Terminal access method, device, equipment, medium and program product
Through the DU on the RAN side, the redundant message transmission between the DU and the CU is reduced, the terminal access process is optimized, the problem of terminal access delay in 5G wireless network is solved, and the fast and secure terminal access is achieved.
Patent Information
- Application Number
- CN202410229332.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-08-29
AI Technical Summary
In the prior art, there is a redundant message transmission process between the base station CU and the DU of the 5G wireless network, resulting in an increase in terminal access delay.
Through the DU on the RAN side, the redundant message transmission process between the DU and the CU is reduced, and the AS security mode activation, RRC connection reconfiguration and NAS message transmission are performed in parallel, thereby optimizing the terminal access process.
Simplify signaling transmission process, reduce terminal access delay, and achieve fast and secure terminal access.
Smart Images

Figure CN120568433A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a terminal access method, apparatus, device, computer-readable storage medium, and computer program product. Background Art
[0002] The base station of a 5G wireless network consists of a CU (Centralized Unit) and a DU (Distributed Unit). The CU and DU exchange control and data information through the F1 interface. The CU is responsible for sending high-level RRC (Radio Resource Control) signaling. NAS (Non-Access Stratum) messages between the UE (User Equipment) and the core network are also included in RRC messages for transmission and need to be carried over SRB2.
[0003] In the prior art, the terminal access process involves a serial process between three network elements: AMF (Access and Mobility Management Function), CU, and DU. RRC messages need to interact between the DU and CU. Although the NAS messages transmitted through SRB2 are included in the RRC messages, these NAS messages do not include any RRC protocol control information. This means that the RRC message at this time is only a carrier of a NAS message, resulting in redundant transmission of some messages between the DU and CU, thereby increasing the latency of terminal access. Summary of the Invention
[0004] The present invention provides a terminal access method, apparatus, device, medium and program product to solve the technical problem in the prior art that the terminal access delay is affected by redundant message transmission processes between DU and CU.
[0005] In order to solve the above technical problem, a first aspect of an embodiment of the present invention provides a terminal access method, which is performed by an access terminal and includes:
[0006] When the RRC connection with the RAN side is established, an initial UE message is sent to the core network through the DU on the RAN side; wherein the initial UE message is used to send an attach request to the core network and instruct it to perform a terminal authentication process;
[0007] receiving an RRC connection reconfiguration indication message and a downlink message transmission signaling sent by the DU; wherein the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters; the downlink message transmission signaling is sent by the core network through the DU when the terminal authentication is passed, and carries an attach accept NAS message;
[0008] Activate the AS security mode according to the AS layer security activation parameter;
[0009] When the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters, and in response to the downlink message transmission signaling, an uplink NAS transmission signaling is sent to the core network through the DU to complete the terminal access process; wherein, the uplink NAS transmission signaling carries the attachment completion NAS message and the bearer activation message.
[0010] As a preferred solution, the method further comprises:
[0011] receiving first indication information sent by the RAN side; wherein the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, or the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, and includes a list of services on the RAN side that allow the terminal fast access method; when the RAN side meets the terminal fast access condition, the DU supports direct interaction with the core network;
[0012] Determining a terminal access mode based on the first indication information; wherein the terminal access mode includes the terminal quick access mode and the traditional terminal access mode;
[0013] When the RRC connection establishment with the RAN side is completed, the second indication information for indicating the terminal access mode is sent to the RAN side to instruct the RAN side to perform the terminal access process according to the terminal access mode.
[0014] As a preferred solution, the method further comprises:
[0015] If the RAN side meets the terminal fast access condition, when the RRC connection establishment between the RAN side and the RAN side is completed, instructing the RAN side not to perform AS layer encryption and decryption through the second indication information;
[0016] If the RAN side does not meet the terminal fast access condition, when the RRC connection between the RAN side is established, the second indication information is used to instruct the RAN side to perform AS layer encryption and decryption, and when the AS security mode activation is completed, each downlink message transmission signaling received from the RAN side is AS downlink decrypted to obtain the NAS message carried by each downlink message transmission signaling; wherein the decryption information required for performing the AS downlink decryption is obtained during the AS security mode activation process.
[0017] As a preferred solution, the method further comprises:
[0018] receiving a NAS security mode command sent by the DU; wherein the NAS security mode command is sent by the core network through the DU when the terminal is authenticated, and carries a NAS layer security algorithm;
[0019] Performing integrity protection check on the NAS security mode command;
[0020] When it is determined that the integrity protection check of the NAS security mode command passes, NAS security mode activation is performed according to the NAS layer security algorithm, and a NAS security mode activation completion message is sent to the core network through the DU.
[0021] A second aspect of an embodiment of the present invention provides a terminal access method, which is performed by a DU on the RAN side and includes:
[0022] When the RRC connection establishment between the access terminal and the core network is completed, an initial UE message is sent to the core network; wherein the initial UE message is used to send an attach request of the access terminal to the core network and instruct it to perform a terminal authentication process;
[0023] In response to a context establishment request sent by the CU, instruct the access terminal to activate AS security mode and reconfigure the RRC connection, and upon receiving downlink NAS transmission signaling carrying an attach accept NAS message sent by the core network, forward the attach accept NAS message to the access terminal; wherein the context establishment request is sent by the core network at the instruction of the CU when the terminal is authenticated; and the downlink NAS transmission signaling is sent by the core network when the terminal is authenticated;
[0024] When detecting that the access terminal completes AS security mode activation and RRC connection reconfiguration, sending a RAN side context establishment success message to the core network through the CU;
[0025] When receiving the uplink message transmission signaling carrying the attach complete NAS message and the bearer activation message sent by the access terminal, the attach complete NAS message and the bearer activation message are forwarded to the core network to complete the terminal access process.
[0026] As a preferred solution, the method further comprises:
[0027] Sending first indication information indicating whether the RAN side meets the terminal fast access condition to the access terminal, or sending first indication information indicating whether the RAN side meets the terminal fast access condition and including a list of services on the RAN side that allow the terminal fast access method to the access terminal; wherein, when the terminal fast access condition is met, direct interaction with the core network is supported;
[0028] When receiving the second indication information sent by the access terminal for indicating the terminal access mode, the terminal access process is executed according to the terminal access mode; wherein the terminal access mode includes a terminal quick access mode and a traditional terminal access mode, which is determined by the access terminal based on the first indication information.
[0029] As a preferred solution, the method further comprises:
[0030] If the terminal access mode indicated by the received second indication information is the terminal fast access mode, upon receiving downlink NAS transmission signaling carrying the NAS message, directly forwarding the NAS message to the access terminal through downlink message transmission signaling;
[0031] If the terminal access mode indicated by the received second indication information is the traditional terminal access mode, upon detecting that the access terminal completes AS security mode activation and receives downlink NAS transmission signaling carrying a NAS message, the NAS message is forwarded to the access terminal through the downlink message transmission signaling after AS downlink encryption.
[0032] As a preferred solution, the method further comprises:
[0033] When receiving the RRC connection request sent by the access terminal, sending an initial uplink RRC message including terminal bottom layer configuration information and terminal dynamic identifier to the CU;
[0034] Receive a downlink RRC message sent by the CU, and obtain the F1 interface identifier of the access terminal from the downlink RRC message to complete access terminal information interaction with the CU.
[0035] As a preferred solution, the method further comprises:
[0036] When receiving a NAS security mode command carrying a NAS layer security algorithm sent by the core network, forwarding the NAS security mode command to the access terminal; wherein the NAS security mode command is sent by the core network when the terminal is authenticated, and is used to instruct the access terminal to activate the NAS security mode;
[0037] When the NAS security mode activation completion message sent by the access terminal is received, the NAS security mode activation completion message is forwarded to the core network.
