Communication method and communication device
By obtaining user identification and establishing user-side connections based on policy information, the problems related to QoS guarantee in the prior art are solved and the terminal device contract data are realized, flexible QoS guarantee based on user identification is realized, and the service quality is improved.
Patent Information
- Application Number
- CN202410138091.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-30
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, the quality of network service (QoS) guarantee of user equipment is related to the contract data of terminal equipment, but has nothing to do with the logged-in application account, resulting in the inability to provide flexible QoS guarantee according to the needs of specific users or applications.
By obtaining the user ID, establishing a user-plane connection based on the user ID, and determining whether it is necessary to create or use an existing user-plane connection based on the policy information, QoS guarantee based on the user ID is achieved.
It realizes flexible QoS guarantees based on the granularity of user identification, improves the precision and flexibility of QoS guarantees, and ensures that the service quality needs of different users or applications are accurately met.
Smart Images

Figure CN120417110A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technologies, and in particular, to communication methods and communication devices. Background Art
[0002] Currently, when a user uses a terminal device (such as a mobile phone) to play games or watch videos, even if the user logs in to their personal user account, the quality of service (QoS) guarantee provided by the network to the terminal device is related to the subscription data of the terminal device. For example, it is related to the subscription data corresponding to the mobile phone number of the terminal device, and has nothing to do with the application account logged in. For example, if user A logs in to a certain game on the mobile phone using user account 1, the QoS guarantee provided by the network is related to the subscription data of the mobile phone. Later, if user B logs in to the same game on the same mobile phone using user account 2, the network also provides the same QoS guarantee.
[0003] The above QoS guarantee method is not applicable in some scenarios. Summary of the Invention
[0004] This application provides a communication method and a communication device to achieve flexible QoS guarantee.
[0005] In a first aspect, an embodiment of this application provides a communication method, which can be executed by a terminal device or a module (such as a chip) applied to the terminal device. The method includes: obtaining a first user identifier, where the first user identifier represents the user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; determining that a user plane connection needs to be newly established based on the first user identifier, and then sending a connection establishment request, where the connection establishment request is used to request to establish a user plane connection based on the first user identifier.
[0006] In the above solution, a user plane connection is established based on the granularity of the user identifier, and the QoS guarantee of the user plane connection is related to the user identifier. The user identifier can represent the user using the terminal device, or represent a first device connected to the terminal device, or represent a user account used to access an application on the terminal device, so as to achieve QoS guarantee based on the granularity of the user identifier, thereby realizing flexible QoS guarantee.
[0007] In a possible implementation method, the determination of the need to establish a user plane connection based on the first user identifier includes: determining the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes a second user identifier, the second user identifier in the service flow information matches the first user identifier, and the routing selection information includes the second user identifier; judging whether a user plane connection matching the second user identifier has been established according to the second user identifier in the routing selection information; if a user plane connection matching the second user identifier has not been established, determining that it is necessary to establish a user plane connection based on the first user identifier.
[0008] In the above solution, according to the policy information, it is possible to accurately judge whether it is necessary to establish a new user plane connection, which helps to implement QoS guarantee based on user identifiers, thereby realizing flexible QoS guarantee.
[0009] In a possible implementation method, the method further includes: determining the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes a second user identifier, the second user identifier in the service flow information matches the first user identifier, and the routing selection information includes the second user identifier; judging whether a user plane connection matching the second user identifier has been established according to the second user identifier in the routing selection information; if the established user plane connections include a user plane connection matching the second user identifier, using the user plane connection matching the second user identifier to transmit the data corresponding to the first user identifier.
[0010] In the above solution, according to the policy information, it is possible to accurately judge whether it is necessary to establish a new user plane connection, which helps to implement QoS guarantee based on user identifiers, thereby realizing flexible QoS guarantee.
[0011] In a possible implementation method, the routing selection information further includes at least one of the following information: the domain name information in the first user identifier, the domain name information in the second user identifier, or the application information corresponding to the first user identifier.
[0012] In a possible implementation method, the determination of the need to create a user plane connection based on the first user identifier includes: determining the policy information corresponding to the first user identifier, where the policy information includes traffic flow information and routing selection information, the traffic flow information includes first domain name information, the first domain name information in the traffic flow information matches the second domain name information in the first user identifier, the routing selection information includes indication information, and the indication information indicates to create different user plane connections for user identifiers that do not match each other; according to the indication information in the routing selection information, determining whether a user plane connection matching the first user identifier has been established; if a user plane connection matching the first user identifier has not been established, determining the need to create a user plane connection based on the first user identifier.
[0013] In the above solution, according to the policy information, it is possible to accurately determine whether a new user plane connection needs to be created, which helps to implement QoS guarantee based on the user identifier, thereby achieving flexible QoS guarantee.
[0014] In a possible implementation method, the method further includes: determining the policy information corresponding to the first user identifier, where the policy information includes traffic flow information and routing selection information, the traffic flow information includes first domain name information, the first domain name information in the traffic flow information matches the second domain name information in the first user identifier, the routing selection information includes indication information, and the indication information indicates to create different user plane connections for user identifiers that do not match each other; according to the indication information in the routing selection information, determining whether a user plane connection matching the first user identifier has been established; if the established user plane connections include a user plane connection matching the first user identifier, using the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
[0015] In the above solution, according to the policy information, it is possible to accurately determine whether a new user plane connection needs to be created, which helps to implement QoS guarantee based on the user identifier, thereby achieving flexible QoS guarantee.
[0016] In a possible implementation method, the routing selection information further includes at least one of the following information: the first domain name information, the second domain name information, or the application information corresponding to the first user identifier.
[0017] In a possible implementation method, the determination of the need to create a user plane connection based on the first user identifier includes: determining the policy information corresponding to the first user identifier, where the policy information includes instructions to create different user plane connections for user identifiers that do not match each other; according to the policy information, determining whether a user plane connection matching the first user identifier has been established; if a user plane connection matching the first user identifier has not been established, determining the need to create a user plane connection based on the first user identifier.
[0018] In the above solution, according to the policy information, it is possible to accurately determine whether a new user plane connection needs to be created, which helps to implement QoS guarantee based on user identifiers, thereby achieving flexible QoS guarantee.
[0019] In a possible implementation method, the method further includes: determining the policy information corresponding to the first user identifier, where the policy information instructs to create different user plane connections for user identifiers that do not match each other; according to the indication information in the routing selection information, determining whether a user plane connection matching the first user identifier has been established; if the established user plane connections include a user plane connection matching the first user identifier, using the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
[0020] In the above solution, according to the policy information, it is possible to accurately determine whether a new user plane connection needs to be created, which helps to implement QoS guarantee based on user identifiers, thereby achieving flexible QoS guarantee.
[0021] In a possible implementation method, the policy information includes service flow information and routing selection information, the service flow information includes first information, and the first information matches any user identifier, and the routing selection information includes the indication information.
[0022] In a possible implementation method, the routing selection information further includes at least one of second information, third information, or fourth information, where the second information instructs to send the first user identifier to the network, the third information instructs to send the domain name information in the first user identifier to the network, and the fourth information instructs to send the application information corresponding to the first user identifier to the network.
[0023] In a possible implementation method, the connection establishment request further includes a first parameter, where the first parameter is used to determine an authentication server, and the authentication server is used to perform authentication on the first user identifier.
[0024] In the above solution, the terminal device provides a first parameter to the network side, enabling the network side to determine an authentication server for providing authentication for the terminal device based on the first parameter, achieving accurate determination of the authentication server and helping to ensure the accuracy of authentication.
[0025] In a possible implementation method, the connection establishment request is carried in a NAS message, and the NAS message further includes a first parameter for determining an authentication server, and the authentication server is used to perform authentication on the first user identifier.
[0026] In the above solution, the terminal device provides a first parameter to the network side, enabling the network side to determine an authentication server for providing authentication for the terminal device based on the first parameter, achieving accurate determination of the authentication server and helping to ensure the accuracy of authentication.
[0027] In a possible implementation method, the first parameter includes one or more of the following information: the first user identifier, domain name information in the first user identifier, identification information of the authentication server, or application information corresponding to the first user identifier.
[0028] In a possible implementation method, the application information includes one or more of the following information: identification information of the application, identification information of the application server, identification information of the application function service, identification information of the application function, identification information of the authentication server, or the domain name corresponding to the application.
[0029] In a possible implementation method, obtaining the first user identifier includes: obtaining the first user identifier from an application on the terminal device; or obtaining the first user identifier from the first device.
[0030] In a second aspect, an embodiment of the present application provides a communication method, which can be executed by a first network element or a module (such as a chip) applied to the first network element. The first network element is a session management network element or a policy control network element. The method includes: receiving a first parameter from a terminal device, where the first parameter includes one or more of the following information: a first user identifier, domain name information in the first user identifier, or application information corresponding to the first user identifier; where the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account for accessing an application on the terminal device; determining an authentication server according to the first parameter, and the authentication server is used to perform authentication on the first user identifier.
[0031] In the above solution, the terminal device provides a first parameter to the first network element, and the first network element determines an authentication server for providing authentication for the terminal device based on the first parameter, achieving accurate determination of the authentication server and helping to ensure the accuracy of authentication.
[0032] In a possible implementation method, determining the authentication server according to the first parameter includes: sending a first request to a unified data management network element or a unified database network element, where the first request includes the first parameter; receiving a first response from the unified data management network element or the unified database network element, where the first response includes the identification information of the authentication server.
[0033] In a possible implementation method, determining the authentication server according to the first parameter includes: determining the identification information of the authentication server corresponding to the first parameter according to pre-configured information, where the pre-configured information includes the correspondence between the first parameter and the identification information of the authentication server.
[0034] In a possible implementation method, the first network element is a policy control network element; the method further includes: sending the identification information of the authentication server to a session management network element.
[0035] In a possible implementation method, the method further includes: sending indication information to the session management network element, where the indication information indicates to perform authentication.
[0036] In a possible implementation method, the method further includes: after successful authentication, receiving the first user identification from the authentication server.
