer corresponding to the first NAS session.
[0205] In a possible scenario, the radio bearer corresponding to the first NAS session may be used for the access network device to forward NAS messages between the first network element and the terminal device. The specific implementation will be introduced later and will not be elaborated here.
[0206] The establishment of the first NAS session is introduced above. After the establishment of the first NAS session is completed, the terminal device sends a first request message to the first network element through the first NAS session. It can be understood that sending the first request message through the first NAS session includes: the terminal device sends the first request message to the access network device, and after receiving the first request message, the access network device sends the first request message to the first network element.
[0207] Combined with the above introduction to the method of transmitting NAS messages through the first NAS session, the terminal device can send the first request message through the first NAS session in the following possible way:
[0208] The terminal device sends an RRC message to the access network device, where the RRC message includes the first request message. And the RRC message is sent through the radio bearer corresponding to the first NAS session, and / or the RRC message includes the identifier of the first NAS session. The access network device can determine to send the first request message to the first network element according to the radio bearer corresponding to the first NAS session, and / or the identifier of the first NAS session. For details, reference can be made to the above introduction and will not be elaborated here.
[0209] After receiving the first request message, the first network element can determine the second network element according to the first request message. Specifically, the first network element determines one or more network elements that can provide services according to the first request message. Further, the first network element determines a network element to provide services for the terminal device, and the network element that actually provides services for the terminal device is the second network element.
[0210] In S302, after the first network element receives the first request message, the first network element can trigger the establishment of the second NAS session, where the second NAS session is used to transmit NAS messages between the terminal device and the second network element. That is to say, the first network element can trigger the establishment of the second NAS session between the second network element and the terminal device.
[0211] For the second NAS session established between the terminal device and the second network element, it can be understood that a communication connection, such as an RRC connection, is established between the terminal device and the access network device, and a communication connection, such as a signaling connection, is established between the access network device and the second network element, so that the access network device forwards the NAS messages between the terminal device and the second network element, and there is no need for the first network element to forward the NAS messages between the terminal device and the second network element.
[0212] The following elaborates on how to trigger the establishment of the second NAS session.
[0213] In the embodiments of this application, the first request message may include the following three cases. The following introduces the specific implementation of the first network element triggering the establishment of the second NAS session in combination with different cases:
[0214] Case 1: The first request message is used to request a service and does not request to establish a NAS session between the terminal device and the second network element.
[0215] In Case 1, the service can be any type of network service, and the embodiments of the present application do not limit this.
[0216] For example, the first request message can be a protocol data unit (PDU) session establishment request. In this case, the second network element can be an SMF network element. Or, the first request message can be a UE policy session establishment request. In this case, the second network element can be a PCF network element. Or, the first request message can be a positioning request message. In this case, the second network element can be an LMF network element. Or, the first request message can request an AI service. In this case, the second network element can be a network element capable of providing the AI service, such as an AI proxy network element.
[0217] In a possible implementation manner of Case 1, the first network element can determine that a second NAS session needs to be established and trigger the establishment of the second NAS session based on at least one of information such as the subscription information of the terminal device and the deployment location of the first network element. For example, the subscription information of the terminal device includes the subscription information of the service requested by the first request message, and the subscription information of the service indicates that the NAS message corresponding to the service does not go out of the park. The first network element can determine that a second NAS session needs to be established based on its own deployment location not being in the park, facilitating the direct transmission of NAS messages between the second network element and the terminal device. In this example, the first network element can select a network element with a deployment location within the park as the second network element for the second NAS session.
[0218] In another possible implementation of Case 1, after receiving the first request message, the first network element can send a fifth request message (which can be the first request message or a request message generated by the first network element for requesting a service) to the second network element. The second network element can determine based on the fifth request message that a second NAS session also needs to be established and send fourth information to the first network element. The fourth information is used to indicate the establishment of the second NAS session. In this implementation, the first network element can trigger the establishment of the second NAS session based on the fourth information.
[0219] For example, assume that the first request message is a positioning request message. After receiving the first request message, the second network element determines that a second NAS session also needs to be established to facilitate the transmission of the location information of the terminal device through the second NAS session. Based on this, the second network element sends fourth information to the first network element to indicate the establishment of the second NAS session.
[0220] Scenario 2: The first request message is used to request a service, and the first request message is also used to request the establishment of a NAS session between the terminal device and the second network element. For example, the first request message includes indication information for requesting the establishment of a second NAS session.
[0221] In Scenario 2, the service requested by the first request message can refer to the introduction of Scenario 1 above and will not be elaborated here.
[0222] In Scenario 2, when the first network element determines that a service needs to be provided based on the first request message, it can also determine that a second NAS session needs to be established. That is, in this implementation, the first network element can trigger the establishment of the second NAS session according to the first request message. For example, the first network element determines that a second NAS session needs to be established based on the indication information for requesting the establishment of a second NAS session included in the first request message.
[0223] In Scenario 1 or Scenario 2, after the second NAS session is established, the NAS messages transmitted through the second NAS session can be NAS messages related to the service (i.e., the service requested by the first request message). That is, the second NAS session provides a NAS signaling channel between the terminal device and the second network element for this service.
[0224] Scenario 3: The first request message is used to request the establishment of a NAS session between the terminal device and the second network element. In Scenario 3, the first request message can also be referred to as a second NAS session establishment request message. In Scenario 3, the second NAS session is used to provide a NAS signaling channel between the terminal device and the second network element, and this NAS signaling channel is used to transmit NAS messages related to the service provided by the second network element.
[0225] In Scenario 3, the first network element can directly determine that a second NAS session needs to be established based on the first request message and trigger the establishment of the second NAS session.
[0226] The different scenarios of the first request message and how to trigger the establishment of the second NAS session in different scenarios are introduced above. In addition, the embodiments of the present application also provide some optional solutions related to triggering the establishment of the second NAS session.
[0227] Optionally, the first request message may further indicate the type of the second NAS session. For example, the first request message may include information indicating the type of the second NAS session. The type of the second NAS session may correspond to the service provided by the second network element. For example, the second NAS session type may be a NAS session of a session type. In this case, the corresponding service (i.e., the service provided by the second network element) is a session service (for example, if the second network element is a SMF network element, it can provide the service of establishing a PDU session). Another example is that the second NAS session type may be a NAS session of a positioning type. In this case, the corresponding service is a positioning service (for example, if the second network element is an LMF network element, it can provide a positioning service).
[0228] Optionally, the first request message may further include other relevant information of the second NAS session. The first network element does not process this information but sends it to the second network element (for example, it can be sent to the second network element together with the second request message introduced later). Exemplarily, when the first request message is used to request the establishment of a PDU session, the first request message may include information such as the session and service continuity (SSC) mode of the PDU session and the type of IP address.
[0229] Optionally, for determining the second network element, the first network element may select the second network element from the network elements that can provide services according to the first information. The first information may also be referred to as network element selection information. The embodiments of the present application do not limit the first information. For example, the first network may determine the first information from the information included in the first request message, or the first network element may determine the first information from the subscription information of the terminal device, or the first network element may determine the first information from the relevant information of the terminal device (such as the location information of the terminal device), etc.
[0230] Exemplarily, if the first request message requests the establishment of a PDU session, the first information may be information such as the data network name (DNN) and slice identifier included in the first request message. The first network element may select a suitable SMF network element as the second network element according to the first information.
[0231] For another example, when the first information is included in the subscription information of the terminal device, if the first request message includes the first information, the first network element may select a suitable network element as the second network element according to the intersection of the first information in the subscription information of the terminal device and the first information included in the first request message. Optionally, the first information in the subscription information of the terminal device may include default network element selection information. If the first request message does not include the first information, the first network element may select a suitable network element as the second network element according to the default network element selection information in the subscription information of the terminal device. In one possible case, the first information in the subscription information of the terminal device may correspond to the type of the NAS session. The first network element may determine the subscribed first information corresponding to the type of the second NAS session according to the type of the second NAS session, and then further select the second network element according to the corresponding subscribed first information.
[0232] For another example, the first network element may select a network element that is closer to the location of the terminal device from the network elements that can provide services as the second network element according to the location information of the terminal device.
[0233] Optionally, before the first network element triggers the establishment of the second NAS session, the first network element may determine whether to allow the establishment of the second NAS session. If it is determined that the establishment of the second NAS session is allowed, the first network element triggers the establishment of the second NAS session and continues with the subsequent process. If it is determined that the establishment of the second NAS session is not allowed, the establishment of the second NAS session will not be triggered.
[0234] Optionally, when the first request message requests the establishment of the second NAS session (for example, the first request message is a second NAS session establishment request message, or the first request message includes indication information for requesting the establishment of the second NAS session), and the first network element determines that the establishment of the second NAS session is not allowed, the first network element may send a response message indicating the failure of the second NAS session establishment to the terminal device.
[0235] For determining whether to allow the establishment of the second NAS session, in one possible implementation, the first network element may determine whether to allow the establishment of the second NAS session according to the subscription information of the terminal device. For example, the subscription information of the terminal device may include the types of NAS sessions allowed to be established. The first request message sent by the terminal device to the first network element indicates the type of the second NAS session. If the first network element determines that the type of the second NAS session belongs to the types of NAS sessions allowed to be established, it may determine that the establishment of the second NAS session is allowed. If not, it may determine that the establishment of the second NAS session is not allowed.
[0236] For another example, the subscription information of the terminal device may include information indicating a service for which a NAS session is allowed to be established for it. The first network element determines whether a NAS session can be established for the service requested by the terminal device based on the first request message and the subscription information of the terminal device. If the first network element determines that a NAS session can be established for the service requested by the terminal device, it may determine to allow the establishment of a second NAS session. If it determines that a NAS session cannot be established for the service requested by the terminal device, it may determine not to allow the establishment of a second NAS session.
[0237] The above describes how to trigger the establishment of a second NAS session. The subsequent processes after triggering the second NAS session are introduced below.
[0238] Optionally, if the first network element triggers the establishment of a second NAS session, the first network element may send a second request message to the second network element. The second request message may also be referred to as a second NAS session establishment request and is used to request the establishment of a second NAS session. It can also be understood that the first network element sends a second request message to the second network element to trigger the establishment of a second NAS session.
[0239] Optionally, the second request message may also request the service requested by the first request message, such as requesting the establishment of a PDU session, requesting information related to LCS, etc.
[0240] In a possible case, if the first network element receives the fourth information from the second network element, the first network element may not need to send a second request message to the second network element. In this case, after triggering the establishment of the second NAS session based on the fourth information, the first network element may directly request the access network device to establish a second NAS session. For example, the fourth information may include information for generating a third request message, such as the address information of the second network element, identification information for indicating the context of the second NAS session in the second network element, etc. The first network element may generate a third request message according to the fourth information and send it to the access network device. The third request message requests the establishment of a second NAS session. For details, reference may be made to the introduction of the establishment of a direct transmission channel between the second network element and the access network device below, which will not be elaborated here for the time being. In this case, the first network element may also send the identifier of the second NAS session to the second network element.