[0038] A third aspect of an embodiment of the present invention provides a terminal access method, which is performed by a core network and includes:
[0039] In response to an initial UE message received from the DU on the RAN side, performing a terminal authentication process; wherein the initial UE message carries an attach request NAS message and a device identification code of the access terminal;
[0040] When the terminal passes authentication, an initial context establishment request is sent to the CU, and a downlink message transmission signaling carrying an attach accept NAS message is sent to the access terminal through the DU; wherein the initial context establishment request is used to instruct the RAN side to perform a context establishment process;
[0041] When a RAN side context establishment success message sent by the CU and an uplink NAS transmission signaling sent by the DU are received, it is determined that the terminal access process is completed; wherein the uplink NAS transmission signaling is sent by the access terminal through the DU in response to the downlink message transmission signaling, and carries an attach complete NAS message and a bearer activation message.
[0042] As a preferred solution, the method further comprises:
[0043] When the terminal passes authentication, a NAS security mode command carrying the NAS layer security algorithm is generated;
[0044] Integrity-protect the NAS security mode command and send it to the access terminal through the DU; wherein the NAS security mode command is used to instruct the access terminal to activate the NAS security mode;
[0045] When a NAS security mode activation completion message sent by the DU is received, it is determined that the access terminal has completed the NAS security mode activation; wherein the NAS security mode activation completion message is sent by the access terminal through the DU when the NAS security mode activation is completed.
[0046] A fourth aspect of an embodiment of the present invention provides a terminal access device, including:
[0047] The attachment request sending module is used to:
[0048] When the RRC connection with the RAN side is established, an initial UE message is sent to the core network through the DU on the RAN side; wherein the initial UE message is used to send an attach request to the core network and instruct it to perform a terminal authentication process;
[0049] Signaling receiving module, used for:
[0050] receiving an RRC connection reconfiguration indication message and a downlink message transmission signaling sent by the DU; wherein the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters; the downlink message transmission signaling is sent by the core network through the DU when the terminal authentication is passed, and carries an attach accept NAS message;
[0051] Signaling response module, used for:
[0052] Activate the AS security mode according to the AS layer security activation parameter;
[0053] When the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters, and in response to the downlink message transmission signaling, an uplink NAS transmission signaling is sent to the core network through the DU to complete the terminal access process; wherein, the uplink NAS transmission signaling carries the attachment completion NAS message and the bearer activation message.
[0054] A fifth aspect of an embodiment of the present invention provides a terminal access device, including:
[0055] The terminal attachment request sending module is used to:
[0056] When the RRC connection establishment between the access terminal and the core network is completed, an initial UE message is sent to the core network; wherein the initial UE message is used to send an attach request of the access terminal to the core network and instruct it to perform a terminal authentication process;
[0057] Terminal context establishment module, used to:
[0058] In response to a context establishment request sent by the CU, instruct the access terminal to activate AS security mode and reconfigure the RRC connection, and upon receiving downlink NAS transmission signaling carrying an attach accept NAS message sent by the core network, forward the attach accept NAS message to the access terminal; wherein the context establishment request is sent by the core network at the instruction of the CU when the terminal is authenticated; and the downlink NAS transmission signaling is sent by the core network when the terminal is authenticated;
[0059] Signaling transmission module, used for:
[0060] When detecting that the access terminal completes AS security mode activation and RRC connection reconfiguration, sending a RAN side context establishment success message to the core network through the CU;
[0061] When receiving the uplink message transmission signaling carrying the attach complete NAS message and the bearer activation message sent by the access terminal, the attach complete NAS message and the bearer activation message are forwarded to the core network to complete the terminal access process.
[0062] A sixth aspect of an embodiment of the present invention provides a terminal access device, including:
[0063] Terminal authentication module, used for:
[0064] In response to an initial UE message received from the DU on the RAN side, performing a terminal authentication process; wherein the initial UE message carries an attach request NAS message and a device identification code of the access terminal;
[0065] Terminal access indication module, used to:
[0066] When the terminal passes authentication, an initial context establishment request is sent to the CU, and a downlink message transmission signaling carrying an attach accept NAS message is sent to the access terminal through the DU; wherein the initial context establishment request is used to instruct the RAN side to perform a context establishment process;
[0067] When a RAN side context establishment success message sent by the CU and an uplink NAS transmission signaling sent by the DU are received, it is determined that the terminal access process is completed; wherein the uplink NAS transmission signaling is sent by the access terminal through the DU in response to the downlink message transmission signaling, and carries an attach complete NAS message and a bearer activation message.
[0068] A seventh aspect of an embodiment of the present invention provides a terminal access device, comprising a memory, a processor, and a computer program stored in the memory and runnable on the processor, wherein when the processor executes the computer program, it implements the terminal access method described in any one of the first aspects, or implements the terminal access method described in any one of the second aspects, or implements the terminal access method described in any one of the third aspects.
[0069] An eighth aspect of an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the terminal access method described in any one of the first aspects, or the terminal access method described in any one of the second aspects, or the terminal access method described in any one of the third aspects.
[0070] A ninth aspect of an embodiment of the present invention provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the terminal access method described in any one of the first aspects, or the terminal access method described in any one of the second aspects, or the terminal access method described in any one of the third aspects.
[0071] Compared with the existing technology, the beneficial effect of the embodiments of the present invention is that, in the terminal access process, the DU on the RAN side directly interacts with the core network, which can reduce the redundant message transmission process between the DU and the CU, thereby simplifying the signaling transmission process and reducing the terminal access delay; in addition, by executing AS security mode activation, RRC connection reconfiguration and NAS message transmission establishment in parallel, the terminal access process is optimized, further reducing the terminal access delay. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 is a schematic flow chart of a terminal access method executed by an access terminal in an embodiment of the present invention;
[0073] Figure 2 1 is a schematic diagram of a parallel process for terminal access in an embodiment of the present invention;
[0074] Figure 3 1 is a flow chart of a terminal access method executed by a DU on the RAN side in an embodiment of the present invention;
[0075] Figure 4 is a flow chart of a terminal access method executed by a core network in an embodiment of the present invention;
[0076] Figure 5 1 is a schematic structural diagram of a terminal access device applied to an access terminal in an embodiment of the present invention;
[0077] Figure 6 1 is a schematic structural diagram of a terminal access device for a DU applied to a RAN side in an embodiment of the present invention;
[0078] Figure 7 1 is a schematic structural diagram of a terminal access device applied to a core network in an embodiment of the present invention;
[0079] Figure 8 It is a structural diagram of a terminal access device in an embodiment of the present invention. DETAILED DESCRIPTION
[0080] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0081] See also Figure 1 and Figure 2 , Figure 1 is a flow chart of a terminal access method executed by an access terminal in an embodiment of the present invention, Figure 2 The first aspect of the present invention provides a terminal access method, which is executed by an access terminal and includes the following steps S11 to S14:
[0082] Step S11: When the RRC connection with the RAN side is established, an initial UE message is sent to the core network via the DU on the RAN side; wherein the initial UE message is used to send an attach request to the core network and instruct it to perform a terminal authentication process;
[0083] Step S12: receiving an RRC connection reconfiguration indication message and a downlink message transmission signaling sent by the DU; wherein the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters; the downlink message transmission signaling is sent by the core network through the DU when the terminal authentication is passed, and carries an attach accept NAS message;
[0084] Step S13, activating the AS security mode according to the AS layer security activation parameter;
[0085] Step S14, when the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters, and in response to the downlink message transmission signaling, an uplink NAS transmission signaling is sent to the core network through the DU to complete the terminal access process; wherein the uplink NAS transmission signaling carries an attachment completion NAS message and a bearer activation message.
