Access network equipment selection method and device
By sending a query message to the DNS containing indication information and GIN, a suitable non-3GPP access network device is selected, which solves the problem of mismatched authentication methods when terminal devices access non-public networks and enables successful online signing or external authentication.
Patent Information
- Application Number
- CN202511664328.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-28
- Publication Date
- 2026-02-24
AI Technical Summary
How to select appropriate non-3GPP access network equipment for terminal devices to support their access to non-public networks, considering the inconsistent capabilities supported by different non-3GPP access network equipment, which leads to mismatched authentication methods.
The terminal device sends a query message to the Domain Name Server (DNS), which includes first indication information, second indication information, and at least one Network Selection Group Identifier (GIN), indicating support for online subscription or external authentication requirements. The DNS selects a suitable non-3GPP access network device based on this information.
It enables the selection of appropriate non-3GPP access network equipment based on the authentication requirements of terminal devices, ensuring successful online signing or external authentication when accessing non-public networks, thereby improving the success rate and efficiency of access.
Smart Images

Figure CN121568091A_ABST
Abstract
Description
[0001] This application is a divisional application. The original application has the application number 202210108074.1 and the original application date is January 28, 2022. The entire contents of the original application are incorporated herein by reference. Technical Field
[0002] This application relates to the field of wireless communication technology, and in particular to an access network equipment selection method and apparatus. Background Technology
[0003] A non-public network is a network that provides services to specific users, distinct from public networks. When a terminal device wants to access services from a non-public network, it can register with the non-public network to obtain the relevant services.
[0004] Currently, terminal devices can be used through the non-third-party partner program (3 rd Access to non-public networks via 3GPP (Generation Partnership Project) access network equipment. In related technologies, terminal equipment accessing non-public networks can be used to obtain non-public network services. Since different non-3GPP access network devices support different capabilities, when a terminal device needs to access a non-public network through a non-3GPP access type, it is necessary to select a suitable non-3GPP access network device for the terminal device and access the non-public network through that non-3GPP access network device.
[0005] Therefore, how to select suitable non-3GPP access network equipment for terminal devices has become a technical problem that needs to be solved. Summary of the Invention
[0006] This application provides an access network equipment selection method and apparatus for selecting suitable non-3GPP access network equipment for terminal equipment.
[0007] Firstly, a method for selecting access network equipment is provided. This method can be executed by a terminal device or a chip with similar terminal device functionality. In this method, the terminal device sends a query message to a domain name server (DNS). The query message includes one or more of the following: first indication information, second indication information, and at least one group identifier for network (GIN). The first indication information indicates online subscription, and the second indication information indicates external authentication. The at least one GIN is the identifier of one or more default credentials servers (DCS) or credentialsholders (CH) belonging to a group. The query message requests the identification of a non-3GPP access network equipment, the non-3GPP access network equipment corresponding to which is located in a first non-public network. The terminal device receives a query response from the DNS, the query response including the non-3GPP access network equipment identification.
[0008] Based on the above scheme, the terminal device can indicate to the DNS whether it needs to support external authentication through one or more of the first indication information, the second indication information, and at least one GIN. Therefore, when selecting a non-3GPP access network device for the terminal device, the DNS can consider one or more of the first indication information, the second indication information, and at least one GIN, and select a suitable non-3GPP access network device for the terminal device according to the terminal device's indication. For example, when the terminal device supports or needs to support external authentication, the DNS can select a non-3GPP access network device capable of performing external authentication for the terminal device, thus enabling the terminal device to access a non-public network through a non-3GPP access network.
[0009] In one possible scenario, the first indication information is used to instruct online contract signing, for example, when the terminal device needs to access a non-public network to perform online contract signing. In another possible scenario, the first indication information is used to indicate whether the terminal device supports online contract signing. In yet another possible scenario, the first indication information can be used to indicate whether a non-3GPP access network device or the non-public network where the non-3GPP access network device resides supports online contract signing or whether online contract signing is required.
[0010] In one possible scenario, the second indication information is used to instruct external authentication, for example, when the terminal device needs to access a non-public network to perform external authentication. In another possible scenario, the second indication information is used to indicate whether the terminal device supports external authentication. In yet another possible scenario, the second indication information can be used to indicate whether a non-3GPP access network device or the non-public network in which the non-3GPP access network device resides supports external authentication or whether external authentication is required.
[0011] For example, suppose the first message contains first indication information and second indication information, such as online signing 1 and external authentication 1. Here, online signing 1 indicates support for online signing, and external authentication 1 indicates support for external authentication. Then it can be assumed that the terminal device supports both online signing and external authentication, or that a non-3GPP access network device supports both online signing and external authentication, or that a non-public network on which a non-3GPP access network is located supports both online signing and external authentication.
[0012] In one example, a GIN can be the identifier of one or more default credential servers or credential holders belonging to a group. Each GIN can indicate support for external authentication or online signing. For example, when a GIN indicates support for external authentication, one or more default credential servers or credential holders within the group corresponding to that GIN support external authentication. Similarly, when a GIN indicates online signing, one or more default credential servers or credential holders within the group corresponding to that GIN support online signing.
[0013] In one possible implementation, the query message also includes a non-public network identifier, where the first non-public network is the non-public network corresponding to the non-public network identifier.
[0014] Based on the above scheme, the terminal device can indicate a non-public network identifier to the DNS, so that the DNS can select a suitable non-3GPP access network device from the non-public network corresponding to the non-public network identifier according to the terminal device's instruction.
[0015] In one possible implementation, the query message also includes domain information, a first indication, a second indication, and one or more of at least one GIN contained within the domain information.
[0016] Based on the above scheme, the structure of the domain name information can be adjusted to include one or more of the following: first indication information, second indication information, and at least one GIN, to indicate the authentication method supported by the terminal device. This allows the DNS to select a suitable non-3GPP access network device through the domain name information when selecting a non-3GPP access network device for the terminal device.
[0017] In one possible implementation, when the query message includes at least one GIN, the first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform online signing, or the first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform external authentication.
[0018] For example, suppose the first message contains GIN 1 and GIN 2, where GIN 1 indicates support for online signing or identifies a group that supports online signing, and GIN 2 indicates support for external authentication or identifies a group that supports external authentication. The first message also contains a non-public network identifier 1. Then, the non-public network corresponding to non-public network identifier 1 (referred to as the first non-public network) can support online signing by connecting to the default credential server or credential holder contained within the group corresponding to GIN 1.
[0019] Based on the above scheme, online signing or external authentication is performed by connecting to the default credential server or credential holder through the first non-public network to authenticate the terminal device, thereby enabling the terminal device to access the non-public network and obtain non-public network services.
[0020] In one possible implementation, non-3GPP access network equipment supports online subscription or external authentication. For example, when the terminal equipment supports or needs to support online subscription, the non-3GPP access network equipment supports online subscription. When the terminal equipment supports or needs to support external authentication, the non-3GPP access network equipment supports external authentication.
[0021] Based on the above scheme, the non-3GPP access network equipment identified by the DNS for the terminal device can support online subscription or external authentication. If the terminal device supports online subscription, the non-3GPP access network equipment can also support online subscription. If the terminal device supports external authentication, the non-3GPP access network equipment can also support external authentication, thereby realizing the authentication of the terminal device and allowing the terminal device to access the non-public network.
[0022] In one possible implementation, the terminal device sends first information to a non-3GPP access network device, the first information indicating online signing or external authentication.
[0023] Based on the above scheme, the terminal device can instruct the non-3GPP access network device to sign up for online subscription or external authentication, which allows the non-3GPP access network device to select a suitable core network device, such as AMF, to provide access services for the terminal device, enabling the terminal device to access a non-public network.
[0024] In one possible implementation, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0025] Secondly, a method for selecting access network equipment is provided. This method can be executed by DNS or a chip with similar DNS functionality. In this method, DNS receives a query message from a terminal device, the query message including one or more of the following: first indication information, second indication information, and at least one GIN. The first indication information indicates online subscription, and the second indication information indicates external authentication. The at least one GIN is an identifier of one or more default credential servers or the group to which the credential holder belongs. The query message requests a non-3GPP access network equipment identifier, the non-3GPP access network equipment corresponding to which the non-3GPP access network equipment identifier is located in a first non-public network. DNS sends a query response to the terminal device, the query response including the non-3GPP access network equipment identifier. The non-3GPP access network equipment identifier is determined based on the query message.
[0026] In one possible implementation, the query message also includes a non-public network identifier, where the first non-public network is the non-public network corresponding to the non-public network identifier.
[0027] In one possible implementation, the query message also includes domain information, a first indication, a second indication, and one or more of at least one GIN contained within the domain information.
[0028] In one possible implementation, when the query message includes at least one GIN, the first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform online signing, or the first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform external authentication.
[0029] In one possible implementation, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0030] Thirdly, a method for selecting access network equipment is provided. This method can be executed by a terminal device or a chip with similar terminal device functionality. In this method, the terminal device determines a non-public network identifier based on configuration information. The configuration information indicates a non-public network that supports online subscription or external authentication. The terminal device sends a query message to a DNS, which includes the non-public network identifier. The terminal device receives a query response from the DNS, which includes a non-3GPP access network equipment identifier, indicating that the non-3GPP access network equipment corresponding to the non-3GPP access network equipment identifier is located in the non-public network corresponding to the non-public network identifier.
[0031] Based on the above scheme, the terminal device can select a non-public network identifier from non-public network identifiers that support online signing or external authentication through configuration information. Therefore, the terminal device can indicate the signing method to the DNS through the non-public network identifier. In this way, the DNS can select a non-3GPP access network device from the non-3GPP access network devices included in the non-public network corresponding to the non-public network identifier.
[0032] In one example, the configuration information may include at least one of the following: a non-public network identifier that supports online contract signing and a non-public network identifier that supports external authentication. There may be one or more non-public network identifiers supporting online contract signing; similarly, there may be one or more non-public network identifiers supporting external authentication.
[0033] It is understandable that if the configuration information does not contain a non-public network identifier that supports online signing, it can be assumed that the terminal device does not support online signing or that there is no non-public network that supports online signing, or that there is no non-3GPP access network device deployed that supports online signing. Similarly, if the configuration information does not contain a non-public network identifier that supports external authentication, it can be assumed that the terminal device does not support external authentication or that there is no non-public network that supports external authentication, or that there is no non-3GPP access network device deployed that supports external authentication.
[0034] In one possible implementation, the configuration information indicates that all non-3GPP access network devices within a non-public network that support online signing also support online signing. And / or, the configuration information indicates that all non-3GPP access network devices within a non-public network that support external authentication also support external authentication.
[0035] Based on the above scheme, when all non-3GPP access network devices in a non-public network that supports online signing support online signing, and the configuration information indicates that all non-3GPP access network devices in a non-public network that supports external authentication support external authentication, the DNS can select any non-3GPP access network device in the non-public network indicated by the terminal device. The authentication method supported by the non-3GPP access network device selected by the DNS will be the same as the authentication method supported by the terminal device. Therefore, the terminal device can access the non-public network through the non-3GPP access network device selected by the DNS.
[0036] In one possible implementation, the terminal device sends first information to a non-3GPP access network device, the first information indicating online signing or external authentication.
[0037] Based on the above scheme, the terminal device can instruct the non-3GPP access network device to sign up for online subscription or external authentication, which allows the non-3GPP access network device to select a suitable core network device, such as AMF, to provide access services for the terminal device, enabling the terminal device to access a non-public network.
[0038] In one possible implementation, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0039] Fourthly, a method for selecting access network equipment is provided. This method can be executed by a non-3GPP access network device or by a chip with similar functionality to a non-3GPP access network device. In this method, the non-3GPP access network device receives first information from a terminal device, the first information indicating online subscription or external authentication. Based on the first information, the non-3GPP access network device selects a mobility management device that supports online subscription or external authentication.
[0040] Based on the above scheme, the terminal device can instruct the non-3GPP access network device to sign up for online subscription or external authentication, which allows the non-3GPP access network device to select a suitable core network device, such as AMF, to provide access services for the terminal device, enabling the terminal device to access a non-public network.
[0041] In one possible implementation, the non-3GPP access network device is either an untrusted non-3GPP access network device or a non-3GPP interoperability function.
[0042] Based on the above scheme, terminal devices can access non-public networks through untrusted non-3GPP access network devices or non-3GPP interoperability functions to obtain services from non-public networks.
[0043] Fifthly, a method for selecting access network equipment is provided. This method can be executed by a terminal device or a chip with similar terminal device functionality. In this method, the terminal device obtains the identifier of at least one non-public network. Based on configuration information, the terminal device determines the identifier of a first non-public network from the identifiers of the at least one non-public network. The configuration information indicates a non-public network that supports online subscription or a non-public network that supports external authentication. The terminal device establishes a connection with a trusted non-3GPP access network device located in the first non-public network.
