Method and apparatus for handover
By providing network slice-specific authentication and authorization status during the handover process, the problem of the target AMF being unable to obtain the allowed NSSAI status is solved, the handover process is optimized, the signaling burden and delay are reduced, and the network performance and service response speed are improved.
Patent Information
- Application Number
- CN202510899107.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-13
- Filing Date
- 2021-03-11
- Publication Date
- 2025-10-03
AI Technical Summary
During the handover process, the target access and mobility management entity cannot obtain the allowed NSSAI state subject to network slice specific authentication and authorization, resulting in the target AMF having to re-execute the network slice specific authentication and authorization process, increasing the signaling burden and delay.
During the handover process, the source access and mobility management entity provides the target access and mobility management entity with the network slice specific authentication and authorization status, and the target AMF decides whether to skip the network slice specific authentication and authorization process based on this status.
The NSSAA process is optimized, unnecessary network signaling is avoided, service response speed and network performance are improved, and operating expenses are reduced.
Smart Images

Figure CN120751377A_ABST
Abstract
Description
This application is a divisional application of the patent application with application number 202180020839.X, application date March 11, 2021, and invention name “Method and device for switching”. Technical Field
[0001] Non-limiting and exemplary embodiments of the present disclosure relate generally to the field of communication technology, and particularly to methods and apparatus for handover. Background Art
[0002] This section introduces various aspects that may contribute to a better understanding of the present disclosure. Therefore, the statements in this section should be read in this light and should not be understood as an admission about what is or is not in the prior art.
[0003] The handover procedure may use a reference point (such as N2) between the RAN and an access and mobility management entity (such as an AMF (Access and Mobility Management Function)) or a reference point (such as Xn) between a source RAN and a target RAN to hand over a terminal device such as a user equipment (UE) from a source radio access network (RAN) (such as an NG-RAN (Next Generation RAN)) node to a target RAN (such as an NG-RAN) node. For example, the handover procedure may be triggered due to new radio conditions, load balancing or due to specific services (such as in the presence of a QoS (Quality of Service) flow for voice). The source NG-RAN node being NR (New Radio) may trigger a handover to E-UTRA (Evolved Universal Telecommunications Radio Access) connected to a 5GC (Fifth Generation Core Network).
[0004] When the access and mobility management entity is changed during the handover process, the target access and mobility management entity may only perform a subset of the registration procedure. For example, in 5GS (fifth generation system), if the UE indicates in the UE MM (Mobility Management) core network capabilities in the registration request that it supports network slice specific authentication and authorization procedures (NSSAA), and any S-NSSAI (Single Network Slice Selection Assistance Information) of the HPLMN (Home PLMN (Public Land Mobile Network)) is subject to network slice specific authentication and authorization, then the network slice specific authentication and authorization procedures need to be performed. Summary of the Invention
[0005] This Summary is provided in a simplified form to introduce selected concepts that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0006] There are some issues with the handover procedure when changing access and mobility management entities. For example, during the N2-based handover preparation phase, the source AMF may create a UE context in the target AMF, but the NSSAA status for allowed NSSAI (Network Slice Selection Assistance Information) subject to network slice specific authentication and authorization is not included in the UE context information. During the N2-based handover execution phase, it is explicitly specified that the target AMF performs only a subset of the registration procedure, in particular skipping the steps for context transfer between the source and target AMFs in the registration procedure. As a result, the target AMF cannot obtain the NSSAA status for allowed NSSAI subject to network slice specific authentication and authorization, and the target AMF has to perform the network slice specific authentication and authorization again, even if the source AMF already has the NSSAA result.
[0007] In order to overcome or alleviate the above problems or other problems, embodiments of the present disclosure propose an improved handover solution.
[0008] In one embodiment, during the handover process, the source access and mobility management entity may provide the target access and mobility management entity with network slice specific authentication and authorization status for the allowed network slices subject to network slice specific authentication and authorization.
[0009] In one embodiment, during the handover process, the target access and mobility management entity decides to skip the network slice specific authentication and authorization for the network slice specific authentication and authorization process during the registration process based on the network slice specific authentication and authorization status from the source access and mobility management entity, and stores the network slice specific authentication and authorization status from the source access and mobility management entity for the allowed network slice(s) subject to the network slice specific authentication and authorization in the UE context.
[0010] In a first aspect of the present disclosure, a method at a first access and mobility management entity is provided. The method includes obtaining at least one authentication and authorization status for a terminal device for at least one network slice of a network. The method also includes sending the at least one authentication and authorization status for the terminal device for at least one network slice of the network to a second access and mobility management entity during a handover procedure.
[0011] In one embodiment, each network slice of at least one network slice of the network may be identified by a single network slice selection assistance information S-NSSAI.
[0012] In one embodiment, the handover process may be an N2-based handover process between Next Generation Radio Access Network (NG-RAN) nodes.
[0013] In one embodiment, the first access and mobility management entity may be an access and mobility management function (AMF) entity, and the second access and mobility management entity may be an AMF entity.
[0014] In one embodiment, at least one authentication and authorization status for the terminal device for at least one network slice of the network may be obtained from another access and mobility management entity and / or from an authentication server.
[0015] In one embodiment, the authentication server may be an authentication server function AUSF entity, and the another access and mobility management entity may be an access and mobility management function AMF entity.
[0016] In one embodiment, at least one authentication and authorization state for the terminal device for at least one network slice of the network may be sent in a request for a first access and mobility management entity to create a context for the terminal device in a second access and mobility management entity during a handover procedure.
[0017] In one embodiment, the request may be a Namf_Communication_CreateUEContext request.
[0018] In one embodiment, the method may further comprise storing at least one authentication and authorization status for the terminal device for at least one network slice of the network.
[0019] In a second aspect of the present disclosure, a method at a second access and mobility management entity is provided. The method includes receiving, from a first access and mobility management entity, at least one authentication and authorization status for a terminal device for at least one network slice of a network during a handover procedure. The method also includes deciding, based on the received at least one authentication and authorization status for the terminal device for at least one network slice of the network, to skip at least one network slice-specific authentication and authorization procedure for the terminal device for at least one network slice of the network.
[0020] In one embodiment, the method further comprises skipping at least one network slice specific authentication and authorization process.
[0021] In one embodiment, deciding to skip at least one network slice-specific authentication and authorization process also includes: if at least one received authentication and authorization status indicates that the result of the network slice-specific authentication and authorization is successful, deciding to skip at least one network slice-specific authentication and authorization process for the terminal device for at least one network slice of the network.
[0022] In one embodiment, deciding to skip at least one network slice-specific authentication and authorization process also includes: if at least one received authentication and authorization status indicates that the result of the network slice-specific authentication and authorization is a failure, deciding to skip at least one network slice-specific authentication and authorization process for the terminal device for at least one network slice of the network.
[0023] In one embodiment, the method may further include: based on the slice selection subscription data of the terminal device, checking whether there are one or more allowed network slices subject to network slice-specific authentication and authorization, and based on the at least one authentication and authorization status received for the terminal device for at least one network slice of the network, checking whether there are already one or more corresponding authentication and authorization states available.
[0024] In one embodiment, the method may further comprise storing at least one authentication and authorization status for the terminal device for at least one network slice of the network.
[0025] In a third aspect of the present disclosure, a first access and mobility management entity is provided. The first access and mobility management entity includes a processor; a memory coupled to the processor, the memory storing instructions executable by the processor, whereby the first access and mobility management entity is operable to obtain at least one authentication and authorization status for a terminal device for at least one network slice of a network. The first access and mobility management entity is further operable to send the at least one authentication and authorization status for the terminal device for at least one network slice of the network to a second access and mobility management entity during a handover procedure.
[0026] In a fourth aspect of the present disclosure, a second access and mobility management entity is provided. The second access and mobility management entity includes a processor; a memory coupled to the processor, the memory storing instructions executable by the processor, whereby the second access and mobility management entity is operable to receive at least one authentication and authorization status for a terminal device for at least one network slice of a network from a first access and mobility management entity during a handover procedure. The second access and mobility management entity is further operable to decide to skip at least one network slice-specific authentication and authorization procedure for the terminal device for at least one network slice of the network based on the received at least one authentication and authorization status for the terminal device for at least one network slice of the network.