[0086] Specifically, this embodiment first completes the RRC connection establishment with the RAN side (Radio Access Network), thereby completing the SRB1 radio bearer establishment and radio resource configuration, and then sends the initial UE message to the core network through the DU on the RAN side. Specifically, based on the SRB1 radio bearer, the RRC connection establishment completion signaling carrying the attachment request NAS message and the device identification code is sent to the DU on the RAN side. The RRC connection establishment completion signaling is RRC Connection SetupComplete signaling. Then, the DU on the RAN side responds to the RRC connection establishment completion signaling and sends the initial UE message carrying the attachment request NAS message and the device identification code to the AMF network element, thereby sending the attachment request of the access terminal to the core network and instructing it to perform the terminal authentication process. The initial UE message is Initial UE Message signaling.
[0087] Furthermore, an RRC connection reconfiguration indication message and downlink message transmission signaling, namely, an RRCConnectionReconfiguration message and a DL Information Transfer signaling, are received from the DU. Since the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters, in response to the RRC connection reconfiguration indication message, AS security mode activation is performed according to the AS layer security activation parameters. Specifically, this embodiment completes security activation based on the AS layer security activation parameters, such as the AS layer security algorithm, using user data in the SIM card, thereby completing PDCP layer key configuration. The keys include user plane integrity protection / verification keys, user plane encryption / decryption keys, signaling plane integrity protection / verification keys, and signaling plane encryption / decryption keys. Furthermore, an AS security mode activation completion message, namely, an RRC Security Mode Complete message, is fed back to the DU on the RAN side.
[0088] When the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters. At the same time, in response to the downlink message transmission signaling, the uplink NAS transmission signaling carrying the attachment completion NAS message and the bearer activation message is sent to the core network through the DU to complete the terminal access process. It can be understood that the reconfiguration parameters include SRB2 radio bearer configuration parameters, DRB data bearer configuration parameters and measurement configuration parameters. RRC connection reconfiguration is performed based on the reconfiguration parameters, thereby completing the establishment of SRB2 radio bearer and DRB data bearer. The SRB2 radio bearer is used to transmit RRC messages carrying NAS messages and is integrity protected and encrypted after the AS security mode is activated. When the RRC connection reconfiguration is completed, the RRC connection reconfiguration completion message, i.e., the RRC Connection Reconfiguration Complete message, is fed back to the DU on the RAN side. In addition, the process of establishing NAS message transmission in this embodiment is specifically as follows: first, in response to the downlink message transmission signaling, an uplink message transmission signaling carrying the attachment completion NAS message and the bearer activation message, i.e., UL Information Transfer signaling, is sent to the DU on the RAN side. Then, in response to the uplink message transmission signaling, the DU on the RAN side sends an uplink NAS transmission signaling carrying the attachment completion NAS message and the bearer activation message, i.e., UL NAS Transfer signaling, to the AMF network element, thereby completing the establishment of NAS message transmission.
[0089] It is worth noting that in this embodiment, the signaling transmission process corresponding to the activation of the AS security mode and the reconfiguration of the RRC connection is executed in parallel with the signaling transmission process corresponding to the establishment of the NAS message transmission. The parallelized signaling transmission process can significantly reduce the terminal access delay. In addition, in order to ensure the security of the NAS message on the access terminal side, this embodiment is designed to respond to the downlink message transmission signaling after the activation of the AS security mode is completed, and then send the uplink NAS transmission signaling to the core network through the DU. In this way, the access terminal can encrypt the RRC message carrying the NAS message transmitted by the SRB2 radio bearer through the PDCP layer, thereby achieving fast terminal access while ensuring the security of the NAS message.
[0090] It is worth noting that, in order to establish an RRC connection with the RAN side, this embodiment first sends an RRC connection request message, i.e., an RRC Connection Request message, to the DU on the RAN side. Upon receiving an RRC connection establishment indication message, i.e., an RRC Connection Setup message, sent by the DU, the DU establishes an RRC connection with the RAN side in response to the RRC connection establishment indication message. Upon completion, RRC connection establishment completion signaling is fed back to the DU.
[0091] It is worth noting that the device identification code sent when the RRC connection establishment with the RAN side is completed is specifically an ISMI code (International Mobile Equipment Identity).
[0092] The terminal access method provided in an embodiment of the present invention directly interacts with the core network through the DU on the RAN side during the terminal access process, which can reduce redundant message transmission processes between the DU and the CU, thereby simplifying the signaling transmission process and reducing the terminal access delay. In addition, by executing AS security mode activation, RRC connection reconfiguration and NAS message transmission establishment in parallel, the terminal access process is optimized, further reducing the terminal access delay.
[0093] As a preferred solution, the method further comprises:
[0094] receiving first indication information sent by the RAN side; wherein the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, or the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, and includes a list of services on the RAN side that allow the terminal fast access method; when the RAN side meets the terminal fast access condition, the DU supports direct interaction with the core network;
[0095] Determining a terminal access mode based on the first indication information; wherein the terminal access mode includes the terminal quick access mode and the traditional terminal access mode;
[0096] When the RRC connection establishment with the RAN side is completed, the second indication information for indicating the terminal access mode is sent to the RAN side to instruct the RAN side to perform the terminal access process according to the terminal access mode.
[0097] Specifically, since some wireless access networks may not have the terminal fast access conditions, that is, the DU on the RAN side does not support direct interaction with the core network, it is necessary to flexibly select the terminal access method based on the terminal access capability of the wireless access network before executing the terminal access process. First, receive the first indication information sent by the RAN side to indicate whether it has the terminal fast access conditions. Optionally, the first indication information also includes a list of services that the RAN side allows to use the terminal fast access method, so that the executing terminal can flexibly select the terminal access method based on its own business needs. Then, based on the first indication information, the terminal access method is determined, and when the RRC connection between the RAN side and the RAN side is established, the second indication information for indicating the terminal access method is sent to the RAN side. It can be understood that the terminal access method includes the terminal fast access method and the traditional terminal access method. The terminal fast access method is the terminal access process when the DU supports direct interaction with the core network, and the traditional terminal access method includes a total of 18 steps due to the redundant message transmission process between the DU and the CU, specifically: (1) The access terminal sends an RRC connection request message to the DU on the RAN side. (2) Upon receiving the RRC Connection Request message and accepting the access terminal, the DU initiates an Initial UL RRC Message Transfer message via the F1AP interface, which includes the terminal's underlying configuration information and the terminal's dynamic identifier assigned by the DU, and transmits it to the CU. (3) The CU assigns an F1 interface identifier, namely the gNB-CU UE F1AP ID, to the access terminal and generates an RRC Connection Establishment Indication message to the access terminal. This message is encapsulated in downlink RRC message transfer signaling, namely, F1AP DL RRC MESSAGE TRANSFER signaling. (4) The DU sends an RRC Connection Establishment Indication message to the access terminal. (5) After completing the RRC connection establishment, the access terminal sends an RRC Connection Establishment Complete message to the DU. (6) The DU encapsulates the RRC Connection Establishment Complete message in uplink RRC message transfer signaling, namely, F1AP UL RRC MESSAGE TRANSFER signaling, and sends it to the CU. (7) The CU sends the Initial UE Message to the AMF network element. (8) The AMF sends an Initial UE Context Setup Request message to the CU. (9) The CU sends a UE Context Setup Request message to the DU to establish the access terminal context in the DU. This message may also encapsulate an RRC Security Mode Command message. (10) The DU sends an RRC Security Mode Command message to the access terminal.(11) The DU sends the UE Context Setup Response message to the CU, which is a response to the UE Context Setup Request. (12) After completing the AS security mode activation, the access terminal responds with an RRC Security Mode Complete message. (13) The DU encapsulates the RRC Security Mode Complete message in the uplink RRC message transmission signaling, namely the F1AP UL RRC MESSAGE TRANSFER signaling, and sends it to the CU. (14) The CU generates an RRC connection reconfiguration indication message, namely the RRC Connection Reconfiguration message, and encapsulates it in the downlink RRC message transmission signaling, namely the F1AP DL RRC MESSAGE TRANSFER signaling. (15) The DU sends the RRC connection reconfiguration indication message to the access terminal. (16) After completing the RRC connection reconfiguration, the access terminal sends the RRC connection setup completion signaling, namely the RRC Connection Setup Complete signaling, to the DU, indicating that the context establishment is successful. (17) The DU encapsulates the RRC Connection Establishment Complete message in the uplink RRC message transmission signaling, namely F1AP ULRRC MESSAGE TRANSFER signaling, and sends it to the CU. (18) The CU sends the Initial UE Context Setup Response message to the AMF network element, which is a response to the Initial UE Context Setup Request.