[0241] Alternatively, after the first network element receives the fourth information from the second network element, the first network element may also send a second request message to the second network element.
[0242] Optionally, the first network element may obtain the identifier of the second NAS session and send the identifier of the second NAS session to the second network element, where the identifier of the second NAS session is used to identify the second NAS session. For example, the second request message may include the identifier of the second NAS session, or the first network element sends the second request message and the identifier of the second NAS session to the second network element together.
[0243] In a possible implementation, the identifier of the second NAS session can be assigned by the terminal device. In this implementation, the terminal device can send the identifier of the second NAS session to the first network element, and then the first network element sends the identifier of the second NAS session to the second network element. For example, the first request message sent by the terminal device to the first network element includes the identifier of the second NAS session. Another example is that the terminal device sends the identifier of the second NAS session together with the first request message to the first network element.
[0244] In another possible implementation, the identifier of the second NAS session can also be assigned by the first network element. After determining that it is necessary to establish a second NAS session (for example, the first network element determines that it is necessary to establish a second NAS session based on the first request message or the fourth information), the first network element can assign the identifier of the second NAS session for the second NAS session.
[0245] It can be understood that, in order to determine the corresponding NAS session according to the identifier of the NAS session, in the embodiments of the present application, the NAS session and the identifier of the NAS session are in a one-to-one correspondence relationship. That is to say, when the terminal device or the first network element assigns an identifier to the NAS session, it is necessary to ensure the uniqueness of the identifiers of each NAS session.
[0246] The following introduces the specific implementation of establishing the second NAS session between the second network element and the terminal device in S303.
[0247] If the first network element sends a second request message to the second network element, after receiving the second request message, the second network element can determine to establish a second NAS session according to the second request message. Further, the second network element sends a first response message for the second request message to the first network element.
[0248] Among them, the first response message can have different uses in different situations, which will be introduced in combination with different situations in the following embodiments and will not be elaborated here for the time being.
[0249] Optionally, after the second network element determines to establish a second NAS session (for example, the second network element determines to establish a second NAS session based on the first request message, or after the second network element receives the second request message), it may obtain the quality of service (QoS) information corresponding to the second NAS session, such as at least one of the following: QoS level (such as scheduling priority, QoS class identifier (QCI), 5G QoS identifier (5QI), or similar information for indicating scheduling priority), maximum bandwidth, indication of whether it is mapped to a data radio bearer (DRB), or guaranteed bandwidth, etc. Among them, the indication of mapping to a DRB is used to indicate that the message of the second NAS session is transmitted through the DRB.
[0250] Among them, in one possible implementation, the second network element may determine the QoS information corresponding to the type of the second NAS session from the subscription information of the terminal device. The embodiments of the present application do not limit how the second network element determines the type of the second NAS session. For example, the second request message may include the type of the second NAS session. Another example is that the second network element may determine the corresponding type of the NAS session based on the services it can provide. For example, if the second network element is an SMF network element and can establish a PDU session, then the second network element may determine the type of the second NAS session as "PDU session" or "NAS session established for the PDU session".
[0251] It can be understood that in order to establish a second NAS session, a direct transmission channel for NAS messages needs to be established between the second network element and the access network device. Taking the scenario where the second network element receives the second request message as an example, the specific implementation of establishing the direct transmission channel between the second network element and the access network device is introduced below.
[0252] In a first possible implementation, the first response message sent by the second network element to the first network element includes a third request message. The third request message is used to request the access network device to establish a second NAS session, and the third request message includes at least one of the following: the address information of the second network element, the identifier information assigned by the second network element for the second NAS session, which is used to indicate the context of the second NAS session in the second network element, or the identifier of the second NAS session. Exemplarily, when the interface between the second network element and the access network device is a service-based interface, the identifier information used to indicate the context of the second NAS session in the second network element can be a string or an identifier set by the second network element. When the interface between the second network element and the access network device is an SCTP interface, the identifier information can be the NGAP UE ID information assigned by the second network element. After receiving the first response message, the first network element forwards the third request message therein to the access network device. The access network device determines to establish a communication connection with the second network element according to the third request message. Further, the access network device may save the correspondence between the identifier of the second NAS session and the address information of the second network element.
[0253] In a second possible implementation, the first response message sent by the second network element to the first network element includes second indication information. The second indication information is used to indicate that the access network device needs to establish a second NAS session. After receiving the first response message, the first network element generates a third request message according to the second indication information therein and sends the third request message to the access network device. In this implementation manner, the first response message further includes the information for generating the third request message. The third request message can specifically refer to the above introduction. The access network device determines to establish a communication connection with the second network element according to the third request message. Further, the access network device may save the correspondence between the identifier of the second NAS session and the address information of the second network element.
[0254] In a third possible implementation, the second network element directly sends a third request message to the access network device ("directly" means without being relayed by the first network element). The third request message can specifically refer to the above introduction. The access network device determines to establish a communication connection with the second network element according to the third request message. Further, the access network device may save the correspondence between the identifier of the second NAS session and the address information of the second network element.
[0255] Optionally, in this implementation, the second request message sent by the first network element to the second network element may include the address information of the access network device (such as the IP address of the access network device) and a first identifier, where the first identifier is used to indicate the context of the terminal device in the access network device. The second network element may determine the access network device according to the address information of the access network device, and thus directly send a third request message to the access network device. The third request message may include the first identifier. After receiving the third request message, the access network device may, according to the third request message, save the correspondence between the identifier of the second NAS session and the address information of the second network element in the context of the terminal device. For example, the access network device may determine the context of the terminal device according to the first identifier in the third request message.
[0256] Optionally, in this implementation, the first identifier obtained by the first network element may be sent by the access network device to the first network element. For example, the access network device may, during the process of establishing the first NAS session, allocate a first identifier for the context of the terminal device and send it to the first network element.
[0257] Optionally, in the above-mentioned various implementations of establishing a direct transmission channel between the second network element and the access network device, in addition to the address information of the second network element and the identifier of the second NAS session, the third request message may further include the quality of service (QoS) information of the second NAS session. Correspondingly, in the second implementation manner, the second network element also needs to send the QoS information of the second NAS session to the first network element through the first response message, so that the first network element can generate the third request message.
[0258] Further, after receiving the third request message and determining to establish a communication connection with the second network element, the access network device may send a third response message for the third request message to the second network element. The third response message includes the address information of the access network device and a second identifier, where the second identifier is used to indicate the context of the second NAS session in the access network device. For example, the second identifier may be a string, or the second identifier may be a RANNGAP UE ID allocated by the access network device for the second NAS session.
[0259] The second network element may save the correspondence between the second identifier, the identifier of the second NAS session, and the address information of the access network device.
[0260] Regarding the access network device sending the third response message to the second network element, in the first and second possible implementation manners of establishing a direct transmission channel between the second network element and the access network device above, the third response message may be sent to the second network element through the first network element. In the third possible implementation manner above, the third response message may be directly sent by the access network device to the second network element (without passing through the first network element).
[0261] At this point, a second NAS session is established between the terminal device and the second network element. The terminal device and the second network element can transmit NAS messages through the access network device without the first network element relaying the NAS messages.
[0262] Optionally, if the second network element directly sends a third request message to the access network device to establish the second NAS session, the second network element may, after receiving the third response message, send a first response message indicating the successful establishment of the second NAS session to the first network element.
[0263] Optionally, after receiving the third request message, the access network device may also allocate an interface identifier for the interface between the access network device and the second network element associated with the second NAS session. Further, the access network device may send the interface identifier to the second network element through the third response message, and the second network element may use the interface identifier to send downlink NAS messages later. Among them, the interface identifier may correspond to the second identifier.
[0264] Or, the interface identifier is the second identifier.
[0265] Exemplarily, when the interface between the second network element and the access network device is a service-based interface, the interface identifier may be a URL, and the URL includes the address of the access network device and the second identifier. Another example is that when the interface between the second network element and the access network device is an SCTP-based interface, the interface identifier may be the RANNGAP UE ID allocated by the access network device for the second NAS session, and the RANNGAP UE ID may indicate the context of the second NAS session in the access network device.
[0266] Optionally, after receiving the third request message, the access network device may configure one or more corresponding radio bearers for the second NAS session. Each radio bearer corresponding to the second NAS session may have a corresponding RB identifier, such as a MAC channel ID.
[0267] The embodiments of the present application do not limit the specific implementation of the access network device configuring corresponding radio bearers for the second NAS session. Exemplarily, if the third request message includes the QoS information of the second NAS session, the access network device may configure corresponding radio bearers for the second NAS session according to the QoS information of the second NAS session.
[0268] Optionally, the access network device may send the second information used to configure the radio bearers corresponding to the second NAS session to the terminal device. After receiving the second information, the terminal device may, when sending NAS messages to the second network element later, send NAS messages to the second network element through the radio bearers corresponding to the second NAS session.
[0269] It can be understood that in the above embodiments, the method for establishing the second NAS session between the terminal device and the second network element can also be applied to establishing other NAS sessions between the terminal device and other network elements. Or rather, the terminal device can establish different second NAS sessions with multiple second network elements respectively.
[0270] The interactions among the access network device, the second network element, and the first network element during the establishment of the second NAS session are introduced above. In addition, the first network element or the second network element can send a second NAS session establishment success indication or a second NAS session establishment indication to the terminal device to notify the terminal device of the establishment of the second NAS session. Among them, the second NAS session establishment success indication is used to indicate that the second NAS session is successfully established, and the second NAS session establishment indication is used to indicate the establishment of the second NAS session. Moreover, the second NAS session establishment success indication or the second NAS session establishment indication is sent to the terminal device together with the identifier of the second NAS session. That is to say, in S303, the terminal device can receive at least one of the second NAS session establishment success indication or the second NAS session establishment indication, and the identifier of the second NAS session. The terminal device can determine that the second NAS session is successfully established based on the second NAS session establishment success indication and the identifier of the second NAS session. Or, the terminal device can determine that it is necessary to establish the second NAS session based on the second NAS session establishment indication and the identifier of the second NAS session.
[0271] According to the three different situations of the first request message in S301, the terminal device receives different indication information (i.e., the second NAS session establishment success indication or the second NAS session establishment indication), which will be introduced separately as follows:
[0272] In the first situation, the terminal device does not request to establish the second NAS session. In this case, during the establishment of the second NAS session, the first network element or the second network element sends a second NAS session establishment indication to the terminal device, that is, it is necessary to notify the terminal device to establish the second NAS session.
[0273] In the second and third situations, the terminal device requests to establish the second NAS session. In these two situations, after the second NAS session is successfully established, the first network element or the second network element sends a second NAS session establishment success indication to the terminal device.
[0274] If the second network element sends an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device, in a possible implementation, when the second network element sends a third request message to the access network device (for example, the first network element forwards the third request message from the second network element to the access network device, or the second network element directly sends the third request message to the access network device), the second network element may send a second response message to the terminal device through the third request message. That is, the third request message includes the second response message to be sent to the terminal device. After receiving the third request message, the access network device sends the second response message therein to the terminal device. Wherein, the second response message includes the identifier of the second NAS session, and at least one of the following: an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session.