[0027] In a fifth aspect of the present disclosure, a first access and mobility management entity is provided. The first access and mobility management entity includes an obtaining module and a sending module. The obtaining module may be configured to obtain at least one authentication and authorization status for a terminal device for at least one network slice of a network. The sending module may be configured to send the at least one authentication and authorization status for the terminal device for at least one network slice of the network to a second access and mobility management entity during a handover procedure.
[0028] In a sixth aspect of the present disclosure, a second access and mobility management entity is provided. The second access and mobility management entity includes a receiving module and a deciding module. The receiving module may be configured to receive at least one authentication and authorization status for a terminal device for at least one network slice of a network from the first access and mobility management entity during a handover procedure. The deciding module may be configured to decide to skip at least one network slice-specific authentication and authorization procedure for the terminal device for at least one network slice of the network based on the received at least one authentication and authorization status for the terminal device for at least one network slice of the network.
[0029] In a seventh aspect of the present disclosure, there is provided a computer program product comprising instructions which, when executed on at least one processor, cause the at least one processor to perform any step of the method according to any one of the first and second aspects of the present disclosure.
[0030] In an eighth aspect of the present disclosure, a computer-readable storage medium storing instructions is provided, which, when executed by at least one processor, causes the at least one processor to perform any step of the method according to any one of the first and second aspects of the present disclosure.
[0031] The embodiments herein provide many advantages, the following is a non-exhaustive list of examples of the advantages. In some embodiments herein, during an N2-based handover procedure, the target AMF may optimize the NSSAA procedure based on the NSSAA state for allowed NSSAI subject to network slice specific authentication and authorization provided by the source AMF during the N2-based handover procedure. In some embodiments herein, during an N2-based handover procedure, unnecessary network signaling traffic may be avoided. In some embodiments herein, for users, fast service response time and minimized latency for an N2-based handover procedure may be achieved. In some embodiments herein, for network operators, OPEX (operating expenses) reduction may be achieved due to avoidance of unnecessary signaling and improved network performance. After reading the following detailed description, those skilled in the art will recognize additional features and advantages. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The above and other aspects, features and benefits of various embodiments of the present disclosure will become more apparent from the following detailed description with reference to the accompanying drawings, wherein like reference numerals or letters are used to designate similar or equivalent elements. The accompanying drawings are provided to facilitate a better understanding of the embodiments of the present disclosure and are not necessarily drawn to scale, wherein:
[0033] Figure 1 The system architecture in which the embodiments of the present disclosure can be implemented is shown;
[0034] Figure 2 A flowchart showing the network slice specific authentication and authorization process;
[0035] Figure 3 shows a flow chart of the handover preparation phase based on N2;
[0036] Figure 4 shows a flow chart of the handover execution phase based on N2;
[0037] Figure 5 A flow chart showing the registration process;
[0038] Figure 6 A flowchart of a method according to an embodiment of the present disclosure is shown;
[0039] Figure 7 A method flow chart according to another embodiment of the present disclosure is shown.
[0040] Figure 8a depicts a flow chart of a UE registration procedure with a Network Slice Specific Authentication and Authorization (NSSAA) procedure in 5GS according to an embodiment of the present disclosure;
[0041] Figure 8b depicts a flow chart of N2-based handover with optimized NSSAA procedure according to an embodiment of the present disclosure;
[0042] Figure 9 is a block diagram illustrating an apparatus suitable for implementing some embodiments of the present disclosure;
[0043] Figure 10 is a block diagram illustrating a first access and mobility management entity according to an embodiment of the present disclosure; and
[0044] Figure 11 is a block diagram illustrating a second access and mobility management entity according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0045] Embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for the purpose of enabling those skilled in the art to better understand and therefore implement the present disclosure, and that no limitation on the scope of the present disclosure is suggested. References to features, advantages or similar language throughout the specification do not mean that all features and advantages that can be implemented with the present disclosure should be in or in any single embodiment of the present disclosure. On the contrary, language referring to features and advantages should be understood to mean that specific features, advantages or characteristics described in conjunction with the embodiments are included in at least one embodiment of the present disclosure. In addition, in one or more embodiments, the features, advantages and characteristics described in the present disclosure may be combined in any suitable manner. Those skilled in the relevant art will recognize that the present disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other cases, additional features and advantages may be recognized in certain embodiments, while the additional features and advantages may not be present in all embodiments of the present disclosure.
[0046] As used herein, the term "network" refers to a network that complies with any suitable (wireless or wired) communication standard. For example, wireless communication standards may include: New Radio (NR), Long Term Evolution (LTE), Advanced LTE, Wideband Code Division Multiple Access (WCDMA), High Speed Packet Access (HSPA), Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single Carrier Frequency Division Multiple Access (SC-FDMA). A CDMA network may implement radio technologies such as Universal Terrestrial Radio Access (UTRA). UTRA includes WCDMA and other variants of CDMA. A TDMA network may implement radio technologies such as Global System for Mobile Communications (GSM). An OFDMA network may implement radio technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, Ad-hoc networks, wireless sensor networks, and the like. In the following description, the terms "network" and "system" may be used interchangeably. Furthermore, communication between two devices in a network may be performed according to any suitable communication protocol, including but not limited to wireless communication protocols or wired communication protocols defined by standards organizations such as the Third Generation Partnership Project (3GPP). For example, wireless communication protocols may include first generation (1G), 2G, 3G, 4G, 4.5G, 5G communication protocols, and / or any other protocols currently known or developed in the future.
[0047] As used herein, the term "entity" refers to a network device, network node, or network function in a communication network. For example, in a wireless communication network such as a 3GPP-type cellular network, core network devices may provide a variety of services to clients interconnected via access network devices. Each access network device may be connected to the core network device via a wired or wireless connection.
[0048] The term "network function (NF)" refers to any suitable function that can be implemented in a network node (physical or virtual) of a communication network. For example, a 5G system (5GS) may include multiple NFs, such as AMF (Access and Mobility Function), SMF (Session Management Function), AUSF (Authentication Service Function), UDM (Unified Data Management), PCF (Policy Control Function), AF (Application Function), NEF (Network Exposure Function), UPF (User Plane Function) and NRF (Network Repository Function), (R)AN ((Radio) Access Network), SCP (Service Communication Agent), NWDAF (Network Data Analysis Function), etc. In other embodiments, for example, depending on the specific type of network, the network function may include different types of NFs.
[0049] The term "terminal device" refers to any end device that can access a wireless communication network and receive services from the wireless communication network. By way of example and not limitation, a terminal device refers to a mobile terminal, user equipment (UE), or other suitable device. A UE may be, for example, a subscriber station (SS), a portable subscriber station, a mobile station (MS), or an access terminal (AT). Terminal devices may include, but are not limited to, portable computers, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback devices, mobile phones, cellular phones, smart phones, voice over IP (VoIP) phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, wearable devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEEs), laptop mounted devices (LMEs), USB dongles, smart devices, wireless customer premises equipment (CPE), etc. In the following description, the terms "terminal device," "terminal," "user equipment," and "UE" may be used interchangeably. As an example, a terminal device may represent a UE configured for communicating in accordance with one or more communication standards promulgated by 3GPP (such as 3GPP's LTE standard or NR standard). As used herein, a "user equipment" or "UE" may not necessarily have a "user" in terms of a human user who owns and / or operates the associated device. In some embodiments, a terminal device may be configured to send and / or receive information without direct human interaction. For example, when triggered by an internal or external event, or in response to a request from a communication network, a terminal device may be designed to send information to the network on a predetermined schedule. Alternatively, a UE may represent a device that is intended to be sold to or operated by a human user but may not initially be associated with a specific human user.
[0050] As another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another terminal device and / or network device. In this case, the terminal device may be a machine-to-machine (M2M) device, which may be referred to as a machine type communication (MTC) device in the 3GPP context. As a specific example, the terminal device may be a terminal device that implements the 3GPP Narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (e.g., power meters), industrial machinery, or household or personal appliances (e.g., refrigerators, televisions), personal wearable devices (e.g., watches), etc. In other cases, the terminal device may represent a vehicle or other device that is capable of monitoring and / or reporting its operating status or other functions associated with its operation.
