Communication method and device
By establishing direct connections between access network devices and core network elements, and utilizing NAS messages and secure mode commands, the AMF congestion and protocol complexity issues in the connection between terminal devices and core network elements in the RAN service architecture are resolved, thereby achieving reliable and secure information transmission.
Patent Information
- Application Number
- CN202411235138.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-03
- Publication Date
- 2026-03-10
AI Technical Summary
In the future RAN-based service architecture, the connection establishment between terminal devices and core network elements has not been effectively resolved, resulting in AMF congestion and high protocol maintenance complexity, and making it difficult to guarantee the reliability and security of information transmission.
By establishing direct connections between access network devices and core network elements, and using NAS messages to carry NF identification or type information, terminal devices can communicate directly with multiple NFs, reducing AMF relays, lowering protocol maintenance complexity, and activating security contexts through security mode commands to enhance the security of information exchange.
It achieves reliable connection between terminal equipment and core network elements, reduces AMF congestion, lowers protocol maintenance complexity, and improves the security and reliability of information transmission.
Smart Images

Figure CN121645406A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology
[0002] Currently, when terminal devices communicate with core network elements, they all need to go through the access and mobility management function (AMF). The AMF can be regarded as the anchor point of the core network. That is to say, if the terminal device needs to communicate with other core network elements besides the AMF (such as the session management function (SMF)), the terminal device first needs to establish a connection with the AMF, and then forward the data between the terminal device and the SMF through the AMF.
[0003] For future RAN-based service architectures, terminal devices can communicate directly with core network elements (including AMFs) without using the AMF as an anchor point, i.e., without going through the AMF for relay. However, how to establish a connection between terminal devices and core network elements based on the RAN service architecture still requires further research. Summary of the Invention
[0004] This application provides a communication method and apparatus, which provides a method for establishing a connection between a terminal device and a core network element to ensure the reliability and security of information transmission.
[0005] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:
[0006] Firstly, a communication method is provided, which can be applied to an access network side device (hereinafter referred to as an access network device). The access network device can be an access network equipment, a component within the access network equipment (e.g., a circuit, a chip, or a chip system); or, the access network device can be a module or unit that performs some or all of the functions of the access network equipment, such as a central unit (CU), a distributed unit (DU), or a radio unit (RU). Alternatively, the access network device can be a logical node, logical module, or software that implements all or part of the functions of the access network equipment. For ease of description, the following example assumes that the access network device is an access network equipment.
[0007] The method includes: an access network device sending a first message to a first network element, receiving a second message from the first network element, and sending a first request message to a first NF. The first network element can be a core network element, such as an AMF. The first message includes a non-access stratum (NAS) message. The second message is used to request the access network device to establish a connection with at least one network function (NF). This second message includes identification information or type information of at least one NF. The first request message includes a first identifier and identification information of the terminal device, used to request the establishment of a connection with the first NF. The first identifier is a unique identifier assigned by the access network device to the terminal device. The first NF belongs to at least one NF.
[0008] In the above method, the first message can be used to trigger a first network element to request the access network device to establish a connection with at least one NF. Alternatively, the first message can be used to trigger a first network element to request the access network device to create a context with at least one NF. For the first network element, if the first message received from the RAN includes a NAS message, it can be assumed that the terminal device needs to establish a connection with the core network element. Therefore, based on the triggering of the first message, the first network element will request the access network device to establish a connection with at least one NF. The access network device can establish a connection with at least one NF in response to the request from the first network element. For example, the access network device sends a first request message to the first NF to establish a connection with the first NF. This method enables the access network device to establish connections with multiple NFs (or core network elements) other than the first network element, so that the terminal device can communicate with the NFs through forwarding by the access network device. For example, if the first network element is an AMF, this method, compared to using the AMF as an anchor point to realize the interaction between the terminal device and the core network element, can reduce AMF congestion, achieve data isolation between the terminal device and each NF, and reduce processing complexity. In addition, compared to using AMF as an anchor point, which requires operators to maintain a set of protocols between access network equipment and AMF, as well as a set of protocols between AMF and other NFs, operators only need to maintain a set of protocols between access network equipment and NFs. This results in fewer protocols to maintain and lower complexity.