[0275] If the first network element sends an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device, in a possible implementation, after receiving the first response message, the first network element may, according to the first response message, send an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device. For example, if the first response message indicates successful establishment of a second NAS session, the first network element determines, according to the first response message, to send an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device. Another example is that the first response message includes indication information for notifying the terminal device of successful establishment of a second NAS session, and the first network element sends an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device according to this indication information. Wherein, when the first network element sends an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device, it sends the indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session together with the identifier of the second NAS session to the access network device, and the access network device sends the indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session together with the identifier of the second NAS session to the terminal device. In another possible implementation, the first network element may send an indication of successful establishment of a second NAS session or an indication of establishment of a second NAS session to the terminal device after receiving the fourth information.
[0276] After the successful establishment of the second NAS session, NAS messages can be transmitted between the terminal device and the second network element through the second NAS session.
[0277] Optionally, in an uplink transmission scenario, after S303, S304 may be included:
[0278] S304: The terminal device sends a first NAS message (the first NAS message may be any NAS message sent through the second NAS session) to the second network element through the second NAS session according to the identifier of the second NAS session.
[0279] Among them, the terminal device sends a first NAS message to a second network element through a second NAS session, including: the terminal device sends the first NAS message to an access network device, and the access network device forwards the first NAS message to the second network element. Specifically, when the terminal device sends an RRC message including the first NAS message to the access network device, it also sends the identifier of the second NAS session together, and / or the terminal device determines the radio bearer corresponding to the second NAS session according to the identifier of the second NAS session, and sends the first NAS message to the access network device through the radio bearer. After receiving the first NAS message, the access network device can determine that the first NAS message is the NAS message corresponding to the second NAS session according to the identifier of the second NAS session or the radio bearer for receiving the first NAS message, and send the first NAS message to the second network element corresponding to the second NAS session. For details, see the description of the uplink message transmission scenario of the third NAS session below.
[0280] Optionally, in the downlink transmission scenario, after S303, S305 may be included:
[0281] S305. The second network element sends a second NAS message to the terminal device through the second NAS session.
[0282] Among them, S305 includes: the second network element sends the second NAS message to the access network device, and the access network device forwards the second NAS message to the terminal device. Specifically, when the second network element sends the second NAS message to the access network device, it performs at least one of the following: sends the identifier of the second NAS session together, sends the second identifier together, or sends the second NAS message through the interface associated with the second NAS session. After receiving the second NAS message, the access network device can determine that the second NAS message corresponds to the second NAS session according to at least one of the following: the identifier of the second NAS session, the second identifier, or the identifier of the interface for receiving the second NAS message. When the access network device sends the second NAS message to the terminal device, it may send the identifier of the second NAS session together, and / or send the second NAS message to the terminal device through the radio bearer corresponding to the second NAS session. After receiving the second NAS message, the terminal device can determine the second NAS session corresponding to the second NAS message according to the identifier of the second NAS session and / or the radio bearer for receiving the second NAS message. For details, see the description of the downlink message transmission of the third NAS session below.
[0283] It can be understood that, in the embodiments of the present application, a first NAS session is established between the terminal device and the first network element, and a second NAS session is established between the terminal device and the second network element. Moreover, the terminal device may also establish other NAS sessions with other network elements. When transmitting messages through the NAS session, the access network device needs to forward the NAS messages. Therefore, in the scenario of transmitting NAS messages through the NAS session, the access network device needs to determine the session to which the received NAS message belongs. Among them, in the uplink transmission scenario, the access network device can determine the NAS session to which the NAS message belongs according to the NAS session identifier received when receiving the NAS message and / or the radio bearer for receiving the NAS message, and further determine the destination network element of the NAS message according to the session to which the NAS message belongs, so as to forward the NAS message to the destination network element. In the downlink transmission scenario, after receiving the NAS message, the access network device can determine the session to which the NAS message belongs according to at least one of the following: the identifier of the received NAS session, the identifier indicating the context of the NAS session in the access network device, or the identifier of the interface for receiving the NAS message, and send the NAS message to the terminal device through the NAS session to which the NAS belongs.
[0284] The following is divided into the uplink transmission scenario and the downlink transmission scenario to elaborate on how the access network device determines the NAS session to which the NAS message belongs and sends the NAS message to the destination network element / terminal device.
[0285] In the uplink transmission scenario, after the terminal device sends a third NAS message (the third NAS message can be any NAS message) through a third NAS session (the third NAS session can be any NAS session established between the terminal device and the first network element, the second network element, or other network elements), the access network device receives the third NAS message from the terminal device. The access network device can determine that the third NAS message belongs to the third NAS session and determine the destination network element of the third NAS message (the destination network element of the third NAS message can be referred to as the third network element), so as to send the third NAS message to the destination network element.
[0286] In a possible implementation, the terminal device sends the identifier of the third NAS session together with the third NAS message to the access network device. After receiving the identifier of the third NAS session and the third NAS message, the access network device determines the destination network element of the third NAS message according to the identifier of the third NAS session and the first corresponding relationship. Among them, the first corresponding relationship is used to indicate the correspondence between the identifier of the third NAS session and the destination network element of the third NAS message. For example, the first corresponding relationship may include the correspondence between the identifier of the third NAS session and the information (such as identifier information, address information, etc.) of the destination network element of the third NAS message. Further, the access network device sends the third NAS message to the destination network element of the third NAS message.
[0287] Among them, for the terminal device to send the third NAS message to the access network device together with the identifier of the third NAS session, the third NAS message and the identifier of the third NAS session can be carried and sent in the same RRC message. Alternatively, the identifier of the third NAS session can be a non-encrypted field of the third NAS message header.
[0288] In another possible implementation, when the terminal device sends the third NAS message, it can send the third NAS message to the access network device through the radio bearer corresponding to the third NAS session. After receiving the third NAS message, the access network device can determine the destination network element of the third NAS message according to the radio bearer used to transmit the third NAS message and the second corresponding relationship. The second corresponding relationship is used to indicate the correspondence between the radio bearer used to transmit the third NAS message and the destination network element of the third NAS message. For example, the second corresponding relationship can include the correspondence between the identifier of the radio bearer used to transmit the third NAS message, the identifier of the third NAS session, and the information (such as identifier information, address information, etc.) of the destination network element of the third NAS message. Further, the access network device sends the third NAS message to the destination network element of the third NAS message.
[0289] Among them, if the access network device determines the destination network element of the third NAS message according to the RB identifier of the radio bearer used to transmit the third NAS message and the second corresponding relationship, the access network device can determine the RB identifier according to the MAC channel ID of the third NAS message. Or, the terminal device can carry the RB identifier in the message header encapsulating the third NAS message. For example, when the third NAS message is encapsulated by the service data adaptation protocol (SDAP), the RB identifier can be carried in the SDAP header.
[0290] In the scenario of downlink transmission, the third network element (the third network element is the network element that has established the third NAS session with the terminal device) sends the fourth NAS message (the fourth NAS message can be any NAS message) through the third NAS session. Among them, in one possible implementation, the third network element can send the fourth NAS message together with the information that can indicate the third NAS session (such as the identifier of the third NAS session or the third identifier, the third identifier is used to indicate the context of the third NAS session in the access network device. Optionally, the third identifier can correspond to the identifier of the interface associated with the third NAS session. For details, please refer to the above introduction about the access network device allocating an interface identifier for the interface associated with the second NAS session) to the access network device. The access network device can determine the third NAS session to which the fourth NAS message belongs according to the information indicating the third NAS session, and thus send the fourth NAS message to the terminal device.
[0291] Among them, for the third network element to send the fourth NAS message to the access network device together with the information that can indicate the third NAS session, the fourth NAS message and the information that can indicate the third NAS session can be carried and sent in the same signaling message, or the identifier of the third NAS session can be used as an unencrypted field in the fourth NAS message header.
[0292] In another possible implementation, the third network element sends the fourth NAS message to the access network device through an interface associated with the third NAS session. After receiving the fourth NAS message, the access network device can determine the third NAS session to which the fourth NAS message belongs according to the identifier of the interface for receiving the fourth NAS message, and thus send the fourth NAS message to the terminal device. Optionally, in this implementation, when the third network element sends the fourth NAS message, it can also send the information indicating the third NAS session together.
[0293] For the access network device to send the fourth message to the terminal device, in one possible implementation, the access network device can send the identifier of the third NAS session and the fourth NAS message to the terminal device together. Correspondingly, after receiving the fourth NAS message and the identifier of the third NAS session, the terminal device can determine the third NAS session to which the fourth NAS message belongs according to the identifier of the third NAS session.
[0294] Specifically, in the case where the third network element sends the identifier of the third NAS session and the fourth NAS message to the access network device together, if the identifier of the third NAS session is an unencrypted field in the fourth NAS message header, the access network device can directly forward the fourth NAS message to the terminal device. If the fourth NAS message and the identifier of the third NAS session are carried and sent in the same signaling message, the access network device can carry and send the fourth NAS message and the identifier of the third NAS session in the same RRC message to the terminal device. In the case where the third network element sends the third identifier and the fourth NAS message to the access network device together, or the third network element sends the fourth NAS message through an interface associated with the third NAS session, the access network device can determine the identifier of the third NAS session according to the third identifier or the identifier of the interface for receiving the fourth NAS message (for example, the identifier of the third NAS session is included in the context of the third NAS session, or for another example, the access network device stores the corresponding relationship between the identifier of the interface for receiving the fourth NAS message and the identifier of the third NAS session), and send the identifier of the third NAS session and the fourth NAS message to the terminal device together (for example, use the identifier of the third NAS session as an unencrypted field in the fourth NAS message header, or carry the fourth NAS message and the identifier of the third NAS session in the same RRC message).
[0295] For the access network device to send the fourth message to the terminal device, in another possible implementation, the access network device may send the fourth NAS message to the terminal device through the radio bearer corresponding to the third NAS session. Correspondingly, the terminal device may determine the third NAS session to which the fourth NAS message belongs according to the third NAS session corresponding to the radio bearer for transmitting the fourth NAS message.
[0296] Optionally, in the uplink transmission scenario or the downlink transmission scenario, at least two of the following implementation methods may work simultaneously: the implementation method of transmitting NAS messages based on the identifier of the NAS session, the implementation method of transmitting NAS messages based on the radio bearer corresponding to the NAS session, or the implementation method of transmitting NAS messages based on the interface associated with the NAS session. For example, if the terminal device simultaneously adopts the implementation method of transmitting NAS messages based on the identifier of the NAS session and the implementation method of transmitting NAS messages based on the radio bearer corresponding to the NAS session, when the terminal device sends the third NAS message, it always sends the third NAS message together with the identifier of the third NAS session. At the same time, the terminal device determines the radio bearer used to send the third NAS message according to the corresponding relationship between the third NAS session and the radio bearer. Similarly, when the access network device sends the fourth NAS message, it always sends the fourth NAS message together with the identifier of the third NAS session. At the same time, the access network device determines the radio bearer used to send the fourth NAS message according to the corresponding relationship between the third NAS session and the radio bearer. Another example is that if the third network element simultaneously adopts the implementation method of transmitting NAS messages based on the identifier of the NAS session and the implementation method of transmitting NAS messages based on the radio bearer corresponding to the NAS session, when the third network element sends the fourth NAS message, it always sends the fourth NAS message together with the information indicating the third NAS session. At the same time, the third network element sends the fourth NAS message through the interface associated with the third NAS session.