[0051] References in the specification to "one embodiment," "an embodiment," "an example embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment necessarily includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. In addition, when a particular feature, structure, or characteristic is described in conjunction with an embodiment, whether or not explicitly described, it is understood that it is within the knowledge of those skilled in the art to incorporate such feature, structure, or characteristic in conjunction with other embodiments.
[0052] It should be understood that although the terms "first" and "second" etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the example embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed terms.
[0053] As used herein, the phrase "at least one of A and B" should be understood to mean "only A, only B, or both A and B." The phrase "A and / or B" should be understood to mean "only A, only B, or both A and B."
[0054] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the example embodiments. As used herein, unless the context clearly indicates otherwise, the singular forms "a," "an," and "the" are intended to include the plural forms as well. It will be further understood that when used herein, the terms "include," "comprising," "having," "containing," "covering," and / or "having" specify the presence of stated features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0055] It should be noted that these terms are used in this document only to facilitate the description and distinction of nodes, devices, or networks, etc. As technology develops, other terms with similar / identical meanings may also be used.
[0056] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0057] It should be noted that some embodiments of the present disclosure are primarily described with respect to a 5G network, which is used as a non-limiting example of certain exemplary network configurations and system deployments. Therefore, the description of the exemplary embodiments given herein specifically refers to terms directly related thereto. Such terms are used only in the context of the non-limiting examples and embodiments presented and naturally do not limit the present disclosure in any way. On the contrary, any other system configuration or radio technology may be used equally as long as the exemplary embodiments described herein are applicable.
[0058] Figure 1 1 shows a system architecture that can implement the embodiments of the present disclosure. Figure 1 The system architecture depicts only some exemplary elements. In practice, the communication system may also include any additional elements suitable for supporting communications between terminal devices or between a wireless device and another communication device (e.g., a landline phone, a service provider, or any other network node or terminal device). The communication system may provide communications and various types of services to one or more terminal devices to facilitate the terminal devices to access and / or use services provided by or via the communication system.
[0059] Figure 1 and 3 GPP TS23.501V16.3.0 Figure 4 .2.3-1, the entire disclosure of which is incorporated herein by reference. Figure 1 The system architecture may include some exemplary elements, such as AMF, SMF, AUSF, UDM, PCF, AF, NEF, UPF and NRF, (R)AN, SCP, etc. Figure 1 The network elements, reference points and interfaces shown may be the same as the corresponding network elements, reference points and interfaces described in 3GPP TS 23.501 V16.3.0.
[0060] Figure 2 Flowchart showing the network slice specific authentication and authorization process, which is consistent with 3GPP TS 23.502 V16.3.0 Figure 4 .Same as 2.9.2-1. Figure 2The steps shown are the same as the corresponding steps described in 3GPP TS 23.502 V16.3.0, Section 4.2.9.2. For S-NSSAI that requires network slice specific authentication and authorization, the EAP (Extensible Authentication Protocol) framework as described in 3GPP TS 33.501 V16.1.0 (the disclosure of which is incorporated herein by reference in its entirety) may be used to trigger the network slice specific authentication and authorization process with the AAA (Authentication, Authorization and Accounting) Server (AAA-S), which may be hosted by the HPLMN operator or a third party that has a business relationship with the HPLMN. For example, if the AAA server belongs to a third party, an AAA proxy (AAA-P) in the HPLMN may be involved.
[0061] The AMF may trigger the network slice specific authentication and authorization process during the registration process when some network slices require slice specific authentication and authorization, when the AMF determines that network slice specific authentication and authorization is required for an NSSAI among the currently allowed NSSAIs (e.g. subscription change), or when the AAA server that authenticates the network slice triggers re-authentication.
[0062] The AMF performs the role of EAP authenticator and communicates with the AAA-S through the AUSF. The AUSF assumes responsibility for any AAA protocols that interoperate with the AAA protocols supported by the AAA-S.
[0063] The serving PLMN may perform network slice specific authentication and authorization for the S-NSSAI of the HPLMN subject to network slice specific authentication and authorization based on the subscription information. The UE may indicate whether it supports this feature in the UE 5GMM Core Network Capabilities in the Registration Request message. If the UE does not support this feature, the AMF may not trigger this procedure for the UE, and if the UE requests these S-NSSAIs subject to network slice specific authentication and authorization, they will be rejected for this PLMN.
[0064] If the UE is configured with S-NSSAI, which is subject to network slice specific authentication and authorization, the UE stores an association between the S-NSSAI and the corresponding credentials used for network slice specific authentication and authorization.
[0065] In order to perform network slice specific authentication and authorization for S-NSSAI, AMF calls the EAP-based network slice specific authorization procedure documented in 3GPP TS 23.502 V16.3.0 clause 4.2.9 for S-NSSAI (see also 3GPP TS 33.501 V16.1.0).
[0066] The AMF may invoke this procedure for a supported UE at any time, for example, when: a. The UE is registered with the AMF and the S-NSSAI in the HPLMN's S-NSSAI (which maps to the S-NSSAI in the requested NSSAI) is requiring network slice specific authentication and authorization (see clause 5.15.5.2.1 for details), and once the network slice specific authentication and authorization for this S-NSSAI succeeds, the AMF may add it to the allowed NSSAIs; or b. The network slice specific AAA server triggers UE re-authentication and re-authorization for S-NSSAI; or C. Based on the operator's policy or contract changes, the AMF decides to initiate a network slice-specific authentication and authorization process for a previously authorized S-NSSAI.
[0067] In the case of recertification and reauthorization (b. and c. above), the following applies: - If the S-NSSAI for which network slice specific authentication and authorization is being requested is included in the allowed NSSAI for each access type, the AMF selects the access type that will be used to perform the network slice specific authentication and authorization procedure based on the network policy. - If the network slice specific authentication and authorization for some S-NSSAI among the allowed NSSAI is unsuccessful, the AMF may update the allowed NSSAI for each access type to the UE through the UE configuration update procedure. - If the network slice specific authentication and authorization fails for all S-NSSAIs among the allowed NSSAIs, the AMF may perform the network initiated deregistration procedure described in section 4.2.2.3.3 of 3GPP TS 23.502 V16.3.0 and may include a list of rejected S-NSSAIs in the explicit Deregistration Request message, with each S-NSSAI in the list carrying an appropriate Reject Cause value.
[0068] After successful or unsuccessful UE network slice specific authentication and authorization, when the UE remains RM-REGISTERED in the PLMN, the UE context in the AMF may maintain the authentication and authorization status for the UE for the relevant specific S-NSSAI for the HPLMN so that the AMF does not need to perform network slice specific authentication and authorization for the UE in every periodic registration update or mobile registration procedure with the PLMN.
[0069] The network slice specific AAA server may revoke authorization or challenge the UE's authentication and authorization at any time. When authorization is revoked for an NSSAI that is among the currently allowed NSSAIs for an access type, the AMF may provide the UE with a new allowed NSSAI and trigger the release of all PDU (Protocol Data Unit) sessions associated with the S-NSSAI for that access type.
[0070] The AMF provides the UE’s GPSI (General Public Subscription Identifier) associated with the S-NSSAI to the AAA server to allow the AAA server to initiate network slice specific authentication and authorization, or authorization revocation procedures, where the UE’s current AMF needs to be identified by the system and the UE’s authorization status can therefore be challenged or revoked.
[0071] Network slice specific authentication and authorization requires that the UE primary authentication and authorization of SUPI (Subscription Permanent Identifier) has been successfully completed. If the SUPI authorization is revoked, the network slice specific authorization is also revoked.
[0072] Figure 3 The flowchart of the handover preparation phase based on N2 is shown, which is consistent with 3GPP TS23.502V16.3.0 Figure 4 .9.1.3.2-1 is the same. Figure 3 The steps shown are the same as the corresponding steps described in 3GPP TS 23.502 V16.3.0 clause 4.9.1.3.2.