[0098] The terminal access method provided in an embodiment of the present invention can flexibly determine the terminal access method based on the first indication information sent by the RAN side to indicate whether it meets the terminal quick access conditions, thereby achieving compatibility with the traditional 5G terminal access process.
[0099] As a preferred solution, the method further comprises:
[0100] If the RAN side meets the terminal fast access condition, when the RRC connection establishment between the RAN side and the RAN side is completed, instructing the RAN side not to perform AS layer encryption and decryption through the second indication information;
[0101] If the RAN side does not meet the terminal fast access condition, when the RRC connection between the RAN side is established, the second indication information is used to instruct the RAN side to perform AS layer encryption and decryption, and when the AS security mode activation is completed, each downlink message transmission signaling received from the RAN side is AS downlink decrypted to obtain the NAS message carried by each downlink message transmission signaling; wherein the decryption information required for performing the AS downlink decryption is obtained during the AS security mode activation process.
[0102] It is worth noting that, in the traditional 5G terminal access process, the NAS message will be encrypted twice during the transmission process, namely AS layer encryption and NAS layer encryption, and there is repeated encryption, which increases the terminal access delay. Therefore, this embodiment indicates whether the RAN side performs AS layer encryption and decryption based on whether the RAN side has the terminal fast access conditions. Specifically, if the RAN side has the terminal fast access conditions, then when the RRC connection between the RAN side is established, the second indication information instructs the RAN side not to perform AS layer encryption and decryption. Since the DU on the RAN side supports direct interaction with the core network in the terminal fast access process, the NAS message will not pass through the PDCP layer of the CU during transmission, and thus does not need to be encrypted through the AS layer. Only the NAS layer encryption is retained, avoiding repeated encryption, which helps to reduce the terminal access delay. If the RAN side does not meet the terminal fast access conditions, then when the RRC connection between the RAN side and the RAN side is established, the second indication information is used to instruct the RAN side to perform AS layer encryption and decryption. Because in the traditional terminal access process, the DU on the RAN side does not support direct interaction with the core network, the NAS message needs to pass through the PDCP layer of the CU during transmission and perform AS layer encryption. Therefore, when the AS security mode is activated, each downlink message transmission signaling received from the RAN side is AS downlink decrypted to obtain the NAS message carried by each downlink message transmission signaling. It can be understood that the decryption information required for performing AS downlink decryption is obtained during the AS security mode activation process.
[0103] The terminal access method provided in an embodiment of the present invention can effectively be compatible with the terminal fast access process and the 5G traditional terminal access process by negotiating with the wireless network whether the NAS message needs to perform AS layer encryption and decryption based on the terminal access capability on the RAN side.
[0104] As a preferred solution, the method further comprises:
[0105] receiving a NAS security mode command sent by the DU; wherein the NAS security mode command is sent by the core network through the DU when the terminal is authenticated, and carries a NAS layer security algorithm;
[0106] Performing integrity protection check on the NAS security mode command;
[0107] When it is determined that the integrity protection check of the NAS security mode command passes, NAS security mode activation is performed according to the NAS layer security algorithm, and a NAS security mode activation completion message is sent to the core network through the DU.
[0108] Specifically, in order to implement NAS layer encryption protection of NAS messages, this embodiment needs to activate the NAS security mode. First, the NAS security mode command sent by the DU is received. The command is sent directly by the core network through the DU when the terminal authentication is passed. It carries the NAS layer security algorithm. Furthermore, since the transmitted NAS security mode command is integrity protected, this embodiment needs to use the NAS layer security algorithm to perform integrity protection verification on the NAS security mode command to ensure that its security capabilities have not been tampered with by attackers. When it is determined that the integrity protection verification has passed, the NAS security mode is activated according to the NAS layer security algorithm, and the NAS security mode activation completion message is sent to the core network through the DU.
[0109] See also Figure 3 , Figure 3 The second aspect of the present invention provides a terminal access method, which is performed by the DU on the RAN side and includes the following steps S21 to S24:
[0110] Step S21: When the RRC connection establishment between the access terminal and the core network is completed, an initial UE message is sent to the core network; wherein the initial UE message is used to send an attach request of the access terminal to the core network and instruct it to perform a terminal authentication process;
[0111] Step S22: In response to the context establishment request sent by the CU, instruct the access terminal to activate the AS security mode and reconfigure the RRC connection, and upon receiving downlink NAS transmission signaling carrying the attach accept NAS message sent by the core network, forward the attach accept NAS message to the access terminal; wherein the context establishment request is sent by the core network at the instruction of the CU when the terminal authentication is passed; and the downlink NAS transmission signaling is sent by the core network when the terminal authentication is passed.
[0112] Step S23: When it is detected that the access terminal completes AS security mode activation and RRC connection reconfiguration, a RAN side context establishment success message is sent to the core network through the CU;
[0113] Step S24: When receiving the uplink message transmission signaling carrying the attach complete NAS message and the bearer activation message sent by the access terminal, forward the attach complete NAS message and the bearer activation message to the core network to complete the terminal access process.
[0114] It is worth noting that the context establishment request received from the CU encapsulates an RRC Security Mode Command message and an RRC Connection Reconfiguration message. Therefore, this embodiment responds to the context establishment request by sending RRC connection reconfiguration indication information carrying reconfiguration parameters and AS layer security activation parameters to the access terminal, thereby instructing the access terminal to activate the AS security mode and reconfigure the RRC connection. At the same time, when receiving the downlink NAS transmission signaling carrying the attach accept NAS message sent by the core network, the downlink message transmission signaling carrying the attach accept NAS message is sent to the access terminal to forward the attach accept NAS message to the access terminal.
[0115] Furthermore, after sending the RRC connection reconfiguration indication information to the access terminal, a UE Context Setup Response message is sent to the CU to respond to the UE Context Setup Request, indicating that the context of the access terminal in the DU has been successfully established. When the RRC Security Mode Complete message and RRC Connection Reconfiguration Complete message sent by the access terminal are received, it is determined that the access terminal has completed the AS security mode activation and RRC connection reconfiguration. At this time, an uplink RRC message transmission signaling carrying the RRC Security Mode Complete message and the RRC Connection Reconfiguration Complete message, namely, F1AP UL RRC MESSAGETRANSFER signaling, is sent to the CU, thereby combining the uplink RRC message transmission signaling encapsulated with the RRC Security Mode Complete message and the uplink RRC message transmission signaling encapsulated with the RRC Connection Setup Complete message in the traditional terminal access method, which helps to reduce the terminal access delay and at the same time informs the CU that the AS security mode activation and RRC connection reconfiguration are completed.
[0116] Furthermore, the CU sends a RAN side context establishment success message, namely the Initial UE Context SetupResponse message, to the AMF network element to respond to the Initial UE Context Setup Request, thereby informing the core network that the context establishment is successful.