[0297] Based on the above embodiments, a possible process for the terminal device to establish a second NAS session with the second network element may be as Figure 4 shown and includes the following steps:
[0298] S401. The terminal device sends a first request message through the first NAS session. The first request message requests to establish a second NAS session and includes the identifier of the second NAS session allocated by the terminal device for the second NAS session. Correspondingly, the access network device receives the first request message.
[0299] Before S401, a first NAS session is established between the terminal device and the first network element. Optionally, as shown in S400, the establishment of the first NAS session can be initiated through a registration process between the terminal device and the first network element, and the first network element can authenticate and authorize the terminal device to determine whether to allow the terminal device to establish the first NAS session.
[0300] S402. The access network device sends a first request message to the first network element. Correspondingly, the first network element receives the first request message.
[0301] Optionally, if the first request message further includes an identifier of the first NAS session, the access network device can determine that the destination network element of the first request message is the first network element based on the identifier of the first NAS session.
[0302] Optionally, if the first request message is sent through the radio bearer corresponding to the first NAS session, the access network device can determine that the destination network element of the first request message is the first network element based on the radio bearer used to transmit the first request message.
[0303] S403. The first network element determines to allow the establishment of a second NAS session and selects a second network element.
[0304] Optionally, the first network element can determine whether to allow the establishment of the second NAS session according to the subscription information of the terminal device.
[0305] Optionally, the first network element can select the second network element according to the first information. Exemplarily, the subscription information of the terminal device and / or the second NAS session establishment request can include the first information.
[0306] S404. The first network element sends a second request message to the second network element. The second request message requests the establishment of a second NAS session and includes an identifier of the second NAS session. Correspondingly, the second network element receives the second request message.
[0307] S405. The second network element obtains the subscription information related to the second NAS session, such as the QoS information corresponding to the second NAS session.
[0308] S406. The second network element sends a first response message to the first network element for the second request message.
[0309] Optionally, the first response message can indicate whether the second NAS sub-session is successfully established.
[0310] Optionally, if the first response message indicates that the establishment of the second NAS session fails, the first network element can send a response message indicating the failure of the establishment of the second NAS session to the terminal device, and the process ends.
[0311] S407. The second network element sends a third request message to the access network device. The third request message requests to establish a second NAS session, and includes the identifier of the second NAS session and the information of the second network element (such as the address information of the second network element). Correspondingly, the access network device receives the third request message. Among them, the third request message includes a second response message sent to the terminal device, and the second response message is used to indicate that the second NAS session is successfully established. The second response message includes the identifier of the second NAS session.
[0312] Optionally, as shown in S407a, the second network element may send the third request message to the access network device through the first network element. Exemplarily, the second network element may carry the third request message in the response message for the second NAS session establishment request in S406. After the first network element receives the response message, it forwards the third request message to the access network device.
[0313] Or, as shown in S407b, the second network element may directly send the third request message to the access network device. In this method, the second request message in S404 further includes the address information of the access network device and a first identifier (used to indicate the context of the terminal device in the access network device). The second network element sends the third request message to the access network device according to the address information of the access network device, and the third request message further includes the first identifier.
[0314] S408. The access network device sends the second response message to the terminal device. Correspondingly, the terminal device receives the second response message.
[0315] Optionally, the access network device may further send second information to the terminal device, and the second information is used to configure the radio bearer corresponding to the second NAS session. The terminal device determines the radio bearer corresponding to the second NAS session according to the second information.
[0316] S409. The access network device sends a third response message for the third request message to the second network element. Correspondingly, the second network element receives the third response message. Among them, the third response message includes the information of the access network device (such as address information), and a second identifier allocated by the access network device for the second NAS session. The second identifier is used to indicate the context of the second NAS session in the access network device.
[0317] After S409, the establishment of the second NAS session between the terminal device and the second network element is completed. The NAS messages can be directly transmitted between the terminal device and the second network element through the access network device without being forwarded by the first network element.
[0318] Exemplarily, in the uplink transmission scenario, after S409, the following steps may be included:
[0319] S410. The terminal device sends a first NAS message via a second NAS session. Correspondingly, the access network device receives the first NAS message.
[0320] When the terminal device sends the first NAS message, it may send the identifier of the second NAS session together, and / or the terminal device may send the first NAS message via the radio bearer corresponding to the second NAS session.
[0321] S411. The access network device determines that the first NAS message belongs to the second NAS session, and sends the first NAS message to the second network element according to the corresponding relationship saved between the second NAS session and the second network element (for example, the corresponding relationship between the identifier of the second NAS session and the address information of the second network element). Correspondingly, the second network element receives the first NAS message.
[0322] For the specific implementation of the access network device determining that the first NAS message belongs to the second NAS session, reference may be made to the above introduction of the access network device determining that the third NAS message belongs to the third NAS session, which will not be elaborated here.
[0323] Exemplarily, in the downlink transmission scenario, after S409, the following steps may be included:
[0324] S412. The second network element sends a second NAS message via the second NAS session. Correspondingly, the access network device receives the second NAS message.
[0325] When the second network element sends the second NAS message, it may send the identifier of the second NAS session together, and / or the second identifier.
[0326] S413. The access network device determines that the second NAS message belongs to the second NAS session, and sends the second NAS message to the terminal device. Correspondingly, the terminal device receives the second NAS message.
[0327] For the specific implementation of the access network device determining that the second NAS message belongs to the second NAS session and sending the second NAS message to the terminal device, reference may be made to the above introduction of the access network device determining that the fourth NAS message belongs to the third NAS session and sending the fourth NAS message to the terminal device, which will not be elaborated here.
[0328] In addition, the embodiment of the present application further provides another communication method. Based on this communication method, a security mode can be activated for the NAS session established between the terminal device and the core network element to protect the security of the NAS messages transmitted via the NAS session and prevent the NAS messages transmitted via the NAS messages from being tampered with. The following takes activating the security mode for the second NAS session as an example to introduce this communication method.
[0329] Figure 5Taking the terminal device and the second network element as the execution entities of this interaction illustration as an example to illustrate this method, but the present application does not limit the execution entities of this interaction illustration. For example, Figure 5 the second network element in [[ ]] can also be a module applied to the second network element, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the second network element; Figure 5 the terminal device in [[ ]] can also be a module applied to the terminal device, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the terminal device.
[0330] As Figure 5 shown, this communication method includes the following steps:
[0331] S501. The second network element sends first indication information to the terminal device. Correspondingly, the terminal device receives the first indication information, and the first indication information is used to instruct the terminal device to activate the security mode for the second NAS session. Among them, the security mode includes one or more of the following: encrypting the NAS messages transmitted through the second NAS session, or performing integrity protection on the NAS messages transmitted through the second NAS session.
[0332] S502. The terminal device activates (which can also be referred to as starting) the security mode for the second NAS session according to the first indication information.
[0333] The following is an expanded introduction to S501 - S502.
[0334] In S501, the second network element can send the first indication information to the terminal device during the process of establishing the second NAS session. Or, the second network element can send second indication information to the terminal device after the second NAS session is established.
[0335] Among them, for sending the first indication information to the terminal device, the second network element can send the first indication information to the terminal device through the first network element and the access network device. Or, the second network element can send the first indication information to the terminal device through the access network device.
[0336] For example, the second network element can carry the first indication information in the first response message sent to the first network element. After receiving the first response message, the first network element sends the first indication information therein to the terminal device.
[0337] Also for example, after the second NAS session is established, the second network element can send the first indication information to the terminal device through the second NAS session. Correspondingly, after receiving the first indication information, the access network device sends the first indication information to the terminal device.
[0338] Optionally, in order to transmit NAS messages in the security mode, the second network element may obtain the key of the second NAS session. The key of the second NAS session includes at least one of the following keys: the key used to encrypt the NAS messages transmitted through the second NAS session (it can be understood that this key can also be used to decrypt the NAS messages transmitted through the second NAS session), or the key used to perform integrity protection on the NAS messages transmitted through the second NAS session. If the second NAS session activates the security mode, the second network element may use the key of the second NAS session to perform corresponding processing on the NAS messages transmitted through the second NAS session.
[0339] For obtaining the key of the second NAS session, in a possible implementation, the second network element may generate the key of the second NAS session according to the root key of the second NAS session and a preset rule.
[0340] The embodiments of this application do not limit the specific implementation of the second network element for obtaining the root key of the second NAS session. For example, the second request message may include the root key of the second NAS session. Or, the subscription information of the terminal device may include the root key of the second NAS session.
[0341] Among them, if the second request message includes the root key of the second NAS session, the root key of the second NAS session included in the second request message may be deduced (or generated) by the first network element according to the root key of the first NAS session (or referred to as the root key of the first network element) and the identifier of the second NAS session. For example, assuming that the first network element is an AMF network element, the root key of the first NAS session may be Kamf or Kseaf. The specific process for the AMF network element to deduce the root key of the second NAS session according to the root key of the first NAS session may refer to the existing key deduction process. Or, the first network element may obtain the root key of the second NAS session from the authentication network element. For example, the authentication network element may be an authentication server function (AUSF) network element. The AUSF network element may generate the root key of the second NAS session and send it to the first network element.
[0342] Optionally, if the second network element obtains the key of the second NAS session, before sending the first indication information, the second network element may use the key of the second NAS session to perform corresponding processing on the first indication information, that is, perform at least one of the following: encryption or integrity protection. In this case, the terminal device may use the key of the second NAS session to verify the first indication information, which is specifically introduced in S502 and will not be elaborated here.
[0343] Optionally, the second network element may obtain the security capability information of the terminal device. The security capability information is used to indicate one or more of the following algorithms supported by the terminal device: an encryption algorithm (i.e., an algorithm for encrypting NAS messages) or an integrity protection algorithm (i.e., an algorithm for integrity protecting NAS messages). The second network element may determine the security algorithm corresponding to the second NAS session according to the security capability information of the terminal device. The security algorithm includes one or more of the following algorithms: an algorithm for encryption or an algorithm for integrity protection.
[0344] The embodiments of the present application do not limit the specific implementation of the second network element for obtaining the security capability information of the terminal device. For example, the second request message may include the security capability information, and / or the subscription information of the terminal device may include the security capability information.
[0345] In S502, optionally, in order to transmit NAS messages in the security mode, the terminal device may obtain the key of the second NAS session.
[0346] In a possible implementation, the terminal device may generate the key of the second NAS session according to the root key of the first NAS session, the identifier of the second NAS session, and a preset rule. The root key of the first NAS session may be generated locally by the terminal device.