[0073] like Figure 3 As shown in step 3, (conditional) S-AMF to T-AMF: Namf_Communication_CreateUEContext request (N2 information (target ID (identifier), source to target transparent container, SM (session management) N2 information list, PDU session ID), UE context information (SUPI, service area restriction, allowed NSSAI for each access type (if any), tracking requirements, LTE M indication, list of PDU session IDs and corresponding SMF information and corresponding S-NSSAI (multiple), PCF ID (multiple), DNN (data network name), UE radio capability ID and UE radio capability information). If the subscription information includes the tracking requirement, the old AMF provides the tracking requirement to the target AMF.
[0074] In case of inter-PLMN mobility, the UE context information includes the HPLMN S-NSSAI corresponding to the allowed NSSAI for each access type, without the allowed NSSAI of the source PLMN. The target AMF may Figure 3The allowed NSSAIs are determined by the HPLMN S-NSSAI received in step 3 of the SUPI, or the target AMF queries the NSSF by invoking the Nnssf_NSSelection_Get service operation with the HPLMN S-NSSAI and the PLMN ID of the SUPI. Figure 4 As described above, when a mobility registration update is performed during the handover execution phase, the target AMF can trigger AMF reallocation.
[0075] The S-AMF initiates the handover resource allocation process by calling the Namf_Communication_CreateUEContext service operation to the T-AMF.
[0076] When the S-AMF is still able to serve the UE, no Figure 3 Step 3 and Step 12.
[0077] As described in clause 5.3.4.1.2 of 3GPP TS 23.501 V16.3.0, if service area restrictions are available in the S-AMF, they can be forwarded to the T-AMF.
[0078] If both the home and visited PCF IDs are provided by the S-AMF, the T-AMF contacts the (V-)PCF identified by the (V-)PCF ID. If the (V-)PCF identified by the (V-)PCF ID is not in use or no PCF ID is received from the S-AMF, the T-AMF may select PCF(s) as described in 3GPP TS 23.501 V16.3.0 Section 6.3.7.1 and according to the V-NRF to H-NRF interaction described in 3GPP TS 23.502 V16.3.0 Section 4.3.2.2.3.3. Figure 3 As defined in step 12 of , the T-AMF notifies the S-AMF that the PCF ID is not in use, and the S-AMF then terminates the AM policy association with the PCF identified by the PCF ID.
[0079] like Figure 3 As described in step 3 of , during the handover preparation phase based on N2, the source AMF creates a UE context in the target AMF, but does not contain the NSSAA state for the allowed NSSAI subject to network slice specific authentication and authorization in the UE context information.
[0080] Figure 4 The flowchart of the handover execution phase based on N2 is shown, which is consistent with 3GPP TS23.502V16.3.0 Figure 4 .9.1.3.3-1 is the same. Figure 4The steps shown are the same as the corresponding steps described in 3GPP TS 23.502 V16.3.0 clause 4.9.1.3.3.
[0081] like Figure 4 As shown in step 12 of 3GPP TS 23.502 V16.3.0, the UE initiates the Mobile Registration Update procedure as described in clause 4.2.2.2.2 of 3GPP TS 23.502 V16.3.0. The target AMF knows that it is a handover procedure, so the target AMF only performs a subset of the registration procedure, in particular skipping the steps used in the registration procedure for context transfer between the source AMF and the target AMF (i.e. Figure 5 Steps 4, 5, and 10).
[0082] Figure 5 A flowchart showing the registration process is shown, which is consistent with 3GPP TS23.502 V16.3.0 Figure 4 .Same as 2.2.2.2-1. Figure 5 The steps shown are the same as the corresponding steps described in 3GPP TS 23.502 V16.3.0 clause 4.2.2.2.2.
[0083] like Figure 5 As shown in step 4, [conditional] new AMF to old AMF: Namf_Communication_UEContextTransfer (complete registration request) or new AMF to UDSF (unstructured data storage function): Nudsf_UnstructuredDataManagementQuery().
[0084] (With UDSF deployment): If the UE's 5G-GUTI (5G Globally Unique Temporary Identifier) is included in the Registration Request and the serving AMF has changed since the last registration procedure, the new AMF and the old AMF are in the same AMF set and UDSF is deployed, the new AMF retrieves the stored UE's SUPI and UE context directly from the UDSF using the Nudsf_UnstructuredDataManagement_Query service operation, or if UDSF is not deployed, they can share the stored UE context in an implementation-specific manner. This also includes event subscription information for each NF consumer for a given UE. In this case, the new AMF performs and verifies integrity protection using the integrity-protected Registration Request NAS message.
[0085] (Deployment without UDSF): If the UE's 5G-GUTI was included in the Registration Request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation (which includes a complete Registration Request NAS message (which may be integrity protected) and the access type) to the old AMF to request the UE's SUPI and UE context. For details of this service operation, see section 5.2.2.2.2 of 3GPP TS 23.502 V16.3.0. In this case, if the Context Transfer service operation invocation corresponds to the requested UE, the old AMF verifies the integrity protection using the 5G-GUTI and the integrity-protected complete Registration Request NAS (Non-Access Stratum) message, or the SUPI and an indication from the new AMF that the UE has been verified. The old AMF also transfers event subscription information for each NF consumer of the UE to the new AMF. If the old AMF has not reported a non-zero MO (Mobile Originated) Exception Data counter to the (H-)SMF, the Context Response also includes the MO Exception Data counter.
[0086] If the old AMF has a PDU Session for another access type (different from the access type indicated in this step) and if the old AMF determines that it is not possible to relocate the N2 interface to the new AMF, the old AMF returns the UE's SUPI and indicates that the Registration Request has passed integrity protection verification, but does not include the rest of the UE context.
[0087] In case the new AMF has performed a successful UE authentication after a previous integrity check failure in the old AMF, the new AMF Figure 5 Step 9a sets an indication that the UE is authenticated.
[0088] After the UE successfully registers at the new AMF, the NF consumer does not need to subscribe to events at the new AMF again.
[0089] If the new AMF has received the UE context from the old AMF during the handover procedure, the Figure 5 Steps 4, 5, and 10.
[0090] For emergency registration, if the UE identifies itself with a 5G-GUTI that is not known to the AMF, steps 4 and 5 are skipped and the AMF immediately requests a SUPI from the UE. If the UE identifies itself with a PEI, the SUPI request shall be skipped. Allowing emergency registration without user identity depends on local regulations.
[0091] like Figure 5As shown in step 5 of [Conditional] Old AMF to New AMF: Response to Namf_Communication_UEContextTransfer (SUPI, UE context in AMF (as per Table 5.2.2.2.2-1 of 3GPP TS 23.502 V16.3.0) or UDSF to New AMF: Nudsf_Unstructured Data Management_Query(). The old AMF may start an implementation specific (protected) timer for the UE context.
[0092] If in Figure 5 If the UDSF is queried in step 4 of the , the UDSF responds to the Nudsf_Unstructured Data Management_Query call to the new AMF with the relevant context including the established PDU session, the old AMF including the SMF information DNN, S-NSSAI (multiple) and PDU session ID, the active NGAP (Next Generation Application Protocol) UE-TNLA (Transport Network Layer Association) bound to the N3IWF / TNGF / W-AGF, and the old AMF including information about the NGAP UE-TNLA binding. Figure 5 If the old AMF is queried in step 4 of the UE, the old AMF responds to the Namf_Communication_UEContextTransfer call by including the UE's SUPI and UE context to the new AMF.
[0093] If the old AMF holds information about an established PDU session, the old AMF includes SMF information, DNN(s), S-NSSAI(s) and PDU session ID(s).
[0094] If the old AMF holds the UE context established via N3IWF (Non-3GPP Interworking Function), W-AGF (Wired Access Gateway Function) or TNGF (Trusted Non-3GPP Gateway Function), the old AMF includes the CM (Connection Management) state via N3IWF, W-AGF or TNGF. If the UE is in CM-CONNECTED state via N3IWF, W-AGF or TNGF, the old AMF includes information about NGAP UE-TNLA binding.
[0095] If the old AMF fails the integrity check of the Registration Request NAS message, the old AMF shall indicate an integrity check failure.