[0044] Based on the above scheme, the terminal device can determine the identifier of the first non-public network through configuration information and the identifier of at least one non-public network. In this way, the authentication method indicated by the non-public network is the authentication method supported by the terminal device. Therefore, the terminal device sends the identifier of the first non-public network to the trusted non-3GPP access network device, indicating the authentication method supported by the terminal device, so that the trusted non-3GPP access network device can select a suitable mobility management device to perform access management for the terminal device.
[0045] In one possible implementation, the terminal device receives one or more of a first indication message, a second indication message, and at least one GIN. The first indication message indicates that at least one non-public network supports online subscription. The second indication message indicates that at least one non-public network supports external authentication. The at least one GIN is an identifier for one or more default credential servers or a group to which the credential holder belongs.
[0046] Based on the above scheme, the terminal device can also indicate the supported authentication method to the trusted non-3GPP access network device through one or more of the first indication information, the second indication information, and at least one GIN, so that the non-3GPP access network device can select a suitable mobility management device to perform access management for the terminal device.
[0047] In one possible implementation, the terminal device obtains the identifier of at least one non-public network from the broadcast message.
[0048] In one example, a broadcast message may include a first indication and identifiers of one or more non-public networks. This can be understood as the one or more non-public networks supporting online subscription. In another possibility, the broadcast message may contain a list of networks. For example, this network list may contain identifiers of one or more non-public networks supporting online subscription, and the first indication may be the name of the network list. Each non-public network in this network list represents a non-public network that a trusted non-3GPP access network device supports connecting to.
[0049] In another example, the broadcast message may include a second indication and identifiers of one or more non-public networks. This can be understood as the one or more non-public networks supporting external authentication. In one possible scenario, the broadcast message may contain a list of networks. For example, this network list may contain identifiers of one or more non-public networks that support external authentication, and the second indication could be the name of the network list. Each non-public network in this network list represents a non-public network that a trusted non-3GPP access network device supports connecting to.
[0050] In another example, a broadcast message may include at least one GIN that supports online subscription, indicating one or more non-public networks that a trusted non-3GPP access network device can connect to, supporting online subscription with the default credential server or credential holder contained in at least one GIN. As another example, a broadcast message may include at least one GIN that supports external authentication, indicating one or more non-public networks that a trusted non-3GPP access network device can connect to, supporting external authentication when connecting to the default credential server or credential holder contained in at least one GIN.
[0051] Sixthly, a method for selecting an access network device is provided. This method can be executed by a trusted non-3GPP access network device (N / A device) or by a chip with similar functionality to a trusted N / A device. In this method, the trusted N / A device sends an identifier of at least one non-public network. The trusted N / A device establishes a connection with a terminal device. The trusted N / A device receives a registration request message from the terminal device. The registration request message includes an identifier of a first non-public network. The identifier of the first non-public network is one of at least one identifier of a non-public network. The trusted N / A device sends the registration request message to a mobility management device (MMD). The MMD performs terminal device access management and is determined based on the identifier of the first public network.
[0052] In one possible implementation, a trusted non-3GPP access network device receives first information from a terminal device, indicating online subscription or external authentication. The trusted non-3GPP access network device selects a mobility management device that supports either online subscription or external authentication. The trusted non-3GPP access network device then sends a registration request message to the mobility management device.
[0053] In one possible implementation, a trusted non-3GPP access network device sends one or more of a first indication message, a second indication message, and at least one GIN. The first indication message indicates that at least one non-public network supports online subscription. The second indication message indicates that at least one non-public network supports external authentication. The at least one GIN is an identifier for one or more default credential servers or a group to which the credential holder belongs.
[0054] In one possible implementation, a trusted non-3GPP access network device sends a broadcast message that includes the identifier of at least one non-public network.
[0055] In one possible implementation, the first or second instruction information is the name of the network list.
[0056] In one possible implementation, the first indication information is the name of a first network list, and the second indication information is the name of a second network list. The first network list contains the identifier of at least one second non-public network, and this at least one second non-public network supports online signing. The second network list contains the identifier of at least one third non-public network, and this at least one third non-public network supports external authentication; the identifier of the at least one non-public network includes the identifier of at least one second non-public network and / or the identifier of at least one third non-public network.
[0057] Based on the above scheme, trusted non-3GPP access network devices can broadcast the identifiers of non-public networks that support online subscription and those that support external authentication in broadcast messages. This allows terminal devices to select one non-public network identifier from the broadcast non-public network identifiers, thereby determining the authentication method supported by the terminal device. As a result, a suitable mobility management device can be selected for the terminal device.
[0058] Seventhly, a method for selecting access network equipment is provided. This method can be executed by a mobility management device or a chip with similar mobility management device functionality. In this method, the mobility management device receives second information from a terminal device, the second information indicating the access technology type of the terminal device, and the mobility management device is located in a non-public network. Based on the access technology type, the mobility management device determines at least one of data network name information and network slice information, wherein the network slice corresponding to the network slice information is a network slice allowed to be used by the terminal device, and the data network corresponding to the data network name information is a data network allowed to be connected to by the terminal device.
[0059] Based on the above scheme, the terminal device can perform non-public network services by using at least one of the network slice information and data network name information determined by the mobility management device. Since the network slice information and data network name information are selected by the mobility management device according to the access technology type of the terminal device, different network slice information and data network name information can be selected according to the access technology type of the terminal device, thus enabling differentiated transmission to the terminal device.
[0060] In one possible implementation, the mobility management device receives third information from the terminal device, indicating an online subscription. When the access technology type indicates that the terminal device is accessing a non-public network via a public network, the mobility management device denies the terminal device's access.
[0061] Eighthly, embodiments of this application provide a communication device, which may be a terminal device or a chip for a terminal device. The device has the function of implementing any of the methods described in the first aspect. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0062] Ninthly, embodiments of this application provide a communication device, which may be a DNS, or a chip or module for DNS. The device has the function of implementing any of the methods described in the second aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0063] Tenthly, embodiments of this application provide a communication device, which may be a terminal device, or a chip or module for a terminal device. The device has the function of implementing any of the methods described in the third aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0064] Eleventhly, embodiments of this application provide a communication device, which may be a non-3GPP access network device, or a chip or module for a non-3GPP access network device. The device has the function of implementing any of the implementation methods of the fourth aspect described above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0065] In a twelfth aspect, embodiments of this application provide a communication device, which may be a terminal device, or a chip or module for a terminal device. The device has the function of implementing any of the methods described in the fifth aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0066] In a thirteenth aspect, embodiments of this application provide a communication device, which may be a trusted non-3GPP access network device, or a chip or module for a trusted non-3GPP access network device. The device has the function of implementing any of the methods described in the sixth aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0067] In a fourteenth aspect, embodiments of this application provide a communication device, which may be a mobility management device, or a chip or module for a mobility management device. The device has the function of implementing any of the methods described in the seventh aspect above. This function can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions.
[0068] In a fifteenth aspect, embodiments of this application provide a communication device, including a processor and a memory; the memory is used to store computer instructions, and when the device is running, the processor executes the computer instructions stored in the memory to cause the device to perform any of the implementation methods in the first to seventh aspects described above.
[0069] In a sixteenth aspect, embodiments of this application provide a communication apparatus including units or means for performing various steps of any of the implementation methods in the first to seventh aspects described above.
[0070] In a seventeenth aspect, embodiments of this application provide a communication device, including a processor and an interface circuit. The processor is configured to communicate with other devices via the interface circuit and execute any of the implementation methods described in the first to seventh aspects. The processor may include one or more devices.
[0071] In an eighteenth aspect, embodiments of this application provide a communication device including a processor coupled to a memory, the processor being configured to invoke a program stored in the memory to execute any of the implementation methods described in the first to seventh aspects. The memory may be located within or outside the device. Furthermore, the processor may be one or more.
[0072] In a nineteenth aspect, embodiments of this application also provide a computer-readable storage medium storing instructions that, when executed on a communication device, cause any of the implementation methods of the first to seventh aspects to be performed.
[0073] In a twentieth aspect, embodiments of this application also provide a computer program product, which includes a computer program or instructions that, when executed by a communication device, cause any of the implementation methods in the first to seventh aspects to be executed.
[0074] In a twentieth aspect, embodiments of this application also provide a chip system, including: a processor for executing any of the implementation methods in the first to seventh aspects described above.
[0075] In a twentieth aspect, embodiments of this application also provide a communication system, including: the communication device of the eighth aspect and the communication device of the ninth aspect described above. Optionally, it also includes the communication device of the eleventh aspect. Optionally, it also includes the communication device of the fourteenth aspect.
[0076] In a twentieth aspect, embodiments of this application also provide a communication system, including: the communication device of the twelfth aspect and the communication device of the thirteenth aspect described above. Attached Figure Description
[0077] Figure 1 A schematic diagram of an untrusted, non-3GPP access network provided in an embodiment of this application; Figure 2 A schematic diagram of a trusted non-3GPP access network provided in an embodiment of this application; Figure 3 This is one of the exemplary flowcharts of an access network device selection method provided in an embodiment of this application; Figure 4 This is one of the exemplary flowcharts of an access network device selection method provided in an embodiment of this application; Figure 5 This is one of the exemplary flowcharts for a terminal device to access a non-public network provided in the embodiments of this application; Figure 6 This is one of the exemplary flowcharts for authenticating terminal devices provided in the embodiments of this application; Figure 7 This is one of the exemplary flowcharts of an access network device selection method provided in an embodiment of this application; Figure 8 This is one of the exemplary flowcharts for a terminal device to access a non-public network provided in the embodiments of this application; Figure 9 This is one of the exemplary flowcharts for authenticating terminal devices provided in the embodiments of this application; Figure 10 A schematic diagram of the interoperability architecture between PLMN and non-public networks provided in the embodiments of this application; Figure 11 This is one of the exemplary flowcharts of an access network device selection method provided in an embodiment of this application; Figure 12 This is one of the exemplary flowcharts of an access network device selection method provided in an embodiment of this application; Figure 13One of the schematic diagrams of a communication device provided in the embodiments of this application; Figure 14 This is one of the schematic diagrams of a communication device provided in an embodiment of this application. Detailed Implementation
[0078] To facilitate understanding of the technical solutions provided in the embodiments of this application, the technical terms involved in this application are explained and described below.
[0079] 1) A non-public network (NPN) is a network that provides services to specific users, distinct from public networks. Depending on whether the core network (CN) is independent, non-public networks can be categorized into two types: A standalone NPN (SNPN) is a network that does not rely on a public land mobile network (PLMN) and is operated by the SNPN operator. This can be understood as the SNPN's core network being independent of the PLMN network; in other words, the SNPN's core network is operated independently by the SNPN.
[0080] A non-standalone (NSA) NPN (public network integrated NPN, PNI-NPN) network relies on a PLMN network operated by a traditional carrier. It can be understood that PNI-NPN is essentially a PLMN, but this PLMN provides special network slices and / or data networks to deliver NPN services. This means that not all terminal devices can access these NPN services; only those devices that pass slice authentication and / or secondary authentication can obtain them. Simply put, PNI-NPN isolates public network services from non-public network services through slicing, thereby providing non-public network services to non-public network users.
[0081] 2) SNPN external subscription means that the terminal device's credentials are owned or belong to the credential holder (CH), or allocated by the credential holder. This CH is different from the SNPN that the terminal device accesses. Therefore, compared to the terminal device's SNPN access process, the difference lies in the fact that the terminal device's primary authentication or security process is executed on the CH, not within the SNPN. For different CH architectures, the network elements participating in the SNPN access process will also differ during the UE's access to the SNPN.
[0082] 3) Default credentials server (DCS): An entity that can perform authentication based on default terminal credentials or an entity that can provide a way to enable other entities to perform authentication based on default terminal credentials.
[0083] 4) Credentials holder (CH): An entity used to authenticate and authorize terminals to access an independent, non-public network other than the credentials holder.
[0084] 5) SNPN online subscription refers to the process where, when a terminal device has not obtained subscription data for accessing a non-public network (e.g., the requested non-public network's subscription data), it needs to use default credentials, default UE credentials, or PLMN credentials to access the online subscription network (which can be understood as the network performing online subscription). The subscription data may include credentials used for authentication. Once the terminal device successfully accesses the online subscription network, it establishes a connection with the providing server (PVS). The PVS provides the terminal device with subscription data for accessing the non-public network, such as credentials used for authentication, through the online subscription network.
[0085] 6) Non-3GPP Access Types: Non-3GPP access types include untrusted non-3GPP access technologies (e.g., access to the core network via personally purchased wireless access nodes), trusted non-3GPP access technologies (e.g., access to the core network via operator-deployed wireless access nodes), and wired access technologies. Non-3GPP access technologies can include wireless communication technologies (WiFi), Bluetooth, or ZigBee. Non-3GPP access network equipment can include non-3GPP interworking functions (N3IWF), trusted non-3GPP gateway functions (TNGF), trusted non-3GPP access points (TNAP), trusted wireless local area network interworking functions (TWIF), and wired access gateway functions (W-AGF). W-AGF can also be referred to as AGF. If the access technology is an untrusted, non-3GPP access technology, its corresponding non-3GPP access network equipment can include N3IWF, whose network topology is equivalent to the radio access network (RAN) in a 3GPP access network, and can support N2 and N3 interfaces. If the access technology is a trusted, non-3GPP access technology, its corresponding non-3GPP access network equipment can include TNGF, whose network topology is equivalent to the RAN in a 3GPP access network, and can support N2 and N3 interfaces.