[0009] In one implementation, the NAS message includes information about the NF (Network Function) and is used to request the establishment of a connection between the terminal device and the NF. The NF information includes either the NF's type information or its identification information.
[0010] By carrying NF information in NAS messages, the first network element can clearly identify the NF that the terminal device needs to establish a connection with, and then request the access network device to establish a connection with that NF. This scheme can ensure, as far as possible, that the NF established by the access network device is the NF that the terminal device needs to establish a connection with, thus satisfying the terminal device's connection requirements.
[0011] In one implementation, the first message also includes the identification information of the terminal device and a first identifier.
[0012] The access network device informs the first network element of the terminal device's identification information, enabling the first network element to clearly identify the terminal device requiring a connection. The access network device also informs the first network element of a first identifier, allowing the first network element to maintain the connection with the access network device based on that identifier. For example, the first network element can determine already connected terminal devices based on the first identifier without triggering network paging.
[0013] In one implementation, the method further includes: an access network device receiving a first response message from a first NF, the first response message including a first identifier and a second identifier. The second identifier is a unique identifier assigned by the first NF to the terminal device. The first response message is used to indicate that the connection between the first NF and the access network device has been established.
[0014] When the first NF responds to a request from the access network device and completes the connection establishment with the access network device, it can explicitly inform the access network device through a first response message. Furthermore, the first response message may include a first identifier and a second identifier, thereby facilitating the access network device to maintain the correspondence between the terminal device and the NF based on the first and second identifiers, and enabling the access network device to determine the appropriate NF to provide services to the terminal device.
[0015] In one implementation, the second message also includes a first identifier and a third identifier, wherein the third identifier is a unique identifier assigned by the first network element to the terminal device.
[0016] In one implementation, the method further includes: the access network device receiving a third message from the terminal device and sending the third message to the first NF, the third message being used to indicate the identifier of the first NF or the type of the first NF.
[0017] The third message is the message that the terminal device needs to send to the first NF. The terminal device can forward the third message to the first NF through the access network device. In order to make the access network device aware of the first NF, the third message also indicates the first NF to avoid the access network device forwarding the message incorrectly.
[0018] In a possible implementation, if the third message indicates the type of the first NF, before sending the third message to the first NF, the method further includes: the access network device determining a second identifier based on the identification information of the terminal device and the information of the first NF, and then determining the first NF based on the second identifier.
[0019] Considering that the terminal device may not know which NFs have established connections with the access network device, it cannot specify which NF to send the third message to. For the access network device, it can select a suitable first NF for the terminal device based on the relationship between the terminal device's identifier, second identifier, the type information of the first NF, and the identifier information of the first NF, thus ensuring the normal operation of the terminal device's services as much as possible.
[0020] Secondly, a communication method is provided, which can be applied to a core network side device (hereinafter referred to as a core network device). This core network device can be an AMF (Application Function), a component within an AMF (e.g., a circuit, a chip, or a chip system); or, the core network device can be a logic node, logic module, or software used to perform some or all of the functions of the AMF. For ease of description, the following example uses the core network device as the first network element.
[0021] The method includes: a first network element receiving a first message, and in response to the first message sending a second message to an access network device. The first message includes a NAS message. The second message is used to request the access network device to establish a connection with at least one NF, and the second message includes identification information or type information of at least one NF.
[0022] In one implementation, the NAS message includes information about the NF (Network Function) and is used to request the establishment of a connection between the terminal device and the NF. The NF information includes either the NF's type information or its identification information.
[0023] In one implementation, the first message also includes the identification information of the terminal device and a first identifier, which is a unique identifier assigned to the terminal device by the access network device.
[0024] In one implementation, the second message further includes the first identifier and / or a third identifier, wherein the third identifier is a unique identifier assigned by the first network element to the terminal device.
[0025] In one implementation, the method further includes: a first network element sending a fourth message to a terminal device, the fourth message including NF type information, used to indicate that the NF corresponding to the type information has established a connection with the terminal device. Alternatively,
[0026] In one implementation, the method further includes: a first network element sending a fourth message to the terminal device, the fourth message including identification information of the NF, used to indicate that the NF and the terminal device have established a connection.