[0096] If the old AMF holds information about AM policy association and information about UE policy association (i.e., policy control request trigger for updating UE policy as defined in 3GPP TS 23.503 V16.3.0, the disclosure of which is incorporated herein by reference in its entirety), the old AMF includes information about AM policy association, UE policy association and PCF ID. In the case of roaming, this includes the V-PCF ID and the H-PCF ID.
[0097] During inter-PLMN mobility, the handling of UE Radio Capability ID in the new AMF is as defined in 3GPP TS 23.501 V16.3.0.
[0098] When the new AMF uses UDSF for context retrieval, the interaction between the old AMF, new AMF and UDSF is an implementation issue due to the UE signalling on the old AMF at the same time.
[0099] like Figure 5 As shown in step 10, [Conditional] New AMF to old AMF: Namf_Communication_RegistrationCompleteNotify (PDU Session ID(s) will be released because slicing is not supported).
[0100] If the AMF has changed, the new AMF notifies the old AMF that the UE registration in the new AMF is complete by calling the Namf_Communication_RegistrationCompleteNotify service operation.
[0101] If the authentication / security procedure fails, the registration shall be rejected and the new AMF shall invoke the Namf_Communication_RegistrationCompleteNotify service operation with a reject indication cause code to the old AMF. The old AMF shall continue as if the UE Context Transfer service operation had never been received.
[0102] If one or more S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU Sessions cannot be supported in the new registration area. The new AMF calls the Namf_Communication_RegistrationCompleteNotify service operation to the old AMF, which includes the rejected PDU Session ID and the rejection reason (e.g., S-NSSAI is no longer available). The new AMF then modifies the PDU Session status accordingly. The old AMF notifies the corresponding SMF to locally release the UE's SM context by calling the Nsmf_PDUSession_ReleaseSMContext service operation.
[0103] If the new AMF receives information about AM policy association and UE policy association in the UE context transfer in step 2 and decides based on local policy not to use the PCF identified by the PCF ID for AM policy association and UE policy association, it will inform the old AMF that the AM policy association and UE policy association in the UE context are no longer used, and then Figure 5 PCF selection is performed in step 15.
[0104] In the N2-based switching execution phase, Figure 4 Step 12 of the Target AMF explicitly specifies that only a subset of the registration procedure should be performed, specifically, skipping Figure 5 Steps 4, 5 and 10 of the registration procedure for context transfer between the source AMF and the target AMF.
[0105] Based on the above information, the target AMF is unable to obtain the NSSAA state with allowed NSSAI subject to network slice specific authentication and authorization. The target AMF may have to perform Figure 5 Step 25, even if the source AMF already has NSSAA result.
[0106] In order to overcome or alleviate the above problems or other problems, embodiments of the present disclosure propose an improved handover solution. In one embodiment, the source AMF may provide the target AMF with an NSSAA state of an allowed NSSAI subject to network slice specific authentication and authorization during the N2-based handover procedure preparation phase. In one embodiment, based on the NSSAA state from the source AMF, the target AMF may decide to skip the network slice specific authentication and authorization process for the network slice specific authentication and authorization process during the registration process, and store the NSSAA state for the allowed S-NSSAI subject to network slice specific authentication and authorization from the source AMF in the UE context during the N2-based handover procedure execution phase.
[0107] Figure 6 A flowchart of a method 600 according to an embodiment of the present disclosure is shown. The method can be performed by a first access and mobility management entity, such as an AMF, or a device that serves as the first access and mobility management entity or is communicatively coupled to the first access and mobility management entity. In this way, the first access and mobility management entity can provide components or modules for completing various parts of the method 600, as well as components or modules for completing other processes in conjunction with other components.
[0108] At block 602, a first access and mobility management entity obtains at least one authentication and authorization status for a terminal device for at least one network slice of a network. A network slice may be a logical network that provides specific network capabilities and network characteristics. A network slice instance may be a set of network function instances and resources (e.g., computing, storage, and network resources) required to constitute a deployed network slice. The network may be any suitable network comprising one or more network slices. For example, the network may be a 5GS or other wireless communication system.
[0109] A network slice may be identified in various ways. For example, a network slice may be identified by a network slice identifier. In one embodiment, each network slice of at least one network slice of a network may be identified by a single network slice selection assistance information (S-NSSAI). The term "S-NSSAI" may be the same as the corresponding term described in 3GPP TS 23.501 V16.3.0.
[0110] At least one authentication and authorization status for a terminal device for at least one network slice of a network can be obtained in a variety of ways. In one embodiment, at least one authentication and authorization status for a terminal device for at least one network slice of a network can be obtained from another access and mobility management entity and / or from an authentication server. For example, when the first access and mobility management entity is the target access and mobility management entity during a handover process, wherein the access and mobility management entity serving the terminal device is switched from the source access and mobility management entity to the target access and mobility management entity, the first access and mobility management entity can obtain at least one authentication and authorization status for the terminal device for at least one network slice of the network from the source access and mobility management entity. When the first access and mobility management entity triggers a network slice-specific authentication and authorization process, the first access and mobility management entity can obtain at least one authentication and authorization status for the terminal device for at least one network slice of the network from the authentication server. In one embodiment, the authentication server can be an AUSF entity, and the another access and mobility management entity can be an AMF entity. The AUSF can obtain at least one authentication and authorization status from the AAA-S.
[0111] In one embodiment, the first access and mobility management entity may obtain at least one authentication and authorization status for the terminal device for at least one network slice of the network according to a network slice-specific authentication and authorization procedure as described in 3GPP TS 23.502 V16.3.0 clause 4.2.9.
[0112] The authentication and authorization status of a network slice may include information about whether the network slice requires network slice-specific authentication and authorization and the result of the network slice-specific authentication and authorization (e.g., success or failure).
[0113] At block 604 (optionally), the first access and mobility management entity may store at least one authentication and authorization state for the terminal device for at least one network slice of the network. For example, the first access and mobility management entity may store at least one authentication and authorization state for the terminal device for at least one network slice of the network in a terminal device context for the terminal device, which may be used later for optimizing a UE re-registration procedure or providing (the latest authentication and authorization state, if updated) to another new target access and mobility management entity during a handover procedure in which the access and mobility management entity changes.
[0114] In block 606, the first access and mobility management entity may send at least one authentication and authorization status for the terminal device for at least one network slice of the network to the second access and mobility management entity during the handover procedure.
[0115] The handover procedure may be any suitable handover procedure in which the access and mobility management entity serving the terminal device may be changed from a first access and mobility management entity to a second access and mobility management entity. In one embodiment, the handover procedure may be an N2-based handover procedure between Next Generation Radio Access Network (NG-RAN) nodes as described in Section 4.9.1.3 of 3GPP TS 23.502 V16.3.0.
[0116] The first and second access and mobility management entities may be any suitable network entities capable of implementing access and mobility management functions. In one embodiment, the first access and mobility management entity may be an AMF entity, and the second access and mobility management entity may be an AMF entity.
[0117] At least one authentication and authorization status for the terminal device for at least one network slice of the network may be sent in any suitable message that can be sent from the first access and mobility management entity to the second access and mobility management entity during the handover procedure. In one embodiment, during the handover procedure, at least one authentication and authorization status for the terminal device for at least one network slice of the network may be sent in a request for the first access and mobility management entity to create a context for the terminal device in the second access and mobility management entity. In one embodiment, the request may be a Namf_Communication_CreateUEContext request as described in clause 4.9.1.3.2 of 3GPP TS 23.502 V16.3.0.
[0118] Figure 7A flowchart of a method 700 according to another embodiment of the present disclosure is shown. The method can be performed by a device in or at a second access and mobility management entity, such as an AMF, or as the second access and mobility management entity, or communicatively coupled to the second access and mobility management entity. In this way, the second access and mobility management entity can provide components or modules for completing various parts of the method 700, as well as components or modules for completing other processes in conjunction with other components. For the sake of brevity, the detailed description of the parts already described in the above embodiments will not be repeated here.