[0086] See Figure 1 This diagram illustrates an untrusted, non-3GPP access system provided in an embodiment of this application. The terminal device first establishes a connection with the untrusted, non-3GPP access point, obtains its Internet Protocol (IP) address, and then, according to the N3IWF discovery and selection criteria, obtains the N3IWF's IP identification information, such as address information, through a DNS server. The terminal device then establishes an Internet Protocol Security (IPSec) tunnel with the N3IWF and accesses the core network through the N3IWF.
[0087] See Figure 2This diagram illustrates a trusted non-3GPP access system provided in an embodiment of this application. For example, a WiFi access point deployed in a public place. The terminal device first selects a PLMN and then selects a non-3GPP access network within that PLMN that provides a trusted connection. The terminal device then selects the connection type.
[0088] The following is an introduction Figure 1 and Figure 2 The functions of each device are shown in the diagram.
[0089] Untrusted, non-3GPP access points can be access nodes that are not deployed by operators, such as WiFi access points (APs) deployed in homes or businesses.
[0090] The N3IWF can be used to enable interconnection between terminal devices and the 3GPP core network using non-3GPP technologies. The N3IWF supports communication with mobility management equipment via the N2 interface and with user plane equipment via the N3 interface.
[0091] A trusted non-3GPP access point can be an access node deployed by an operator and can be called a trusted non-3GPP access point (TNAP).
[0092] TNAP can be used to send authentication, authorization, and accounting (AAA) messages. For example, it can encapsulate extensible authentication protocol (EAP) packets in AAA messages and interact with TNGF, and can also be used to forward EAP messages.
[0093] TNGF can be used to support N2 and N3 interfaces, terminate EAP-5G signaling, and enable AMF selection, processing, and N2 signaling (relayed by SMF) to support functions such as session and quality of service (QoS) and transparent relay of protocol data units (PDUs) between terminal equipment and user plane equipment.
[0094] 3GPP access points can be access nodes deployed by operators.
[0095] User plane function (UPF) network elements are used to perform functions such as user plane data forwarding, session / flow-based billing statistics, and bandwidth limiting.
[0096] The Session Management Function (SMF) network element is responsible for performing functions such as session management, execution of control policies, selection of user plane function network elements, and allocation of Internet Protocol (IP) addresses for terminals. The Access and Mobility Management Function (AMF) network element is responsible for performing functions such as mobility management and access authentication / authorization. Furthermore, the AMF network element is also responsible for transmitting user policies to terminals.
[0097] Terminal equipment can also be called user equipment (UE), mobile station, mobile terminal, etc. Figure 1 In this application, UE represents the terminal. Terminals can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminals can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiments of this application do not limit the specific technologies or device forms used in the terminal.
[0098] Currently, terminal devices can access non-public networks through non-3GPP access network devices. In related technologies, when a terminal device accesses a non-public network through a non-3GPP access network device, authentication of the terminal device is required to determine whether it is authorized to access the non-public network. Because different non-3GPP access network devices exist, the authentication methods also differ.
[0099] Therefore, if the authentication methods supported by non-3GPP access network equipment differ from those supported by the terminal equipment, authentication of the terminal equipment cannot be performed. For example, a terminal equipment can register an SNPN using SNPN credentials, or it can register an SNPN using default terminal credentials to perform online signing, or it can register an SNPN using the credential holder's credentials. To support a terminal equipment registering an SNPN through a non-3GPP access network equipment, the terminal equipment needs to consider whether the non-3GPP access network equipment supports online signing or external authentication. Otherwise, when the terminal equipment accesses a non-public network, if the non-3GPP access network equipment does not support online signing or external authentication, the terminal equipment cannot further perform online signing or external authentication. Therefore, when selecting a non-3GPP access network equipment, the terminal equipment needs to consider whether the network supports online signing or external authentication services; otherwise, the non-3GPP access network equipment cannot recognize the terminal equipment as performing online signing or external authentication, or it cannot select a suitable core network equipment, such as AMF, for the terminal equipment. Therefore, how to select a suitable non-3GPP access network equipment for the terminal equipment becomes a technical problem that needs to be solved.
[0100] In view of this, embodiments of this application provide a method for selecting access network devices. See also... Figure 3 The following is an exemplary flowchart of an access network device selection method provided in an embodiment of this application, which may include the following operations. Figure 3 The illustrated embodiments can be applied to untrusted, non-3GPP communication systems, such as... Figure 1 The communication system shown.
[0101] S301: The terminal device sends the first message to the DNS.
[0102] Accordingly, DNS receives the first message.
[0103] This first message can be used to obtain the identifier of a non-3GPP access network device. In S301, the terminal device can send a query message to the DNS. The following describes the information contained in the first message, which may contain any one or more of the following 1 to 3: 1. First instruction information.
[0104] In one possible scenario, the first instruction information may indicate online contract signing. For example, when a terminal device needs to access a non-public network to perform online contract signing, the first message may include the first instruction information to indicate online contract signing. For example, if the first message contains the first instruction information, it can be assumed that the terminal device needs to perform online contract signing, or the terminal device is performing online contract signing, or the non-3GPP access network device that the terminal device requests to connect to needs to support online contract signing, or the non-public network where the non-3GPP access network device that the terminal device requests to connect to is located needs to support online contract signing. If the first message does not contain the first instruction information, it can be assumed that the terminal device does not need to perform online contract signing, or the terminal device does not perform online contract signing, or the non-3GPP access network device that the terminal device requests to connect to does not need to support online contract signing, or the non-public network where the non-3GPP access network device that the terminal device requests to connect to is located does not need to support online contract signing.
[0105] It should be noted that when a terminal device supports or performs online signing, it can be understood that when accessing a non-public network, the terminal device can use the default terminal credentials for authentication, or it can perform authentication through other methods. When a terminal device needs to support or perform online signing, it can be understood that when accessing a non-public network, the terminal device needs to use the default terminal credentials for authentication. When a non-3GPP access network device supports or needs to support online signing, it can be understood that the non-3GPP access network device can recognize the online signing instruction information sent by the terminal device, or it can be understood that the non-3GPP access network device can select a mobility management device (such as an AMF) that supports online signing. When a non-public network supports or needs to support online signing, it can be understood that the non-public network supports connecting to the default credential server to support the authentication process for terminal devices that use the default terminal credentials for authentication; or it can be understood that the non-public network supports connecting to the providing server or opening server to send credentials (or the credentials of the SNPN that the terminal device wants to access) to the terminal device.
[0106] For example, a bit carrying the first indication information of 0 indicates support for or a requirement for online signing; conversely, a bit carrying the first indication information of 1 indicates support for or a requirement for online signing. Another example is the addition of a field to the first message to carry the first indication information, such as "onboarding." The inclusion of an "onboarding" field in the first message indicates that the terminal device supports or requires support for online signing.
[0107] In another possible scenario, the first indication information can be used to indicate whether the terminal device supports online signing or needs to support online signing. For example, a bit carrying the first indication information of 0 indicates that online signing is supported or required, while a bit carrying the first indication information of 1 indicates that online signing is not supported or not required. Conversely, a bit carrying the first indication information of 0 indicates that online signing is not supported or not required, while a bit carrying the first indication information of 1 indicates that online signing is supported or required.
[0108] In another possible scenario, the first indication information can be used to indicate whether a non-3GPP access network device or a non-public network in which the non-3GPP access network device resides supports online subscription or requires online subscription support. For example, a bit carrying the first indication information with a value of 0 indicates that online subscription is supported or required, while a bit carrying the first indication information with a value of 1 indicates that online subscription is not supported or not required. Conversely, a bit carrying the first indication information with a value of 0 indicates that online subscription is not supported or not required, while a bit carrying the first indication information with a value of 1 indicates that online subscription is supported or required.
[0109] In another possible scenario, the first indication information can be included in the domain name information, such as the full qualified domain name (FQDN). In one possible implementation, a portion of the domain name information serves as the first indication information. For example, the full qualified domain name could be “n3iwf.5gc.snpnid999123456789ABCDE.mnc012,mcc345.onboarding0.pub.3gppnetwork.org”; where “onboarding” can be the first indication information, and 0 represents the value of the first indication information. This application does not restrict the name of the first indication information, nor does it restrict the position of the field containing the first indication information within the full qualified domain name.
[0110] It is understood that the number of bits used to carry the first indication information can be set according to empirical values, such as 1 bit, 2 bits or 3 bits, etc., and this application does not make specific limitations.
[0111] For example, a field could be added to the first message to carry the first instruction information. For instance, "onboarding 0" and "onboarding 1". "Onboarding 0" means online signing is not supported or not required, while "onboarding 1" means online signing is supported or required. Conversely, "onboarding 1" means online signing is not supported or not required, while "onboarding 0" means online signing is supported or required.
[0112] It should be noted that the embodiments of this application do not specifically limit the structure of the first indication information. The first indication information can indicate online signing, or indicate whether the terminal device supports online signing, or indicate whether the terminal device needs to support online signing, or whether the non-3GPP access network device supports online signing, or whether the non-3GPP access network device needs to support online signing, or indicate whether the non-public network where the non-3GPP access network device is located supports online signing, or indicate whether the non-public network where the non-3GPP access network device is located needs to support online signing.
[0113] Based on the above scheme, the terminal device can indicate to the DNS via the first indication information whether the terminal device, the non-3GPP access network device, or the non-public network where the non-3GPP access network device is located needs to support online subscription. Therefore, the DNS can consider this first indication information when selecting a non-3GPP access network device for the terminal device, and thus select a suitable non-3GPP access network device for the terminal device according to the terminal device's indication. For example, if the terminal device supports online subscription or needs to support online subscription, or if the non-3GPP access network device supports online subscription or needs to support online subscription, or if the non-public network where the non-3GPP access network device is located needs to support online subscription, the DNS can select a non-3GPP access network device capable of performing online subscription for the terminal device. This allows the terminal device to register a non-public network through a non-3GPP access network to perform online subscription.
[0114] 2. Second instruction information.
[0115] In one possible scenario, the first indication information could instruct external authentication. For example, when the terminal device requires external authentication or needs to access the SNPN using external credentials, the first message could include second indication information to instruct external authentication, external credentials, or that the terminal device accesses the SNPN using credentials from a credential holder outside the SNPN. For instance, if the first message contains second indication information, it could mean that the terminal device needs to support external authentication, or the terminal device supports external authentication, or the non-3GPP access network device supports external authentication, or the non-3GPP access network device needs to support external authentication, or the non-public network where the non-3GPP access network device is located supports external authentication, or the non-public network where the non-3GPP access network device is located needs to support external authentication. When the first message does not contain the second instruction information, it can be assumed that the terminal device does not need to support external authentication, or the terminal device does not support external authentication, or the non-3GPP access network device does not support external authentication, or the non-3GPP access network device does not need to support external authentication, or the non-public network where the non-3GPP access network device is located does not support external authentication, or the non-public network where the non-3GPP access network device is located does not need to support external authentication.
[0116] It should be noted that supporting external authentication for terminal devices means that when accessing non-public networks, the terminal device can perform authentication through external authentication methods, or it can also perform authentication through other methods. The requirement for terminal devices to support external authentication means that when accessing non-public networks, the terminal device needs to perform authentication through external authentication methods. Supporting or requiring external authentication for non-3GPP access network devices means that non-3GPP access network devices can choose a mobility management device (such as an AMF) that supports external authentication. The requirement for non-3GPP access network devices to be located on a non-public network that supports or requires external authentication means that the non-public network can support connections with credential holders outside the non-public network to perform authentication procedures on terminal devices using those credential holders' credentials.
[0117] For example, a bit carrying the second indication information of 0 indicates that external authentication is supported or required; conversely, a bit carrying the second indication information of 1 indicates that external authentication is supported or required. Another example is that a field can be added to the first message to carry the second indication information, such as "external authentication." The inclusion of an external authentication field in the first message indicates that the terminal device supports or requires external authentication.
[0118] In another possible scenario, the second indication information can be used to indicate whether the terminal device supports external authentication or requires external authentication. For example, a bit carrying the second indication information of 0 indicates that external authentication is supported or required, while a bit carrying the second indication information of 1 indicates that external authentication is not supported or not required. Conversely, a bit carrying the second indication information of 0 indicates that external authentication is not supported or not required, while a bit carrying the second indication information of 1 indicates that external authentication is supported or required.