[0037] In the above solution, after successful authentication, the authentication server provides the first user identification to the first network element, thereby ensuring the security of the first user identification.
[0038] In a third aspect, an embodiment of the present application provides a communication device, which may be a terminal device or a module (such as a chip) for a terminal device. The device has the function of implementing any implementation method of the first aspect above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0039] In a fourth aspect, an embodiment of the present application provides a communication device, which may be the first network element or a module (such as a chip) for the first network element. The device has the function of implementing any implementation method of the second aspect above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0040] In a fifth aspect, an embodiment of the present application provides a communication device, including units or means for executing each step of any implementation method in the first aspect to the second aspect above.
[0041] Sixth aspect, an embodiment of the present application provides a communication device, including a processor and an interface circuit. The processor is used to communicate with other devices through the interface circuit and execute any implementation method in the above first aspect to the second aspect. The processor includes one or more.
[0042] Seventh aspect, an embodiment of the present application provides a communication device, including a processor. The processor is used to call a program to execute any implementation method in the above first aspect to the second aspect. And the processor can be one or more.
[0043] Optionally, the communication device may further include a memory, which is coupled to the processor. The memory may be located inside the device or outside the device.
[0044] Eighth aspect, an embodiment of the present application provides a communication device, including a processor; when the device runs, the processor executes computer instructions to enable the device to execute any implementation method in the above first aspect to the second aspect.
[0045] Optionally, the communication device may further include a memory, which is used to store the computer instructions.
[0046] Ninth aspect, an embodiment of the present application further provides a computer program product, which includes a computer program or instructions. When the computer program or instructions are run on a communication device, any implementation method in the above first aspect to the second aspect is executed.
[0047] Tenth aspect, an embodiment of the present application further provides a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When it runs on a communication device, any implementation method in the above first aspect to the second aspect is executed.
[0048] Eleventh aspect, an embodiment of the present application further provides a chip system, including: a processor, which is used to execute any implementation method in the above first aspect to the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is a schematic diagram of a 5G network architecture based on a service-oriented architecture;
[0050] FIG. 2(a) is a schematic flowchart of a communication method provided by an embodiment of the present application;
[0051] FIG. 2(b) is a schematic flowchart of a communication method provided by an embodiment of the present application;
[0052] Figures 3 to 7 It is a schematic flowchart of a communication method provided by an embodiment of the present application;
[0053] Figure 8Schematic diagram of the communication device provided by the embodiment of the present application;
[0054] Figure 9 Schematic diagram of the communication device provided by the embodiment of the present application. Detailed implementation manners
[0055] To address the challenges of wireless broadband technology and maintain the leading edge of the 3rd generation partnership project (3GPP) network, the 3GPP standards group has developed the architecture of the next generation mobile communication network system (next generation System), known as the 5th generation (5G) network architecture. This architecture not only supports the access of radio access technologies defined by the 3GPP standards group (such as long term evolution (LTE) access technology, 5G radio access network (RAN) access technology, etc.) to the 5G core network (CN), but also supports the access to the core network using non-3GPP access technologies through the non-3GPP interworking function (N3IWF) or the next generation packet data gateway (ngPDG).
[0056] Figure 1 Schematic diagram of the 5G network architecture based on the service-based architecture. Figure 1The 5G network architecture shown may include access network devices and core network devices. The terminal device accesses the data network (DN) through the access network devices and core network devices. Among them, the core network devices include, but are not limited to, some or all of the following network elements: authentication server function (AUSF) network element, unified data management (UDM) network element, unified data repository (UDR) network element, network repository function (NRF) network element, network exposure function (NEF) network element, application function (AF) network element, policy control function (PCF) network element, access and mobility management function (AMF) network element, session management function (SMF) network element, user plane function (UPF) network element.
[0057] The terminal device may be a user equipment (UE), a mobile station, a mobile terminal device, etc. The terminal device can be widely used in various scenarios, for example, device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, remote medical treatment, smart grid, smart furniture, smart office, smart wearables, smart transportation, smart city, etc. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, an urban air vehicle (such as an unmanned aircraft, a helicopter, etc.), a ship, a robot, a robotic arm, a smart home device, etc. For the convenience of description, this application takes the UE as an example of the terminal device for description, and the UE that appears at any subsequent position can be replaced by the terminal device.
[0058] The access network device can be a wireless access network device or a wired access network device. Among them, the wireless access network device includes a 3GPP access network device, a non-trusted non-3GPP access network device, and a trusted non-3GPP access network device. The 3GPP access network device includes but is not limited to: the evolved NodeB (eNodeB) in LTE, the next generation NodeB (gNB) in the 5G mobile communication system, the base station in the future mobile communication system, or a module or unit that completes part of the base station functions, such as the central unit (CU), the distributed unit (DU), etc. The non-trusted non-3GPP access network device includes but is not limited to: the non-trusted non-3GPP access gateway or N3IWF device, the non-trusted wireless local area network (WLAN) access point (AP), the switch, and the router. The trusted non-3GPP access network device includes but is not limited to: the trusted non-3GPP access gateway, the trusted WLAN AP, the switch, and the router. The wired access network device includes but is not limited to: the wireline access gateway, the fixed telephone network device, the switch, and the router. For ease of explanation, this application uses the base station as an example of the access network device for illustration, and the base station that appears at any subsequent position can be replaced with the access network device.
[0059] The base station and the UE can be in a fixed position or movable. The base station and the UE can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; they can also be deployed on the water surface; they can also be deployed on airplanes, balloons, and artificial satellites in the air. The embodiments of this application do not limit the application scenarios of the base station and the UE.
[0060] The AMF network element includes functions such as performing mobility management, or access authentication / authorization, etc. In addition, it is also responsible for transmitting user policies between the UE and the PCF.
[0061] The SMF network element includes functions such as performing session management, executing the control policies issued by the PCF network element, selecting the UPF network element, or allocating the internet protocol (IP) address of the UE, etc.
[0062] The UPF network element includes functions such as completing user plane data forwarding, session / flow-level billing statistics, or bandwidth limitation, etc.
[0063] The UDM network element includes functions such as performing management of subscription data, or user access authorization, etc.
[0064] The UDR includes access functions for types of data such as execution signing data, policy data, or application data.
[0065] The NEF network element is used to support the opening of capabilities and events.
[0066] The AF network element transmits the requirements of the application side to the network side. For example, quality of service (QoS) requirements or user status event subscriptions, etc. The AF can be a third-party functional entity or an application service deployed by the operator, such as an IP Multimedia Subsystem (IMS) voice call service. Among them, the AF network element includes the AF network element within the core network (i.e., the operator's AF network element) and the third-party AF network element (such as an enterprise's application server).
[0067] The PCF network element includes policy control functions such as being responsible for charging, QoS bandwidth guarantee, and mobility management at the session and service flow levels, or UE policy decision-making, etc. The PCF network element includes the access and mobility management policy control network element (access and mobility management policy control function, AM PCF) network element and the session management policy control function (session management PCF, SM PCF) network element. Among them, the AM PCF network element is used to formulate AM policies and user policies for the UE, and the AM PCF network element can also be called the policy control network element that provides services for the UE (PCF for a UE). The SM PCF network element is used to formulate session management policies (session management policy, SM policy) for the session, and the SM PCF network element can also be called the policy control network element that provides services for the protocol data unit (PDU) session ((PCF for a PDU session)).
[0068] The NRF network element can be used to provide a network element discovery function and provide network element information corresponding to the network element type based on the requests of other network elements. The NRF network element also provides network element management services, such as network element registration, update, deregistration, or network element status subscription and push, etc.
[0069] The AUSF network element is responsible for authenticating users to determine whether to allow users or devices to access the network.
[0070] A DN is a network located outside of a carrier network. A carrier network can connect to multiple DNs, and a variety of services can be deployed on the DN, providing UEs with data and / or voice services. For example, a DN is the private network of a smart factory. Sensors installed in the workshop can be UEs. The DN houses a control server for these sensors, which can provide services to the sensors. The sensors can communicate with the control server, receive instructions from the control server, and transmit collected sensor data to the control server based on the instructions. Another example is a DN that is a company's internal office network. An employee's mobile phone or computer can be a UE, allowing them to access information and data resources on the company's internal office network.
[0071] Figure 1 Nausf, Npcf, Nudr, Nudm, Naf, Namf, Nsmf, Nnef, and Nnrf are the service-based interfaces (SBIs) provided by the above-mentioned AUSF, PCF, UDR, UDM, AF, AMF, SMF, NEF, and NRF, respectively, and are used to invoke corresponding service-based operations. N1, N2, N3, N4, and N6 are interface serial numbers, and their meanings are as follows:
[0072] 1) N1: The interface between the AMF network element and the UE, which can be used to deliver non-access stratum (NAS) signaling to the UE (such as QoS rules from the AMF network element).
[0073] 2) N2: The interface between the AMF network element and the base station, which can be used to transmit radio bearer control information from the core network side to the base station.
[0074] 3) N3: The interface between the base station and the UPF network element, mainly used to transmit uplink and downlink user plane data between the base station and the UPF network element.
[0075] 4) N4: The interface between the SMF network element and the UPF network element, which can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information on the user plane.
[0076] 5) N6: The interface between UPF network element and DN, used to transmit uplink and downlink user data flows between UPF network element and DN.
[0077] It can be understood that the above network element or function can be either a network element in a hardware device, or a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the above network element or function can be implemented by one device, or jointly implemented by multiple devices, or can also be a functional module within a device. The embodiments of the present application do not make specific limitations in this regard.
[0078] The session management network element, policy control network element, unified data management network element, and unified database network element in the present application can respectively be Figure 1 the SMF network element, PCF network element, UDM network element, and UDR network element in [reference], or can also be network elements with the functions of the above SMF network element, PCF network element, UDM network element, and UDR network element in future communications such as 6G networks. The present application does not make limitations in this regard. In the embodiments of the present application, the SMF network element, PCF network element, UDM network element, and UDR network element are described by way of an example as the session management network element, policy control network element, unified data management network element, and unified database network element respectively, and the SMF network element, PCF network element, UDM network element, and UDR network element are abbreviated as SMF, PCF, UDM, and UDR respectively.