[0117] The terminal access method provided by an embodiment of the present invention can reduce redundant message transmission processes with the CU by directly interacting with the core network during the terminal access process, thereby simplifying the signaling transmission process and reducing the terminal access delay; in addition, by executing AS security mode activation, RRC connection reconfiguration and NAS message transmission establishment in parallel, the terminal access process is optimized, further reducing the terminal access delay.
[0118] As a preferred solution, the method further comprises:
[0119] Sending first indication information indicating whether the RAN side meets the terminal fast access condition to the access terminal, or sending first indication information indicating whether the RAN side meets the terminal fast access condition and including a list of services on the RAN side that allow the terminal fast access method to the access terminal; wherein, when the terminal fast access condition is met, direct interaction with the core network is supported;
[0120] When receiving the second indication information sent by the access terminal for indicating the terminal access mode, the terminal access process is executed according to the terminal access mode; wherein the terminal access mode includes a terminal quick access mode and a traditional terminal access mode, which is determined by the access terminal based on the first indication information.
[0121] Specifically, to facilitate flexible selection of a terminal access mode by the access terminal, this embodiment broadcasts first indication information indicating whether the RAN side meets the terminal quick access conditions to the access terminal. As an optional embodiment, the first indication information also includes a list of services on the RAN side that allow the use of the terminal quick access mode, providing a reference for the access terminal to select a terminal access mode. Upon receiving second indication information indicating the terminal access mode sent by the access terminal, the terminal access process is executed according to the terminal access mode, which includes the terminal quick access mode and the traditional terminal access mode.
[0122] The terminal access method provided in an embodiment of the present invention, by sending a first indication information to the access terminal to indicate whether the RAN side has the terminal quick access conditions, can facilitate the access terminal to flexibly determine the terminal access method based on the first indication information, thereby achieving compatibility with the traditional 5G terminal access process.
[0123] As a preferred solution, the method further comprises:
[0124] If the terminal access mode indicated by the received second indication information is the terminal fast access mode, upon receiving downlink NAS transmission signaling carrying the NAS message, directly forwarding the NAS message to the access terminal through downlink message transmission signaling;
[0125] If the terminal access mode indicated by the received second indication information is the traditional terminal access mode, upon detecting that the access terminal completes AS security mode activation and receives downlink NAS transmission signaling carrying a NAS message, the NAS message is forwarded to the access terminal through the downlink message transmission signaling after AS downlink encryption.
[0126] Specifically, since in the traditional 5G terminal access process, the NAS message will be encrypted twice during the transmission process, namely AS layer encryption and NAS layer encryption, there is repeated encryption, which increases the terminal access delay. Therefore, this embodiment determines whether to perform AS layer encryption and decryption based on the terminal access mode indicated by the second indication information sent by the access terminal. Specifically, if the RAN side has the terminal fast access conditions, then when the RRC connection between the access terminal is established and the terminal access mode indicated by the received second indication information is the terminal fast access mode, since the DU itself supports direct interaction with the core network in the terminal fast access process, the NAS message will not pass through the PDCP layer of the CU during transmission, and thus does not need to be encrypted through the AS layer. Only the NAS layer encryption is retained, avoiding repeated encryption, which helps to reduce the terminal access delay. If the RAN side does not meet the terminal fast access conditions, then after the RRC connection establishment between the access terminal and the terminal access mode indicated by the received second indication information is a traditional terminal access mode, since the DU itself does not support direct interaction with the core network in the traditional terminal access process, the NAS message needs to pass through the PDCP layer of the CU during transmission and perform AS layer encryption. Therefore, when it is detected that the access terminal has completed AS security mode activation and receives downlink NAS transmission signaling carrying the NAS message, the NAS message is forwarded to the access terminal via the downlink message transmission signaling after AS downlink encryption. It can be understood that the encryption information required for performing AS downlink encryption is obtained during the AS security mode activation process.
[0127] The terminal access method provided in an embodiment of the present invention can effectively be compatible with the terminal fast access process and the 5G traditional terminal access process by negotiating with the access terminal whether the NAS message needs to perform AS layer encryption and decryption.
[0128] As a preferred solution, the method further comprises:
[0129] When receiving the RRC connection request sent by the access terminal, sending an initial uplink RRC message including terminal bottom layer configuration information and terminal dynamic identifier to the CU;
[0130] Receive a downlink RRC message sent by the CU, and obtain the F1 interface identifier of the access terminal from the downlink RRC message to complete access terminal information interaction with the CU.
[0131] Specifically, when this embodiment receives an RRC connection request sent by an access terminal and accepts the access terminal, it initiates an initial uplink RRC message, i.e., an Initial UL RRC Message Transaction, on the F1AP interface. The message includes terminal underlying configuration information and a terminal dynamic identifier, i.e., a C-RNTI (Cell-Radio Network Temporary Identifier), and transmits it to the CU. At this time, the CU allocates an F1 interface identifier, i.e., a gNB-CU UE F1AP ID, to the access terminal and encapsulates it in a downlink RRC message for transmission. Thus, when this embodiment receives a downlink RRC message sent by the CU, it can obtain the F1 interface identifier of the access terminal from it to complete the access terminal information exchange with the CU.
[0132] It is worth noting that if Figure 2 As shown, in this embodiment, the access terminal information interaction process with the CU and the RRC connection establishment process with the access terminal are executed in parallel, which helps to reduce the terminal access delay.
[0133] As a preferred solution, the method further comprises:
[0134] When receiving a NAS security mode command carrying a NAS layer security algorithm sent by the core network, forwarding the NAS security mode command to the access terminal; wherein the NAS security mode command is sent by the core network when the terminal is authenticated, and is used to instruct the access terminal to activate the NAS security mode;
[0135] When the NAS security mode activation completion message sent by the access terminal is received, the NAS security mode activation completion message is forwarded to the core network.
[0136] Specifically, since this embodiment interacts directly with the core network, during the NAS security mode activation process between the core network and the access terminal, the NAS security mode command sent by the core network can be directly received and forwarded to the access terminal, thereby saving redundant message transmission processes with the CU and helping to reduce terminal access delay.
[0137] See also Figure 4 , Figure 4 The third aspect of the present invention provides a terminal access method, which is executed by the core network and includes the following steps S31 to S33:
[0138] Step S31, performing a terminal authentication process in response to an initial UE message received from the DU on the RAN side; wherein the initial UE message carries an attach request NAS message and a device identification code of the access terminal;
[0139] Step S32: When the terminal passes authentication, an initial context establishment request is sent to the CU, and a downlink message transmission signaling carrying an attach accept NAS message is sent to the access terminal via the DU; wherein the initial context establishment request is used to instruct the RAN side to perform a context establishment process;
[0140] Step S33: When the RAN side context establishment success message sent by the CU and the uplink NAS transmission signaling sent by the DU are received, it is determined that the terminal access process is completed; wherein the uplink NAS transmission signaling is sent by the access terminal through the DU in response to the downlink message transmission signaling, and carries the attach complete NAS message and the bearer activation message.
[0141] Specifically, during the terminal authentication process, this embodiment generates an authentication vector based on the device identification code (i.e., ISMI code) in the initial UE message, then encrypts the key information in the authentication vector and generates an authentication response message. The authentication response message is sent to the access terminal via the DU on the RAN side, so that the access terminal calculates the authentication request. Finally, this embodiment determines whether the terminal authentication is successful based on the authentication request.
[0142] The terminal access method provided in an embodiment of the present invention can reduce redundant message transmission processes between the DU and the CU by directly interacting with the DU on the RAN side during the terminal access process, thereby simplifying the signaling transmission process, reducing the terminal access delay, and optimizing the terminal access process.