[0347] Optionally, if the terminal device obtains the key of the second NAS session, and the second network element uses the key of the second NAS session to perform at least one of the following on the first indication information: encryption or integrity protection, after receiving the first indication information, the terminal device may use the key of the second NAS session to verify the first indication information. If the verification is passed, the terminal device activates the security mode. If the verification fails, the terminal device does not activate the security mode.
[0348] Optionally, after S502, the following steps may further be included:
[0349] The terminal device sends a response message to the second network element for the first indication information, and the response message is used to indicate that the terminal device has activated the security mode for the second NAS session.
[0350] It can be understood that S501 - S502 are introduced by taking the activation of the security mode for the second NAS session as an example. The method for activating the security mode for the NAS session provided by the embodiments of the present application can be applied not only to the second NAS session, but also can be adaptively applied to other NAS sessions, such as the first NAS session. The embodiments of the present application do not limit this. Exemplarily, if the security mode is activated for the first NAS session, the first network element may send indication information instructing the terminal device to activate the security mode for the first NAS session to the terminal device. The terminal device activates the security mode for the first NAS session according to this indication information. Among them, the first network element may send this indication information to the terminal device during the establishment process of the first NAS session or after the establishment of the first NAS session is completed. Specifically, reference can be made to the introduction of S501 - S502 above, and details will not be elaborated here.
[0351] In addition, the embodiments of the present application also provide another communication method. Based on this communication method, corresponding radio bearers can be configured for the QoS flows included in the NAS session established between the terminal device and the core network element, avoiding problems such as information congestion and increased latency that may be caused by different QoS flows included in the NAS session being transmitted through the same radio bearer. The following takes configuring the corresponding radio bearer for the QoS flows included in the second NAS session as an example to introduce this communication method.
[0352] Figure 6 In the example, the access network device, the terminal device, and the second network element are used as the execution entities of this interaction schematic to illustrate the method, but the present application does not limit the execution entities of this interaction schematic. For example, Figure 6 the second network element in can also be a module applied to the second network element, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the second network element; Figure 6 the access network device in can also be a module applied to the access network device, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the access network device; Figure 6 the terminal device in can also be a module applied to the terminal device, such as a chip, a chip system, or a processor, and can also be a logical node, a logical module, or software that can implement all or part of the functions of the terminal device.
[0353] As Figure 6 shown, this communication method includes the following steps:
[0354] S601. The second network element sends a fourth request message to the access network device. Correspondingly, the access network device receives the fourth request message. Among them, the fourth request message is used to request to configure the radio bearer corresponding to each QoS flow among one or more QoS flows included in the second NAS session.
[0355] Among them, the QoS flows included in the second NAS session refer to the QoS flows configured by the second network element for the second NAS session and to which the NAS messages transmitted through the second NAS session can be mapped.
[0356] In S601, the second network element may send a fourth request message to the access network device during the establishment process of the second NAS session. Exemplarily, the fourth request message may be carried in the third request message.
[0357] Alternatively, the second network element may also send a fourth request message to the access network device after the establishment of the second NAS session is completed.
[0358] In S601, the fourth request message may include the following information: the identification information of each QoS flow among one or more QoS flows included in the second NAS session, and the QoS parameters corresponding to each QoS flow, such as QoS level, 5QI, maximum bandwidth, and other information.
[0359] Among them, the one or more QoS flows included in the second NAS session may be all the QoS flows included in the second NAS session or may be some of the QoS flows included in the second NAS session. That is to say, the access network device may, based on the fourth request message, configure a corresponding radio bearer for each QoS flow among all the QoS flows included in the second NAS session, or may also configure a corresponding radio bearer for each QoS flow among some of the QoS flows included in the second NAS session.
[0360] Optionally, the fourth request message may further include a mapping rule for the uplink NAS message, where the mapping rule includes the correspondence between the uplink NAS message transmitted through the second NAS session and each QoS flow. In this case, after receiving the fourth request message, the access network device may send the mapping rule to the terminal device so that the terminal device can determine the QoS flow corresponding to the NAS message when transmitting NAS messages through the second NAS session subsequently.
[0361] S602. The access network device configures a corresponding radio bearer for each QoS flow among one or more QoS flows included in the second NAS session according to the fourth request message.
[0362] Among them, one or more QoS flows included in the second NAS session and the configured radio bearers may have a one-to-one correspondence relationship, that is, among the one or more QoS flows included in the second NAS session, different QoS flows correspond to different radio bearers. Alternatively, it may also be a many-to-one relationship, that is, multiple QoS flows are mapped to one radio bearer. For example, the access network device maps all the QoS flows among the one or more QoS flows included in the second NAS session to one radio bearer. Another example is that the access network device maps some of the QoS flows among the one or more QoS flows included in the second NAS session to one radio bearer, and maps other QoS flows to other radio bearers.
[0363] S603. The access network device sends third information to the terminal device, and the third information is used to configure the radio bearer corresponding to each QoS flow among the one or more QoS flows included in the second NAS session.
[0364] Correspondingly, after receiving the third information, the terminal device may determine the correspondence relationship between each QoS flow among the one or more QoS flows included in the second NAS session and the configured radio bearer according to the third information. Subsequently, the terminal device may send an uplink NAS message through the radio bearer corresponding to the QoS flow of the uplink NAS message according to the correspondence relationship between the QoS flow and the radio bearer. Alternatively, the terminal device may determine the QoS flow corresponding to the downlink NAS message according to the radio bearer for receiving the downlink NAS message.
[0365] Optionally, after S603, in the uplink transmission scenario, that is, when the terminal device sends a NAS message through the second NAS session, the QoS flow corresponding to the NAS message may be indicated.
[0366] Exemplarily, after S603, the following steps may be included:
[0367] The terminal device sends a first NAS message and identification information of a first QoS flow corresponding to the first NAS message through the second NAS session. Correspondingly, the access network device receives the first NAS message and the identification information of the first QoS flow. The first QoS flow is a certain QoS flow among the one or more QoS flows included in the second NAS session. Further, the access network device sends the first NAS message and the identification information of the first QoS flow to the second network element.
[0368] Optionally, after S603, in the uplink transmission scenario, when the terminal device sends a NAS message through the second NAS session, it may determine the radio bearer corresponding to the QoS flow corresponding to the NAS message, and thus send the NAS message through the radio bearer corresponding to the QoS flow. After receiving the NAS message, the access network device may determine the QoS flow corresponding to the NAS message according to the radio bearer used to transmit the NAS message, and thus may indicate the QoS flow corresponding to the NAS message when sending the NAS message to the second network element.
[0369] Exemplarily, after S603, the following steps may be included:
[0370] The terminal device sends a first NAS message through the second NAS session. Correspondingly, the access network device receives the first NAS message. The access network device determines a first QoS flow corresponding to the first NAS message according to the radio bearer used to transmit the first NAS message. The access network device sends the first NAS message and the identification information of the first QoS flow to the second network element.
[0371] Optionally, after S603, in the downlink transmission scenario, that is, when the second network element sends a NAS message through the second NAS session, it may indicate the QoS flow corresponding to the NAS message. After receiving the NAS message, the access network device may determine the QoS flow corresponding to the NAS message and determine the radio bearer corresponding to the QoS flow, and thus send the NAS message to the terminal device through the radio bearer corresponding to the QoS flow.
[0372] Exemplarily, after S603, the following steps may be included:
[0373] The second network element sends a second NAS message and the identification information of the second QoS flow corresponding to the second NAS message through the second NAS session. Correspondingly, the access network device receives the second NAS message and the identification information of the second QoS flow. The second QoS flow is a certain QoS flow among one or more QoS flows included in the second NAS session. The access network device determines the radio bearer corresponding to the second QoS flow according to the identification information of the second QoS flow. Further, the access network device sends the second NAS message to the terminal device through the radio bearer corresponding to the second QoS flow.
[0374] Wherein, in the uplink transmission scenario or the downlink transmission scenario, if the terminal device or the second network element sends the NAS message and the identification information of the QoS flow corresponding to the NAS message together, the identification information of the QoS flow may be included in the non-encrypted header of the NAS message, or may be sent in a message together with the NAS message.
[0375] It can be understood that S601 - S603 are introduced by taking the configuration of radio bearers for each QoS flow included in the second NAS session as an example. The method for configuring radio bearers for each QoS flow included in the NAS session provided by the embodiments of the present application can be applied not only to the second NAS session, but also can be adaptively applied to other NAS sessions, such as the first NAS session. The embodiments of the present application do not limit this. Exemplarily, if radio bearers are configured for each QoS flow included in the first NAS session, the first network element may send a request message to the access network device to request the configuration of radio bearers corresponding to each QoS flow included in the first NAS session. The access network device configures radio bearers corresponding to each QoS flow included in the first NAS session according to this request message. Among them, the first network element may send this request message during the establishment process of the first NAS session or after the establishment of the first NAS session is completed. Specifically, reference can be made to the above introduction of S601 - S603, and details will not be elaborated here.
[0376] Optionally, in the above embodiments, as Figure 3 shown in the embodiments, as Figure 5 shown in the embodiments and as Figure 6 shown in the embodiments can be applied independently or in combination. The embodiments of the present application do not limit this.
[0377] It can be understood that the above Figures 3 - 6 shown process is only a logically schematic process provided for the convenience of understanding the embodiments of the present application, and does not represent the actual timing of the embodiments of the present application. The embodiments of the present application do not limit Figures 3 - 6 the timing between different steps in the shown process.
[0378] The above mainly introduced the solution provided by the embodiments of the present application from the perspective of the interaction between each network element. Correspondingly, the embodiments of the present application also provide a communication device, which is used to implement the above various methods. The communication device may be the first network element, the second network element, an access network device or a terminal device in the above method embodiments, or a device including the above first network element, second network element, access network device or terminal device, or a component that can be used for the above first network element, second network element, access network device or terminal device. It can be understood that, in order to implement the above functions, the communication device includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, combining the units and algorithm steps of each example described in the embodiments disclosed in this article, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0379] The embodiments of the present application can divide the functional modules of the communication device according to the above method embodiments. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. It should be understood that the division of modules in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation.
[0380] Figure 7 Fig. shows a schematic structural diagram of a communication device 700. The communication device 700 includes a processing module 701 and a transceiver module 702. Optionally, the communication device 700 may further include a storage module 703. The transceiver module 702, also referred to as a transceiver unit, is used to implement the transceiver function. For example, it may be a transceiver circuit, a transceiver, a transceiver or a communication interface.
[0381] Taking the communication device 700 as the terminal device in the above embodiment as an example, in a possible implementation manner:
[0382] A transceiver module 702 is configured to send a first request message to a first network element via a first NAS session. The first NAS session is used to transmit NAS messages between the terminal device and the first network element. The first request message is used to request a service; alternatively, the first request message is used to request a service and is further used to request the establishment of a second NAS session; or the first request message is used to request the establishment of a second NAS session. The transceiver module 702 is further configured to receive an identifier of the second NAS session, where the second NAS session is used to transmit NAS messages between the terminal device and a second network element. The transceiver module 702 is further configured to send a first NAS message to the second network element via the second NAS session according to the identifier of the second NAS session.