[0079] To facilitate the understanding of the present invention, the background involved in the present invention will be described first below.
[0080] 1. User Equipment Routing Selection Policy (URSP) Rule
[0081] The URSP rule is used for the UE to determine whether a new PDU session needs to be established for a new traffic flow. The URSP rule includes at least one traffic descriptor (TD) and a route selection descriptor (RSD) corresponding to each TD. Among them, the TD contains information for matching traffic flows. Exemplarily, the TD contains an application descriptor (such as one or more operating system identifiers (OSId) or operating system application identifiers (OSAppId)), an IP descriptor (such as a destination IP triple), a non-IP descriptor (such as medium access control (MAC) address information), a domain name (such as a fully qualified domain name (FQDN)), a data network name (DNN), or connection capability information, or one or more of them.
[0082] The UE can use the TD in the URSP rule to match the information of the service flow. When the information of the service flow matches a certain TD in a certain URSP rule, the RSD corresponding to the TD in the URSP rule is determined, and the parameters of the PDU session to be established are determined based on the RSD. If there is a PDU session that matches the parameters in the already established PDU sessions, the already established PDU session is reused to transmit the service flow. If there is no PDU session that matches the parameters in the already established PDU sessions, a new PDU session is created and the new PDU session is used to transmit the service flow.
[0083] 2. Secondary authentication (also known as secondary authorization)
[0084] Secondary authentication means that after the UE successfully accesses the 5G network, when accessing a specific network, it needs to perform authentication again. The authentication performed by the UE through the AUSF and UDM when accessing the 5G network is called primary authentication, primary authorization, primary authentication, or primary authorization.
[0085] The purpose of secondary authentication is to ensure the security of special networks. For example, if an employee of a certain bank wants to access the bank's internal network on a mobile phone, it is best to perform secondary authentication, and business access can only be performed after passing the authentication.
[0086] During secondary authentication, the UE needs to carry special user credential information. This user credential is not a credential from the operator, but a credential between the UE and a specific network (such as an enterprise network). This credential is generally a credential issued by the enterprise network. Secondary authentication is performed between the UE and the authentication server (such as an authentication authorization and accounting (AAA) server). Among them, the AAA server can also be called a DN-AAA server.
[0087] To provide more flexible QoS guarantee, the embodiments of the present application provide corresponding solutions. Referring to FIG. 2(a), it is a schematic flowchart of a communication method provided by the embodiments of the present application. This method can be executed by the UE or a module of the UE (such as a chip). The following takes the UE executing this method as an example for description.
[0088] The method includes the following steps:
[0089] Step 201a, the UE obtains the first user identifier.
[0090] In one implementation method, the first user identifier represents the user using the UE. Based on this implementation method, different users use different user identifiers, and each user identifier is used to represent a user. Exemplarily, the UE is a shared terminal, and different users can all log in. Among them, the user identifier may include a user account, or include a user account and a user password. For example, if the user identifier of user 1 is user identifier 1, then user 1 can use user identifier 1 to log in to the UE and access the applications on the UE. For example, if the user identifier of user 2 is user identifier 2, then user 2 can use user identifier 2 to log in to the UE and access the applications on the UE.
[0091] In another implementation method, the first user identifier represents the first device connected to the UE. For example, the UE is a mobile phone, and the first device is a wearable device (such as a smart watch, a bracelet, etc.) that can be connected to the mobile phone. In the present invention, the first device connected to the UE may be a 3GPP device or a non-3GPP device, which is not limited in this application and is uniformly described here without further elaboration in other places later. Based on this implementation method, different first devices use different user identifiers, and each user identifier is used to represent a first device. For example, if the user identifier of smart watch 1 is user identifier 1, then smart watch 1 can use user identifier 1 to connect to the mobile phone. For example, if the user identifier of smart watch 2 is user identifier 2, then smart watch 2 can use user identifier 2 to connect to the mobile phone. For example, if the user identifier of smart bracelet 1 is user identifier 3, then smart bracelet 1 can use user identifier 3 to connect to the mobile phone. For example, if the user identifier of smart bracelet 2 is user identifier 4, then smart bracelet 2 can use user identifier 4 to connect to the mobile phone.
[0092] In another implementation method, the first user identifier represents the user account used to access the applications on the UE. Based on this implementation method, for a specific application, different user identifiers can be used to access the application, that is, the user identifier refers to the user identifier associated with the specific application. Among them, the user identifier may include a user account, or include a user account and a user password. For example, using user identifier 1, user identifier 2, user identifier 3, etc., can all log in to a certain video APP.
[0093] Exemplarily, step 201a may specifically be: The UE obtains the first user identifier from the applications on the UE, or obtains the first user identifier from the first device connected to the UE. For example, obtains the first user identifier from the first device through wireless fidelity (WiFi).
[0094] Exemplarily, in an embodiment of the present application, the user identifier may include domain name information and / or user name. The domain name information may be, for example, information about the domain where the authentication server is located. For example, the domain name information is FQDN or realm part. The user name is used to distinguish different users. Among them, the user identifier may be, for example, the first user identifier introduced here or the second user identifier described later, etc.
[0095] Step 202a, if the UE determines that a user plane connection needs to be newly established based on the first user identifier, it sends a connection establishment request.
[0096] Among them, the connection establishment request is used to request the establishment of a user plane connection based on the first user identifier.
[0097] Exemplarily, the user plane connection may be a protocol data unit (PDU) session, or other types of connections, and the present application is not limited thereto.
[0098] In the above solution, a user plane connection is established based on the user identifier. The QoS guarantee of the user plane connection is related to the user identifier. The user identifier may represent the user using the terminal device, or the first device connecting to the terminal device, or the user account used to access the application on the terminal device, so as to realize QoS guarantee based on the granularity of the user identifier, thereby realizing flexible QoS guarantee.
[0099] In one implementation method, when the user identifier represents the user using the UE, after a user logs in to the UE using the user identifier, the QoS guarantees adopted for accessing different applications on the UE are all related to the subscribed data corresponding to the user identifier. When different users log in to the UE using different user identifiers, the QoS guarantees adopted for accessing the applications on the UE are related to the user currently using the UE. For example, user 1 logs in to the UE using user identifier 1 and accesses the applications on the UE. Regardless of the application accessed, the corresponding QoS guarantee is adopted according to the subscribed data corresponding to user identifier 1. For example, user 2 logs in to the UE using user identifier 2 and accesses the applications on the UE. Regardless of the application accessed, the corresponding QoS guarantee is adopted according to the subscribed data corresponding to user identifier 2.
[0100] In another implementation method, when the user identifier represents the first device connecting to the UE, after a certain first device connects to the UE using the user identifier, the QoS guarantee adopted for the services of the first device is related to the first device connected to the UE. For example, after smartwatch 1 connects to the mobile phone using user identifier 1, the QoS guarantee adopted for the services of smartwatch 1 is related to smartwatch 1. For example, after smartwatch 2 connects to the mobile phone using user identifier 2, the QoS guarantee adopted for the services of smartwatch 2 is related to smartwatch 2.
[0101] In another implementation method, when the user identifier represents a user account for accessing an application on the UE, after logging in to the application using a certain user account, QoS guarantee is performed according to the subscribed data corresponding to the user account. When different user accounts are used to log in to the same application respectively, corresponding QoS guarantee is performed according to the subscribed data corresponding to different user accounts. For example, after logging in to a certain video APP using user account 1, corresponding QoS guarantee is performed according to the subscribed data corresponding to user account 1. For example, after logging in to the same video APP using user account 2, corresponding QoS guarantee is performed according to the subscribed data corresponding to user account 2.
[0102] As an implementation method, after step 201a above, the UE determines the policy information corresponding to the first user identifier, and judges whether a user plane connection needs to be newly established based on the first user identifier according to the policy information. If a user plane connection needs to be newly established based on the first user identifier, step 202a is executed, that is, a connection establishment request is sent. If a user plane connection does not need to be newly established based on the first user identifier, an already established user plane connection can be used to transmit the data corresponding to the first user identifier.
[0103] The following introduces the specific implementation of how the UE judges whether a user plane connection needs to be newly established based on the first user identifier for different implementation methods of the policy information.
[0104] Implementation method 1: The policy information includes traffic flow information and routing selection information. The traffic flow information includes a second user identifier, and the routing selection information includes a second user identifier. Optionally, the routing selection information may further include at least one of the following information: domain name information in the first user identifier, domain name information in the second user identifier, or application information corresponding to the first user identifier.
[0105] If the UE determines that the second user identifier in the traffic flow information matches the first user identifier, it obtains the routing selection information corresponding to the traffic flow information, and judges whether a user plane connection matching the second user identifier has been established according to the second user identifier in the routing selection information. If a user plane connection matching the second user identifier has not been established, it is determined that a user plane connection needs to be newly established based on the first user identifier, and the data corresponding to the first user identifier can be transmitted using the newly established user plane connection subsequently. If the established user plane connections include a user plane connection matching the second user identifier, the user plane connection matching the second user identifier is used to transmit the data corresponding to the first user identifier.
[0106] Among them, the second user identifier matches the first user identifier. For example, the second user identifier may be the same as the first user identifier, or have a corresponding relationship, or the second user identifier and the first user identifier contain the same information, such as containing the same domain name information.
[0107] Implementing Method 2, the policy information includes service flow information and routing selection information. The service flow information includes first domain name information, and the routing selection information includes indication information that indicates to establish different user plane connections for user identifiers that do not match each other. Optionally, the routing selection information may further include at least one of the following information: the first domain name information, the second domain name information in the first user identifier, or the application information corresponding to the first user identifier.