[0119] In another possible scenario, the second indication information can be used to indicate whether a non-3GPP access network device or a non-public network in which the non-3GPP access network device is located supports external authentication or requires external authentication. For example, a bit carrying the second indication information with a value of 0 indicates that external authentication is supported or required, while a bit carrying the second indication information with a value of 1 indicates that external authentication is not supported or not required. Conversely, a bit carrying the second indication information with a value of 0 indicates that external authentication is not supported or not required, while a bit carrying the second indication information with a value of 1 indicates that external authentication is supported or required.
[0120] In another possible scenario, the second indication information can be included in the domain name information, such as in the fully qualified domain name (FQDN). In one possible implementation, a portion of the domain name information is the second indication information. For example, the fully qualified domain name could be "n3iwf.5gc.snpnid999123456789ABCDE.mnc012,mcc345.ExternalAuthentication0.pub.3gppnetwork.org"; where ExternalAuthentication can be the first indication information, and 0 is the value of the second indication information. This application does not restrict the name of the second indication information, nor does it restrict the position of the field within the fully qualified domain name containing the second indication information.
[0121] It is understood that the number of bits used to carry the second indication information can be set according to empirical values, such as 1 bit, 2 bits or 3 bits, etc., and this application does not make specific limitations.
[0122] For example, a field could be added to the first message to carry the first indication information. For instance, "external authentication 0" and "external authentication 1". For example, "external authentication 0" indicates that external authentication is not supported or is not required, while "external authentication 1" indicates that external authentication is supported or is required. Conversely, "external authentication 1" indicates that external authentication is not supported or is not required, while "external authentication 0" indicates that external authentication is supported or is required.
[0123] It should be noted that the embodiments of this application do not specifically limit the structure of the second indication information. The second indication information can be used for external authentication, or to indicate whether the terminal device supports external authentication, or whether the terminal device needs to support external authentication.
[0124] The following explanation combines the first and second instruction information.
[0125] For example, suppose the first message contains first indication information and second indication information, such as online signing 1 and external authentication 1. Here, online signing 1 indicates support for online signing, and external authentication 1 indicates support for external authentication. Then it can be assumed that the terminal device supports both online signing and external authentication, or that a non-3GPP access network device supports both online signing and external authentication, or that a non-public network on which a non-3GPP access network is located supports both online signing and external authentication.
[0126] For example, suppose the first message contains first indication information and second indication information, such as online signing 0 and external authentication 1. Here, online signing 0 indicates that online signing is not supported, and external authentication 1 indicates that external authentication is supported. Then it can be assumed that the terminal device does not support online signing but supports external authentication; or that a non-3GPP access network device may not need to support online signing but needs to support external authentication; or that a non-3GPP access network device located on a non-public network may not need to support online signing but needs to support external authentication.
[0127] Based on the above scheme, the terminal device can indicate to the DNS via the second indication information whether it needs to support external authentication, or whether it needs to select a non-3GPP access network device or a non-public network that supports external authentication. Therefore, the DNS can consider this second indication information when selecting a non-3GPP access network device for the terminal device, and thus select a suitable non-3GPP access network device for the terminal device according to the terminal device's indication. For example, if the terminal device supports or needs to support external authentication, or if the non-3GPP access network device needs to support external authentication, or if the non-public network where the non-3GPP access network device is located needs to support external authentication, the DNS can select a non-3GPP access network device that can perform external authentication for the terminal device. This allows the terminal device to register a non-public network using external credentials through the non-3GPP access network.
[0128] 3. At least one GIN.
[0129] A GIN can be an identifier for one or more default credential servers or credential holders belonging to a group. Each GIN can indicate support for external authentication or online signing. For example, if a GIN indicates support for external authentication, then one or more default credential servers or credential holders within the group corresponding to that GIN support external authentication. Similarly, if a GIN indicates support for online signing, then one or more default credential servers or credential holders within the group corresponding to that GIN support online signing.
[0130] Optionally, when the terminal device supports or needs to support online signing, or when the terminal device needs to select a non-3GPP access network device or non-public network that supports online signing, at least one GIN can indicate online signing. When the terminal device supports or needs to support external authentication, or when the terminal device needs to select a non-3GPP access network device or non-public network that supports external authentication, at least one GIN can indicate external authentication.
[0131] For example, when a terminal device supports online subscription or needs to select a non-3GPP access network device or non-public network that supports online subscription, it can instruct the selected non-3GPP access network device to support online subscription, or instruct the non-public network where the non-3GPP access network device is located to support connection with one or more default credential servers or credential holders contained in the group corresponding to the GIN to perform online subscription. When a terminal device supports external authentication or needs to select a non-3GPP access network device or non-public network that supports external authentication, it can instruct the selected non-3GPP access network device to support external authentication, or instruct the non-public network where the non-3GPP access network device is located to support connection with one or more default credential servers or credential holders contained in the group corresponding to the GIN to perform external authentication.
[0132] Based on the above scheme, the terminal device can indicate to the DNS via the GIN whether it supports online subscription or external authentication, or indicate whether the selected non-3GPP access network device or non-public network needs to support online subscription or external authentication. Therefore, the DNS can consider this GIN when selecting a non-3GPP access network device for the terminal device, and thus select a suitable non-3GPP access network device for the terminal device according to the terminal device's instructions. For example, if the terminal device supports or needs to support external authentication, or if the non-3GPP access network device or non-public network needs to support external authentication, the DNS can select a non-3GPP access network device capable of performing external authentication for the terminal device. This allows the terminal device to register a non-public network using external credentials through the non-3GPP access network.
[0133] In one example, the first message may also include a non-public network identifier. For example, the first message may include one or more non-public network identifiers. These non-public network identifiers may include either an SNPN identifier or a PNI-NPN identifier. For instance, the first message may include one or more SNPN identifiers, or it may include one or more PNI-NPN identifiers, or it may include both SNPN and PNI-NPN identifiers. In one possible implementation, the PNI-NPN identifier is a PLMN ID; where the PLMN ID (Public Land Mobile Network Identifier) can be a combination of a mobile country code (MCC) and a mobile network code (MNC). In another possible implementation, the SNPN identifier is a combination of a PLMN ID and a network identifier (NID).
[0134] The one or more non-public network identifiers mentioned above, along with one or more non-3GPP access network devices within the corresponding non-public network, can support online subscription for terminal devices, or the one or more non-public network identifiers mentioned above can support external authentication for terminal devices. For example, if the first message contains a non-public network identifier 1, then the one or more non-3GPP access network devices within the non-public network 1 corresponding to non-public network identifier 1 can support online subscription for terminal devices, or support external authentication for terminal devices. Optionally, a non-public network identifier can contain one or more non-3GPP access network devices. Each non-3GPP access network device can only support online subscription for terminal devices, or can only support external authentication for terminal devices. Optionally, each non-3GPP access network device can support both online subscription and external authentication for terminal devices.
[0135] For example, suppose the first message contains GIN 1 and GIN 2, where GIN 1 indicates support for online signing or identifies a group that supports online signing, and GIN 2 indicates support for external authentication or identifies a group that supports external authentication. The first message also contains a non-public network identifier 1. Then, the non-public network corresponding to non-public network identifier 1 (referred to as the first non-public network) can support online signing by connecting to the default credential server or credential holder within the group corresponding to GIN 1. The first non-public network also supports external authentication by connecting to the default credential server or credential holder within the group corresponding to GIN 2. Optionally, when the terminal device supports or needs to support online signing, or when the terminal device needs to select a non-3GPP access network device or non-public network that supports online signing, the first non-public network can connect to the default credential server or credential holder contained in the group corresponding to GIN1 to perform online signing. When the terminal device supports or needs to support external authentication, or when the terminal device needs to select a non-3GPP access network device or non-public network that supports external authentication, the first non-public network can connect to the default credential server or credential holder contained in the group corresponding to GIN2 to perform external authentication.
[0136] In another example, the first message may also include domain name information. For example, the first message may include a full qualified domain name (FQDN). Optionally, one or more of the first instruction information, the second instruction information, and at least one GIN may be included in the domain name information; that is, the domain name information may include one or more of the first instruction information, the second instruction information, and at least one GIN. For example, when the domain name information includes one or more of the first instruction information, the second instruction information, and at least one GIN, the implementation can be referred to in 1 to 3 above.
[0137] In one possible implementation, one or more GINs can be included in the domain name information, such as a full qualified domain name (FQDN). In another possible implementation, some fields of the domain name information are one or more GINs. For example, the full qualified domain name could be “n3iwf.5gc.GIN999123456789ABCDE.snpnid999123456789ABCDE.mnc012,mcc345..pub.3gppnetwork.org”; where 999123456789ABCDE is the value of the GIN. This application does not restrict the name or value of the GIN, nor does it restrict the position of the GIN within the full qualified domain name.
[0138] S302: DNS sends the first response to the terminal device.
[0139] Accordingly, the terminal device receives a first response. This first response can be a response message to the first message in S301. For example, DNS can send a query response to the terminal device.
[0140] The first response in S302 may include a non-3GPP access network device identifier. This non-3GPP access network device identifier can correspond to an untrusted non-3GPP access network device or an N3IWF. This non-3GPP access network device identifier can be determined by DNS based on the first message in S301.
[0141] For example, suppose the first message contains a first indication, and the first indication indicates online subscription. Then, the DNS can select a non-3GPP access network device capable of online subscription for the terminal device based on the first indication. As another example, suppose the first message contains a second indication, and the second indication indicates external authentication. Then, the DNS can select a non-3GPP access network device capable of external authentication for the terminal device based on the second indication. Similarly, the DNS can select a suitable non-3GPP access network device for the terminal device based on information contained in the first message, such as the first indication, the second indication, and at least one or more of a GIN. The DNS can then send the identifier of the selected non-3GPP access network device to the terminal device.
[0142] Based on the above scheme, the terminal device can indicate to the DNS the capabilities that the selected non-3GPP access network device needs to support, such as supporting online subscription or external authentication, through the first indication information, the second indication information, and at least one GIN. In this way, when the DNS selects a non-3GPP access network device for the terminal device, it can select a suitable non-3GPP access network device for the terminal device according to the terminal device's indication.
[0143] In one possible implementation, the terminal device may send first information to a non-3GPP access network device. This first information indicates online subscription or external authentication. That is, the terminal device may send an authentication method to the non-3GPP access network device. For example, if the terminal device supports online subscription, needs to perform online subscription, or needs to select a non-3GPP access network device that supports online subscription, then the first information sent by the terminal device to the non-3GPP access network device may indicate online subscription. The implementation of the first information may refer to the aforementioned first indication information.
[0144] For example, if the terminal device supports external authentication, needs to perform external authentication, or needs to select a non-3GPP access network device that supports external authentication, then the first information sent by the terminal device to the non-3GPP access network device can indicate external authentication. The implementation of the first information can refer to the aforementioned second indication information.
[0145] In the above Figure 3 In the illustrated embodiment, the terminal device indicates to the DNS whether online subscription or external authentication is supported, thus allowing the DNS to select a suitable non-3GPP access network device for the terminal device. The following will explain... Figure 4 This application introduces an embodiment of another method for selecting access network devices. Figure 4 In the illustrated embodiment, non-public network identifiers supporting external authentication and online subscription can be pre-configured. Therefore, by indicating the non-public network identifier to the DNS, the terminal device can indicate to the DNS whether it supports online subscription or external authentication. In this way, the DNS can also select a suitable non-3GPP access network device for the terminal device.
[0146] See Figure 4 The following is an exemplary flowchart of an access network device selection method provided in an embodiment of this application, which may include the following operations.
[0147] S401: The terminal device determines the non-public network identifier based on the configuration information.
[0148] The configuration information may include at least one of the following non-public network identifiers: one that supports online contract signing and one that supports external authentication. Similarly, the configuration information may include one or more non-public network identifiers that support online contract signing and one or more non-public network identifiers that support external authentication.
[0149] It is understandable that non-public network devices within non-public networks that support online signing can all support online signing. Similarly, non-public network devices within non-public networks that support external authentication can all support external authentication.
[0150] In S401, if the terminal device supports or needs to support online signing, it can determine a non-public network identifier from one or more non-public network identifiers that support online signing included in the configuration information. If the terminal device supports or needs to support external authentication, it can determine a non-public network identifier from one or more non-public network identifiers that support external authentication included in the configuration information.
[0151] It is understandable that if the configuration information does not contain a non-public network identifier that supports online signing, it can be assumed that the terminal device does not support online signing or that there is no non-public network that supports online signing, or that there is no non-3GPP access network device deployed that supports online signing. Similarly, if the configuration information does not contain a non-public network identifier that supports external authentication, it can be assumed that the terminal device does not support external authentication or that there is no non-public network that supports external authentication, or that there is no non-3GPP access network device deployed that supports external authentication.