[0119] At block 702, a second access and mobility management entity receives at least one authentication and authorization status for a terminal device for at least one network slice of a network from a first access and mobility management entity during a handover procedure. For example, the first access and mobility management entity may receive at least one authentication and authorization status for a terminal device for at least one network slice of a network from a first access and mobility management entity during a handover procedure. Figure 6 Block 606 sends at least one authentication and authorization status for the terminal device, and then the second access and mobility management entity may receive the at least one authentication and authorization status.
[0120] At block 704 (optionally), the second access and mobility management entity may store at least one authentication and authorization state for the terminal device for at least one network slice of the network. Block 704 is similar to Figure 6 604 of the box.
[0121] At block 706 (optionally), the second access and mobility management entity may check, based on the slice selection subscription data of the terminal device, whether there are one or more allowed network slices subject to network slice-specific authentication and authorization, and, based on the received at least one authentication and authorization status for the terminal device for at least one network slice of the network, whether one or more corresponding authentication and authorization states are already available. The slice selection subscription data for the terminal device may be obtained from a data management entity, such as a UDM, or the slice selection subscription data for the terminal device may be obtained from the first access and mobility management entity. For example, the second access and mobility management entity may request the slice selection subscription data from the UDM. The request may only obtain the slice selection subscription data, or may obtain user access and mobility management data including the slice selection subscription data. The UDM may return the user slice selection subscription data to the second access and mobility management entity, and the UDM should include information on whether network slice-specific authentication and authorization are required for each subscribed network slice, such as an S-NSSAI. The slice selection subscription data may include the subscribed network slices, such as the S-NSSAI, to which the terminal device subscribes. In the case of roaming, the subscribed network slices may indicate the PLMN for which the subscribed network slices are applicable. The slice selection subscription data may also include default network slice(s), e.g., subscribed network slice(s) marked as default network slices. The slice selection subscription data may also include network slice(s) subject to network slice-specific authentication and authorization, e.g., subscribed network slice(s) marked as subject to network slice-specific authentication and authorization. In one embodiment, the slice selection subscription data may be the same as the slice selection subscription data described in clause 5.2.3.3 of 3GPP TS 23.502 V16.3.0.
[0122] In block 708, the second access and mobility management entity may decide to skip at least one network slice-specific authentication and authorization process for the terminal device for at least one network slice of the network based on the received at least one authentication and authorization status for the terminal device for at least one network slice of the network. For example, assuming that the authentication and authorization status for the terminal device is as follows: for S-NSSAI requiring NSSAA: {S-NSSAI1: success, S-NSSAI2: success, S-NSSAI3: failure}, for S-NSSAI not requiring NSSAA: S-NSSAI4, the second access and mobility management entity may decide to skip the network slice-specific authentication and authorization process for the terminal device for S-NSSAI1, S-NSSAI2, and S-NSSAI3, where S-NSSAIx represents network slice x, "success" represents that the network slice-specific authentication and authorization is successful, and "failure" represents that the network slice-specific authentication and authorization is failed.
[0123] In one embodiment, the method further comprises skipping at least one network slice specific authentication and authorization process.
[0124] In one embodiment, deciding to skip at least one network slice-specific authentication and authorization process also includes: if at least one received authentication and authorization status indicates that the result of the network slice-specific authentication and authorization is successful, deciding to skip at least one network slice-specific authentication and authorization process for the terminal device for at least one network slice of the network.
[0125] In one embodiment, deciding to skip at least one network slice-specific authentication and authorization process also includes: if at least one received authentication and authorization status indicates that the result of the network slice-specific authentication and authorization is a failure, deciding to skip at least one network slice-specific authentication and authorization process for the terminal device for at least one network slice of the network.
[0126] In one embodiment, for at least one network slice that requires network slice-specific authentication and authorization, at least one network slice-specific authentication and authorization process can be triggered with an AAA server hosted by the operator of the network or by a third party having a business relationship with the network.
[0127] In one embodiment, the network slice specific authentication and authorization process may be the same as the corresponding network slice specific authentication and authorization process as described in clause 4.2.9.2 of 3GPP TS 23.502 V16.3.0.
[0128] Figure 8a A flowchart of a UE registration process with an NSSAA procedure in a 5GS according to an embodiment of the present disclosure is depicted. For example, the UE has subscribed to four S-NSSAIs, three of which are subject to network slice-specific authentication and authorization, and one of which is a default S-NSSAI that does not require network slice-specific authentication and authorization.
[0129] In step 801, the UE accesses the network ( Figure 8a Source NG-RAN in the Figure 8a The source AMF in the 5G-GUTI sends a registration request, and the information contained in the request may include the user identity, such as SUPI or 5G-GUTI, and the requested NSSAI: S-NSSAI1, S-NSSAI2, S-NSSAI3, S-NSSAI4. For example,
[0130] SUPI:imsi-xxxx, associated GPSI:msisdn-yyyy
[0131] List of S-NSSAIs subscribed by the user, where S-NSSAI4 is the default S-NSSAI: S-NSSAI1: { "sst":2, "sd":"URLLC-SD1" } S-NSSAI2: { "sst":3, "sd":"mIOT-SD1" } S-NSSAI3: { "sst":4, "sd":"V2X-SD1" } S-NSSAI4: { "sst":1, "sd":"eMBB-SD1" }
[0132] The UE may indicate in the Registration Request message whether it supports network slice specific authentication and authorization in the UE 5GMM Core Network Capabilities. If the UE does not support this feature, the AMF shall not trigger the NSSAA procedure for the UE and if the UE requests these S-NSSAIs subject to network slice specific authentication and authorization, they shall be rejected for that PLMN.
[0133] For simplicity in the following steps, it is assumed that the UE supports network slice specific authentication and authorization features.
[0134] It is also possible that the requested S-NSSAI may need to be mapped to the S-NSSAI subscribed to by the HPLMN, but in this embodiment, for simplicity, it is assumed that the mapping is simple and direct because standardized SST (Slice / Service Type) values are used in this embodiment.
[0135] In step 802, if it is an initial registration and the user identity is a SUCI, the AMF shall decide to trigger the main authentication and authorization process for PLMN access. Once authenticated by the network, the SUPI corresponding to the SUCI is returned and the AMF may retain the mapping in the context; or if it is not an initial registration and the user identity is a 5G-GUTI, the AMF may obtain the SUPI from the AMF context through the 5G-GUTI and skip the main authentication and authorization process.
[0136] In step 803, the AMF requests slice selection subscription data from the UDM. This request can only obtain the slice selection subscription data, or can obtain user access and mobility management data including the slice selection subscription data.
[0137] In step 804, the UDM returns the user slice selection subscription data to the AMF. The UDM shall include information on whether network slice specific authentication and authorization are required for each subscribed S-NSSAI, as defined below (true means required, false means not required): S-NSSAI1 requiredAuthnAuthz: true S-NSSAI2 requiredAuthnAuthz: true S-NSSAI3 requiredAuthnAuthz: true S-NSSAI4 requiredAuthnAuthz:false
[0138] At step 805: the AMF parses the user slice selection subscription data to decide whether to trigger network slice specific authentication and authorization for each requested S-NSSAI. For example, S-NSSAI1, S-NSSAI2, and S-NSSAI3 are subject to network slice specific authentication and authorization.
[0139] In step 806, the AMF sends a registration accept message to the UE through the access network. As an example, the allowed NSSAI only contains S-NSSAI4 because it is subscribed by the user and does not require network slice specific authentication and authorization.
[0140] The AMF triggers the network slice specific authentication and authorization process for S-NSSAI1, S-NSSAI2, and S-NSSAI3 because they require network slice specific authentication and authorization.
[0141] In step 807, for the case where the AAA server (AAA-S) is hosted by the HPLMN operator, the AMF sends a network slice specific authentication and authorization request for S-NSSAI1 to the AAA server, for example through the AUSF.
[0142] In step 808, for the case where, for example, the AAA server belongs to a third party and an AAA proxy (AAA-P) in the serving PLMN may be involved, the AMF sends a network slice specific authentication and authorization request for S-NSSAI2 to the AAA server, for example through the AUSF, the AAA proxy.
[0143] In step 809, for the case where, for example, the AAA proxy (AAA-P) in the serving PLMN may be involved if the AAA server belongs to a third party, the AMF sends a network slice specific authentication and authorization request for S-NSSAI3 to the AAA server, for example through the AUSF, the AAA proxy.