[0027] In one implementation, before sending a second message to the access network device in response to the first message, the method further includes: the first network element sending a security mode command message to the terminal device and receiving a security mode completion message from the terminal device. The security mode command message includes a key identifier and information about at least one NF (Network Function), used to activate the security context of the terminal device to the at least one NF. The security mode completion message indicates that the security mode control process has been completed.
[0028] In this method, the first network element can activate a security context between at least one NF and the terminal device, thereby creating security contexts in each NF. When the terminal device sends information to a certain NF, the information can be encrypted and its integrity protected according to the security context between the terminal device and that NF. This method improves the security of information exchange.
[0029] In one implementation, the security mode completion message includes information about the first NF, indicating that the security context of the terminal device and the first NF is activated.
[0030] In one implementation, the security mode command message includes information about the security algorithm between the terminal device and each NF.
[0031] The beneficial effects of the second aspect and its various implementation methods can be referred to the beneficial effects of the first aspect and its various implementation methods mentioned above, and will not be repeated here.
[0032] Thirdly, a communication method is provided, which can be applied to a terminal-side device (hereinafter referred to as a terminal device). This terminal device can be a terminal equipment, or a module or unit that performs some of the functions of a terminal equipment, such as a circuit or chip / chip system (e.g., a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip) or other functional module within the terminal equipment. For ease of description, the following example uses a terminal equipment as the terminal device.
[0033] The method includes: a terminal device sending a fifth message to a first network element, the fifth message including information about a first network element (NF), for requesting the establishment of a connection between the terminal device and the first NF. Wherein, the terminal device and the first NF do not have a NAS signaling connection.
[0034] In this method, when the terminal device does not have a NAS signaling connection with the first NF, the terminal device can request the first network element to establish a connection between the terminal device and the first NF, thereby triggering the first network element to request the access network device to establish a connection to the first NF. This method enables the establishment of connections between the terminal device and other network elements based on the first network element, and activates AS layer security, ensuring the security and reliability of message transmission from the terminal device. Furthermore, compared to forwarding messages from the terminal device using the first network element as an anchor point, it reduces congestion on the first network element.
[0035] In one implementation, the method further includes: a terminal device receiving a sixth message from a first network element, the sixth message including information about the first network element (NF) for indicating that the first NF has completed establishing a connection.
[0036] The first network element can notify the terminal device of the first NF that the connection has been established, thereby avoiding the terminal device from sending messages to NFs that have not established a connection, thus avoiding the waste of signaling.
[0037] In one implementation, the information of the first NF includes the identification information of the first NF or the type information of the first NF.
[0038] In one implementation, before sending the fifth message to the first network element, the method further includes: the terminal device receiving a fourth message from the first network element, the fourth message including information of at least one NF, the at least one NF including the first NF.
[0039] In one implementation, before receiving the fourth message from the first network element, the method further includes: the terminal device receiving a security mode command message from the first network element and sending a security mode completion message to the first network element. The security mode command message includes a key identifier and / or information about at least one NF (Network Function), used to activate the terminal device's security context to at least one NF. The security mode completion message indicates that the security mode control flow has been completed.
[0040] In one implementation, the security mode completion message includes information about the first NF, indicating that the security context of the terminal device and the first NF is activated.
[0041] In one implementation, the security mode command message includes information about the security algorithm between the terminal device and each NF.
[0042] The beneficial effects of the third aspect and its various implementation methods can be found in the aforementioned first to second aspects and their various implementation methods, and will not be repeated here.
[0043] Fourthly, a communication method is provided, which can be applied to a terminal device (hereinafter referred to as a terminal device). The terminal device can be referred to in the relevant description of the terminal device in the aforementioned third aspect, and will not be repeated here. For ease of description, the terminal device is exemplified as a terminal equipment below.
[0044] The method includes: a terminal device sending a seventh message to a first security context (NF), receiving a security mode command message from the first NF, and activating a security context between the terminal device and the first NF based on information from the first NF. The seventh message is used to request activation of the first NF. The security mode command message includes a key identifier and information about the first NF, used to activate the security context between the terminal device and the first NF. The first NF can activate the security context between the terminal device and the first NF.