[0143] As a preferred solution, the method further comprises:
[0144] When the terminal passes authentication, a NAS security mode command carrying the NAS layer security algorithm is generated;
[0145] Integrity-protect the NAS security mode command and send it to the access terminal through the DU; wherein the NAS security mode command is used to instruct the access terminal to activate the NAS security mode;
[0146] When a NAS security mode activation completion message sent by the DU is received, it is determined that the access terminal has completed the NAS security mode activation; wherein the NAS security mode activation completion message is sent by the access terminal through the DU when the NAS security mode activation is completed.
[0147] Specifically, to implement NAS-layer encryption protection for NAS messages, this embodiment requires activating NAS security mode. First, upon successful terminal authentication, a NAS security mode command carrying a NAS-layer security algorithm is generated. The NAS security mode command is integrity-protected based on the NAS-layer security algorithm to prevent tampering with its security capabilities. The command is then directly sent to the access terminal via the DU, instructing the access terminal to activate NAS security mode. Receiving a NAS security mode activation completion message from the DU indicates that the access terminal has completed NAS security mode activation. Consequently, during subsequent NAS message transmissions, NAS-layer encryption and decryption can be performed on NAS messages based on the encryption and decryption information obtained during the NAS security mode activation process.
[0148] See also Figure 5 , Figure 5 1 is a schematic diagram of the structure of a terminal access device 100 applied to an access terminal in an embodiment of the present invention. A fourth aspect of an embodiment of the present invention provides a terminal access device 100, comprising:
[0149] The attachment request sending module 11 is configured to:
[0150] When the RRC connection with the RAN side is established, an initial UE message is sent to the core network through the DU on the RAN side; wherein the initial UE message is used to send an attach request to the core network and instruct it to perform a terminal authentication process;
[0151] The signaling receiving module 12 is configured to:
[0152] receiving an RRC connection reconfiguration indication message and a downlink message transmission signaling sent by the DU; wherein the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters; the downlink message transmission signaling is sent by the core network through the DU when the terminal authentication is passed, and carries an attach accept NAS message;
[0153] The signaling response module 13 is configured to:
[0154] Activate the AS security mode according to the AS layer security activation parameter;
[0155] When the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters, and in response to the downlink message transmission signaling, an uplink NAS transmission signaling is sent to the core network through the DU to complete the terminal access process; wherein, the uplink NAS transmission signaling carries the attachment completion NAS message and the bearer activation message.
[0156] As a preferred solution, the device further includes a terminal access mode indication module, which is used to:
[0157] receiving first indication information sent by the RAN side; wherein the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, or the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, and includes a list of services on the RAN side that allow the terminal fast access method; when the RAN side meets the terminal fast access condition, the DU supports direct interaction with the core network;
[0158] Determining a terminal access mode based on the first indication information; wherein the terminal access mode includes the terminal quick access mode and the traditional terminal access mode;
[0159] When the RRC connection establishment with the RAN side is completed, the second indication information for indicating the terminal access mode is sent to the RAN side to instruct the RAN side to perform the terminal access process according to the terminal access mode.
[0160] As a preferred solution, the device further includes an AS layer encryption and decryption indication module, which is used to:
[0161] If the RAN side meets the terminal fast access condition, when the RRC connection establishment between the RAN side and the RAN side is completed, instructing the RAN side not to perform AS layer encryption and decryption through the second indication information;
[0162] If the RAN side does not meet the terminal fast access condition, when the RRC connection between the RAN side is established, the second indication information is used to instruct the RAN side to perform AS layer encryption and decryption, and when the AS security mode activation is completed, each downlink message transmission signaling received from the RAN side is AS downlink decrypted to obtain the NAS message carried by each downlink message transmission signaling; wherein the decryption information required for performing the AS downlink decryption is obtained during the AS security mode activation process.
[0163] As a preferred solution, the signaling receiving module 12 is further configured to:
[0164] receiving a NAS security mode command sent by the DU; wherein the NAS security mode command is sent by the core network through the DU when the terminal is authenticated, and carries a NAS layer security algorithm;
[0165] The signaling response module 13 is further configured to:
[0166] Performing integrity protection check on the NAS security mode command;
[0167] When it is determined that the integrity protection check of the NAS security mode command passes, NAS security mode activation is performed according to the NAS layer security algorithm, and a NAS security mode activation completion message is sent to the core network through the DU.
[0168] The terminal access device 100 provided in an embodiment of the present invention directly interacts with the core network through the DU on the RAN side during the terminal access process, which can reduce the redundant message transmission process between the DU and the CU, thereby simplifying the signaling transmission process and reducing the terminal access delay; in addition, by executing AS security mode activation, RRC connection reconfiguration and NAS message transmission establishment in parallel, the terminal access process is optimized, further reducing the terminal access delay.
[0169] See also Figure 6 , Figure 6 1 is a schematic diagram of the structure of a terminal access device 200 for a DU on the RAN side according to an embodiment of the present invention. A fifth aspect of an embodiment of the present invention provides a terminal access device 200, including:
[0170] The terminal attachment request sending module 21 is used to:
[0171] When the RRC connection establishment between the access terminal and the core network is completed, an initial UE message is sent to the core network; wherein the initial UE message is used to send an attach request of the access terminal to the core network and instruct it to perform a terminal authentication process;
[0172] The terminal context establishing module 22 is used to:
[0173] In response to a context establishment request sent by the CU, instruct the access terminal to activate AS security mode and reconfigure the RRC connection, and upon receiving downlink NAS transmission signaling carrying an attach accept NAS message sent by the core network, forward the attach accept NAS message to the access terminal; wherein the context establishment request is sent by the core network at the instruction of the CU when the terminal is authenticated; and the downlink NAS transmission signaling is sent by the core network when the terminal is authenticated;
[0174] The signaling transmission module 23 is used to:
[0175] When detecting that the access terminal completes AS security mode activation and RRC connection reconfiguration, sending a RAN side context establishment success message to the core network through the CU;
[0176] When receiving the uplink message transmission signaling carrying the attach complete NAS message and the bearer activation message sent by the access terminal, the attach complete NAS message and the bearer activation message are forwarded to the core network to complete the terminal access process.
[0177] As a preferred solution, the device further includes a terminal access capability indication module, which is configured to:
[0178] Sending first indication information indicating whether the RAN side meets the terminal fast access condition to the access terminal, or sending first indication information indicating whether the RAN side meets the terminal fast access condition and including a list of services on the RAN side that allow the terminal fast access method to the access terminal; wherein, when the terminal fast access condition is met, direct interaction with the core network is supported;
[0179] When receiving the second indication information sent by the access terminal for indicating the terminal access mode, the terminal access process is executed according to the terminal access mode; wherein the terminal access mode includes a terminal quick access mode and a traditional terminal access mode, which is determined by the access terminal based on the first indication information.
[0180] As a preferred solution, the device further includes an AS layer encryption and decryption indication response module, which is used to:
[0181] If the terminal access mode indicated by the received second indication information is the terminal fast access mode, upon receiving downlink NAS transmission signaling carrying the NAS message, directly forwarding the NAS message to the access terminal through downlink message transmission signaling;
[0182] If the terminal access mode indicated by the received second indication information is the traditional terminal access mode, upon detecting that the access terminal completes AS security mode activation and receives downlink NAS transmission signaling carrying a NAS message, the NAS message is forwarded to the access terminal through the downlink message transmission signaling after AS downlink encryption.
[0183] As a preferred solution, the signaling transmission module 23 is further configured to:
[0184] When receiving the RRC connection request sent by the access terminal, sending an initial uplink RRC message including terminal bottom layer configuration information and terminal dynamic identifier to the CU;
[0185] Receive a downlink RRC message sent by the CU, and obtain the F1 interface identifier of the access terminal from the downlink RRC message to complete access terminal information interaction with the CU.