[0108] In a possible implementation manner, not matching each other includes being completely different or not completely the same. Here, "being completely different" means that the information contained in the two user identifiers is completely different. Here, "not completely the same" means that part of the information contained in the two user identifiers is the same and the other part is different. In other words, if the information contained in the two user identifiers is completely the same, then the two user identifiers match each other. Exemplarily, user identifier 1 is composed of domain name information 1 and user name 1, and user identifier 2 is composed of domain name information 2 and user name 2. If domain name information 1 is the same as domain name information 2, and user name 1 is the same as user name 2, then user identifier 1 and user identifier 2 are completely the same, so user identifier 1 and user identifier 2 match each other. If domain name information 1 is the same as domain name information 2, but user name 1 is different from user name 2, then user identifier 1 and user identifier 2 are not completely the same, so user identifier 1 and user identifier 2 do not match each other. If domain name information 1 is different from domain name information 2, but user name 1 is the same as user name 2, then user identifier 1 and user identifier 2 are not completely the same, so user identifier 1 and user identifier 2 do not match each other. If domain name information 1 is different from domain name information 2, and user name 1 is different from user name 2, then user identifier 1 and user identifier 2 are completely different, so user identifier 1 and user identifier 2 do not match each other.
[0109] In another possible implementation, "mutual mismatch" means non-correspondence, and correspondingly, "mutual match" means correspondence. Here, "correspondence" means that there is a corresponding relationship or mapping relationship between two user identifiers. Exemplarily, if user identifier 1 has a corresponding relationship with user identifier 2, that is, "correspondence", then the same user plane connection can be established for user identifier 1 and user identifier 2. If user identifier 1 has no corresponding relationship with user identifier 2, that is, "non-correspondence", then different user plane connections can be established for user identifier 1 and user identifier 2. It should be noted that whether two user identifiers match has no necessary relationship with whether the information of the two user identifiers is the same. That is, if two user identifiers match each other, the information contained in the two user identifiers may be exactly the same, may be completely different, or may not be completely the same. If two user identifiers do not match each other, the information contained in the two user identifiers may also be exactly the same, may be completely different, or may not be completely the same.
[0110] The explanation of "mutual mismatch" here can be applied to any embodiment of this application. A unified description is made here and will not be repeated later.
[0111] If the UE determines that the first domain name information in the service flow information matches the second domain name information in the first user identifier, it obtains the routing selection information corresponding to the service flow information, and determines whether a user plane connection matching the first user identifier has been established according to the indication information in the routing selection information. If a user plane connection matching the first user identifier has not been established, it is determined that a new user plane connection needs to be established based on the first user identifier, and the newly established user plane connection can be used to transmit the data corresponding to the first user identifier later. If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit the data corresponding to the first user identifier.
[0112] Among them, the second domain name information matches the first domain name information. For example, the second domain name information may be the same as the first domain name information, or have a corresponding relationship, or the second domain name information and the first domain name information contain the same information.
[0113] Implementation method three: The policy information instructs to establish different user plane connections for user identifiers indicated as mutually mismatched.
[0114] After the UE obtains the first user identifier, it determines whether a user plane connection matching the first user identifier has been established according to the policy information. If a user plane connection matching the first user identifier has not been established, it is determined that a new user plane connection needs to be established based on the first user identifier, and the newly established user plane connection can be used to transmit data corresponding to the first user identifier subsequently. If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
[0115] Exemplarily, the policy information includes traffic flow information and routing selection information. The traffic flow information includes first information that matches any user identifier. The routing selection information includes the above indication information. Based on this method, after the UE obtains the first user identifier, if it determines that the first user identifier matches the first information in the traffic flow information, it obtains the routing selection information corresponding to the traffic flow information, and determines whether a user plane connection matching the first user identifier has been established according to the indication information in the routing selection information. If a user plane connection matching the first user identifier has not been established, it is determined that a new user plane connection needs to be established based on the first user identifier, and the newly established user plane connection can be used to transmit data corresponding to the first user identifier subsequently. If the established user plane connections include a user plane connection matching the first user identifier, the user plane connection matching the first user identifier is used to transmit data corresponding to the first user identifier.
[0116] Optionally, in addition to the indication information, the routing selection information may further include at least one of second information, third information, or fourth information. The second information indicates sending the first user identifier to the network. The third information indicates sending the domain name information in the first user identifier to the network. The fourth information indicates sending the application information corresponding to the first user identifier to the network.
[0117] Exemplarily, the policy information in Implementation Methods 1 to 3 above may be URSP. The traffic flow information in the policy information may be TD in URSP. The routing selection information in the policy information may be RSD in URSP.
[0118] As an implementation method, the connection establishment request in step 202a above includes a first parameter, which is used to determine the authentication server. The authentication server is used to perform authentication on the first user identifier. The authentication server may be an AAA server or an AUSF network element, etc.
[0119] As another implementation method, the connection establishment request in step 202a above is carried in an NAS message. In addition to including the connection establishment request, the NAS message further includes a first parameter, which is used to determine an authentication server for performing authentication on the first user identifier. The authentication server may be an AAA server, an AUSF network element, or the like.
[0120] Exemplarily, the first parameter includes one or more of the following information: the first user identifier, the domain name information in the first user identifier, the identification information of the authentication server, or the application information corresponding to the first user identifier. Optionally, the information included in the first parameter may come from the above-mentioned policy information.
[0121] In the embodiments of the present application, the application information corresponding to the first user identifier includes one or more of the following information: the identification information of the application (for example, it may be APP ID, APP address, or APP domain), the identification information of the application server (for example, it may be APP server ID, APP server address, or APP server domain), the identification information of the application function service (for example, it may be AF service ID), the identification information of the application function (for example, it may be AF ID, AF address, or AF domain), the identification information of the authentication server (for example, it may be AAA server ID, AAA server address, AAA server domain, AUSF ID, or AUSF address), or the domain name corresponding to the application.
[0122] To implement the selection of the correct authentication server, the embodiments of the present application provide corresponding solutions. Referring to FIG. 2(b), it is a schematic flowchart of a communication method provided by the embodiments of the present application. This method is executed by a first network element or a module (such as a chip) of the first network element. The following takes the first network element executing this method as an example for description. The first network element is an SMF or a PCF.
[0123] The method includes the following steps:
[0124] Step 201b, the first network element receives a first parameter from the UE.
[0125] As an implementation method, the first parameter is carried in a connection establishment request for requesting to establish a user plane connection based on a first user identifier. For example, the UE sends a NAS message to the AMF. The NAS message contains a session management container (SM container). The session management container contains a connection establishment request. The connection establishment request contains the first parameter and is used to request the establishment of a user plane connection based on the first user identifier. The AMF sends the session management container to the SMF. If the first network element is the SMF, the SMF can obtain the first parameter from the connection establishment request. If the first network element is the PCF, the PCF receives the first parameter sent by the SMF after the SMF obtains the first parameter from the connection establishment request.
[0126] As another implementation method, the UE sends a NAS message to the AMF. The NAS message contains a session management container. The session management container contains the first parameter and a connection establishment request. The connection establishment request is used to request the establishment of a user plane connection based on the first user identifier. The AMF sends the session management container to the SMF. If the first network element is the SMF, the SMF can obtain the first parameter from the session management container. If the first network element is the PCF, the PCF receives the first parameter sent by the SMF after the SMF obtains the first parameter from the session management container.
[0127] Exemplarily, the first parameter includes one or more of the following information: the first user identifier, the domain name information in the first user identifier, or the application information corresponding to the first user identifier. Among them, the specific meanings of the first user identifier and the application information corresponding to the first user identifier can refer to the description in the embodiment of FIG. 2(a) above.
[0128] Step 202b, the first network element determines an authentication server according to the first parameter.
[0129] The authentication server is used to perform authentication on the first user identifier. The authentication server can be an AAA server or an AUSF network element, etc.
[0130] In an implementation method, step 202b may specifically be: the first network element sends a first request to the UDM. The first request includes the first parameter. The UDM determines the authentication server according to the first parameter, and then the UDM sends a first response to the first network element. The first response includes the identification information of the authentication server. Among them, the identification information of the authentication server may include the identifier of the authentication server, the address information of the authentication server, or the domain name information of the authentication server, etc.
[0131] In another implementation method, step 202b may specifically be: The first network element sends a first request to the UDR. The first request includes a first parameter. The UDR determines an authentication server according to the first parameter, and then the UDR sends a first response to the first network element. The first response includes the identification information of the authentication server.
[0132] In another implementation method, step 202b may specifically be: The first network element sends a first request to the NRF. The first request includes a first parameter. The NRF determines an authentication server according to the first parameter, and then the NRF sends a first response to the first network element. The first response includes the identification information of the authentication server.
[0133] In another implementation method, when the first network element is the SMF, step 202b may specifically be: The first network element sends a first request to the PCF. The first request includes a first parameter. The PCF determines an authentication server according to the first parameter, and then the PCF sends a first response to the first network element. The first response includes the identification information of the authentication server.
[0134] In another implementation method, step 202b may specifically be: The first network element determines the identification information of the authentication server corresponding to the first parameter according to the pre-configured information locally. The pre-configured information includes the correspondence between the first parameter and the identification information of the authentication server.
[0135] Exemplarily, if the first network element is the PCF, after the PCF determines the identification information of the authentication server based on any of the foregoing methods (that is, after step 202b), it may send the identification information of the authentication server to the SMF. Thus, the SMF cooperates with the authentication server according to the identification information of the authentication server to authenticate the first user identification.
[0136] Exemplarily, if the first network element is the PCF, when the PCF sends the identification information of the authentication server to the SMF, it may also send indication information to the SMF. The indication information indicates to perform authentication. Of course, if the PCF does not send the indication information to the SMF, the SMF may also determine that authentication needs to be performed according to the received identification information of the authentication server. That is, the identification information of the authentication server can be used to implicitly indicate to perform authentication.
[0137] As an implementation method, after successful authentication, the authentication server may send the first user identification to the first network element. Based on this method, the first user identification may not be included in the foregoing first parameter or an incomplete first user identification may be included, and then after successful authentication, the authentication server provides the first user identification to the first network element, so as to ensure the security of the first user identification.
[0138] In the above solution, the UE provides a first parameter to the first network element, enabling the first network element to determine an authentication server for providing authentication for the UE based on the first parameter, achieving accurate determination of the authentication server and helping to ensure the accuracy of authentication.