[0383] Optionally, the transceiver module 702 is further configured to receive first indication information for indicating that the terminal device activates a security mode for the second NAS session. The security mode includes one or more of the following: encrypting NAS messages transmitted via the second NAS session, or performing integrity protection on NAS messages transmitted via the second NAS session. The processing module 701 is configured to activate the security mode for the second NAS session according to the first indication information.
[0384] Optionally, the processing module 701 is further configured to generate a key for the second NAS session according to a root key of the first NAS session and the identifier of the second NAS session. The key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted via the second NAS session, or a key for performing integrity protection on NAS messages transmitted via the second NAS session.
[0385] Optionally, the processing module 701 activates the security mode for the second NAS session according to the first indication information, including: verifying the first indication information by using the key for the second NAS session; where the key for the second NAS session includes at least one of the following keys: a key for encrypting NAS messages transmitted via the second NAS session, or a key for performing integrity protection on NAS messages transmitted via the second NAS session. In the case where the verification is passed, the security mode is activated.
[0386] Optionally, the transceiver module 702 sends the first request message to the first network element via the first NAS session, including: sending an RRC message to an access network device, where the RRC message includes the first request message. The RRC message is sent via a radio bearer corresponding to the first NAS session, and / or the RRC message includes an identifier of the first NAS session. The radio bearer corresponding to the first NAS session or the identifier of the first NAS session is used for the access network device to determine to send the first request message to the first network element.
[0387] Optionally, the transceiver module 702 sends a first NAS message to a second network element through a second NAS session, including: sending an RRC message to an access network device, where the RRC message includes the first NAS message. The RRC message is sent through a radio bearer corresponding to the second NAS session, and / or the RRC message includes an identifier of the second NAS session. The radio bearer corresponding to the second NAS session or the identifier of the second NAS session is used for the access network device to determine to send the first NAS message to the second network element.
[0388] Optionally, the transceiver module 702 is further configured to receive second information from the access network device, where the second information is used to configure one or more radio bearers corresponding to the second NAS session. The transceiver module 702 sends a first NAS message to a second network element through a second NAS session, including: sending the first NAS message to the second network element through the radio bearer corresponding to the second NAS session.
[0389] Optionally, the second NAS session includes one or more QoS flows. The transceiver module 702 sends a first NAS message to a second network element through a second NAS session, including: sending the first NAS message to the second network element through the radio bearer corresponding to the first QoS flow. The first NAS message corresponds to the first QoS flow, and the one or more QoS flows include the first QoS flow.
[0390] Optionally, the transceiver module 702 is further configured to receive a mapping rule, where the mapping rule includes the correspondence between the first NAS message and the first QoS flow. The transceiver module 702 is further configured to receive third information from the access network device, where the third information is used to configure the radio bearer corresponding to the first QoS flow.
[0391] Taking the communication device 700 as the first network element in the above embodiment as an example, in a possible implementation:
[0392] The transceiver module 702 is configured to receive a first request message from a terminal device through a first NAS session, where the first NAS session is a NAS session established between the terminal device and the first network element and is used to transmit NAS messages between the terminal device and the first network element. The first request message is used to request a service; or, the first request message is used to request a service and is further used to request the establishment of a second NAS session; or, the first request message is used to request the establishment of a second NAS session. The processing module 701 is configured to trigger the establishment of the second NAS session, where the second NAS session is used to transmit NAS messages between the terminal device and the second network element.
[0393] Optionally, the processing module 701 is further configured to obtain an identifier of the second NAS session. The transceiver module 702 is further configured to send the identifier of the second NAS session to the second network element.
[0394] Optionally, the processing module 701 is further configured to determine whether to allow the establishment of a second NAS session according to the subscription information of the terminal device. The processing module 701 triggers the establishment of the second NAS session, including: triggering the establishment of the second NAS session when the first network element determines that the establishment of the second NAS session is allowed.
[0395] Optionally, the processing module 701 triggers the establishment of the second NAS session, including: triggering the establishment of the second NAS session when the subscription information of the terminal device indicates to create a second NAS session for the service.
[0396] Optionally, the transceiver module 702 is further configured to send a fifth request message to the second network element. The transceiver module 702 is further configured to receive fourth information from the second network element, where the fourth information is used to indicate the establishment of the second NAS session. The processing module 701 triggers the establishment of the second NAS session, including: triggering the establishment of the second NAS session according to the fourth information.
[0397] Optionally, the processing module 701 is further configured to select a second network element from the network elements providing services according to the first information; where the first request message includes the first information, or the subscription information of the terminal device includes the first information.
[0398] Optionally, the processing module 701 triggers the establishment of the second NAS session, including: sending a second request message to the second network element through the transceiver module 702, where the second request message is used to request the establishment of the second NAS session.
[0399] Optionally, the processing module 701 is further configured to generate a root key for the second NAS session according to the root key of the first NAS session and the identifier of the second NAS session.
[0400] Optionally, the transceiver module 702 is further configured to receive first indication information from the second network element, where the first indication information is used to indicate that the terminal device activates a security mode for the second NAS session. Wherein, the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session. The first network element sends the first indication information to the terminal device.
[0401] Optionally, the transceiver module 702 is further configured to send a third request message to the access network device, where the third request message is used to request the establishment of the second NAS session, and the third request message includes the identifier of the second NAS session.
[0402] Optionally, the transceiver module 702 is further configured to receive second indication information from a second network element, where the second indication information indicates to establish a second NAS session. The transceiver module 702 sends a third request message to the access network device, including: sending the third request message to the access network device according to the second indication information.
[0403] Optionally, the transceiver module 702 is further configured to send the identifier of the second NAS session to the terminal device.
[0404] Optionally, the transceiver module 702 is further configured to receive a first identifier from the access network device.
[0405] Taking the communication device 700 as the second network element in the foregoing embodiment as an example, in a possible implementation:
[0406] The transceiver module 702 is configured to receive a second request message from a first network element, where the second request message is used to request the establishment of a second NAS session, and the second NAS session is used for transmitting NAS messages between the terminal device and the second network element. Moreover, there is a first NAS session for transmitting NAS messages between the first network element and the terminal device. The transceiver module 702 is further configured to send a first response message to the first network element for the second request message.
[0407] Optionally, the transceiver module 702 is further configured to send a third request message to the access network device, where the third request message is used to request the access network device to establish a second NAS session, and the third request message includes the address information of the second network element and the identifier of the second NAS session.
[0408] Optionally, when the transceiver module 702 sends a third request message to the access network device, it includes: sending the third request message to the access network device according to the address information of the access network device and the first identifier.
[0409] Optionally, the transceiver module 702 is further configured to send a second response message to the terminal device through the third request message, where the second response message is used to indicate that the establishment of the second NAS session is successful, and the second response message includes the identifier of the second NAS session.
[0410] Optionally, the transceiver module 702 is further configured to receive a fifth request message from the first network element, where the fifth request message is used to request a service. The transceiver module 702 is further configured to send fourth information to the first network element according to the fifth request message, where the fourth information is used to indicate the establishment of a second NAS session.
[0411] Optionally, the transceiver module 702 is further configured to receive a third response message from the access network device, where the third response message includes the address information of the access network device and a second identifier; the second identifier is used to indicate the context of the second NAS session in the access network device.
[0412] Optionally, the transceiver module 702 is further configured to send first indication information to the first network element, where the first indication information is used to indicate that the terminal device activates a security mode for the second NAS session, and the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.
[0413] Optionally, the transceiver module 702 is further configured to send first indication information to the terminal device through the second NAS session, where the first indication information is used to indicate that the terminal device activates a security mode for the second NAS session; the security mode includes one or more of the following: encrypting NAS messages transmitted through the second NAS session, or performing integrity protection on NAS messages transmitted through the second NAS session.
[0414] Optionally, the processing module 701 is further configured to obtain a key for the second NAS session, where the key for the second NAS session includes at least one of the following keys: a key for encryption, or a key for integrity protection. The processing module 701 is further configured to use the key for the second NAS session to perform at least one of the following on the first indication information: encryption or integrity protection. The transceiver module 702 is further configured to send the first indication information to the terminal device.
[0415] Optionally, the processing module 701 obtaining the key for the second NAS session includes: generating the key for the second NAS session according to the root key of the second NAS session, where the second request message includes the root key of the second NAS session, or the subscription information of the terminal device includes the root key of the second NAS session.
[0416] Optionally, the processing module 701 is further configured to obtain the security capability information of the terminal device, where the security capability information is used to indicate one or more of the following algorithms supported by the terminal device: an encryption algorithm, or an integrity protection algorithm. The processing module 701 is further configured to determine the security algorithm corresponding to the second NAS session according to the security capability information of the terminal device; where the security algorithm includes one or more of the following algorithms: an algorithm for encryption, or an algorithm for integrity protection.
[0417] Optionally, the second NAS session includes one or more QoS flows, and the transceiver module 702 is further configured to send a mapping rule to the terminal device, where the mapping rule includes the correspondence between the NAS messages transmitted through the second NAS session and each of the one or more QoS flows.
[0418] Optionally, the second NAS session includes one or more QoS flows, and the transceiver module 702 is further configured to send a fourth request message to the access network device, where the fourth request message is used to request the configuration of a radio bearer corresponding to each of the one or more QoS flows.
[0419] Optionally, the transceiver module 702 is further configured to send a second NAS message and identification information of a second QoS flow corresponding to the second NAS message through a second NAS session. The identification information of the second QoS flow is used for the access network device to determine and send the second NAS message to the terminal device through the second NAS session.
[0420] Taking the communication device 700 as the access network device in the above embodiment as an example, in a possible implementation:
[0421] The transceiver module 702 is configured to receive a third NAS message from the terminal device. The processing module 701 is configured to determine the destination network element of the third NAS message according to the third NAS session to which the third NAS message belongs. The transceiver module 702 is further configured to send the third NAS message to the destination network element.
[0422] Optionally, the transceiver module 702 receiving the third NAS message from the terminal device includes: receiving the third NAS message from the terminal device and the identification of the third NAS session to which the third NAS message belongs. The processing module 701 determining the destination network element of the third NAS message according to the third NAS session to which the third NAS message belongs includes: determining the destination network element of the third NAS message according to the identification of the third NAS session and a first correspondence relationship; where the first correspondence relationship includes the correspondence relationship between the identification of the third NAS session and the destination network element of the third NAS message.
[0423] Optionally, the processing module 701 determining the destination network element of the third NAS message according to the third NAS session to which the third NAS message belongs includes: determining the destination network element of the third NAS message according to the radio bearer for transmitting the third NAS message and a second correspondence relationship; where the second correspondence relationship includes the correspondence relationship between the radio bearer for transmitting the third NAS message, the third NAS session to which the third NAS message belongs, and the destination network element of the third NAS message.
[0424] Optionally, the transceiver module 702 is further configured to receive a fourth NAS message from a third network element and the identification of the third NAS session to which the fourth NAS message belongs. The processing module 701 is further configured to determine the third NAS session to which the fourth NAS message belongs according to the identification of the third NAS session.