[0045] In one implementation, the safe mode command message also includes information about the first NF.
[0046] In one implementation, the information of the first NF includes the type information of the first NF.
[0047] In one implementation, the security mode command message includes a security algorithm from the terminal device to the first NF.
[0048] In one implementation, the method further includes: the terminal device sending a security mode completion message to the first network element, the security mode completion message being used to indicate that the security mode control process has been completed.
[0049] In one implementation, the security mode completion message includes information about the first NF, indicating that the security context of the terminal device and the first NF is activated.
[0050] The beneficial effects of the fourth aspect and its various implementation methods can be found in the aforementioned second to third aspects and their various implementation methods, and will not be repeated here.
[0051] Fifthly, a communication method is provided, which can be applied to a core network device (hereinafter referred to as a core network device). This core network device may be, for example, an SMF, a component within an SMF (e.g., a circuit, a chip, or a chip system); or, the core network device may be a logical node, logical module, or software used to perform some or all of the functions of an AMF. For ease of description, the following example uses the first NF as the core network device.
[0052] The method includes: a first NF receiving a seventh message from a terminal device and sending a security mode command message to the terminal device. The seventh message is used to request activation of the first NF. The security mode command message includes a key identifier and information about the first NF, used to activate the security context between the terminal device and the first NF.
[0053] In one implementation, the security context between the terminal device and the first NF is activated based on the type information of the first NF.
[0054] In one implementation, the safe mode command message also includes information about the first NF.
[0055] In one implementation, the information of the first NF includes the type information of the first NF.
[0056] In one implementation, the security mode command message includes a security algorithm from the terminal device to the first NF.
[0057] Sixthly, a communication method is provided, which can be applied to an access network side device (hereinafter referred to as an access network device). The access network device can be referred to in the relevant description of the access network device in the first aspect above, and will not be repeated here. For ease of description, the following example assumes that the access network device is an access network equipment.
[0058] The method includes: an access network device receiving a release message from a first NF, the release message being used to request the release of the connection between a terminal device and the first NF; if the terminal device is also connected to a second NF, the access network device releases the connection between the access network device and the first NF, and sends a first message to the terminal device. The first message includes information about the first NF, used to indicate the release of the connection from the terminal device to the first NF.
[0059] In this method, the connection release can be triggered by the first NF. When the first NF triggers the connection release, if the UE is connected to more than one NF, the access network device can release the connection with the first NF in order to release unnecessary connections as much as possible and save resources.
[0060] In one implementation, if the terminal device is only connected to the first NF, the access network device releases the connection between the first NF and the radio access network, releases the terminal device's radio resource control (RRC) connection, and sends a second message to the terminal device. This second message instructs the terminal device to release its connection with the access network device.
[0061] In this method, when the first NF triggers connection release, if the UE is only connected to the first NF, the access network device can release the connection with the first NF and release the RRC connection of the terminal device to release as many connections as possible and save more resources.
[0062] In one implementation, the information of the first NF includes the type information of the first NF or the identification information of the first NF.
[0063] Seventhly, a communication method is provided, which can be applied to a terminal-side device (hereinafter referred to as a terminal device). The terminal device can be referred to in the relevant description of the terminal device in the aforementioned third aspect, and will not be repeated here. For ease of description, the terminal device is exemplified below as a terminal equipment.
[0064] The method includes: a terminal device receiving a first message from an access network device, and recording, based on the first message, whether a first NF is in an idle state or a deactivated state, wherein the first message includes identification information or type information of the first NF, used to indicate that the connection from the terminal device to the first NF is released. Alternatively,
[0065] The method includes: a terminal device receiving a second message from an access network device, and recording all NFs as being in an idle state or a deactivated state according to the second message, wherein the second message is used to indicate that the connection from the terminal device to the access network device is released.
[0066] It should be understood that the first NF being in an idle or deactivated state indicates that there is no end-to-end connection between the UE and the first NF. By recording the connection status of the NFs, the terminal device can clearly identify which NFs are in an idle or deactivated state. Therefore, when the terminal device needs to communicate with the NF, it can re-establish a connection with the NF. This method avoids the terminal device directly sending information to the NF, thus preventing the waste of signaling.