[0139] It should be noted that the embodiments of FIG. 2(a) and FIG. 2(b) above can be implemented separately or in combination, and the present application does not limit this.
[0140] To facilitate understanding of the embodiments of FIG. 2(a) and FIG. 2(b), the following Figures 3 to 7 embodiments will be used to specifically illustrate the embodiments of FIG. 2(a) and FIG. 2(b) above. In the following Figures 3 to 7 embodiments, a specific example of using an AAA server as the authentication server and a PDU session as a specific example of the user plane connection will be described. It should be noted that in the following Figures 3 to 7 embodiments, any AAA server can be replaced with an Authentication Server Function (AUSF) or other types of authentication servers. Correspondingly, the information related to the AAA server is also replaced with the information related to the AUSF. For example, the identification information of the AAA server is replaced with the identification information of the AUSF, etc. And in the following Figures 3 to 7 embodiments, the PDU session can be replaced with other types of user plane connections.
[0141] Figure 3 This is a flowchart of a communication method provided by an embodiment of the present application. In this method, the first user identification is assigned by the application, and the SMF determines the identification information of the AAA server, which is the AAA server in the DN.
[0142] The method includes the following steps:
[0143] Step 301, the UE obtains policy information.
[0144] For example, during the UE registration process or after the UE registration process is completed, the PCF sends policy information to the UE through the AMF.
[0145] Regarding the meaning of this policy information, reference can be made to the description in the embodiment of FIG. 2(a).
[0146] Step 302, the UE obtains the first user identification.
[0147] Exemplarily, the UE obtains the first user identification from an application on the UE or from another UE connected to the UE. For example, the UE obtains the first user identification from another UE through WiFi.
[0148] Step 303: The UE determines, based on the policy information, that a PDU session needs to be newly established based on the first user identifier.
[0149] For the specific implementation of this step, reference can be made to the description in the embodiment of FIG. 2(a) above.
[0150] Step 304: The UE sends a PDU session establishment request (PDU Session Establishment Request) to the AMF. Correspondingly, the AMF receives the PDU session establishment request.
[0151] Exemplarily, the UE sends a NAS message to the AMF via the base station, and the NAS message includes the PDU session establishment request.
[0152] As an implementation method, in this step 304, the UE also sends a first parameter to the AMF, and this first parameter is used to determine the AAA server. For example, this first parameter can be carried in the PDU session establishment request. For another example, this first parameter is carried in the NAS message, that is, the NAS message includes the first parameter and the PDU session establishment request.
[0153] For the specific content of this first parameter, reference can be made to the description in the embodiment of FIG. 2(a) above.
[0154] Exemplarily, the PDU session establishment request may also include a PDU session identifier (PDU session ID), slice information (such as single network slice selection assistance information (S-NSSAI)), and a data network name (DNN).
[0155] Step 305: The AMF sends a session context establishment request to the SMF. Correspondingly, the SMF receives the session context establishment request.
[0156] Exemplarily, this session context establishment request may be Nsmf_PDUSession_CreateSMContextRequest.
[0157] This session context establishment request includes the UE's identification information (such as subscription permanent identifier (SUPI)) and the PDU session establishment request.
[0158] As an implementation method, if in the above step 304, the UE also carried the first parameter in the PDU session establishment request, then the SMF can obtain the first parameter from the PDU session establishment request.
[0159] As another implementation method, if in step 304 above, the UE also carries the first parameter in the NAS message sent to the AMF, the session context establishment request may include the first parameter, that is, the session context establishment request includes the UE identification information, the PDU session establishment request, and the first parameter. Thus, the SMF can obtain the first parameter from the session context establishment request.
[0160] Step 306: The SMF determines to perform authentication and determines the AAA server according to the first parameter.
[0161] The authentication here can be secondary authentication or primary authentication, which is not limited in this application.
[0162] In one possible implementation, the SMF directly determines the AAA server based on the first parameter. For example, if the first parameter includes the first user identifier or domain name information in the first user identifier, the SMF may determine the AAA server corresponding to the domain name information based on the domain name information in the first user identifier. For another example, if the first parameter includes identification information of the AAA server, the SMF may determine the AAA server based on the identification information of the AAA server.
[0163] In another possible implementation, SMF requests UDM to obtain the identification information of the AAA server. The specific implementation process of UDM storing the identification information of the AAA server can be referred to Figure 5 For the specific implementation of SMF requesting UDM to obtain the identification information of the AAA server, please refer to Figure 5 Related description in the embodiments of the present invention.
[0164] Step 307: N4 session is established.
[0165] This step 307 is an optional step. When there is no existing N4 session that can be used to transmit messages between the SMF and the DN, the SMF selects the UPF and triggers the establishment of the N4 session.
[0166] Step 308: Authentication is performed between the UE and the AAA server.
[0167] Exemplarily, authentication is performed between the UE and the AAA server via the AMF, SMF, and UPF. Upon successful authentication, the AAA server sends a message indicating successful authentication to the SMF. For detailed information on the authentication process between the UE and the AAA server, please refer to the relevant description of the prior art and will not be repeated here.
[0168] In a possible implementation, to ensure security and privacy, the first parameter may not include the first user identifier or may include an incomplete first user identifier. Instead, during the authentication process, the UE provides the first user identifier to the AAA server. Then, after successful authentication, the AAA server sends the first user identifier to the SMF. Thus, the SMF obtains the corresponding QoS requirement information based on the first user identifier and completes the subsequent session establishment process based on the QoS requirement information to achieve QoS guarantee.
[0169] Step 309, when the authentication is successful, the SMF continues to complete the subsequent session establishment process.
[0170] In the above solution, it can be implemented to establish a PDU session based on the granularity of the user identifier, and then achieve differential QoS guarantee according to the granularity of the user identifier, improving the fineness and flexibility of QoS guarantee. Moreover, for the scenario where multiple AAA servers are deployed within the same DN, in this solution, the UE provides the first parameter to the SMF, enabling the SMF to determine the AAA server used to authenticate the UE from multiple AAA servers within the same DN based on the first parameter, achieving accurate determination of the AAA server for authentication. In addition, it can also be implemented that after successful authentication, the AAA server sends the first user identifier to the SMF instead of the UE directly sending the first user identifier to the SMF, enhancing the security and privacy of the user identifier.
[0171] Figure 4 The flowchart of a communication method provided by an embodiment of this application. In this method, the first user identifier is assigned by the application, and the PCF determines the identification information of the AAA server and sends the identification information of the AAA server to the SMF. This AAA server is the AAA server in the DN. This method includes the following steps:
[0172] Steps 401 to 405 are the same as Figure 3 Steps 301 to 305 in the embodiment.
[0173] Step 406, the SMF sends a policy association establishment request to the PCF. Correspondingly, the PCF receives the policy association establishment request.
[0174] This policy association establishment request is used to request to obtain the policies related to the session.
[0175] Exemplarily, this policy association establishment request may be an SM Policy Association EstablishmentRequest.
[0176] Among them, the policy association establishment request contains a second parameter, and this second parameter is used to determine the AAA server. This second parameter is obtained based on the first parameter.
[0177] The second parameter may include one or more of the following information 1) to 4):
[0178] 1) Identification information of the UE.
[0179] 2) The first user identification.
[0180] 3) Domain name information in the first user identification.
[0181] 4) Application information corresponding to the first user identification.
[0182] Step 407, the PCF determines the AAA server according to the second parameter.
[0183] In a possible implementation, the PCF directly determines the AAA server according to the second parameter. For example, if the second parameter includes the first user identification or the domain name information in the first user identification, the PCF may determine the AAA server corresponding to the domain name information according to the domain name information in the first user identification. For another example, if the second parameter includes the identification information of the AAA server, the PCF determines the AAA server according to the identification information of the AAA server.
[0184] In another possible implementation, the PCF requests the UDR to obtain the identification information of the AAA server. The specific implementation process of storing the identification information of the AAA server in the UDR can refer to Figure 5 or Figure 6 the description of the embodiments. For the specific implementation manner of the PCF requesting the UDR to obtain the identification information of the AAA server, reference can be made to Figure 5 or Figure 6 the relevant description in the embodiments.
[0185] Step 408, the PCF sends a policy association establishment response to the SMF. Correspondingly, the SMF receives the policy association establishment response.
[0186] Among them, if the PCF determines that authentication needs to be performed, the identification information of the AAA server is carried in the policy association establishment response. Optionally, the policy association establishment response further includes indication information for indicating the execution of authentication.
[0187] Step 409, an N4 session is established.
[0188] This step 509 is an optional step. When there is no existing N4 session available for transmitting messages between the SMF and the DN, the SMF selects a UPF and triggers the establishment of an N4 session.
[0189] Step 410, authentication is performed between the UE and the AAA server.
[0190] Among them, if the above-mentioned policy association establishment response contains indication information for indicating the execution of authentication, the SMF determines that authentication needs to be executed according to the indication information. If the above-mentioned policy association establishment response does not contain indication information for indicating the execution of authentication, the SMF determines whether authentication needs to be executed according to the identification information of the AAA server.
[0191] Exemplarily, authentication is executed between the UE and the AAA server through the AMF, SMF, and UPF. After successful authentication, the AAA server sends information indicating successful authentication to the SMF. For the detailed process of authentication between the UE and the AAA server, reference can be made to the relevant descriptions of the prior art, which will not be elaborated here.
[0192] In a possible implementation manner, in order to ensure security and privacy, the first parameter in the foregoing step 404 may not include the first user identifier or include an incomplete first user identifier. Instead, during the authentication process, the UE provides the first user identifier to the AAA server. Then, after successful authentication, the AAA server sends the first user identifier to the SMF. Thus, the SMF obtains the corresponding QoS requirement information according to the first user identifier and completes the subsequent session establishment process based on the QoS requirement information to achieve QoS guarantee.
[0193] Step 411, when authentication is successful, the SMF continues to complete the subsequent session establishment process.