[0425] Optionally, the transceiver module 702 is further configured to receive a fourth NAS message and a third identifier from a third network element, where the third identifier is used to indicate the context of the third NAS session to which the fourth NAS message belongs in the access network device. The processing module 701 is further configured to determine the third NAS session to which the fourth NAS message belongs according to the third identifier.
[0426] Optionally, the transceiver module 702 is further configured to send a fourth NAS message and an identifier of a third NAS session to the terminal device, and / or send the fourth NAS message to the terminal device via a radio bearer corresponding to the third NAS session.
[0427] Optionally, the transceiver module 702 is further configured to receive a third request message for requesting the establishment of a third NAS session. The third request message includes an identifier of the third NAS session and address information of a third network element. The third NAS session is used to transmit NAS messages between the terminal device and the third network element. The transceiver module 702 is further configured to send a third response message to the third network element according to the address information of the third network element. The third response message includes address information of the access network device and a third identifier, and the third identifier is used to indicate the context of the third NAS session in the access network device.
[0428] Optionally, the transceiver module 702 is further configured to receive a fourth request message from the third network element. The fourth request message is used to request the configuration of radio bearers corresponding to each of one or more QoS flows included in the third NAS session. The processing module 701 is further configured to configure corresponding radio bearers for each QoS flow according to the fourth request message.
[0429] Optionally, the transceiver module 702 is further configured to receive a fourth NAS message from the third network element and identification information of a QoS flow corresponding to the fourth NAS message. One or more QoS flows included in the third NAS session include the QoS flow corresponding to the fourth NAS message. The processing module 701 is further configured to determine a radio bearer corresponding to the fourth NAS message according to the identification information of the QoS flow corresponding to the fourth NAS message. The transceiver module 702 is further configured to send the fourth NAS message to the terminal device via the radio bearer.
[0430] Taking the communication device 700 as the access network device in the foregoing embodiment as an example, in another possible implementation:
[0431] The transceiver module 702 is configured to receive a fourth request message from a second network element. The fourth request message is used to request the configuration of radio bearers corresponding to each of one or more QoS flows included in a second NAS session. The second NAS session is used to transmit NAS messages between the terminal device and the second network element. The processing module 701 is configured to configure corresponding radio bearers for each QoS flow according to the fourth request message. The transceiver module 702 is further configured to send third information to the terminal device, and the third information is used to configure radio bearers corresponding to each QoS flow.
[0432] Optionally, the fourth request message further includes a mapping rule, where the mapping rule includes the correspondence between the NAS messages transmitted through the second NAS session and each QoS flow. The transceiver module 702 is further configured to send the mapping rule to the terminal device.
[0433] Optionally, the transceiver module 702 is further configured to receive a first NAS message from the terminal device. The processing module 701 is further configured to determine, according to the radio bearer used for transmitting the first NAS message, that the first NAS message corresponds to a first QoS flow, and the second NAS session includes the first QoS flow. The transceiver module 702 is further configured to send the first NAS message and the identification information of the first QoS flow to the second network element.
[0434] Optionally, the transceiver module 702 is further configured to receive a first NAS message from the terminal device and the identification information of the first QoS flow corresponding to the first NAS message, where the second NAS session includes the first QoS flow. Optionally, the transceiver module 702 is further configured to send the first NAS message and the identification information of the first QoS flow to the second network element.
[0435] Optionally, the transceiver module 702 is further configured to receive a second NAS message from the second network element and the identification information of the second QoS flow corresponding to the second NAS message. The processing module 701 is further configured to determine the radio bearer corresponding to the second QoS flow according to the identification information of the second QoS flow. The transceiver module 702 is further configured to send the second NAS message to the terminal device through the radio bearer corresponding to the second QoS flow.
[0436] All relevant content of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.
[0437] Optionally, Figure 7 the modules in can also be referred to as units. For example, the processing module can be referred to as a processing unit, and the transceiver module can be referred to as a transceiver unit. Additionally, in Figure 7 the embodiments shown, the names of each unit may not be the names shown in the figure. For example, the transceiver module can also be referred to as a communication module or a communication unit.
[0438] Figure 7If each unit in [the application] is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The storage media for storing the computer software product include: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0439] In the embodiments of the present application, the communication device 700 is presented in the form of dividing each functional module in an integrated manner. Here, a "module" can refer to an application-specific integrated circuit (ASIC), a circuit, a processor and a memory that execute one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.
[0440] In a simple embodiment, those skilled in the art can conceive that the communication device 700 can adopt Figure 8 the form of the communication device shown.
[0441] As Figure 8 shown, the communication device 800 includes one or more processors 801, a communication line 802, and at least one communication interface ( only exemplary in [the description] to include the communication interface 804 and one processor 801 as an example for illustration), and optionally may further include a memory 803.
[0442] The processor 801 can be a general-purpose central processing unit (CPU), a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the programs of the solution of the present application.
[0443] The communication line 802 can include a path for connecting different components.
[0444] The communication interface 804, which can be a transceiver module, is used to communicate with other devices or communication networks, such as Ethernet, RAN, terminals, wireless local area networks (WLAN), etc. For example, the transceiver module can be a device such as a transceiver or a transceiver unit. Optionally, the communication interface 804 can also be a transceiver circuit or an input / output interface located within the processor 801 for realizing signal input and signal output of the processor.
[0445] The memory 803 can be a device with a storage function. For example, it can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processor through the communication line 802. The memory can also be integrated with the processor.
[0446] Among them, the memory 803 is used to store computer-executable instructions for executing the solution of this application, and is controlled by the processor 801 for execution. The processor 801 is used to execute the computer-executable instructions stored in the memory 803, thereby implementing the communication method provided in the embodiments of this application.
[0447] Alternatively, optionally, in the embodiments of this application, it can also be that the processor 801 executes the functions related to processing in the communication method provided in the following embodiments of this application, and the communication interface 804 is responsible for communicating with other devices or communication networks. The embodiments of this application do not make specific limitations in this regard.
[0448] Optionally, the computer-executable instructions in the embodiments of this application can also be referred to as application code. The embodiments of this application do not make specific limitations in this regard.
[0449] In a specific implementation, as an embodiment, the processor 801 can include one or more CPUs, such as CPU0 and CPU1 in
[0450] In a specific implementation, as an example, the communication device 800 may include multiple processors, such as the processor 801 and the processor 807 in []. Each of these processors may be a single-core processor or a multi-core processor. The processors here may include, but are not limited to, at least one of the following: CPU, microprocessor, digital signal processing (DSP) processor, microcontroller unit (MCU), or artificial intelligence processor, etc., which are various computing devices that run software, and each computing device may include one or more cores for executing software instructions to perform operations or processing.
[0451] In a specific implementation, as an example, the communication device 800 may further include an output device 805 and an input device 806. The output device 805 communicates with the processor 801 and can display information in various ways. For example, the output device 805 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device 806 communicates with the processor 801 and can receive user input in various ways. For example, the input device 806 may be a mouse, a keyboard, a touch screen device, or a sensing device, etc.
[0452] The above-mentioned communication device 800 may sometimes also be referred to as a communication equipment, which may be a general device or a dedicated device. For example, the communication device 800 may be various network elements, access network devices, or devices with a similar structure in []. The embodiments of the present application do not limit the type of the communication device 800.
[0453] In addition, the shown composition structure in [] does not constitute a limitation on the communication device. Except for the shown components, the communication device 800 may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0454] Optionally, the functions / implementation processes of the transceiver module 702 and the processing module 701 in [] may be implemented by the processor 801 in the communication device 800 shown in invoking computer execution instructions stored in the memory 803. Or, The function / implementation process of the processing module 701 in can be implemented by the processor 801 in the communication device 800 shown in calling the computer-executable instructions stored in the memory 803. The function / implementation process of the transceiver module 702 in can be implemented by the communication interface 804 in the communication device 800 shown in.
[0455] It should be understood that one or more of the above modules or units can be implemented by software, hardware, or a combination of both. When any of the above modules or units is implemented by software, the software exists in the form of computer program instructions and is stored in the memory. The processor can be used to execute the program instructions and implement the above method flow. The processor can be built into the SoC or ASIC, or can be an independent semiconductor chip. In addition to the core for executing software instructions for arithmetic or processing in the processor, it may further include necessary hardware accelerators, such as FPGA, programmable logic device (PLD), or logic circuits for implementing dedicated logic operations.
[0456] When any of the above modules or units is implemented by hardware, the hardware can be any one or any combination of CPU, microprocessor, DSP chip, MCU, artificial intelligence processor, ASIC, SoC, FPGA, PLD, dedicated digital circuit, hardware accelerator, or non-integrated discrete device, which can run the necessary software or execute the above method flow without relying on software.
[0457] Optionally, an embodiment of the present application further provides a communication device (for example, the communication device can be a chip or a chip system), the communication device includes a processor for implementing the method in any of the above method embodiments. In a possible design, the communication device further includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the communication device to execute the method in any of the above method embodiments. Of course, the memory may not be in the communication device. When the communication device is a chip system, it can be composed of chips or can include chips and other discrete devices. The embodiment of the present application does not make specific limitations in this regard.
[0458] Optionally, an embodiment of the present application further provides a computer-readable storage medium, in which computer programs or instructions are stored. When it runs on a communication device, the communication device can execute the method described in any of the above method embodiments or any of its implementation manners.
[0459] Optionally, an embodiment of the present application further provides a communication system, which includes a plurality of devices described in the foregoing method embodiment, such as a first network element, a second network element, an access network device, and a terminal device.
[0460] In the above embodiment, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more media integrated therein. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state drive (SSD)).
[0461] Although the present application has been described in conjunction with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other changes of the disclosed embodiments by viewing the drawings, the disclosure content, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit can implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0462] Although the present application has been described in connection with specific features and their embodiments, it will be apparent that various modifications and combinations can be made thereto without departing from the scope of the present application. Accordingly, the specification and drawings are merely exemplary illustrations of the present application as defined by the appended claims and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.
Claims
1. A communication method, characterized in that, The method includes: The terminal device sends a first request message to a first network element through a first non-access stratum session. The first request message is used to request a service provided by a second network element. The first non-access stratum session is used to transmit non-access stratum messages between the terminal device and the first network element. The terminal device receives an identifier of a second non-access stratum session. The second non-access stratum session is used to transmit non-access stratum messages between the terminal device and the second network element. The terminal device sends a first non-access stratum message to the second network element through the second non-access stratum session according to the identifier of the second non-access stratum session.
2. The method according to claim 1, wherein The first request message is further used to request the establishment of a non-access stratum session between the terminal device and the second network element.
3. The method according to claim 2, characterized in that, The first request message includes the identifier of the second non-access stratum session.
4. The method according to any one of claims 1 to 3, characterized in that The method further includes: The terminal device receives first indication information, which is used to indicate that the terminal device activates a security mode for the second non-access stratum session. The security mode includes one or more of the following: encrypting non-access stratum messages transmitted through the second non-access stratum session, or performing integrity protection on non-access stratum messages transmitted through the second non-access stratum session. The terminal device activates the security mode for the second non-access stratum session according to the first indication information.