[0152] For example, if the configuration information includes one or more non-public network identifiers that support online subscription, but does not include one or more non-public network identifiers that support external authentication, it can be assumed that the terminal device does not support external authentication, or does not need to select a non-3GPP access network device or non-public network that supports external authentication, or assumes that there is no non-public network that supports external authentication, or assumes that there is no non-3GPP access network device deployed that supports external authentication. The terminal device can determine one non-public network identifier from one or more non-public network identifiers that support online subscription.
[0153] S402: The terminal device sends the first message to the DNS.
[0154] The aforementioned first message can be a query message. This first message can be used to request the identification of a non-3GPP access network device. This first message may include the non-public network identification determined in S401.
[0155] S403: DNS sends the first response to the terminal device.
[0156] The aforementioned first response can be a response to the first message in S402, such as a query response. This first response may include the non-3GPP access network device selected by the DNS for the terminal device. For example, the DNS can select a non-3GPP access network device from the non-public network corresponding to the non-public network identifier included in the first message in S402, and send the identifier of the selected non-3GPP access network device to the terminal device in the first response.
[0157] Based on the above Figure 4 In the embodiment shown, the terminal device can select a non-public network identifier through configuration information. Therefore, the terminal device can use the non-public network identifier to indicate to the DNS the capabilities that the selected non-public network or non-3GPP access network device needs to support. In this way, the DNS can select a non-3GPP access network device from the non-3GPP access network devices included in the non-public network corresponding to the non-public network identifier.
[0158] The above Figure 3 and Figure 4 This paper introduces how DNS selects non-3GPP access network devices for terminal devices. The following section, in conjunction with... Figure 5 The registration process for terminal devices can include the following steps.
[0159] S501: The terminal device establishes an IPsec Security Association (IPSec SA) with the non-3GPP access network device.
[0160] For example, a terminal device can establish an IPsec SA with a non-3GPP access network device by initiating an initial exchange of Internet Key Exchange (IKE). This non-3GPP access network device can be the non-3GPP access network device corresponding to the non-3GPP access network device identifier sent by DNS to the terminal device in S302 or S403.
[0161] S502: The terminal device sends a first request message to a non-3GPP access network device.
[0162] Correspondingly, non-3GPP access network devices receive the first request message.
[0163] For example, a terminal device can send an IKE_AUTH request message to a non-3GPP access network device.
[0164] Optionally, the first request message may not contain an AUTH payload, indicating that the first request message is used for authentication. For example, when the first request message does not contain a payload, it may indicate that the first request message is used for extensible authentication protocol (EAP) signaling interaction.
[0165] S503: Non-3GPP access network equipment sends a first response message to the terminal equipment.
[0166] Accordingly, the terminal device receives the first response message.
[0167] The aforementioned first response message can be a response message to the first request message in S502. For example, the first response message can be an IKE_AUTH response message.
[0168] Optionally, the response message may include an EAP request or a 5G mobile communication technology (5G) request. thThe 5G (5G) generation mobile communication technology - Start packet. This EAP request or 5G start packet can be used to notify the terminal device to initiate an EAP-5G session.
[0169] S504: The terminal device sends a second request message to a non-3GPP access network device.
[0170] Correspondingly, non-3GPP access network devices receive the second request message.
[0171] For example, a terminal device can send an IKE_AUTH Request message to a non-3GPP access network device.
[0172] The second request message mentioned above may include an EAP response or a 5G-NAS data packet.
[0173] The aforementioned 5G-NAS data packet may include access network (AN) parameters and registration request messages. AN parameters contain information used by non-3GPP access network devices to select an AMF (Access Network Provider), such as a globally unique AMF identifier (GUAMI) or the selected PLMN ID. Optionally, the AMF selection parameters may also include a network identification (NID). It is understood that in an SNPN scenario, the PLMN ID and NID can uniquely identify an SNPN.
[0174] Optionally, the terminal device may include the first information in the AN parameters. For example, if the terminal device performs online signing, the first information may indicate online signing. As another example, if the terminal device performs external authentication, the first information may indicate external authentication.
[0175] S505: Non-3GPP access network devices send a registration request message to the AMF.
[0176] In one possible implementation, the non-3GPP access network device selects an AMF and sends a registration request message to the selected AMF. In another possible implementation, the non-3GPP access network device can select an AMF based on AN parameters.
[0177] For example, if the AN parameters include first information indicating online subscription, then the non-3GPP access network device selects an AMF that supports online subscription for the terminal device. If the AN parameters include first information indicating external authentication, then the non-3GPP access network device selects an AMF that supports external authentication for the terminal device.
[0178] S506: AMF initiates or requests authentication of the terminal device.
[0179] For example, when a terminal device indicates that it needs to perform online signing, the AMF can select the corresponding authentication device to authenticate the terminal device. For instance, when the default credential server domain indicated by the terminal device's identifier has both an authentication server function (AUSF) and a unified data management (UDM) device deployed, the AMF selects the ASF in the default credential server domain to perform authentication on the terminal device. When the default credential server indicated by the terminal device's identifier has an AAA server deployed, the AMF selects the local ASF (an ASF located in the same network as the AMF) to perform authentication on the terminal device or participate in the authentication process of that terminal device. When a terminal device instructs or requires external authentication, the AMF can select the corresponding authentication device to authenticate the terminal device. For example, when the credential holder indicated by the terminal device's identifier has deployed an authentication server function (AUSF) and a unified data management (UDM) device, the AMF selects the ASF among the credential holders to perform authentication on the terminal device. When the credential holder indicated by the terminal device's identifier has deployed an authentication, authorization, and accounting (AAA) server, the AMF selects the local ASF (an ASF located in the same network as the AMF) to perform authentication on the terminal device or participate in the authentication process of that terminal device.
[0180] It is understandable that the authentication service for terminal devices can be provided by the Authentication Server Function (AUSF), meaning that the authentication operation for terminal devices can be performed by the AUSF. The AUSF can obtain the authentication data or subscription data of the terminal devices from the Unified Data Management (UDM) function. If the terminal device performs online subscription and the DCS domain deploys AUSF and UDM, then the AUSF and UDM can be considered as the DCS domain's AUSF and UDM, which can be understood as the AUSF and UDM deployed in the DCS. If the terminal device performs external authentication and the CH deploys AUSF and UDM, then the AUSF and UDM can be considered as the CH domain's AUSF and UDM, which can be understood as the CH domain's AUSF and UDM. Optionally, if the terminal device performs online subscription and the DCS domain deploys an authentication, authorization, and accounting (AAA) server, the UDM can be replaced by the AAA server in the DCS domain, and the AUSF can be an AUSF located in the same network as the AMF. In other words, the AAA server in the DCS domain performs the authentication of the terminal device. Alternatively, if the terminal device performs external authentication and the CH deploys an AAA server, the UDM can be replaced by the AAA server in the CH, and the AUSF can be an AUSF located in the same network as the AMF. In other words, the AAA server in the CH can perform the authentication of the terminal device.
[0181] The following is through Figure 6 This application describes the method for authenticating terminal devices in its embodiments. Figure 6 An exemplary flowchart for authentication provided in this application includes the following operations.
[0182] S601: AMF sends an authentication request message to AUSF.
[0183] Accordingly, AUSF receives authentication request messages.
[0184] The AMF can choose the AUSF and send an authentication request message to the AUSF. The AUSF can provide authentication services to authenticate terminal devices.
[0185] S602: AUSF performs the authentication process on the terminal device and obtains authentication data from UDM.
[0186] In this context, authentication-related data packets are all encapsulated using non-access stratum (NAS) messages. These NAS messages are transmitted via EAP or 5G mobile communication technology (5G). th Generation Mobile Technology (5G) - NAS packet encapsulation. After authentication, the ASF sends the Security Anchor Function (SEAF) key to the AMF. The AMF uses this key to deduce the NAS security key and the N3IWF security key. This N3IWF key is used by the terminal device and the N3IWF to establish IPSe SA.
[0187] S603: AMF sends a NAS security mode command to the terminal device.
[0188] The NAS security mode command can be used to activate NAS security. The command may include EAP success information, indicating that the 3G to WLAN interconnection authentication and key agreement (EAP-AKA) performed by the core network was successful. The N3IWF forwards the NAS security mode command sent by the AMF to the terminal device and sends the NAS security mode complete message from the terminal device to the AMF.
[0189] S604: The AMF sends an NGAP initial context setup request message to the N3IWF.
[0190] For example, after receiving a NAS security mode completion message from the terminal device, the AMF can send an NGAP initial connection establishment request to the N3IWF. This NAP initial connection establishment request may include the N3IWF key.
[0191] The N3IWF can send EPA success information to the terminal device.
[0192] S605: The terminal device and N3IWF establish an IPSec SA.
[0193] For example, terminal devices can establish an IPSec SA with N3IWF using the N3IWF key.
[0194] This IPSec SA is called a signaling IPSec SA. After the signaling IPSec SA is established, the N3IWF notifies the AMF that the UE context has been created via the NGAP initial context setup response.
[0195] At this point, the IPSec SA signal will be configured to operate in tunnel mode, and the N3IWF will assign an inner IP address and a NAS address (NAS_IP_ADDRESS) to the terminal device. All subsequent NAS messages will be transmitted through this IPSec SA signal. Specifically, for NAS messages sent from the terminal device to the AMF, the source address is the UE's inner IP address, and the destination address is the NAS address. For NAS messages sent from the AMF to the terminal device, the source address is the NAS address, and the destination address is the UE's inner IP address.
[0196] S606: AMF sends N2 message to N3IWF.
[0197] The N2 message may include a NAS registration accept message sent to the terminal device. When the AMF registers with the UDM, it must provide the UDM with an access type that is non-3GPP access.
[0198] S607: The N3IWF sends a NAS registration request to the terminal device via the IPSec SA signal.
[0199] Based on the above S601~S607, authentication of terminal devices can be achieved. Therefore, terminal devices can register or access non-public networks through non-3GPP access network devices.
[0200] The above Figures 3 to 6 The illustrated embodiments can be applied to untrusted, non-3GPP access systems. The following, in conjunction with... Figure 8 This application introduces another method for selecting access network devices based on embodiments. Figure 7 The illustrated embodiments can be applied to feasible non-3GPP access systems, such as Figure 3 The communication system shown may include the following operations.
[0201] S701: Trusted non-3GPP access network devices send an identifier of at least one non-public network.
[0202] For example, a trusted non-3GPP access network device can send a broadcast message. This broadcast message may include the identifier of at least one non-public network. For instance, a trusted non-3GPP access network device can broadcast a network list. This network list may include the identifier of at least one non-public network. The identifier of the at least one non-public network indicates a non-public network that the trusted non-3GPP access network device supports connecting to.
[0203] In one possible implementation, the broadcast message may also include one or more of a first instruction message, a second instruction message, and at least one GIN, which will be described below.
[0204] First instruction information: Used to instruct online signing. For example, the first instruction information may instruct at least one non-public network in S701 to support online signing.
[0205] For example, a broadcast message may include a first indication and the identifiers of one or more non-public networks. This can be understood as the one or more non-public networks supporting online subscription. In another possibility, the broadcast message may contain a list of networks. For instance, this network list may contain identifiers of one or more non-public networks that support online subscription, and the first indication may be the name of the network list. Each non-public network in this network list represents a non-public network that a trusted non-3GPP access network device supports connecting to.
[0206] Second indication information: used to indicate external authentication. For example, the second indication information may indicate that at least one non-public network in S701 supports external authentication.
[0207] For example, a broadcast message may include a second indication and the identifiers of one or more non-public networks. This can be understood as the one or more non-public networks supporting external authentication. In another possibility, the broadcast message may contain a list of networks. For instance, this network list may contain identifiers of one or more non-public networks that support external authentication, and the second indication could be the name of the network list. Each non-public network in this list represents a non-public network that a trusted non-3GPP access network device supports connecting to.
[0208] At least one GIN: refers to the identifier of one or more default credential servers or credential holders belonging to a group. It is used to indicate one or more non-public networks that a trusted non-3GPP access network device can connect to, supporting external authentication or online subscription through connections with the default credential servers or credential holders contained in the at least one GIN.
[0209] For example, a broadcast message may include at least one GIN that supports online subscription, indicating one or more non-public networks that a trusted non-3GPP access network device can connect to, supporting online subscription with the default credential server or credential holder contained in at least one GIN. As another example, a broadcast message may include at least one GIN that supports external authentication, indicating one or more non-public networks that a trusted non-3GPP access network device can connect to, supporting external authentication when connecting to the default credential server or credential holder contained in at least one GIN.
[0210] The following table, Table 1, lists the networks included in the broadcast message.