[0067] Eighthly, embodiments of this application provide a communication device that has the functionality to implement the behavior in any of the method examples of the first to seventh aspects described above. The beneficial effects can be found in the relevant descriptions of the first to seventh aspects and will not be repeated here. For example, the communication device may be an access network device as described in the first or sixth aspect, or it may be a device capable of supporting the access network device in implementing the functions required by the methods provided in the first or sixth aspect; for example, the communication device may be a chip or chip system in the access network device. As another example, the communication device may be an AMF as described in the second aspect, or it may be a device capable of supporting the AMF in implementing the functions required by the methods provided in the second aspect; for example, the communication device may be a chip or chip system in the AMF. As yet another example, the communication device may be a terminal device as described in the third, fourth, or seventh aspect, or it may be a device capable of supporting the terminal device in implementing the functions required by the methods provided in the third, fourth, or seventh aspect; for example, the communication device may be a chip or chip system in the terminal device. For example, the communication device may be the first NF in the fifth aspect, or the communication device may be a device capable of supporting the NF to perform the functions required by the method provided in the fifth aspect, such as the communication device may be a chip or chip system in the NF.
[0068] In one possible design, the communication device is an access network device or a terminal device, which includes a baseband device and a radio frequency device.
[0069] In one possible design, the communication device includes corresponding means, modules, or units for performing the methods of any of the first to seventh aspects. These modules, units, or means can be implemented in software, hardware, or a combination of both. For example, the communication device includes a processing unit (sometimes also called a processing module or processor) and / or a transceiver unit (sometimes also called a transceiver module or transceiver). The transceiver unit is capable of both transmitting and receiving functions. When the transceiver unit performs the transmitting function, it can be called a transmitting unit (sometimes also called a transmitting module), and when it performs the receiving function, it can be called a receiving unit (sometimes also called a receiving module). The transmitting unit and the receiving unit can be the same functional unit, referred to as the transceiver unit, which performs both transmitting and receiving functions; or, the transmitting unit and the receiving unit can be different functional units, with "transceiver unit" being a general term for these functional units. These units (modules) can perform the corresponding functions in the method examples of any of the first to seventh aspects described above, as detailed in the method examples, and will not be repeated here.
[0070] For example, the communication device is used to implement the corresponding function in the method example of the first aspect. Accordingly, the transceiver module is used to send a first message to a first network element, receive a second message from the first network element, and send a first request message to a first NF. The first message includes a NAS message. The second message is used to request the communication device to establish a connection with at least one NF. The second message includes identification information of at least one NF or type information of at least one NF. The first request message includes a first identifier and identification information of the terminal device, used to request to establish a connection with the first NF. The first identifier is a unique identifier assigned by the communication device to the terminal device. The first NF belongs to at least one NF.
[0071] For example, the communication device is used to implement the corresponding function in the method example of the second aspect. Accordingly, the transceiver module is used to receive a first message and, in response to the first message, send a second message to the access network device. The first message includes a NAS message. The second message is used to request the access network device to establish a connection with at least one NF, and the second message includes identification information or type information of at least one NF.
[0072] For example, the communication device is used to implement the corresponding function in the method example of the third aspect. Accordingly, the transceiver module is used to send a fifth message to the first network element, the fifth message including information about the first NF, for requesting the establishment of a connection between the communication device and the first NF. Wherein, the communication device and the first NF do not have a NAS signaling connection.
[0073] For example, the communication device is used to implement the corresponding function in the method example of the fourth aspect. Accordingly, the transceiver module is used to send a seventh message to the first NF, receive a security mode command message sent by the first NF, and activate the security context between the communication device and the first NF based on the information of the first NF. The seventh message is used to request the activation of the first NF. The security mode command message includes a key identifier and information about the first NF, used to activate the security context between the communication device and the first NF.
[0074] For example, the communication device is used to implement the corresponding function in the method example of the fifth aspect. Accordingly, the transceiver module is used to receive a seventh message from the terminal device and send a security mode command message to the terminal device. The seventh message is used to request the activation of the first NF. The security mode command message includes a key identifier and information about the communication device, used to activate the security context between the terminal device and the communication device.