[0194] In the above solution, it can be implemented to establish a PDU session based on the granularity of the user identifier, and further achieve differential QoS guarantee according to the granularity of the user identifier, improving the fineness and flexibility of QoS guarantee. Moreover, for the scenario where multiple AAA servers are deployed within the same DN, in this solution, the UE provides the first parameter to the SMF, and then the SMF provides the second parameter to the PCF, enabling the PCF to determine the AAA server for providing authentication for the UE from multiple AAA servers within the same DN based on the second parameter, achieving accurate determination of the AAA server for authentication. In addition, it can also be implemented that after successful authentication, the AAA server sends the first user identifier to the SMF instead of the UE directly sending the first user identifier to the SMF, improving the security and privacy of the user identifier.
[0195] Figure 5 It is a flowchart of a communication method provided by an embodiment of the present application. This method can be used to store the identification information of the AAA server in the UDM and / or UDR. The method includes the following steps:
[0196] Step 501, the AF sends a request message to the NEF. Correspondingly, the NEF receives the request message.
[0197] Exemplarily, the request message may be a parameter provision creation request (e.g., Nnef_ParameterProvision_Create Request), or it may also be a parameter provision update request (e.g., Nnef_ParameterProvision_Update Request).
[0198] The request message includes one or more of the identification information of the application function (such as AF ID or AF address), the first user identification, user configuration information, service configuration information, the identification information of the AAA server (such as AAA server ID or AAA server address), or the identification information of the UE (e.g., SUPI). Among them, the user configuration information includes the first user identification and the identification information of the AAA server. Optionally, the user configuration information further includes QoS requirements. The service configuration information includes the identification information of the AAA server, and further includes the identification information of the application function and / or the identification information of the application function service.
[0199] Step 502, the NEF sends a request message to the UDM. Correspondingly, the UDM receives the request message.
[0200] Exemplarily, the request message may be a parameter provision creation request (e.g., Nudm_ParameterProvision_Create Request), or it may also be a parameter provision update request (e.g., Nudm_ParameterProvision_Update Request).
[0201] The request message includes one or more of the identification information of the application function, the first user identification, user configuration information, service configuration information, the identification information of the AAA server, or the identification information of the UE.
[0202] As a first implementation method, the UDM determines the subscribed data corresponding to the identification information of the UE and determines the user configuration information in the subscribed data. Based on this first implementation method, then Figure 3In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, the SMF sends a query request to the UDM, and the query request includes the identification information of the UE and the first user identification. The UDM determines the subscription data corresponding to the identification information of the UE according to the identification information of the UE, and then the UDM determines the user configuration information corresponding to the first user identification from the subscription data, and sends the identification information of the AAA server included in the user configuration information to the SMF. Alternatively, the SMF sends a query request to the UDM, and the query request includes the identification information of the UE. The UDM determines the subscription data corresponding to the identification information of the UE according to the identification information of the UE, and sends the subscription data to the SMF. The SMF determines the user configuration information corresponding to the first user identification from the subscription data, and determines the identification information of the AAA server included in the user configuration information.
[0203] As a second implementation method, the UDM determines the user configuration information corresponding to the user identification according to the user identification. Based on this second implementation method, Figure 3 In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, the SMF sends a query request to the UDM, and the query request includes the first user identification. The UDM determines the user configuration information corresponding to the first user identification according to the first user identification, and sends the identification information of the AAA server included in the user configuration information to the SMF. Alternatively, the SMF sends a query request to the UDM, and the query request includes the first user identification. The UDM determines the user configuration information corresponding to the first user identification according to the first user identification, and then the UDM sends the user configuration information to the SMF. The SMF determines the identification information of the AAA server included in the user configuration information.
[0204] As a third implementation method, the UDM determines the service configuration information according to the service identification information. Based on this third implementation method, Figure 3In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, it may be that the SMF sends a query request to the UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service according to the identification information of the application function and / or the identification information of the application function service, and sends the identification information of the AAA server included in the service configuration information to the SMF. Or, the SMF sends a query request to the UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service according to the identification information of the application function and / or the identification information of the application function service, and then the UDM sends the service configuration information to the SMF, and the SMF determines the identification information of the AAA server included in the service configuration information.
[0205] As a fourth implementation method, the UDM stores the association information between the identification information of the AAA server and the index information. The index information includes one or more of the following information: the identification information of the application function, the first user identification, or the identification information of the UE. Based on this fourth implementation method, Figure 3 In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, it may be that the SMF sends a query request to the UDM, and the query request includes the index information. The UDM determines the identification information of the AAA server corresponding to the index information according to the index information and sends the identification information of the AAA server to the SMF.
[0206] Step 503, the UDM stores part of the information in the UDR.
[0207] This step 503 is an optional step.
[0208] As a first implementation method, the UDM stores the user configuration information in the UDR.
[0209] Based on this first implementation method, Figure 3In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, it can be that the SMF sends a query request to the UDM, and the query request includes the first user identifier. The UDM sends a query request to the UDR, and the query request includes the first user identifier. The UDR obtains the user configuration information corresponding to the first user identifier according to the first user identifier, and sends the identifier information of the AAA server included in the user configuration information to the UDM. Then the UDM sends the identifier information of the AAA server to the SMF. Or, the SMF sends a query request to the UDM, and the query request includes the first user identifier. The UDM sends a query request to the UDR, and the query request includes the first user identifier. The UDR determines the user configuration information corresponding to the first user identifier according to the first user identifier, and then the UDR sends the user configuration information to the UDM. The UDM then sends the user configuration information to the SMF, and the SMF determines the identifier information of the AAA server included in the user configuration information.
[0210] Based on the first implementation method, then Figure 4 In step 407 of the embodiment, the PCF determines the AAA server according to the second parameter. For example, it can be that the PCF sends a query request to the UDR, and the query request includes the identifier information of the UE and the first user identifier. The UDR determines the subscribed data corresponding to the identifier information of the UE according to the identifier information of the UE, and then the UDR determines the user configuration information corresponding to the first user identifier in the subscribed data according to the first user identifier, and sends the identifier information of the AAA server included in the user configuration information to the PCF. Or, the PCF sends a query request to the UDR, and the query request includes the identifier information of the UE. The UDR obtains the subscribed data corresponding to the identifier information of the UE according to the identifier information of the UE, and then the UDR sends the subscribed data to the PCF. The PCF determines the user configuration information corresponding to the first user identifier in the subscribed data according to the first user identifier, and determines the identifier information of the AAA server included in the user configuration information.
[0211] As a second implementation method, the UDM stores the service configuration information in the UDR.
[0212] Based on the second implementation method, then Figure 3In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, the SMF sends a query request to the UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM sends a query request to the UDR, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service according to the identification information of the application function and / or the identification information of the application function service, and sends the identification information of the AAA server included in the service configuration information to the UDM. The UDM then sends the identification information of the AAA server to the SMF. Or, the SMF sends a query request to the UDM, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDM sends a query request to the UDR, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service according to the identification information of the application function and / or the identification information of the application function service, and then the UDR sends the service configuration information to the UDM. The UDM sends the service configuration information to the SMF, and the SMF determines the identification information of the AAA server included in the service configuration information.
[0213] Based on the second implementation method, then Figure 4 In step 407 of the embodiment, the PCF determines the AAA server according to the second parameter. For example, the PCF sends a query request to the UDR, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service according to the identification information of the application function and / or the identification information of the application function service, and sends the identification information of the AAA server included in the service configuration information to the PCF. Or, the PCF sends a query request to the UDR, and the query request includes the identification information of the application function and / or the identification information of the application function service. The UDR determines the service configuration information corresponding to the identification information of the application function and / or the identification information of the application function service according to the identification information of the application function and / or the identification information of the application function service, and then the UDR sends the service configuration information to the PCF. The PCF determines the identification information of the AAA server included in the service configuration information.
[0214] As a third implementation method, the UDM stores the association information between the identification information of the AAA server and the index information in the UDR. The index information includes one or more of the following information: the identification information of the application function, the first user identification, or the identification information of the UE.
[0215] Based on this third implementation method, Figure 3 In step 306 of the embodiment, the SMF determines the AAA server according to the first parameter. For example, it can be that the SMF sends a query request to the UDM, and the query request includes index information. The UDM sends a query request to the UDR, and the query request includes index information. The UDR determines the identification information of the AAA server corresponding to the index information according to the index information and sends the identification information of the AAA server to the UDM. The UDM then sends the identification information of the AAA server to the SMF.
[0216] Based on this third implementation method, Figure 4 In step 407 of the embodiment, the PCF determines the AAA server according to the second parameter. For example, it can be that the PCF sends a query request to the UDR, and the query request includes index information. The UDR determines the identification information of the AAA server corresponding to the index information from the UDR according to the index information and sends the identification information of the AAA server to the PCF.
[0217] Step 504, the UDM sends a response message to the NEF. Correspondingly, the NEF receives the response message.
[0218] The response message can be a parameter provision establishment response (such as Nudm_ParameterProvision_CreateResponse), or it can also be a parameter provision update response (such as Nudm_ParameterProvision_Update Response).
[0219] Step 505, the NEF sends a response message to the AF. Correspondingly, the AF receives the response message.
[0220] Exemplarily, the response message can be a parameter provision establishment response (such as Nnef_ParameterProvision_Create Response), or it can also be a parameter provision update response (such as Nnef_ParameterProvision_Update Response).
[0221] The above solution can achieve storing the identification information of the AAA server in the UDM and / or UDR, so that the SMF can request the UDM to determine the identification information of the AAA server, and / or so that the PCF can request the UDR to determine the identification information of the AAA server.
[0222] Figure 6 It is a flowchart of a communication method provided by an embodiment of the present application. This method can achieve storing the identification information of the AAA server in the UDR. This method includes the following steps:
[0223] Step 601, AF sends a request message to the NEF. Correspondingly, the NEF receives the request message.
[0224] Exemplarily, the request message can be a service parameter creation request (such as Nnef_ServiceParameter_Create Request), or it can also be a service parameter update request (such as Nnef_ServiceParameter_Update Request).
[0225] The request message includes service description information and service parameters corresponding to the service description information.