5. The method according to claim 4, wherein The method further includes: The terminal device generates a key for the second non-access stratum session according to the root key of the first non-access stratum session and the identifier of the second non-access stratum session. The key for the second non-access stratum session includes at least one of the following keys: a key for the encryption, or a key for the integrity protection.
6. The method according to any one of claims 1-5, characterized in that, The terminal device sending a first non-access stratum message to the second network element through the second non-access stratum session includes: The terminal device sends a first message to an access network device. The first message includes the first non-access stratum message. The first message is sent through a radio bearer corresponding to the second non-access stratum session, and / or the first message includes the identifier of the second non-access stratum session. The radio bearer corresponding to the second non-access stratum session or the identifier of the second non-access stratum session is used for the access network device to determine to send the first non-access stratum message to the second network element.
7. A communication method, characterized in that, The method includes: A first network element receives a first request message from a terminal device through a first non-access stratum session. The first request message is used to request a service provided by a second network element. The first non-access stratum session is used to transmit non-access stratum messages between the terminal device and the first network element. The first network element triggers the establishment of a second non-access stratum session, which is used to transmit non-access stratum messages between the terminal device and the second network element.
8. The method according to claim 7, wherein The method further includes: The first network element sends the identifier of the second non-access stratum session to the second network element.
9. The method according to claim 7 or 8, characterized in that The first request message is further used to request the establishment of a non-access stratum session between the terminal device and the second network element.
10. The method according to claim 9, wherein The first network element triggers the establishment of a second non-access stratum session, including: When the subscription information of the terminal device indicates that the establishment of a non-access stratum session between the terminal device and the second network element is allowed, the first network element triggers the establishment of the second non-access stratum session.
11. The method according to claim 7, 8 or 10, characterized in that, The method further includes: The first network element sends a fifth request message to the second network element, and the fifth request message is used to request the service; The first network element receives fourth information from the second network element, and the fourth information is used to indicate the establishment of the second non-access stratum session; The first network element triggers the establishment of a second non-access stratum session, including: The first network element triggers the establishment of the second non-access stratum session according to the fourth information.
12. The method according to any one of claims 7-11, characterized in that, The first network element triggers the establishment of a second non-access stratum session, including: The first network element sends a second request message to the second network element, and the second request message is used to request the establishment of the second non-access stratum session.
13. The method according to claim 12, wherein The second request message includes the root key of the second non-access stratum session, and the root key of the second non-access stratum session is used to generate the key of the second non-access stratum session. The key of the second non-access stratum session includes at least one of the following keys: a key for encrypting non-access stratum messages transmitted through the second non-access stratum session, or a key for integrity protecting non-access stratum messages transmitted through the second non-access stratum session.
14. The method according to claim 13, wherein The method further includes: The first network element generates the root key of the second non-access stratum session according to the root key of the first non-access stratum session and the identifier of the second non-access stratum session.
15. The method according to any one of claims 12-14, wherein The second request message further includes the security capability information of the terminal device. The security capability information is used to indicate one or more encryption algorithms supported by the terminal device, and / or one or more integrity protection algorithms supported by the terminal device. The security capability information is used to determine the security algorithm corresponding to the second non-access stratum session. The security algorithm includes at least one of the following algorithms: an encryption algorithm for encrypting non-access stratum messages transmitted through the second non-access stratum session, or an integrity protection algorithm for integrity protecting non-access stratum messages transmitted through the second non-access stratum session.
16. The method according to any one of claims 7 - 15, characterized in that, The method further includes: The first network element sends a third request message to the access network device, and the third request message is used to request the establishment of the second non-access stratum session. The third request message includes the identifier of the second non-access stratum session.
17. The method according to claim 16, wherein The method further includes: The first network element receives second indication information from the second network element, and the second indication information indicates the establishment of the second non-access stratum session; The first network element sends a third request message to the access network device, including: The first network element sends the third request message to the access network device according to the second indication information.
18. The method according to any one of claims 7-17, characterized in that, The method further includes: The first network element sends the identifier of the second non-access stratum session to the terminal device.
19. A communication method, characterized in that, The method includes: The second network element receives a second request message from the first network element, where the second request message is used to request the establishment of a second non-access stratum session; the second non-access stratum session is used to transmit non-access stratum messages between the terminal device and the second network element; there is a first non-access stratum session for transmitting non-access stratum messages between the first network element and the terminal device. The second network element sends a first response message to the first network element for the second request message.
20. The method according to claim 19, wherein The first response message includes a third request message, where the third request message is used to request an access network device to establish the second non-access stratum session, and the third request message includes the address information of the second network element and the identifier of the second non-access stratum session.
21. The method according to claim 19, wherein The method further includes: The first response message includes second indication information, where the second indication information indicates that the access network device establishes the second non-access stratum session, and the second indication information is used to trigger the first network element to send a third request message to the access network device, and the third request message is used to request the establishment of the second non-access stratum session.
22. The method according to any one of claims 19 - 21, characterized in that, Before the second network element receives the second request message from the first network element, the method further includes: The second network element receives a fifth request message from the first network element, where the fifth request message is used to request a service provided by the second network element. The second network element sends fourth information to the first network element according to the fifth request message, where the fourth information is used to indicate the establishment of the second non-access stratum session.
23. The method according to any one of claims 19-22, characterized in that, The method further includes: The second network element sends first indication information to the first network element, where the first indication information is used to indicate that the terminal device activates a security mode for the second non-access stratum session; the security mode includes one or more of the following: encrypting non-access stratum messages transmitted through the second non-access stratum session, or performing integrity protection on non-access stratum messages transmitted through the second non-access stratum session.
24. The method according to any one of claims 19-22, characterized in that, The method further includes: The second network element sends first indication information to the terminal device through the second non-access stratum session, where the first indication information is used to indicate that the terminal device activates a security mode for the second non-access stratum session; the security mode includes one or more of the following: encrypting non-access stratum messages transmitted through the second non-access stratum session, or performing integrity protection on non-access stratum messages transmitted through the second non-access stratum session.
25. The method according to claim 23 or 24, characterized in that, The method further includes: The second network element obtains security capability information of the terminal device, where the security capability information is used to indicate one or more encryption algorithms supported by the terminal device, and / or one or more integrity protection algorithms supported by the terminal device. The second network element determines a security algorithm corresponding to the second non-access stratum session according to the security capability information of the terminal device; where the security algorithm includes one or more of the following algorithms: an encryption algorithm for the encryption, or an integrity protection algorithm for the integrity protection.
26. A communication method, characterized in that, The method further includes: The access network device receives a third non-access stratum message from the terminal device. The access network device determines that the third non-access stratum message belongs to a third non-access stratum session, where the third non-access stratum session is a non-access stratum session between the terminal device and a third network element; The access network device sends the third non-access stratum message to the third network element.
27. The method according to claim 26, wherein The access network device receives a third non-access stratum message from the terminal device, including: The access network device receives the third non-access stratum message and the identifier of the third non-access stratum session from the terminal device; The access network device determines that the third non-access stratum message belongs to a third non-access stratum session, including: The access network device determines that the third non-access stratum message belongs to the third non-access stratum session according to the identifier of the third non-access stratum session.
28. The method according to claim 26, wherein The access network device determines that the third non-access stratum message belongs to a third non-access stratum session, including: The access network device determines that the third non-access stratum message belongs to the third non-access stratum session according to the radio bearer used to transmit the third non-access stratum message.
29. The method according to any one of claims 26-28, characterized in that, The method further includes: The access network device receives a fourth non-access stratum message from the third network element; The access network device determines that the fourth non-access stratum message belongs to the third non-access stratum session; The access network device sends the fourth non-access stratum message and the identifier of the third non-access stratum session to the terminal device; and / or, The access network device sends the fourth non-access stratum message to the terminal device through the radio bearer corresponding to the third non-access stratum session.
30. The method according to claim 29, wherein The access network device receives a fourth non-access stratum message from the third network element, including: The access network device receives the fourth non-access stratum message and the identifier of the third non-access stratum session from the third network element; The access network device determines that the fourth non-access stratum message belongs to the third non-access stratum session, including: The access network device determines that the fourth non-access stratum message belongs to the third non-access stratum session according to the identifier of the third non-access stratum session.
31. The method according to claim 29, characterized in that, The access network device receives a fourth non-access stratum message from the third network element, including: The access network device receives the fourth non-access stratum message and a third identifier from the third network element; the third identifier is used to indicate the context of the third non-access stratum session in the access network device; The access network device determines that the fourth non-access stratum message belongs to the third non-access stratum session, including: The access network device determines that the fourth non-access stratum message belongs to the third non-access stratum session according to the third identifier.
32. The method according to any one of claims 26 - 31, characterized in that, The method further includes: The access network device receives a third request message, where the third request message is used to request the establishment of the third non-access stratum session, and the third non-access stratum session is used to transmit non-access stratum messages between the terminal device and the third network element; The access network device sends a third response message to the third network element; the third response message includes the address information of the access network device and the third identifier, and the third identifier is used to indicate the context of the third non-access stratum session in the access network device.
33. The method according to claim 32, wherein The method further includes: The access network device receives a fourth request message from the third network element; the fourth request message is used to request configuration of radio bearers corresponding to each of one or more quality of service (QoS) flows included in the third non-access stratum session. The access network device configures radio bearers corresponding to each of the QoS flows according to the fourth request message.
34. The method according to claim 33, wherein The method further includes: The access network device receives a fourth non-access stratum message from the third network element and identification information of a QoS flow corresponding to the fourth non-access stratum message, and the one or more QoS flows include the QoS flow corresponding to the fourth non-access stratum message. The access network device determines a radio bearer corresponding to the fourth non-access stratum message according to the identification information of the QoS flow corresponding to the fourth non-access stratum message. The access network device sends the fourth non-access stratum message to the terminal device through the radio bearer corresponding to the fourth non-access stratum message.
35. A communication device, characterized in that, The communication device includes a module or unit for performing the method according to any one of claims 1-6, or claims 7-18, or claims 19-25, or claims 26-34.
36. A communication device, characterized in that, The communication device includes: a processor; the processor is configured to execute a computer program or instruction stored in a memory, so that the communication device performs the method according to any one of claims 1-6, or claims 7-18, or claims 19-25, or claims 26-34.
37. A computer-readable storage medium, characterized in that, A computer program or instruction is stored thereon, and when the computer program or instruction is executed by a computer, the computer is caused to execute the method according to any one of claims 1-6, or claims 7-18, or claims 19-25, or claims 26-34.
38. A communication system, characterized in that, The communication system includes a first network element and a second network element; wherein, the first network element is configured to perform the method according to any one of claims 7-18; the second network element is configured to perform the method according to any one of claims 19-25.
39. The communication system according to claim 38, wherein The communication system further includes an access network device; wherein, the access network device is configured to perform the method according to any one of claims 26-34.
Citation Information
Cited By
Communication method, apparatus and system
WO2025157191A1
Communication method, terminal, and network-side device
WO2026145300A1