[0075] For example, the communication device is used to implement the corresponding function in the method example of the sixth aspect. Accordingly, the transceiver module is used to receive a release message from the first NF, which requests the release of the connection between the terminal device and the first NF; if the terminal device is also connected to the second NF, the processing module is used to release the connection between the communication device and the first NF and send a first message to the terminal device. The first message includes information about the first NF, indicating that the connection from the terminal device to the first NF is released.
[0076] For example, the communication device is used to implement the corresponding function in the method example of the seventh aspect. Accordingly, the transceiver module is used to receive a first message from the access network device, and according to the first message, record that the first NF is in an idle state, wherein the first message includes identification information or type information of the first NF, used to indicate that the connection from the communication device to the first NF is released. Alternatively, the transceiver module is used to receive a second message from the access network device, and according to the second message, record that all NFs are in an idle state, wherein the second message is used to indicate that the connection from the communication device to the access network device is released.
[0077] In a ninth aspect, embodiments of this application provide a communication device including a processor configured to execute methods from any of the first to seventh aspects and any implementation thereof. Optionally, the communication device further includes a communication interface. Optionally, the communication device also includes a memory for storing computer programs (also referred to as code or instructions), data, etc. The processor is coupled to the memory and the communication interface. When the processor reads the computer program, data, etc., from the memory, it causes the communication device to execute methods from any of the first to seventh aspects and any implementation thereof.
[0078] In a tenth aspect, embodiments of this application provide a communication device including an input / output interface and logic circuitry. The input / output interface is used for inputting and / or outputting information. The input / output interface may be an interface circuit, an output circuit, an input circuit, a pin, or related circuitry, etc. The logic circuitry is used to execute the methods described in any of the first to seventh aspects.
[0079] In the ninth and tenth aspects, the communication device may be an access network device as described in the first or sixth aspect. Alternatively, the communication device may be a means capable of supporting the access network device in implementing the functions required by the methods provided in the first or sixth aspect, for example, the communication device may be a chip or chip system in the access network device. The chip may be a baseband chip and / or a radio frequency chip, and the chip system may be composed of chips or may include chips and other discrete devices. Alternatively, the communication device may be an AMF as described in the second aspect. Alternatively, the communication device may be a means capable of supporting the AMF in implementing the functions required by the methods provided in the second aspect, for example, the communication device may be a chip or chip system in a terminal device. Alternatively, the communication device may be a terminal device as described in the third, fourth, or sixth aspect. Alternatively, the communication device may be a means capable of supporting the terminal device in implementing the functions required by the methods provided in the third, fourth, or sixth aspect, for example, the communication device may be a chip or chip system in a terminal device. Alternatively, the communication device may be a first NF as described in the fifth aspect. Alternatively, the communication device may be a means capable of supporting the NF in implementing the functions required by the methods provided in the fifth aspect, for example, the communication device may be a chip or chip system in the NF. The chip can be a baseband chip and / or a radio frequency chip. The chip system can be composed of chips or may include chips and other discrete components.
[0080] In one implementation of the tenth aspect, when the communication device is a terminal device, the interface circuit can be a radio frequency processing chip in the terminal device, and the processing circuit can be a baseband processing chip in the terminal device. When the communication device is a network device, the interface circuit can be a radio frequency processing chip in the network device, and the processing circuit can be a baseband processing chip in the network device.
[0081] In one implementation of the tenth aspect, when the communication device is a chip or chip system, the input circuit can be an input pin, the output circuit can be an output pin, and the logic circuit can be a transistor, gate circuit, flip-flop, or various other logic circuits. The input signal received by the input circuit can be received and input by, for example, but not limited to, a receiver; the signal output by the output circuit can be, for example, but not limited to, output to a transmitter and transmitted by the transmitter. Furthermore, the input circuit and the output circuit can be the same circuit, which is used as both the input circuit and the output circuit at different times. This application does not limit the specific implementation of the input / output interface and the logic circuit.