[0211] Table 1: Example of a network list
[0212] Table 2: An example of a network list
[0213] Table 3: An example of a network list
[0214] Table 4: An example of a network list
[0215] As shown in Table 1, non-public network identifiers supporting online signing can include non-public network identifier 1, non-public network identifier 2, and non-public network identifier 3, and GINs supporting online signing can include GIN1 and GIN3. This means that trusted non-3GPP access network devices can connect to the non-public network corresponding to any one of the non-public network identifiers 1, 2, and 3, and the non-public networks corresponding to non-public network identifiers 1, 2, and 3 can connect to the default credential server or credential holder within the group corresponding to any one of GINs 1 and 3 to perform online signing for the terminal device. Non-public network identifiers supporting external authentication can include non-public network identifier 4 and 5, and GINs supporting external authentication can include GIN2. This can be understood as follows: a trusted non-3GPP access network device can connect to the non-public network corresponding to any one of the non-public network identifiers 4 and 5, and this non-public network can connect to the default credential server or credential holder contained within the group corresponding to any GIN in GIN2, to perform external authentication for the terminal device. Table 1 shows an example of a network list.
[0216] It is understood that Table 1 does not constitute a limitation on the network list. Table 1 may include one or more rows, such as the first or second row, and may also include any one or more columns, such as the first, second, and third columns; this application does not impose any specific limitations.
[0217] As shown in Table 2, the non-public network identifiers supporting online contract signing can include non-public network identifier 1, non-public network identifier 2, and non-public network identifier 3. Furthermore, the GINs corresponding to non-public network identifier 1 that support online contract signing can include GIN1 and GIN3. Therefore, it can be understood that trusted non-3GPP access network devices can connect to the non-public network corresponding to any one of the non-public network identifiers 1, 2, and 3. Additionally, the non-public network corresponding to non-public network identifier 1 can connect to the default credential server or credential holder within the group corresponding to any one of GIN1 and GIN2, enabling online contract signing for the terminal device. Alternatively, the non-public network corresponding to non-public network identifier 2 can connect to the default credential server or credential holder within the group corresponding to any one of GIN1 and GIN3, enabling online contract signing for the terminal device. Similarly, the non-public network corresponding to non-public network identifier 3 can connect to the default credential server or credential holder within the group corresponding to any one of GIN2 and GIN3, enabling online contract signing for the terminal device. Non-public network identifiers supporting external authentication can include non-public network identifier 4 and non-public network identifier 5, and the GINs corresponding to non-public network identifier 4 that support external authentication can include GIN4 and GIN5. This can be understood as follows: trusted non-3GPP access network devices can connect to the non-public networks corresponding to non-public network identifiers 4 and 5; and the non-public network corresponding to non-public network identifier 4 can connect to the default credential server or credential holder within the group corresponding to either GIN4 or GIN5 to perform external authentication for the terminal device; or the non-public network corresponding to non-public network identifier 5 can connect to the default credential server or credential holder within the group corresponding to either GIN5 or GIN6 to perform external authentication for the terminal device. Table 2 shows an example of a network list.
[0218] In one possible implementation, a trusted non-3GPP access network device can broadcast one or more GINs and one or more non-public network identifiers corresponding to each GIN. Each GIN can be used to indicate support for online subscription or external authentication. For example, the group corresponding to GIN1 in Table 3 includes one or more default credential servers, and GIN1 indicates support for online subscription. That is, the non-public networks corresponding to non-public network identifiers 1, 2, and 3 can support online subscription. As another example, the group corresponding to GIN3 in Table 3 includes one or more credential holders, and GIN3 supports external authentication. That is, the non-public networks corresponding to non-public network identifiers 4 and 5 can support external authentication.
[0219] In another possible implementation, a trusted non-3GPP access network device can broadcast one or more non-public network identifiers and one or more GINs corresponding to each non-public network identifier. The GINs can be used to indicate support for online subscription or external authentication. For example, the groups corresponding to GIN1, GIN2, and GIN3 in Table 4 include one or more default credential servers, and GIN1, GIN2, and GIN3 are used to indicate support for online subscription. The group corresponding to GIN4 includes one or more default credential servers, and GIN4 is used to indicate support for external authentication. That is, the non-public network corresponding to non-public network identifier 1 supports online subscription, and the non-public network corresponding to non-public network identifier 2 can support either online subscription or external authentication.
[0220] Optionally, the broadcast message may also include a priority order of service set identifiers (SSIDs) that support online signing or external authentication.
[0221] S702: The terminal device determines the identifier of the first non-public network from the identifiers of at least one non-public network based on the configuration information.
[0222] The configuration information mentioned above may include the identifiers of one or more non-public networks that support online signing and the identifiers of one or more non-public networks that support external authentication, and the identifier of at least one non-public network.
[0223] In one possible scenario, the configuration information could be pre-configured for the terminal device, which can be referenced. Figure 4 The illustrated embodiment is implemented as follows. In another possible implementation, the configuration information may be sent to the terminal device by a trusted non-3GPP access network device or by the terminal device's home network, and can be implemented with reference to the network list in S701.
[0224] In S702, if the terminal device performs or needs to perform online signing, it can select an identifier of a non-public network that supports online signing from at least one identifier of a non-public network. If the terminal device performs or needs to perform external authentication, it can select an identifier of a non-public network that supports external authentication from at least one identifier of a non-public network.
[0225] S703: The terminal device sends a registration request message to a trusted non-3GPP access network device.
[0226] Correspondingly, trusted non-3GPP access network devices receive registration request messages.
[0227] The registration request message may include an identifier of a first non-public network. This identifier may be the identifier of the non-public network selected by the terminal device in S702.
[0228] S704: Trusted non-3GPP access network devices send registration request messages to the mobility management device.
[0229] The mobility management device here can perform access management for terminal devices. For example, the mobility management device can be an AMF (Active Mobile Controller).
[0230] For example, a trusted non-3GPP access network device can select a mobility management device that supports online subscription or external authentication for a terminal device. Exemplarily, the trusted non-3GPP access network device can select a mobility management device based on the identifier of the first non-public network selected by the terminal device in S702. For instance, if the terminal device selects the identifier of a first non-public network that supports online subscription in S702, then the trusted non-3GPP access network device can select a mobility management device that supports online subscription within that first non-public network. Similarly, if the terminal device selects the identifier of a first non-public network that supports external authentication in S702, then the trusted non-3GPP access network device can select a mobility management device that supports external authentication within that first non-public network.
[0231] Optionally, the terminal device may send first information to a trusted non-3GPP access network device. This first information may instruct online subscription or external authentication. For example, the first information may instruct the terminal device to perform online subscription or indicate that the terminal device needs to perform online subscription. In this case, the trusted non-3GPP access network device can select a mobility management device that supports online subscription in a first non-public network. Alternatively, the first information may instruct the terminal device to perform external authentication or indicate that the terminal device needs to perform external authentication. In this case, the trusted non-3GPP access network device can select a mobility management device that supports external authentication in a first non-public network.
[0232] This allows terminal devices to establish connections with trusted non-3GPP access network devices. For example, a terminal device can establish a layer 2 connection with a trusted non-3GPP access network device.
[0233] Based on the above scheme, the terminal device can determine the identifier of the first non-public network through configuration information and the identifier of at least one non-public network. In this way, the authentication method indicated by the non-public network is the authentication method executed by the terminal device. Therefore, the terminal device sends the identifier of the first non-public network to the trusted non-3GPP access network device, indicating the authentication method supported by the terminal device. The trusted non-3GPP access network device located in the non-public network corresponding to the identifier of the first non-public network can select a suitable mobility management device to perform access management for the terminal device according to the instructions of the terminal device.
[0234] exist Figure 7 In the illustrated embodiment, trusted non-3GPP access network equipment may include TNAP and TNGF. Figure 7 In the illustrated embodiment, operations S701 and S702 can be performed by TNAP, and operations S703 and S704 can be performed by TNGF.
[0235] The following, combined with Figure 8 The registration process for terminal devices can include the following steps. Figure 8 The following explanation uses non-3GPP access network equipment, including TNAP and TNGF, as examples.
[0236] S801: TNAP sends an EAP request or identification message to the terminal device.
[0237] Accordingly, the terminal device receives an EAP request or identification message. This message is used to request the terminal device's identification information.
[0238] S802: The terminal device sends a network access identifier (NAI) to TNAP.
[0239] NAI indicates a request for 5G connectivity to a specific PLMN.
[0240] For example, NAI = "<any_username> @nai.5gc.mnc <mnc>.mcc <mcc>The NAI (Network Identity) is located at ".3gppnetwork.org". This NAI triggers TANP to send an AAA request to TNGF. EAP packets between TNAP and TNGF are encapsulated using AAA messages. The AAA request also includes the TNAP identifier, which can be used as user location information (ULI).
[0241] S803: TNGF sends an EAP request or a 5G-start data packet to the terminal device.
[0242] The EAP request or 5G-start packet is used to notify the terminal device to initiate an EAP-5G session.
[0243] S804: The terminal device sends an EAP-response or 5G-NAS data packet to the TNGF.
[0244] The aforementioned EAP-response or 5G-NAS data packet may include AN parameters and a registration request message. The AN parameters contain information used by the TNGF to select an AMF, such as the GUAMI or the selected PLMN ID. Optionally, the AMF selection parameters may also include an NID. It is understood that in an SNPN scenario, the PLMN ID and NID can uniquely identify an SNPN.
[0245] Optionally, the terminal device may include the first information in the AN parameters. For example, if the terminal device performs online signing, the first information may indicate online signing. As another example, if the terminal device performs external authentication, the first information may indicate external authentication.
[0246] S805: TNGF sends a registration request message to AMF.
[0247] For example, TNGF can select an AMF for the terminal device and send a registration request message to the selected AMF.
[0248] For example, if the AN parameters include first information indicating online signing, then TNGF selects an AMF that supports online signing for the terminal device. If the AN parameters include first information indicating external authentication, then TNGF selects an AMF that supports external authentication for the terminal device.
[0249] S806: AMF initiates or requests access authentication process.
[0250] For example, when a terminal device instructs or requires online signing, the AMF can select an appropriate authentication device to authenticate the terminal device. For instance, if both an AFS and a UDM device are deployed in the CH indicated by the terminal device's identifier, the AMF will select the AFS in the CH to perform authentication. If an AAA server is deployed in the CH indicated by the terminal device's identifier, the AMF will select a local AFS (an AFS located in the same network as the AMF) to perform authentication or participate in the terminal device's authentication process. After selecting a suitable authentication device, the AMF can initiate the authentication process or request the authentication device to perform authentication of the terminal device.
[0251] The following is through Figure 9 This application describes the method for authenticating terminal devices in its embodiments. It should be noted that if the terminal device is performing an online contract signing, then... Figure 9 The AUSF shown can be an AUSF of the DCS domain. If the terminal device performs external authentication, then Figure 9 The AUSF shown can be a CH AUSF. Optionally, if the terminal device performs online subscription and the DCS domain deploys AAA services, the AUSF can be considered an AUSF located in the network where the AMF resides; that is, it can be executed by an AUSF located in the network where the AMF resides. Figure 9 The AUSF function shown is performed by the AAA server in the DCS domain to authenticate the terminal device. Optionally, if the terminal device performs external authentication and the CH deploys the AAA server, the AUSF can be replaced by the AUSF located in the AMF's network; that is, the AUSF in the AMF's network can perform the authentication. Figure 9 The AUSF function shown is performed by the AAA server in CH to authenticate the terminal device.
[0252] Figure 9 An exemplary flowchart for authentication provided in this application includes the following operations.
[0253] S901: AMF sends an authentication request message to AUSF.
[0254] Accordingly, AUSF receives authentication request messages.
[0255] AMF can select AUSF and send an authentication request message to AUSF.
[0256] S902: AUSF performs the authentication process on the terminal device and obtains authentication data from UDM.
[0257] All authentication-related data packets are encapsulated using NAS messages. These NAS messages are encapsulated using EAP or 5G-NAS data packets. After authentication, the AUSF sends the Security Anchor Function (SEAF) key to the AMF. The AMF uses this key to deduce the NAS security key and the TNGF security key.
[0258] S903: AMF sends a NAS security mode command to the terminal device.
[0259] The NAS security mode command can be used to activate NAS security. The command may include EAP success information, indicating that the 3G to WLAN interconnection authentication and key agreement (EAP-AKA) performed by the core network was successful. The N3IWF forwards the NAS security mode command sent by the AMF to the terminal device and sends the NAS security mode complete message from the terminal device to the AMF.
[0260] S904: The AMF sends an NGAP initial context setup request message to the TNGF.
[0261] For example, after receiving a NAS security mode completion message from the terminal device, the AMF can send an NGAP initial connection establishment request to the TNGF. This NGAP initial connection establishment request may include the TNGF key.
[0262] The TNGF sends an EAP request or a 5G notification to the terminal device. The EAP request or 5G notification may include the TNGF's address information, which is used by the terminal device to establish an IPSec SA with the TNGF.
[0263] The UE sends an EAP response or 5G notification to the TNGF. Upon receiving the EAP response or 5G notification, the TNGF sends an AAA message to the TNAP, which may include EAP success information sent to the terminal device. The TNGF then sends the TNAP key, derived from the TNGF, to the TNAP. The TNGF then sends the EAP success information to the terminal device. The TNAP key is used to establish layer-2 security between the terminal device and the TNAP.