[0144] In step 810, the AMF obtains the result (e.g., success) of the network slice-specific authentication and authorization for S-NSSAI1, for example, from the AAA server, AUSF to the AMF.
[0145] At step 811, the AMF stores the NSSAA status for S-NSSAI1 in the UE context: {S-NSSAI1: Success}.
[0146] In step 812, the AMF sends a UE configuration update to the UE through the access network, for example, updating the allowed NSSAI to include the allowed S-NSSAI1.
[0147] In step 813, the AMF obtains the result (e.g., success) of the network slice specific authentication and authorization for S-NSSAI2, e.g., from the AAA server, AAA proxy, AUSF to the AMF.
[0148] At step 814, the AMF stores the NSSAA status for S-NSSAI2 in the UE context: {S-NSSAI2: Success}.
[0149] In step 815, the AMF sends a UE configuration update to the UE through the access network, for example, updating the allowed NSSAI to include allowed S-NSSAI2.
[0150] In step 816: AMF obtains the result (e.g., failure) of the network slice specific authentication and authorization for S-NSSAI3, e.g., from the AAA server, AAA proxy, AUSF to AMF.
[0151] In step 817, the AMF stores the NSSAA status for S-NSSAI3 in the UE context: {S-NSSAI3: Failed}.
[0152] In step 818, the AMF sends a UE configuration update to the UE through the access network, for example, updating the allowed NSSAI to include the rejected S-NSSAI3 and the cause.
[0153] Please note that in this embodiment, the network slice-specific authentication and authorization results for S-NSSAI1, S-NSSAI2, and S-NSSAI3 are updated to the UE respectively, and multiple results can also be included in one configuration update to the UE.
[0154] Figure 8b A flow chart of N2-based handover with optimized NSSAA procedure according to an embodiment of the present disclosure is depicted. 8b is due to mobility for the same user Figure 8a Continue the call process.
[0155] Introduction Figure 8b Step 822 is used by the source AMF to Figure 8a The NSSAA status obtained during the registration procedure is provided to the target AMF so that during UE initiated mobility registration update after N2 based handover, the target AMF can optimize the NSSAA status from the source AMF. Figure 8b Steps 831-832 of the NSSAA process are skipped Figure 8a The network slice specific authentication and authorization procedures have been performed in the target AMF, and the NSSAA state is stored in the UE context in the target AMF, which avoids unnecessary signaling traffic ( Figure 8a 807-818) and improves the handover performance measured in terms of delay.
[0156] The source NG-RAN decides to initiate an N2-based handover to the target NG-RAN at step 819. For example, an N2-based handover may be triggered due to new radio conditions or load balancing.
[0157] In step 820, source RAN to source AMF: handover required (target ID, source-to-target transparent container, SM N2 information list, PDU session ID, intra-system handover indication).
[0158] Step 821, target AMF selection: When the source AMF can no longer serve the UE, the source AMF selects the target AMF.
[0159] In step 822, the source AMF sends a Namf_Communication_CreateUEContext request to the target AMF.
[0160] For UE context information, in addition to the allowed NSSAI for each access type, it also contains the NSSAA status (e.g. success / failure) of the allowed NSSAI subject to network slice specific authentication and authorization.
[0161] For example: - For S-NSSAI that requires NSSAA: {S-NSSAI1: success, S-NSSAI2: success, S-NSSAI3: failure}. - For S-NSSAI that does not require NSSAA: S-NSSAI4.
[0162] In step 823, other operations for N2-based handover preparation, such as PDU session management context update between SMF, UPF (target UPF, source UPF, anchor UPF), etc. are performed.
[0163] In step 824, the target AMF sends a Namf_Communication_CreateUEContext response to the source AMF.
[0164] In step 825, source AMF to source RAN to UE: Handover Command.
[0165] In step 826, the source RAN sends an uplink RAN status transfer message to the source AMF. The target AMF sends this information to the target RAN via a downlink RAN status transfer.
[0166] In step 827, the UE sends a Handover Confirm message to the target RAN: After the UE has successfully synchronized to the target cell, the UE sends a Handover Confirm message to the target RAN. Through this message, the UE considers the handover successful.
[0167] Target RAN to Target AMF: Handover Notification, with this message, the handover is considered successful in the target-RAN.
[0168] In step 828, other operations are performed for handover based on N2, such as PDU session management context update between SMF, UPF (source UPF, target UPF, anchor UPF), etc.
[0169] At step 829, the UE initiates a mobile registration update procedure.
[0170] In step 830, the target AMF may decide whether to initiate the main authentication and authorization process based on local policy and security context.
[0171] Compared with the prior art, steps 831 to 833 are new steps.
[0172] In step 831, the target AMF Figure 8a The slice selection subscription data of step 804 is used to check whether there is an allowed NSSAI subject to network slice specific authentication and authorization, and to check whether there is already a corresponding NSSAA state available (with the help of step 822 from the source AMF).
[0173] At step 832, based on the availability of the NSSAA state from step 22, the target AMF decides to skip the network slice specific authentication and authorization procedure for the S-NSSAI subject to network slice specific authentication and authorization.
[0174] If the source AMF does not provide NSSAA status during the N2 based handover procedure, the target AMF must perform the network slice specific authentication and authorization procedure. In this embodiment, the Figure 8a 807-818. It is therefore clear that the proposed step 822 of using the source AMF to provide the NSSAA status to the target AMF can optimize the NSSAA procedure at the target AMF, avoiding unnecessary network signaling traffic for the NSSAA procedure during N2-based handover. Advantages of the proposed solution may include: for users, fast service response time and minimized latency for the N2-based handover procedure; for network operators, OPEX reduction can be achieved because unnecessary signaling is avoided and network performance is improved.
[0175] At step 833, the target AMF stores the NSSAA status in the UE context for the UE, which can be used later to optimize the UE re-registration procedure or to provide the latest NSSAA status (if updated) to another new target AMF during an N2-based handover procedure.
[0176] At step 834, a Registration Accept with NSSAA status is sent back to the UE, for example: - For S-NSSAI that requires NSSAA: {S-NSSAI1: success, S-NSSAI2: success, S-NSSAI3: failure}, - For S-NSSAI that does not require NSSAA: S-NSSAI4.
[0177] like Figure 8a and 8b Some of the messages shown in are the same as the corresponding messages described in 3GPP TS 23.502 V16.3.0.
[0178] Figure 6 、 7 , 8a and 8b can be viewed as method steps, and / or operations generated by the operation of computer program code, and / or multiple coupled logic circuit elements configured to perform related function(s). The schematic flow charts described above are generally described as logic flow charts. Therefore, the depicted order and the marked steps indicate a specific embodiment of the presented method. Other steps and methods that are equivalent to one or more steps or parts thereof of the illustrated method in function, logic or effect can be envisioned. In addition, the order in which a particular method occurs may or may not strictly adhere to the order of the corresponding steps shown.
[0179] Embodiments herein provide many advantages, the following is a non-exhaustive list of examples of the advantages. In some embodiments herein, during an N2-based handover procedure, the target AMF may optimize the NSSAA procedure based on the NSSAA state for allowed NSSAI subject to network slice specific authentication and authorization provided by the source AMF during the N2-based handover procedure. In some embodiments herein, during an N2-based handover procedure, unnecessary network signaling traffic may be avoided. In some embodiments herein, for users, fast service response time and minimized latency for an N2-based handover procedure may be achieved. In some embodiments herein, for network operators, OPEX reduction may be achieved due to avoidance of unnecessary signaling and improved network performance. After reading the following detailed description, those skilled in the art will recognize additional features and advantages.
[0180] Figure 9 900 is a block diagram illustrating an apparatus suitable for practicing some embodiments of the present disclosure. For example, any one of the first access and mobility management entity and the second access and mobility management entity described above may be implemented as the apparatus 900 or through the apparatus 900.