[0226] Among them, the service description information is used to indicate the service. For example, the service description information includes at least one of the following information: identification information of the application (such as APP ID or APP address), identification information of the application server (such as APP server ID or APP server address), identification information of the application function service (such as AF service ID), or identification information of the application function (such as AF ID or AF address).
[0227] The service parameters are used to indicate the parameter information corresponding to the service. For example, the service parameters include the identification information of the AAA server, and the optional service parameters further include at least one of the first user identification, domain name information, or UE identification information.
[0228] Step 602, the NEF stores the service description information and the service parameters corresponding to the service description information in the UDR.
[0229] Exemplarily, Figure 4 In step 407 of the embodiment, the PCF determines the AAA server according to the second parameter. For example, it can be: the PCF sends a query request to the UDR, and the query request includes at least one of the UE identification information, the first user identification, the domain name information, the application identification information, the application server identification information, the application function service identification information, or the application function identification information. The UDR determines the identification information of the AAA server in the service parameters according to the query request and sends the identification information of the AAA server to the PCF.
[0230] Step 603, the NEF sends a response message to the AF. Correspondingly, the AF receives the response message.
[0231] Exemplarily, the response message can be a service parameter establishment response (e.g., Nnef_ServiceParameter_Create Response), or it can also be a service parameter update response (e.g., Nnef_ServiceParameter_Update Response).
[0232] The above solution can store the identification information of the AAA server in the UDR, enabling the PCF to request the UDR to determine the identification information of the AAA server.
[0233] Figure 7 The flowchart of a communication method provided by an embodiment of this application. In this method, the first user identification is assigned by the operator, and the SMF determines the identification information of the AAA server based on local configuration. This AAA server is not the AAA server in the DN, but the AAA server deployed by the operator, and this AAA server has nothing to do with the application service. This method includes the following steps:
[0234] Steps 701 to 705 are the same as Figure 3 Steps 301 to 305 of the embodiment.
[0235] In step 706, when the SMF determines that the PDU session requested to be established by the UE is a session established for the user identification managed by the operator and determines to perform authentication, it determines the identification information of the AAA server according to the first parameter.
[0236] The correspondence between the first parameter and the identification information of the AAA server is pre-configured on the SMF. Therefore, after the SMF obtains the first parameter, it can determine the corresponding identification information of the AAA server according to the first parameter. The AAA server here can refer to the AAA server deployed by the operator. Exemplarily, the SMF can determine that the AAA server needs to perform authentication according to the user identification included in the session establishment request and select the corresponding AAA server to perform the authentication process.
[0237] In step 707, the N4 session is established.
[0238] This step 709 is an optional step. When there is no existing N4 session available for transmitting messages between the SMF and the DN, the SMF selects a UPF and triggers the establishment of the N4 session.
[0239] In step 708, authentication is performed between the UE and the AAA server.
[0240] Exemplarily, authentication is performed between the UE and the AAA server via the AMF, SMF, and UPF. After successful authentication, the AAA server sends information indicating successful authentication to the SMF. For the detailed process of performing authentication between the UE and the AAA server, reference can be made to the relevant descriptions in the prior art, which will not be elaborated here.
[0241] In a possible implementation manner, to ensure security and privacy, the first parameter may not include the first user identifier or may include an incomplete first user identifier. Instead, during the authentication process, the UE provides the first user identifier to the AAA server. Then, after successful authentication, the AAA server sends the first user identifier to the SMF. Thus, the SMF obtains the corresponding QoS requirement information based on the first user identifier and completes the subsequent session establishment process based on the QoS requirement information to achieve QoS guarantee.
[0242] Step 709, when authentication is successful, the SMF continues to complete the subsequent session establishment process.
[0243] In the above solution, it can be implemented to establish a PDU session based on the granularity of the user identifier, and then achieve differentiated QoS guarantee according to the granularity of the user identifier, improving the fineness and flexibility of QoS guarantee. Moreover, for the scenario where the operator deploys multiple AAA servers, in this solution, the UE provides the first parameter to the SMF, and then the SMF determines the AAA server used for authenticating the UE according to the pre-configured information and the first parameter, achieving accurate determination of the AAA server for authentication. In addition, it can also be implemented that after successful authentication, the AAA server sends the first user identifier to the SMF instead of the UE directly sending the first user identifier to the SMF, enhancing the security and privacy of the user identifier.
[0244] It can be understood that to implement the functions in the above embodiments, the terminal device or the first network element includes the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, combined with the units and method steps of each example described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving the hardware depends on the specific application scenario and design constraint conditions of the technical solution.
[0245] Figure 8 and Figure 9A schematic structural diagram of a communication device provided by an embodiment of the present application. These communication devices can be used to implement the functions of the terminal device or the first network element in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments. In the embodiments of the present application, the communication device can be a terminal device or a first network element, or can be a module (such as a chip) applied to the terminal device or the first network element.
[0246] Figure 8 The communication device 800 shown in the figure includes a processing unit 810 and a transceiver unit 820. The communication device 800 is used to implement the functions of the terminal device or the first network element in the above method embodiments.
[0247] When the communication device 800 is used to implement the functions of the terminal device in the above method embodiments, the processing unit 810 is used to obtain a first user identifier, where the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account used to access an application on the terminal device; determine that a user plane connection needs to be newly established based on the first user identifier; the transceiver unit 820 is used to send a connection establishment request, and the connection establishment request is used to request to establish a user plane connection based on the first user identifier.
[0248] In a possible implementation method, the processing unit 810 is used to determine that a user plane connection needs to be newly established based on the first user identifier, specifically including: being used to determine the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes a second user identifier, the second user identifier in the service flow information matches the first user identifier, and the routing selection information includes the second user identifier; according to the second user identifier in the routing selection information, determine whether a user plane connection matching the second user identifier has been established; if a user plane connection matching the second user identifier has not been established, then determine that a user plane connection needs to be newly established based on the first user identifier.
[0249] In a possible implementation method, the processing unit 810 is further used to determine that a user plane connection needs to be newly established based on the first user identifier, specifically including: being used to determine the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes a second user identifier, the second user identifier in the service flow information matches the first user identifier, and the routing selection information includes the second user identifier; according to the second user identifier in the routing selection information, determine whether a user plane connection matching the second user identifier has been established; if the established user plane connections include a user plane connection matching the second user identifier, then use the user plane connection matching the second user identifier to transmit data corresponding to the first user identifier.
[0250] In a possible implementation method, the routing selection information further includes at least one of the following information: the domain name information in the first user identifier, the domain name information in the second user identifier, or the application information corresponding to the first user identifier.
[0251] In a possible implementation method, the processing unit 810 is configured to determine that a user plane connection needs to be newly established based on the first user identifier, specifically including: determining the policy information corresponding to the first user identifier, the policy information including traffic flow information and routing selection information, the traffic flow information including first domain name information, the first domain name information in the traffic flow information matching the second domain name information in the first user identifier, the routing selection information including indication information, the indication information indicating to establish different user plane connections for mutually unmatched user identifiers; judging whether a user plane connection matching the first user identifier has been established according to the indication information in the routing selection information; if a user plane connection matching the first user identifier has not been established, determining that a user plane connection needs to be newly established based on the first user identifier.
[0252] In a possible implementation method, the processing unit 810 is further configured to determine the policy information corresponding to the first user identifier, the policy information including traffic flow information and routing selection information, the traffic flow information including first domain name information, the first domain name information in the traffic flow information matching the second domain name information in the first user identifier, the routing selection information including indication information, the indication information indicating to establish different user plane connections for mutually unmatched user identifiers; judging whether a user plane connection matching the first user identifier has been established according to the indication information in the routing selection information; if the established user plane connections include a user plane connection matching the first user identifier, using the user plane connection matching the first user identifier to transmit the data corresponding to the first user identifier.
[0253] In a possible implementation method, the routing selection information further includes at least one of the following information: the first domain name information, the second domain name information, or the application information corresponding to the first user identifier.
[0254] In a possible implementation method, a processing unit 810 is configured to determine that a user plane connection needs to be newly established based on the first user identifier. Specifically, it includes: being configured to determine policy information corresponding to the first user identifier, where the policy information includes instructions to establish different user plane connections for user identifiers that do not match each other; according to the policy information, determining whether a user plane connection matching the first user identifier has been established; if a user plane connection matching the first user identifier has not been established, determining that a user plane connection needs to be newly established based on the first user identifier.
[0255] In a possible implementation method, the processing unit 810 is further configured to determine policy information corresponding to the first user identifier, where the policy information instructs to establish different user plane connections for user identifiers that do not match each other; according to the indication information in the routing selection information, determining whether a user plane connection matching the first user identifier has been established; if the established user plane connections include a user plane connection matching the first user identifier, using the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
[0256] In a possible implementation method, the policy information includes service flow information and routing selection information. The service flow information includes first information that matches any user identifier, and the routing selection information includes the indication information.
[0257] In a possible implementation method, the routing selection information further includes at least one of second information, third information, or fourth information. The second information instructs to send the first user identifier to the network, the third information instructs to send the domain name information in the first user identifier to the network, and the fourth information instructs to send the application information corresponding to the first user identifier to the network.
[0258] In a possible implementation method, the connection establishment request further includes a first parameter for determining an authentication server, and the authentication server is configured to perform authentication on the first user identifier.
[0259] In a possible implementation method, the connection establishment request is carried in a NAS message, and the NAS message further includes a first parameter for determining an authentication server, and the authentication server is configured to perform authentication on the first user identifier.
[0260] In a possible implementation method, the first parameter includes one or more of the following information: the first user identifier, the domain name information in the first user identifier, the identification information of the authentication server, or the application information corresponding to the first user identifier.
[0261] In a possible implementation method, the application information includes one or more of the following information: the identification information of the application, the identification information of the application server, the identification information of the application function service, the identification information of the application function, the identification information of the authentication server, or the domain name corresponding to the application.
[0262] In a possible implementation method, the processing unit 810 is configured to obtain a first user identifier, specifically including: obtaining the first user identifier from an application on the terminal device; or obtaining the first user identifier from the first device.