[0264] S905: The terminal device receives the IP configuration of TNAN.
[0265] For example, terminal devices obtain IP addresses through the Dynamic Host Configuration Protocol (DHCP).
[0266] S906: The terminal device initiates a secure interface (NWt) connection with the TNGF.
[0267] TNGF assigns the UE an inner IP address, a transmission control protocol (TCP) port, a NAS address, and a differentiated services codepoint (DSCP) value.
[0268] All IP packets transmitted between the terminal device and the TNGF need to be tagged with this DSCP value. The terminal device and TNAP may map the DSCP value to the corresponding QoS level. After establishing a signaling IPSec SA, the terminal device establishes a TCP connection with the TNGF using a NAS address and TCP port.
[0269] All subsequent NAS messages are transmitted via this IPSec SA signal. Specifically, for NAS messages sent from the terminal device to the AMF, the source address is the UE's internal IP address, and the destination address is the NAS address. For NAS messages sent from the AMF to the terminal device, the source address is the NAS address, and the destination address is the UE's internal IP address.
[0270] S907: TNGF sends an NGAP initial context setup response to AMF.
[0271] The NGAP initial connection establishment response message is used to notify the AMF that the UE context has been created.
[0272] S908: AMF sends an N2 message to TNGF.
[0273] The N2 message may include a NAS registration accept message sent to the terminal device. When the AMF registers with the UDM, it must provide the UDM with an access type that is non-3GPP access.
[0274] Based on the above S901~S908, authentication of terminal devices can be achieved. Therefore, terminal devices can register with non-public networks through trusted non-3GPP access network devices.
[0275] Currently, in order to enable terminal devices that can successfully register with the PLMN to also access non-public network services, such as SNPN services. Figure 10 This illustrates the interoperability architecture between a non-public network and a PLMN. The requirement for this interoperability architecture is that when a terminal needs to simultaneously access both non-public network and PLMN services, and the non-public network and PLMN do not share coverage, or they do share coverage but the terminal device does not support dual-radio mode, this interoperability architecture can enable the terminal device to simultaneously access both non-public network and PLMN services. In this case, the terminal device needs to hold subscriptions to both the PLMN and the non-public network and support maintaining two independent registration states, one for accessing the non-public network and the other for accessing the PLMN. Figure 10 The interconnection architecture shown involves the terminal device first registering with the PLMN using a PLMN subscription and establishing a user plane connection. Subsequently, the terminal device can use a non-public network subscription or credentials to establish a connection with the non-public network's N3IWF via the PLMN's user plane connection. The terminal device initiates a registration and session establishment process with the non-public network through the non-public network's N3IWF to obtain non-public network services. Therefore, from the perspective of the non-public network, the terminal device accesses the non-public network through non-3GPP access technology, and the PLMN can be viewed as a non-3GPP access network to which the terminal device connects.
[0276] When a terminal device establishes a connection with the N3IWF of a non-public network via a PLMN-Non-Public Network Interoperability Architecture, and when the terminal device is located within the coverage area of the non-public network but accesses it via WiFi, the terminal device's location differs. In the former case, the terminal device is outside the non-public network coverage area, while in the latter case, the terminal device is within the non-public network coverage area. If data transmission for certain services on the non-public network is not permitted outside its coverage area, the terminal device in the former case will be unable to access those services, while the terminal device in the latter case will be allowed to access them. Therefore, mechanisms are needed to enable the non-public network to distinguish whether the terminal device connects to the N3IWF within the non-public network via a PLMN or directly connects to the N3IWF via the N3GPP access technology of the non-public network, thereby performing differentiated data transmission for the terminal device.
[0277] In view of this, embodiments of this application provide an access network device selection method. See also... Figure 11 The following is an exemplary flowchart of an access network device selection method provided in an embodiment of this application, which may include the following operations.
[0278] S1101: The terminal device sends a second message to the mobility management device.
[0279] Correspondingly, the mobile management device receives second information from the terminal device.
[0280] The aforementioned mobility management device is located in a non-public network. This second information can indicate the access technology type of the terminal device. The access technology type can include non-3GPP access or PLMN access. Non-3GPP access can be understood as the terminal device accessing a non-public network through a non-3GPP access network, and PLMN access can be understood as the terminal device accessing a non-public network through a PLMN.
[0281] S1102: The mobility management device determines at least one of the data network name information and network slice information based on the access technology type.
[0282] For example, a mobility management device can determine the data network name (DNN) of the data network that a terminal device is allowed to connect to based on the technology access type. Another example is that the mobility management device can determine the network slices that a terminal device is allowed to use based on the access technology type. The aforementioned network slice information includes network slice selection assistance information (NSSAI) and single network slice selection assistance information (S-NSSAI).
[0283] For example, when the second information indicates that the access technology type is non-3GPP access, the mobility management device can select or determine the data network for the terminal device from the data network corresponding to the non-3GPP access access technology type, or select S-NSSAIS for the terminal device from the network slice corresponding to the non-3GPP access access technology type.
[0284] For example, when the second information indicates that the access technology type is PLMN access, the mobility management device can select or determine a data network for the terminal device from the data network corresponding to the PLMN access access technology type, or select a network slice for the terminal device from the network slices corresponding to the PLMN access access technology type.
[0285] Based on S1101 and S1102 above, the terminal device can obtain non-public network services by providing at least one of the network slice information and data network name information determined by the mobility management device. Since the network slice information and data network name information are selected by the mobility management device based on the terminal device's access technology type, different network slice information and data network name information can be selected or determined according to the terminal device's access technology type, thus enabling differentiated management or data transmission for the terminal device.
[0286] In one possible implementation, the terminal device can send a third message to the mobility management device, which indicates that the terminal device is accessing a non-public network to perform an online subscription. When the second message indicates that the access technology type of the terminal device is PLMN access, that is, when the terminal device accesses a non-public network through a PLMN, the mobility management device can refuse the terminal device's access.
[0287] In one example, the above Figure 11 The embodiments shown can be applied to, for example Figure 5 In the AMF shown below. The following is through... Figure 12 Let me introduce it.
[0288] S1201: The terminal device sends a second request message to a non-3GPP access network device.
[0289] Correspondingly, non-3GPP access network devices receive the second request message.
[0290] S1201 can be implemented with reference to S504.
[0291] The second request message mentioned above may include an EAP response or a 5G-NAS data packet.
[0292] The aforementioned 5G-NAS data packet may include AN parameters and a registration request message. The AN parameters contain information used by non-3GPP access network devices to select an AMF, such as the GUAMI or the selected PLMN ID. Optionally, the AMF selection information may also include an NID.
[0293] The AN parameters mentioned above may also include second information, which can be implemented with reference to Figure S1101.
[0294] S1202: Non-3GPP access network equipment sends a registration request message to the AMF.
[0295] For example, a non-3GPP access network device can select an AMF for the terminal device and send a registration request message to the selected AMF.
[0296] If the AN parameter includes the second information, then the N3IWF needs to send the second information to the AMF, which is the access technology type of the terminal device. This information is used by the AMF to determine whether the terminal device accesses the non-public network through a PLMN or within the coverage area of the non-public network. If so, it accesses the non-public network through a non-3GPP access network device.
[0297] S1203: AMF determines at least one of DNN and S-NSSAIS based on the second information.
[0298] S1203 can be implemented with reference to S1102.
[0299] For example, when the second information indicates that the access technology type is non-3GPP access, the AMF can select or determine the DNN for the terminal device from the DNN corresponding to this access technology type, and select or determine the S-NSSAIS for the terminal device from the S-NSSAIS corresponding to this access technology type. Here, S-NSSAIS can be one implementation of network slicing information.
[0300] For example, when the second information indicates that the access technology type is PLMN access, the AMF can select or determine the DNN for the terminal device from the DNN corresponding to the PLMN access access technology type, and select or determine the S-NSSAIS for the terminal device from the S-NSSAIS corresponding to the PLMN access access technology type.
[0301] Optionally, the registration request message in S1202 may also include third information. When the third information indicates online signing and the second information in S1202 indicates the access technology type is PLMN access, the AMF may refuse access to the terminal device. For example, the AMF may send a registration reject message to the terminal device.
[0302] Based on the same concept as the above embodiments, this application provides a communication device. Figure 13 and Figure 14 The diagram illustrates the possible structures of communication devices provided in the embodiments of this application. These communication devices can be used to implement the functions of the terminal device, DNS, non-3GPP access network device, trusted non-3GPP access network device, or mobility management device in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the communication device can be a terminal device, DNS, non-3GPP access network device, trusted non-3GPP access network device, or mobility management device, and can also be a module (such as a chip) applied to the terminal device, DNS, non-3GPP access network device, trusted non-3GPP access network device, or mobility management device.
[0303] like Figure 13 As shown, the communication device 1300 includes a processing unit 1310 and a transceiver unit 1320. The communication device 1300 is used to implement the above-mentioned... Figures 3 to 12 The methods illustrated in this embodiment include the functions of a terminal device, a non-3GPP access network device, a trusted non-3GPP access network device, or a mobility management device.
[0304] When the communication device 1300 is used to implement the functions of a terminal device: The processing unit 1310 is used to generate a query message. The query message includes one or more of the following: first indication information, second indication information, and at least one GIN. The first indication information is used to indicate online subscription, and the second indication information is used to indicate external authentication. The at least one GIN is an identifier of one or more default credential servers or the group to which the credential holder belongs. The query message is used to request the identification of a non-3GPP access network device, the non-3GPP access network device corresponding to which the non-3GPP access network device is located in a first non-public network. The transceiver unit 1320 is used to send the query message to the DNS and receive a query response from the DNS. The query response includes the non-3GPP access network device identifier.
[0305] In one design, the query message also includes a non-public network identifier, where the first non-public network is the non-public network corresponding to the non-public network identifier.
[0306] In one design, the query message also includes domain information, a first indication, a second indication, and one or more of at least one GIN contained within the domain information.
[0307] In one design, when the query message includes at least one GIN, a first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform online signing, or the first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform external authentication.
[0308] In one design, non-3GPP access network equipment supports online signing or external authentication.
[0309] In one design, the transceiver unit 1320 is also used to send first information to non-3GPP access network equipment, the first information indicating online signing or external authentication.
[0310] In one design, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0311] When the communication device 1300 is used to implement DNS functionality: the transceiver unit 1320 is used to receive a query message from a terminal device, the query message including one or more of the following: first indication information, second indication information, and at least one GIN. The first indication information is used to indicate online subscription, and the second indication information is used to indicate external authentication. The at least one GIN is an identifier of one or more default credential servers or a group to which the credential holder belongs. The query message is used to request the acquisition of a non-3GPP access network device identifier, the non-3GPP access network device corresponding to the non-3GPP access network device identifier being located in a first non-public network. The processing unit 1310 is used to determine the non-3GPP access network device identifier based on the query message. The transceiver unit 1320 is also used to send a query response to the terminal device, the query response including the non-3GPP access network device identifier.
[0312] In one design, the query message also includes a non-public network identifier, where the first non-public network is the non-public network corresponding to the non-public network identifier.
[0313] In one design, the query message also includes domain information, a first indication, a second indication, and one or more of at least one GIN contained within the domain information.
[0314] In one design, when the query message includes at least one GIN, a first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform online signing, or the first non-public network supports connecting to the default credential server or credential holder corresponding to at least one GIN to perform external authentication.
[0315] In one design, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0316] When the communication device 1300 is used to implement the functions of a terminal device: The processing unit 1310 is used to determine a non-public network identifier based on configuration information. The configuration information indicates a non-public network that supports online subscription or external authentication. The transceiver unit 1320 is used to send a query message to the DNS, the query message including the non-public network identifier. The transceiver unit 1320 is also used to receive a query response from the DNS, the query response including a non-3GPP access network device identifier. The non-3GPP access network device corresponding to the non-3GPP access network device identifier is located in the non-public network corresponding to the non-public network identifier.
[0317] In one design, the configuration information indicates that all non-3GPP access network devices within a non-public network that support online signing also support online signing. And / or, the configuration information indicates that all non-3GPP access network devices within a non-public network that support external authentication also support external authentication.
[0318] In one design, the transceiver unit 1320 is also used to send first information to non-3GPP access network equipment, the first information indicating online signing or external authentication.
[0319] In one design, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0320] When the communication device 1300 is used to implement the functions of a non-3GPP access network device: the transceiver unit 1320 is used to receive first information from the terminal device, the first information indicating online subscription or external authentication. The processing unit 1310 is used to select a mobility management device that supports online subscription or external authentication based on the first information.
[0321] In one design, the non-3GPP access network equipment is an untrusted non-3GPP access network equipment, a non-3GPP interoperability function, a trusted non-3GPP access network equipment, a trusted non-3GPP access point, a trusted non-3GPP network management function, a trusted wireless LAN interoperability function, a wired access network management function, or a trusted non-3GPP access network.