[0181] The apparatus 900 includes at least one processor 921, such as a DP, and at least one memory 922 coupled to the processor 921. The apparatus 920 may also include a transmitter TX and a receiver RX 923 coupled to the processor 921. The memory 922 stores a program 924. The program 924 may include instructions that, when executed on the associated processor 921, enable the apparatus 920 to operate in accordance with embodiments of the present disclosure. The combination of the at least one processor 921 and the at least one memory 922 may form a processing device 925 suitable for implementing various embodiments of the present disclosure.
[0182] Various embodiments of the present disclosure may be implemented by a computer program executable by one or more of the processor 921 , software, firmware, hardware, or a combination thereof.
[0183] The memory 922 may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology such as, by way of non-limiting example, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory.
[0184] Processor 921 may be of any type suitable to the local technical environment, and may include, by way of non-limiting example, one or more of a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture.
[0185] In an embodiment where the apparatus is implemented as or at a first access and mobility management entity, the memory 922 stores instructions executable by the processor 921, whereby the first access and mobility management entity performs the following operations according to the reference Figure 6 Method 600 may be operated in any of the ways described.
[0186] In an embodiment where the apparatus is implemented as or at a second access and mobility management entity, the memory 922 stores instructions executable by the processor 921 whereby the second access and mobility management entity manages the access and mobility of the user in accordance with the instructions described in reference to FIG. Figure 7 The method 700 is described to operate.
[0187] Figure 10 1 is a block diagram illustrating a first access and mobility management entity according to an embodiment of the present disclosure. As shown in the figure, the first access and mobility management entity 1000 includes an obtaining module 1002 and a sending module 1004. The obtaining module 1002 may be configured to obtain at least one authentication and authorization status for a terminal device for at least one network slice of a network. The sending module 1004 may be configured to send at least one authentication and authorization status for a terminal device for at least one network slice of a network to a second access and mobility management entity during a handover process.
[0188] Figure 11 1 is a block diagram illustrating a second access and mobility management entity according to an embodiment of the present disclosure. As shown in the figure, the second access and mobility management entity 1100 includes a receiving module 1102 and a determining module 1104. The receiving module 1102 may be configured to receive at least one authentication and authorization status for a terminal device for at least one network slice of a network from the first access and mobility management entity during a handover process. The determining module 1104 may be configured to decide to skip at least one network slice-specific authentication and authorization process for the terminal device for at least one network slice of the network based on the received at least one authentication and authorization status for the terminal device for at least one network slice of the network.
[0189] The term unit or module may have a conventional meaning in the field of electronics, electrical devices and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, output and / or display functions, etc. (such as those described herein).
[0190] Through the functional units, the first and second access and mobility management entities no longer require fixed processors or memory, and any computing and storage resources can be allocated from the first and second access and mobility management entities in the communication system. The introduction of virtualization and network computing technologies can improve the efficiency of network resource utilization and network flexibility.
[0191] According to one aspect of the present disclosure, there is provided a computer program product tangibly stored on a computer-readable storage medium and comprising instructions which, when executed on at least one processor, cause the at least one processor to perform any of the methods described above.
[0192] According to one aspect of the present disclosure, a computer-readable storage medium storing instructions is provided. When the instructions are executed by at least one processor, the instructions cause the at least one processor to perform any of the methods described above.
[0193] In addition, the present disclosure may also provide a carrier containing the computer program as described above, wherein the carrier is one of the following: an electric signal, an optical signal, a radio signal, or a computer-readable storage medium. The computer-readable storage medium may be, for example, an optical disc or an electronic storage device (such as RAM (random access memory), ROM (read-only memory), flash memory), a magnetic tape, a CD-ROM, a DVD, a Blu-ray disc, etc.
[0194] The techniques described herein can be implemented by various components, so that the device that implements one or more functions of the corresponding device described in the embodiment includes not only the components of the prior art, but also includes components for implementing one or more functions of the corresponding device described in the embodiment, and it may include separate components for each individual function or components that can be configured to perform one or more functions. For example, these techniques can be implemented in hardware (one or more devices), firmware (one or more devices), software (one or more modules), or a combination thereof. For firmware or software, it can be implemented by modules (e.g., processes, functions, etc.) that perform the functions described herein.
[0195] The example embodiments of the present invention have been described above with reference to block diagrams and flowchart illustrations of methods and apparatus. It will be understood that each block of the block diagrams and flowcharts, and combinations of blocks in the block diagrams and flowcharts, respectively, can be implemented by various means including computer program instructions. These computer program instructions can be loaded onto a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, when executed on the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart block or blocks.
[0196] In addition, although the operations are described in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in a continuous order, or that all operations shown be performed to achieve the desired result. In some cases, multitasking and parallel processing can be advantageous. Similarly, although several specific implementation details are included in the above discussion, these specific implementation details should not be interpreted as limiting the scope of the subject matter described herein, but should be interpreted as descriptions of features that can be specific to a particular embodiment. Certain features described in the context of a separate embodiment may also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment may also be implemented in multiple embodiments or in any suitable sub-combination.
[0197] Although this specification contains many specific implementation details, these should not be interpreted as limitations on the scope of any embodiment or the scope that may be claimed, but rather as descriptions of features that may be specific to a particular embodiment of a particular embodiment. Certain features described in this specification in the context of separate embodiments may also be implemented in a single embodiment in combination. Conversely, various features described in the context of a single embodiment may also be implemented in multiple embodiments or in any suitable sub-combination. Moreover, although features may be described above as working in certain combinations, and even initially claimed as such, in some cases one or more features from a claimed combination may be removed from that combination, and a claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0198] It will be apparent to those skilled in the art that, as technology advances, the concepts of the present invention may be implemented in various ways. The above embodiments are provided to illustrate the present disclosure rather than to limit the present disclosure, and it should be understood that, as readily understood by those skilled in the art, modifications and variations may be made without departing from the spirit and scope of the present disclosure. Such modifications and variations are considered to be within the scope of the present disclosure and the appended claims. The scope of protection of the present disclosure is defined by the appended claims.
Claims
1. A method at a first access and mobility management entity, comprising: obtaining at least one authentication and authorization status for the terminal device for at least one network slice of the network; as well as sending, during a handover procedure, to a second access and mobility management entity, the at least one authentication and authorization status for the terminal device for at least one network slice of the network, Wherein, during the handover process, the at least one authentication and authorization state for the terminal device for at least one network slice of the network is sent in a request for the first access and mobility management entity to create a context for the terminal device in the second access and mobility management entity.
2. The method according to claim 1, wherein Each network slice of the at least one network slice of the network is identified by a single network slice selection assistance information S-NSSAI.
3. The method according to claim 1 or 2, wherein: The handover process is an N2-based handover process between Next Generation Radio Access Network (NG-RAN) nodes.
4. The method according to any one of claims 1 to 3, wherein The first access and mobility management entity is an access and mobility management function AMF entity, and the second access and mobility management entity is an AMF entity.
5. The method according to any one of claims 1 to 4, wherein The at least one authentication and authorization status for the terminal device for at least one network slice of the network is obtained from another access and mobility management entity and / or from an authentication server.
6. The method according to claim 5, wherein: The authentication server is an authentication server function AUSF entity, and the other access and mobility management entity is an access and mobility management function AMF entity.
7. The method according to any one of claims 1 to 6, wherein The request is a Namf_Communication_CreateUEContext request.
8. The method according to any one of claims 1 to 7, further comprising: Storing the at least one authentication and authorization status for the terminal device for at least one network slice of the network.
9. A first access and mobility management entity, comprising: processor; and a memory coupled to the processor, the memory storing instructions executable by the processor, whereby the first access and mobility management entity is operable to: obtaining at least one authentication and authorization status for the terminal device for at least one network slice of the network; as well as sending, during a handover procedure, to a second access and mobility management entity, the at least one authentication and authorization status for the terminal device for at least one network slice of the network, Wherein, during the handover process, the at least one authentication and authorization state for the terminal device for at least one network slice of the network is sent in a request for the first access and mobility management entity to create a context for the terminal device in the second access and mobility management entity.
10. The first access and mobility management entity according to claim 9, wherein: The first access and mobility management entity is further operable to perform the method according to any one of claims 2 to 8.
11. A computer-readable storage medium storing instructions, which, when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 8.
12. A computer program product comprising instructions which, when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 8.