[0082] Eleventhly, embodiments of this application provide a communication system comprising a terminal device, an access network device, and multiple core network elements, the multiple core network elements including a first network element. The access network device is used to implement the function described in the first aspect, the first network element is used to implement the function described in the second aspect, and the terminal device is used to implement the function described in the third or fourth aspect. Alternatively, the communication system comprises a terminal device, an access network device, and multiple core network elements, the multiple core network elements including a first network element. The access network device is used to implement the function described in the sixth aspect, the first network element is used to implement the function described in the second aspect, and the terminal device is used to implement the function described in the seventh aspect. The communication system also includes a first NF, the first NF being used to implement the function described in the fifth aspect.
[0083] In a twelfth aspect, embodiments of this application provide a computer-readable storage medium for storing a computer program or instructions that, when executed, cause the methods described in any of the first to seventh aspects and any implementation thereof to be implemented.
[0084] In a thirteenth aspect, embodiments of this application also provide a computer program product containing instructions that, when run on a computer, cause the methods described in any of the first to seventh aspects and any implementation thereof to be implemented.
[0085] The beneficial effects of aspects eight through thirteen and their implementation methods can be referenced to the beneficial effects of any aspect one through seven and any implementation method therein. Attached Figure Description
[0086] Figure 1 This is a 5G network architecture based on a service-oriented architecture.
[0087] Figure 2 A flowchart illustrating the process of establishing a connection between a terminal device and an NF (Network Functions).
[0088] Figure 3 This is a schematic diagram of a RAN-based service architecture;
[0089] Figure 4 A flowchart illustrating the communication method 400 provided in an embodiment of this application;
[0090] Figure 5 A flowchart illustrating the communication method 400A provided in an embodiment of this application;
[0091] Figure 6 A flowchart illustrating the communication method 400B provided in an embodiment of this application;
[0092] Figure 7 A flowchart illustrating the communication method 400C provided in an embodiment of this application;
[0093] Figure 8 A flowchart illustrating the communication method 400D provided in an embodiment of this application;
[0094] Figure 9 A flowchart illustrating the communication method 900 provided in an embodiment of this application;
[0095] Figure 10 A flowchart illustrating the communication method 900A provided in an embodiment of this application;
[0096] Figure 11 A flowchart illustrating the communication method 900B provided in an embodiment of this application;
[0097] Figure 12 A flowchart illustrating the communication method 1200 provided in an embodiment of this application;
[0098] Figure 13 A schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0099] Figure 14 This is another schematic diagram of the communication device provided in the embodiments of this application. Detailed Implementation
[0100] The 3rd Generation Partnership Project (3GPP) standards group defined the 5G network architecture. This architecture supports radio access technologies defined by the 3GPP standards group (such as Long Term Evolution (LTE) and the Sixth Generation (5G) radio access network ((R)AN)) to access the 5G core network (CN). (R)AN and RAN are interchangeable; for ease of description, RAN will be used as an example below.
[0101] Please see Figure 1 This is a 5G network architecture based on a service-oriented architecture. Figure 1 The document illustrates the interaction relationships between network functions and entities, as well as their corresponding interfaces. For example, terminals (such as user equipment (UE)) and AMFs can interact through the N1 interface, and the interaction messages are called N1 messages. Figure 1 Some interfaces in the network are implemented using a service-oriented approach. The network architecture comprises three parts: terminal equipment, data network (DN), and carrier network. The functions of some of these network elements are briefly described below.
[0102] (1) Terminal equipment
[0103] Any device capable of data communication with RAN equipment can be considered a terminal device. Terminal devices are also called terminals, terminal equipment, user devices, mobile stations, or mobile terminals. Terminal devices can be widely used in various scenarios. Examples include: mobile phones, computers, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, stations (STAs), robotic arms, cameras, robots, vehicles, drones, helicopters, airplanes, ships, or smart home devices (such as televisions, air conditioners, robot vacuums, speakers, set-top boxes), relays, and customer premises equipment (CPEs).
[0104] Furthermore, in this embodiment, the terminal device can also be a terminal device in an IoT system, such as a water meter or electricity meter. IoT is an important component of future information technology development. Its main technical characteristic is connecting objects to networks through communication technology, thereby realizing an intelligent network that enables human-machine interconnection and object-to-object interconnection.