[0263] When the communication device 800 is used to implement the function of the first network element in the above method embodiment, the transceiver unit 820 is configured to receive a first parameter from the terminal device, where the first parameter includes one or more of the following information: the first user identifier, the domain name information in the first user identifier, or the application information corresponding to the first user identifier; wherein, the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account for accessing an application on the terminal device; the processing unit 810 is configured to determine an authentication server according to the first parameter, and the authentication server is used to perform authentication on the first user identifier.
[0264] In a possible implementation method, the processing unit 810 is configured to determine an authentication server according to the first parameter, specifically including: sending a first request including the first parameter to a unified data management network element or a unified database network element through the transceiver unit 820; and receiving a first response from the unified data management network element or the unified database network element, where the first response includes the identification information of the authentication server.
[0265] In a possible implementation method, the processing unit 810 is configured to determine an authentication server according to the first parameter, specifically including: determining the identification information of the authentication server corresponding to the first parameter according to pre-configured information, where the pre-configured information includes the correspondence between the first parameter and the identification information of the authentication server.
[0266] In a possible implementation method, the first network element is a policy control network element; the transceiver unit 820 is further configured to send the identification information of the authentication server to a session management network element.
[0267] In a possible implementation method, the transceiver unit 820 is further configured to send indication information to the session management network element, where the indication information indicates to perform authentication.
[0268] In a possible implementation method, the transceiver unit 820 is further configured to receive the first user identifier from the authentication server after successful authentication.
[0269] For a more detailed description of the above processing unit 810 and transceiver unit 820, reference can be directly made to the relevant descriptions in the above method embodiments, and no further elaboration will be provided here.
[0270] Figure 9 The illustrated communication device 900 includes a processor 910 and an interface circuit 920. The processor 910 and the interface circuit 920 are coupled to each other. It can be understood that the interface circuit 920 can be a transceiver or an input / output interface. Optionally, the communication device 900 may further include a memory 930 for storing instructions executed by the processor 910 or input data required for the processor 910 to run the instructions or data generated after the processor 910 runs the instructions.
[0271] When the communication device 900 is used to implement the above method embodiments, the processor 910 is used to implement the functions of the above processing unit 810, and the interface circuit 920 is used to implement the functions of the above transceiver unit 820.
[0272] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0273] The method steps in the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions may be composed of corresponding software modules, and the software modules may be stored in a random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC. Additionally, the ASIC may be located in an access network device or a terminal device. Of course, the processor and the storage medium may also exist as discrete components in the access network device or the terminal device.
[0274] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, an access network device, a terminal device, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.
[0275] In various embodiments of the present application, if there is no special description and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments according to their internal logical relationships.
[0276] In the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. In the written description of the present application, the character " / " generally represents an "or" relationship between the associated objects before and after; in the formulas of the present application, the character " / " represents a "division" relationship between the associated objects before and after.
[0277] It can be understood that the various numerical numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The magnitudes of the serial numbers of the above processes do not mean the sequence of execution, and the execution sequence of each process should be determined by its function and internal logic.
Claims
1. A communication method, characterized in that, Applied to a terminal device or a module of a terminal device, the method includes: Obtain a first user identifier, where the first user identifier represents a user using the terminal device, or represents a first device connected to the terminal device, or represents a user account for accessing an application on the terminal device; Determine that a user plane connection needs to be newly established based on the first user identifier, and then send a connection establishment request, where the connection establishment request is used to request to establish a user plane connection based on the first user identifier.
2. The method according to claim 1, characterized in that The determination that a user plane connection needs to be newly established based on the first user identifier includes: Determine the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes a second user identifier, and the second user identifier in the service flow information matches the first user identifier, and the routing selection information includes the second user identifier; According to the second user identifier in the routing selection information, determine whether a user plane connection matching the second user identifier has been established; If a user plane connection matching the second user identifier has not been established, determine that a user plane connection needs to be newly established based on the first user identifier.
3. The method according to claim 1, wherein The method further includes: Determine the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes a second user identifier, and the second user identifier in the service flow information matches the first user identifier, and the routing selection information includes the second user identifier; According to the second user identifier in the routing selection information, determine whether a user plane connection matching the second user identifier has been established; If the established user plane connections include a user plane connection matching the second user identifier, use the user plane connection matching the second user identifier to transmit data corresponding to the first user identifier.
4. The method according to claim 3, wherein The routing selection information further includes at least one of the following information: domain name information in the first user identifier, domain name information in the second user identifier, or application information corresponding to the first user identifier.
5. The method according to claim 1, characterized in that, The determination that a user plane connection needs to be newly established based on the first user identifier includes: Determine the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes first domain name information, the first domain name information in the service flow information matches the second domain name information in the first user identifier, and the routing selection information includes indication information, and the indication information indicates to establish different user plane connections for user identifiers that do not match each other; According to the indication information in the routing selection information, determine whether a user plane connection matching the first user identifier has been established; If a user plane connection matching the first user identifier has not been established, determine that a user plane connection needs to be newly established based on the first user identifier.
6. The method according to claim 1, wherein The method further includes: Determine the policy information corresponding to the first user identifier, where the policy information includes service flow information and routing selection information, the service flow information includes first domain name information, and the first domain name information in the service flow information matches the second domain name information in the first user identifier. The routing selection information includes indication information, and the indication information indicates to establish different user plane connections for user identifiers that do not match each other. According to the indication information in the routing selection information, determine whether a user plane connection matching the first user identifier has been established. If the established user plane connections include a user plane connection matching the first user identifier, use the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
7. The method according to claim 5 or 6, characterized in that The routing selection information further includes at least one of the following information: the first domain name information, the second domain name information, or the application information corresponding to the first user identifier.
8. The method according to claim 1, characterized in that, The determination of the need to newly establish a user plane connection based on the first user identifier includes: Determine the policy information corresponding to the first user identifier, where the policy information includes indication information to establish different user plane connections for user identifiers that do not match each other. According to the policy information, determine whether a user plane connection matching the first user identifier has been established. If a user plane connection matching the first user identifier has not been established, determine that a new user plane connection needs to be established based on the first user identifier.
9. The method according to claim 1, characterized in that, The method further includes: Determine the policy information corresponding to the first user identifier, where the policy information indicates to establish different user plane connections for user identifiers that do not match each other. According to the indication information in the routing selection information, determine whether a user plane connection matching the first user identifier has been established. If the established user plane connections include a user plane connection matching the first user identifier, use the user plane connection matching the first user identifier to transmit data corresponding to the first user identifier.
10. The method according to claim 8 or 9, characterized in that The policy information includes service flow information and routing selection information. The service flow information includes first information, and the first information matches any user identifier. The routing selection information includes the indication information.
11. The method according to claim 10, characterized in that, The routing selection information further includes at least one of the second information, the third information, or the fourth information. The second information indicates to send the first user identifier to the network, the third information indicates to send the domain name information in the first user identifier to the network, and the fourth information indicates to send the application information corresponding to the first user identifier to the network.
12. The method according to any one of claims 1 to 11, characterized in that, The connection establishment request further includes a first parameter for determining an authentication server, and the authentication server is used to perform authentication on the first user identifier.
13. The method according to any one of claims 1 to 11, characterized in that The connection establishment request is carried in a non-access stratum (NAS) message, and the NAS message further includes a first parameter for determining an authentication server, and the authentication server is used to perform authentication on the first user identifier.
14. The method according to claim 12 or 13, characterized in that, The first parameter includes one or more of the following information: the first user identifier, the domain name information in the first user identifier, the identifier information of the authentication server, or the application information corresponding to the first user identifier.
15. The method according to claim 4, 7, 11 or 14, characterized in that The application information includes one or more of the following information: the identifier information of the application, the identifier information of the application server, the identifier information of the application function service, the identifier information of the application function, the identifier information of the authentication server, or the domain name corresponding to the application.
16. The method according to any one of claims 1 to 15, characterized in that, The obtaining of the first user identifier includes: obtaining the first user identifier from an application on the terminal device; or, obtaining the first user identifier from the first device.
17. A communication method, characterized in that, Applied to a first network element or a module of a first network element, the method includes: receiving a first parameter from a terminal device, the first parameter including one or more of the following information: a first user identifier, the domain name information in the first user identifier, or the application information corresponding to the first user identifier; wherein, the first user identifier represents the user using the terminal device, or represents the first device connected to the terminal device, or represents the user account for accessing the application on the terminal device; determining an authentication server according to the first parameter, the authentication server being used to perform authentication on the first user identifier.
18. The method according to claim 17, wherein The determining of the authentication server according to the first parameter includes: sending a first request to a unified data management network element or a unified database network element, the first request including the first parameter; receiving a first response from the unified data management network element or the unified database network element, the first response including the identifier information of the authentication server.
19. The method according to claim 17, wherein The determining of the authentication server according to the first parameter includes: determining the identifier information of the authentication server corresponding to the first parameter according to pre-configured information, the pre-configured information including the correspondence between the first parameter and the identifier information of the authentication server.
20. The method according to any one of claims 17 to 19, characterized in that, The first network element is a policy control network element; the method further includes: sending the identifier information of the authentication server to a session management network element.
21. The method according to claim 20, wherein The method further includes: sending indication information to the session management network element, the indication information indicating to perform authentication.
22. The method according to any one of claims 17 to 21, characterized in that, The method further includes: after successful authentication, receiving the first user identifier from the authentication server.
23. A communication device, characterized in that, Includes a module for executing the method according to any one of claims 1 to 16, or executing the method according to any one of claims 17 to 22.
24. A communication device, characterized in that, Includes a processor and an interface circuit, the processor being used to communicate with other devices through the interface circuit and execute the method according to any one of claims 1 to 16, or execute the method according to any one of claims 17 to 22.
25. A computer program product, characterized in that, The computer program product includes instructions that, when run on a processor, cause the processor to execute the method according to any one of claims 1 to 16, or execute the method according to any one of claims 17 to 22.
26. A computer-readable storage medium, characterized in that, A computer program or instructions are stored in the storage medium, and when the computer program or instructions are executed by a communication device, the method described in any one of claims 1 to 16 or the method described in any one of claims 17 to 22 is implemented.