[0186] As a preferred solution, the signaling transmission module 23 is further configured to:
[0187] When receiving a NAS security mode command carrying a NAS layer security algorithm sent by the core network, forwarding the NAS security mode command to the access terminal; wherein the NAS security mode command is sent by the core network when the terminal is authenticated, and is used to instruct the access terminal to activate the NAS security mode;
[0188] When the NAS security mode activation completion message sent by the access terminal is received, the NAS security mode activation completion message is forwarded to the core network.
[0189] The terminal access device 200 provided in an embodiment of the present invention can reduce redundant message transmission processes with the CU by directly interacting with the core network during the terminal access process, thereby simplifying the signaling transmission process and reducing the terminal access delay; in addition, by executing AS security mode activation, RRC connection reconfiguration and NAS message transmission establishment in parallel, the terminal access process is optimized, further reducing the terminal access delay.
[0190] See also Figure 7 , Figure 7 3 is a schematic diagram of the structure of a terminal access device 300 applied to a core network in an embodiment of the present invention. A sixth aspect of an embodiment of the present invention provides a terminal access device 300, including:
[0191] The terminal authentication module 31 is used to:
[0192] In response to an initial UE message received from the DU on the RAN side, performing a terminal authentication process; wherein the initial UE message carries an attach request NAS message and a device identification code of the access terminal;
[0193] The terminal access indication module 32 is configured to:
[0194] When the terminal passes authentication, an initial context establishment request is sent to the CU, and a downlink message transmission signaling carrying an attach accept NAS message is sent to the access terminal through the DU; wherein the initial context establishment request is used to instruct the RAN side to perform a context establishment process;
[0195] When a RAN side context establishment success message sent by the CU and an uplink NAS transmission signaling sent by the DU are received, it is determined that the terminal access process is completed; wherein the uplink NAS transmission signaling is sent by the access terminal through the DU in response to the downlink message transmission signaling, and carries an attach complete NAS message and a bearer activation message.
[0196] As a preferred solution, the terminal access indication module 32 is further configured to:
[0197] When the terminal passes authentication, a NAS security mode command carrying the NAS layer security algorithm is generated;
[0198] Integrity-protect the NAS security mode command and send it to the access terminal through the DU; wherein the NAS security mode command is used to instruct the access terminal to activate the NAS security mode;
[0199] When a NAS security mode activation completion message sent by the DU is received, it is determined that the access terminal has completed the NAS security mode activation; wherein the NAS security mode activation completion message is sent by the access terminal through the DU when the NAS security mode activation is completed.
[0200] The terminal access device 300 provided in an embodiment of the present invention can reduce the redundant message transmission process between the DU and the CU by directly interacting with the DU on the RAN side during the terminal access process, thereby simplifying the signaling transmission process, reducing the terminal access delay, and optimizing the terminal access process.
[0201] See also Figure 8 , Figure 8 is a schematic diagram of the structure of a terminal access device 400 according to an embodiment of the present invention. A seventh aspect of the embodiments of the present invention provides a terminal access device 400, comprising a memory 42, a processor 41, and a computer program stored in the memory 42 and executable on the processor 41. When the processor 41 executes the computer program, it implements the terminal access method described in any embodiment of the first aspect, the terminal access method described in any embodiment of the second aspect, or the terminal access method described in any embodiment of the third aspect.
[0202] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory 42 and executed by the processor 41 to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal access device 400.
[0203] The terminal access device 400 may include, but is not limited to, a processor 41 and a memory 42. Those skilled in the art will appreciate that the schematic diagram is merely an example of the terminal access device 400 and does not limit the terminal access device 400. The terminal access device 400 may include more or fewer components than shown in the diagram, or may combine certain components or different components. For example, the terminal access device 400 may also include input and output devices, network access devices, buses, and the like.
[0204] The processor 41 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. The processor 41 is the control center of the terminal access device 400 and connects various parts of the entire terminal access device 400 using various interfaces and lines.
[0205] The memory 42 can be used to store the computer programs and / or modules. The processor 41 implements the various functions of the terminal access device 400 by running or executing the computer programs and / or modules stored in the memory 42 and calling the data stored in the memory 42. The memory 42 may mainly include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, a phone book, etc.). In addition, the memory 42 may include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0206] An eighth aspect of the embodiments of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the terminal access method described in any embodiment of the first aspect, or execute the terminal access method described in any embodiment of the second aspect, or execute the terminal access method described in any embodiment of the third aspect.
[0207] A ninth aspect of an embodiment of the present invention provides a computer program product, comprising a computer program / instruction, which, when executed by a processor 41, implements the terminal access method described in any embodiment of the first aspect, or implements the terminal access method described in any embodiment of the second aspect, or implements the terminal access method described in any embodiment of the third aspect.
[0208] In particular, if the modules / units integrated in the terminal access device 400 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor 41, it can implement the steps of the above-mentioned various method embodiments. In particular, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc.
[0209] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A terminal access method, characterized in that: The method is performed by an access terminal and includes: When the RRC connection with the RAN side is established, an initial UE message is sent to the core network through the DU on the RAN side; wherein the initial UE message is used to send an attach request to the core network and instruct it to perform a terminal authentication process; receiving an RRC connection reconfiguration indication message and a downlink message transmission signaling sent by the DU; wherein the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters; the downlink message transmission signaling is sent by the core network through the DU when the terminal authentication is passed, and carries an attach accept NAS message; Activate the AS security mode according to the AS layer security activation parameter; When the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters, and in response to the downlink message transmission signaling, an uplink NAS transmission signaling is sent to the core network through the DU to complete the terminal access process; wherein, the uplink NAS transmission signaling carries the attachment completion NAS message and the bearer activation message.
2. The terminal access method according to claim 1, wherein: The method further comprises: receiving first indication information sent by the RAN side; wherein the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, or the first indication information is used to indicate whether the RAN side meets the terminal fast access condition, and includes a list of services on the RAN side that allow the terminal fast access method; when the RAN side meets the terminal fast access condition, the DU supports direct interaction with the core network; Determining a terminal access mode based on the first indication information; wherein the terminal access mode includes the terminal quick access mode and the traditional terminal access mode; When the RRC connection establishment with the RAN side is completed, the second indication information for indicating the terminal access mode is sent to the RAN side to instruct the RAN side to perform the terminal access process according to the terminal access mode.
3. The terminal access method according to claim 2, wherein: The method further comprises: If the RAN side meets the terminal fast access condition, when the RRC connection establishment between the RAN side and the RAN side is completed, instructing the RAN side not to perform AS layer encryption and decryption through the second indication information; If the RAN side does not meet the terminal fast access condition, when the RRC connection between the RAN side is established, the second indication information is used to instruct the RAN side to perform AS layer encryption and decryption, and when the AS security mode activation is completed, each downlink message transmission signaling received from the RAN side is AS downlink decrypted to obtain the NAS message carried by each downlink message transmission signaling; wherein the decryption information required for performing the AS downlink decryption is obtained during the AS security mode activation process.
4. The terminal access method according to claim 1, wherein: The method further comprises: receiving a NAS security mode command sent by the DU; wherein the NAS security mode command is sent by the core network through the DU when the terminal is authenticated, and carries a NAS layer security algorithm; Performing integrity protection check on the NAS security mode command; When it is determined that the integrity protection check of the NAS security mode command passes, NAS security mode activation is performed according to the NAS layer security algorithm, and a NAS security mode activation completion message is sent to the core network through the DU.