[0322] When the communication device 1300 is used to implement the functions of a terminal device: the transceiver unit 1320 is used to acquire the identifier of at least one non-public network. The processing unit 1310 is used to determine the identifier of a first non-public network from the identifiers of at least one non-public network according to configuration information. The configuration information indicates a non-public network that supports online subscription or a non-public network that supports external authentication. The transceiver unit 1320 is also used to establish a connection with a trusted non-3GPP access network device located in the first non-public network.
[0323] In one design, the transceiver unit 1320 is further configured to receive one or more of a first indication message, a second indication message, and at least one GIN. The first indication message indicates that at least one non-public network supports online subscription. The second indication message indicates that at least one non-public network supports external authentication. The at least one GIN is an identifier for one or more default credential servers or a group to which the credential holder belongs.
[0324] In one design, transceiver unit 1320 is specifically used to obtain the identifier of at least one non-public network from a broadcast message.
[0325] When the communication device 1300 is used to implement the functions of a trusted non-3GPP access network device: the transceiver unit 1320 is used to send the identifier of at least one non-public network and establish a connection with the terminal device. The transceiver unit 1320 is also used to receive a registration request message from the terminal device. The registration request message includes the identifier of a first non-public network, which is one of the identifiers of at least one non-public network. The processing unit 1310 is used to determine a mobility management device based on the identifier of the first non-public network. The mobility management device is used to perform terminal device access management. The transceiver unit 1320 is also used to send the registration request message to the mobility management device.
[0326] In one design, the transceiver unit 1320 is further configured to receive first information from the terminal device, the first information indicating online signing or external authentication. The processing unit 1310 is specifically configured to select a mobility management device that supports online signing or external authentication. The transceiver unit 1320 is further configured to send a registration request message to the mobility management device.
[0327] In one design, the transceiver unit 1320 is further configured to send one or more of a first indication message, a second indication message, and at least one GIN. The first indication message indicates that at least one non-public network supports online subscription. The second indication message indicates that at least one non-public network supports external authentication. At least one GIN is an identifier for one or more default credential servers or a group to which the credential holder belongs.
[0328] In one design, transceiver unit 1320 is specifically used to send broadcast messages, which include at least one identifier of a non-public network.
[0329] In one design, the first or second instruction information is the name of the network list.
[0330] In one design, the first indication information is the name of a first network list, and the second indication information is the name of a second network list. The first network list contains the identifier of at least one second non-public network, and this at least one second non-public network supports online signing. The second network list contains the identifier of at least one third non-public network, and this at least one third non-public network supports external authentication. The identifier of the at least one non-public network includes the identifier of at least one second non-public network and / or the identifier of at least one third non-public network.
[0331] When the communication device 1300 is used to implement the functions of a mobility management device: the transceiver unit 1320 is used to receive second information from a terminal device, the second information indicating the access technology type of the terminal device, and the mobility management device being located in a non-public network. The processing unit 1310 is used to determine at least one of data network name information and network slice information according to the access technology type, wherein the network slice corresponding to the network slice information is a network slice that the terminal device is allowed to use, and the data network corresponding to the data network name information is a data network that the terminal device is allowed to connect to.
[0332] In one design, the transceiver unit 1320 is further configured to receive third information from the terminal device, the third information indicating an online subscription. When the access technology type indicates that the terminal device is accessing a non-public network via a public network, the processing unit 1310 is further configured to reject the terminal device's access.
[0333] For a more detailed description of the processing unit 1310 and the transceiver unit 1320, please refer to [the relevant documentation]. Figures 3 to 12 The relevant descriptions in the method embodiments shown are directly obtained and will not be repeated here.
[0334] like Figure 14 As shown, the communication device 1400 includes a processor 1410 and an interface circuit 1420. The processor 1410 and the interface circuit 1420 are coupled to each other. It is understood that the interface circuit 1420 can be a transceiver or an input / output interface. Optionally, the communication device 1400 may also include a memory 1430 for storing instructions executed by the processor 1410, or storing input data required by the processor 1410 to execute instructions, or storing data generated after the processor 1410 executes instructions.
[0335] When the communication device 1400 is used to implement Figures 3 to 12 In the method shown, the processor 1410 is used to implement the functions of the processing unit 1310, and the interface circuit 1420 is used to implement the functions of the transceiver unit 1320.
[0336] Specifically, when the communication device 1400 is used to implement the functions of a terminal device: the processor 1410 is used to generate a query message. The query message includes one or more of the following: first indication information, second indication information, and at least one GIN. The first indication information is used to indicate online subscription, and the second indication information is used to indicate external authentication. The at least one GIN is an identifier of one or more default credential servers or the group to which the credential holder belongs. The query message is used to request the identification of a non-3GPP access network device, the non-3GPP access network device corresponding to which the non-3GPP access network device is located in a first non-public network. The interface circuit 1420 is used to output the query message to the DNS and input a query response from the DNS. The query response includes the non-3GPP access network device identifier.
[0337] When the communication device 1400 is used to implement DNS functionality: Interface circuitry 1420 is used to input a query message from a terminal device, the query message including one or more of the following: first indication information, second indication information, and at least one GIN. The first indication information indicates online subscription, and the second indication information indicates external authentication. At least one GIN is an identifier of one or more default credential servers or a group to which the credential holder belongs. The query message requests a non-3GPP access network device identifier, the non-3GPP access network device corresponding to which the non-3GPP access network device identifier is located in a first non-public network. Processor 1410 is used to determine the non-3GPP access network device identifier based on the query message. Interface circuitry 1420 is also used to output a query response to the terminal device, the query response including the non-3GPP access network device identifier.
[0338] When the communication device 1400 is used to implement the functions of a non-3GPP access network device: Interface circuit 1420 is used to input first information from the terminal device, the first information indicating online subscription or external authentication. Processor 1410 is used to select a mobility management device that supports online subscription or external authentication based on the first information.
[0339] When the communication device 1400 is used to implement the functions of a terminal device: the processor 1410 is used to determine a non-public network identifier based on configuration information. The configuration information indicates a non-public network that supports online subscription or a non-public network that supports external authentication. The interface circuit 1420 is used to output a query message to the DNS, the query message including the non-public network identifier. The interface circuit 1420 is also used to input a query response from the DNS, the query response including a non-3GPP access network device identifier. The non-3GPP access network device corresponding to the non-3GPP access network device identifier is located in the non-public network corresponding to the non-public network identifier.
[0340] When the communication device 1400 is used to implement the functions of a terminal device: Interface circuit 1420 is used to input the identifier of at least one non-public network. Processor 1410 is used to determine the identifier of a first non-public network from the identifiers of at least one non-public network according to configuration information. The configuration information indicates a non-public network that supports online subscription or a non-public network that supports external authentication. Interface circuit 1420 is also used to establish a connection with a trusted non-3GPP access network device located in the first non-public network.
[0341] When the communication device 1400 is used to implement the functions of a trusted non-3GPP access network device: Interface circuit 1420 is used to output the identifier of at least one non-public network and establish a connection with the terminal device. Interface circuit 1420 is also used to input a registration request message from the terminal device. The registration request message includes the identifier of a first non-public network, which is one of at least one non-public network identifiers. Processor 1410 is used to determine a mobility management device based on the identifier of the first non-public network. The mobility management device is used to perform terminal device access management. Interface circuit 1420 is also used to output the registration request message to the mobility management device.
[0342] When the communication device 1400 is used to implement the functions of a mobility management device: Interface circuit 1420 is used to input second information from a terminal device, the second information indicating the access technology type of the terminal device, and the mobility management device is located in a non-public network. Processor 1410 is used to determine at least one of data network name information and network slice information based on the access technology type, wherein the network slice corresponding to the network slice information is a network slice that the terminal device is allowed to use, and the data network corresponding to the data network name information is a data network that the terminal device is allowed to connect to.
[0343] For a more detailed description of the processor 1410 and interface circuit 1420 mentioned above, please refer to [link / reference]. Figures 3 to 12 The relevant descriptions in the method embodiments shown are directly obtained and will not be repeated here.
[0344] This application also provides a communication system, including a terminal device and a DNS. Optionally, it also includes a non-3GPP access network device. Optionally, it also includes a mobility management device.
[0345] This application also provides a communication system, including a terminal device and a trusted non-3GPP access network device. Optionally, it also includes a mobility management device.
[0346] This application also provides a communication system, including a terminal device and a mobility management device.
[0347] It is understood that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.
[0348] Those skilled in the art will understand that the various numerical designations, such as "first" and "second," used in this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application, nor do they indicate a sequential order. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. "At least one" refers to one or more. "At least two" refers to two or more. "At least one" or similar expressions refer to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. "Multiple" refers to two or more, and other quantifiers are similar.
[0349] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0350] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0351] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0352] The various illustrative logic units and circuits described in the embodiments of this application can be implemented or operate the described functions using a general-purpose processor, digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof. The general-purpose processor can be a microprocessor; alternatively, it can also be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented using a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.
[0353] The steps of the methods or algorithms described in the embodiments of this application can be directly embedded in hardware, software units executed by a processor, or a combination of both. The software units can be stored in random access memory (RAM), flash memory, read-only memory (ROM), EPROM, EEPROM, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and storage medium can be housed in an ASIC.
[0354] In one or more exemplary designs, the functions described herein can be implemented in hardware, software, firmware, or any combination of these three. If implemented in software, these functions can be stored on a computer-readable medium or transmitted on a computer-readable medium in the form of one or more instructions or code. Computer-readable media includes computer storage media and communication media that facilitate the transfer of computer programs from one location to another. Storage media can be any available media accessible to a general-purpose or special-purpose computer. For example, such computer-readable media can include, but is not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disc storage, disk storage or other magnetic storage devices, or any other medium that can be used to carry or store program code in the form of instructions or data structures and other formats readable by a general-purpose or special-purpose computer or processor. Furthermore, any connection can be suitably defined as a computer-readable medium, for example, if the software is transmitted from a website, server, or other remote resource via a coaxial cable, fiber optic computer, twisted pair, digital subscriber line (DSL), or wirelessly, such as infrared, wireless, and microwave, it is also included in the definition of a computer-readable medium. The disks and discs mentioned include compressed disks, laser discs, optical discs, Digital Versatile Discs (DVDs), floppy disks, and Blu-ray discs. Disks typically copy data magnetically, while discs typically copy data optically using lasers. Combinations of the above can also be contained in computer-readable media.< / mcc> < / mnc>
Claims
1. A method for selecting access network equipment, characterized in that, include: Trusted non-third-party partner program 3GPP access network equipment sends at least one identifier of a non-public network; The trusted non-3GPP access network device establishes a connection with the terminal device; The trusted non-3GPP access network device receives a registration request message from the terminal device; the registration request message includes an identifier of a first non-public network; The identifier of the first non-public network is one of the identifiers of the at least one non-public network; The trusted non-3GPP access network device sends the registration request message to the mobility management device; the mobility management device is used to perform the terminal device access management, and the mobility management device is determined based on the identifier of the first public network.
2. The method according to claim 1, characterized in that, Also includes: The trusted non-3GPP access network device receives first information from the terminal device, the first information indicating online signing or external authentication; The trusted non-3GPP access network equipment is selected from mobile management equipment that supports online signing or external authentication; The trusted non-3GPP access network device sends the registration request message to the mobility management device.
3. The method according to claim 1 or 2, characterized in that, Also includes: The trusted non-3GPP access network device sends one or more of the following: a first indication message, a second indication message, and at least one network selection group identifier (GIN). Wherein, the first indication information indicates that the at least one non-public network supports online signing; the second indication information indicates that the at least one non-public network supports external authentication; and the at least one GIN is the identifier of one or more default credential servers or the group to which the credential holder belongs.
4. The method according to any one of claims 1 to 3, characterized in that, The trusted non-3GPP access network device sends at least one identifier of a non-public network, including: The trusted non-3GPP access network device sends a broadcast message, which includes the identifier of the at least one non-public network.
5. The method according to any one of claims 3 to 4, characterized in that, The first or second instruction is the name of the network list.
6. The method according to claim 5, characterized in that, The first indication information is the name of the first network list, and the second indication information is the name of the second network list; The first network list contains the identifier of at least one second non-public network, which supports online signing; the second network list contains the identifier of at least one third non-public network, which supports external authentication, and the identifier of the at least one non-public network includes the identifier of the at least one second non-public network and / or the identifier of the at least one third non-public network.
7. A communication device, characterized in that, Includes a module for performing the method as described in any one of claims 1 to 6.
8. A communication device, characterized in that, The device includes a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices besides the communication device and transmit them to the processor, or to send signals from the processor to other communication devices besides the communication device. The processor is used to implement the method as described in any one of claims 1 to 6 through logic circuits or execution code instructions.
9. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions, which, when executed by a communication device, implement the method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, It includes computer-executable instructions that, when run on a computer, cause the method as described in any one of claims 1 to 6 to be performed.