5. A terminal access method, characterized in that: The method is performed by the DU on the RAN side and includes: When the RRC connection establishment between the access terminal and the core network is completed, an initial UE message is sent to the core network; wherein the initial UE message is used to send an attach request of the access terminal to the core network and instruct it to perform a terminal authentication process; In response to a context establishment request sent by the CU, instruct the access terminal to activate AS security mode and reconfigure the RRC connection, and upon receiving downlink NAS transmission signaling carrying an attach accept NAS message sent by the core network, forward the attach accept NAS message to the access terminal; wherein the context establishment request is sent by the core network at the instruction of the CU when the terminal is authenticated; and the downlink NAS transmission signaling is sent by the core network when the terminal is authenticated; When detecting that the access terminal completes AS security mode activation and RRC connection reconfiguration, sending a RAN side context establishment success message to the core network through the CU; When receiving the uplink message transmission signaling carrying the attach complete NAS message and the bearer activation message sent by the access terminal, the attach complete NAS message and the bearer activation message are forwarded to the core network to complete the terminal access process.
6. The terminal access method according to claim 5, wherein: The method further comprises: Sending first indication information indicating whether the RAN side meets the terminal fast access condition to the access terminal, or sending first indication information indicating whether the RAN side meets the terminal fast access condition and including a list of services on the RAN side that allow the terminal fast access method to the access terminal; wherein, when the terminal fast access condition is met, direct interaction with the core network is supported; When receiving the second indication information sent by the access terminal for indicating the terminal access mode, the terminal access process is executed according to the terminal access mode; wherein the terminal access mode includes a terminal quick access mode and a traditional terminal access mode, which is determined by the access terminal based on the first indication information.
7. The terminal access method according to claim 6, wherein: The method further comprises: If the terminal access mode indicated by the received second indication information is the terminal fast access mode, upon receiving downlink NAS transmission signaling carrying the NAS message, directly forwarding the NAS message to the access terminal through downlink message transmission signaling; If the terminal access mode indicated by the received second indication information is the traditional terminal access mode, upon detecting that the access terminal completes AS security mode activation and receives downlink NAS transmission signaling carrying a NAS message, the NAS message is forwarded to the access terminal through the downlink message transmission signaling after AS downlink encryption.
8. The terminal access method according to claim 5, wherein: The method further comprises: When receiving the RRC connection request sent by the access terminal, sending an initial uplink RRC message including terminal bottom layer configuration information and terminal dynamic identifier to the CU; Receive a downlink RRC message sent by the CU, and obtain the F1 interface identifier of the access terminal from the downlink RRC message to complete access terminal information interaction with the CU.
9. The terminal access method according to claim 5, wherein: The method further comprises: When receiving a NAS security mode command carrying a NAS layer security algorithm sent by the core network, forwarding the NAS security mode command to the access terminal; wherein the NAS security mode command is sent by the core network when the terminal is authenticated, and is used to instruct the access terminal to activate the NAS security mode; When the NAS security mode activation completion message sent by the access terminal is received, the NAS security mode activation completion message is forwarded to the core network.
10. A terminal access method, characterized in that: The method is performed by a core network and includes: In response to an initial UE message received from the DU on the RAN side, performing a terminal authentication process; wherein the initial UE message carries an attach request NAS message and a device identification code of the access terminal; When the terminal passes authentication, an initial context establishment request is sent to the CU, and a downlink message transmission signaling carrying an attach accept NAS message is sent to the access terminal through the DU; wherein the initial context establishment request is used to instruct the RAN side to perform a context establishment process; When a RAN side context establishment success message sent by the CU and an uplink NAS transmission signaling sent by the DU are received, it is determined that the terminal access process is completed; wherein the uplink NAS transmission signaling is sent by the access terminal through the DU in response to the downlink message transmission signaling, and carries an attach complete NAS message and a bearer activation message.
11. The terminal access method according to claim 10, wherein: The method further comprises: When the terminal passes authentication, a NAS security mode command carrying the NAS layer security algorithm is generated; Integrity-protect the NAS security mode command and send it to the access terminal through the DU; wherein the NAS security mode command is used to instruct the access terminal to activate the NAS security mode; When a NAS security mode activation completion message sent by the DU is received, it is determined that the access terminal has completed the NAS security mode activation; wherein the NAS security mode activation completion message is sent by the access terminal through the DU when the NAS security mode activation is completed.
12. A terminal access device, characterized in that: include: The attachment request sending module is used to: When the RRC connection with the RAN side is established, an initial UE message is sent to the core network through the DU on the RAN side; wherein the initial UE message is used to send an attach request to the core network and instruct it to perform a terminal authentication process; Signaling receiving module, used for: receiving an RRC connection reconfiguration indication message and a downlink message transmission signaling sent by the DU; wherein the RRC connection reconfiguration indication message carries reconfiguration parameters and AS layer security activation parameters; the downlink message transmission signaling is sent by the core network through the DU when the terminal authentication is passed, and carries an attach accept NAS message; Signaling response module, used for: Activate the AS security mode according to the AS layer security activation parameter; When the AS security mode activation is completed, the RRC connection is reconfigured according to the reconfiguration parameters, and in response to the downlink message transmission signaling, an uplink NAS transmission signaling is sent to the core network through the DU to complete the terminal access process; wherein, the uplink NAS transmission signaling carries the attachment completion NAS message and the bearer activation message.
13. A terminal access device, characterized in that: include: The terminal attachment request sending module is used to: When the RRC connection establishment between the access terminal and the core network is completed, an initial UE message is sent to the core network; wherein the initial UE message is used to send an attach request of the access terminal to the core network and instruct it to perform a terminal authentication process; Terminal context establishment module, used to: In response to a context establishment request sent by the CU, instruct the access terminal to activate AS security mode and reconfigure the RRC connection, and upon receiving downlink NAS transmission signaling carrying an attach accept NAS message sent by the core network, forward the attach accept NAS message to the access terminal; wherein the context establishment request is sent by the core network at the instruction of the CU when the terminal is authenticated; and the downlink NAS transmission signaling is sent by the core network when the terminal is authenticated; Signaling transmission module, used for: When detecting that the access terminal completes AS security mode activation and RRC connection reconfiguration, sending a RAN side context establishment success message to the core network through the CU; When receiving the uplink message transmission signaling carrying the attach complete NAS message and the bearer activation message sent by the access terminal, the attach complete NAS message and the bearer activation message are forwarded to the core network to complete the terminal access process.
14. A terminal access device, characterized in that: include: Terminal authentication module, used for: In response to an initial UE message received from the DU on the RAN side, performing a terminal authentication process; wherein the initial UE message carries an attach request NAS message and a device identification code of the access terminal; Terminal access indication module, used to: When the terminal passes authentication, an initial context establishment request is sent to the CU, and a downlink message transmission signaling carrying an attach accept NAS message is sent to the access terminal through the DU; wherein the initial context establishment request is used to instruct the RAN side to perform a context establishment process; When a RAN side context establishment success message sent by the CU and an uplink NAS transmission signaling sent by the DU are received, it is determined that the terminal access process is completed; wherein the uplink NAS transmission signaling is sent by the access terminal through the DU in response to the downlink message transmission signaling, and carries an attach complete NAS message and a bearer activation message.
15. A terminal access device, characterized in that: The present invention comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the terminal access method according to any one of claims 1 to 4 is implemented, or the terminal access method according to any one of claims 5 to 9 is implemented, or the terminal access method according to any one of claims 10 to 11 is implemented.
16. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein, when the computer program is run, the device where the computer-readable storage medium is located is controlled to execute the terminal access method according to any one of claims 1 to 4, or the terminal access method according to any one of claims 5 to 9, or the terminal access method according to any one of claims 10 to 11.
17. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the terminal access method according to any one of claims 1 to 4 is implemented, or the terminal access method according to any one of claims 5 to 9 is implemented, or the terminal access method according to any one of claims 10 to 11 is implemented.