[0105] When the terminal device is applied to V2X, it can also be called a V2X device, such as a smart car, an unmanned car, a driverless car, a pilotless car, or an automobile, or a roadside unit (RSU). All the terminal devices described above, if located on a vehicle (e.g., placed / installed inside the vehicle), can be considered in-vehicle terminal devices. In-vehicle terminal devices can be built into a vehicle's on-board module, on-board unit, on-board component, on-board chip, or on-board unit as one or more components or units. The vehicle can implement the methods of this application through the built-in on-board module, on-board unit, on-board component, on-board chip, or on-board unit. In-vehicle terminal devices can be vehicle equipment, on-board modules, vehicles, on-board units (OBU), RSUs, in-vehicle infotainment systems (or on-board transmitting units) (telematics boxes, T-boxes), chips, or SoCs, etc., and the aforementioned chips or SoCs can be installed in the vehicle, OBU, RSU, or T-box.
[0106] Terminal devices can establish connections with the operator's network through interfaces provided by the operator's network (such as N1), and use data and / or voice services provided by the operator's network. Terminal devices can also access the DN (Network Provider) through the operator's network, and use operator services deployed on the DN, and / or services provided by third parties. These third parties can be service providers outside of the operator's network and terminal devices, and can provide other data and / or voice services to the terminal devices. The specific form of these third parties can be determined based on the actual application scenario and is not limited here.
[0107] (2)DN
[0108] A DN, also known as a packet data network (PDN), is a network located outside of a carrier's network. A carrier's network can connect to multiple DNs, and various services can be deployed on a DN, providing data and / or voice services to terminal devices. For example, a DN might be the private network of a smart factory. Sensors installed in the workshop can act as terminal devices, and a control server for these sensors is deployed within the DN. The control server provides services to the sensors. Sensors can communicate with the control server, receive instructions from it, and transmit the collected sensor data back to the control server accordingly. Another example is a DN serving as an internal office network for a company. Employees' mobile phones or computers can act as terminal devices, accessing information and data resources on the company's internal office network.
[0109] (3)RAN
[0110] RAN is a sub-network of an operator's network, serving as the implementation system between service nodes and terminal devices within the operator's network. For a terminal device to access the operator's network, it first passes through the RAN, and then connects to service nodes in the operator's network via the RAN. In this application's embodiments, the RAN can be a 3GPP-related cellular system, such as a 5G / new radio (NR) mobile communication system, or a future-oriented evolution system. The RAN can also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), a virtualized radio access network (vRAN), a non-terrestrial network (NTN), etc. The RAN can also be a communication system that integrates two or more of the above systems. In this application's embodiments, the RAN device can also be referred to as a RAN node, RAN entity, or access node, etc.
[0111] In one possible scenario, a RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), or a base station in a future mobile communication system. RAN nodes can also be macro base stations, micro base stations, indoor stations, relay nodes, donor / host nodes, or radio controllers. RAN nodes can also be servers, wearable devices, vehicles, or in-vehicle equipment. For example, in V2X technology, the RAN node can be a roadside unit (RSU).
[0112] In another possible scenario, the RAN node can be a module or unit that performs some of the functions of the base station; or multiple RAN nodes can cooperate to assist terminal equipment in achieving wireless access, with different RAN nodes performing some of the functions of the base station. For example, the RAN node can be a CU, DU, or RU. The function of the CU can be implemented by a single entity or by different entities. For example, the function of the CU can be further divided, that is, the control plane and the user plane can be separated and implemented by different entities, namely the control plane CU entity (i.e., CU-control plane (CP) entity) and the user plane CU entity (i.e., CU-user plane (UP) entity). The CU-CP entity and the CU-UP entity can be coupled with the DU to jointly complete the function of the RAN node. The CU and DU can be set up separately or included in the same network element, such as in the baseband unit (BBU). Any of the units among the CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented by software modules, hardware modules, or a combination of software modules and hardware modules.
[0113] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples.
[0114] The CU and DU can be configured according to the protocol layer functions of the wireless network they implement: for example, the CU can be configured to implement the functions of the Packet Data Convergence Protocol (PDCP) layer and above (such as the Radio Resource Control (RRC) layer and / or the Service Data Adaptation Protocol (SDAP) layer); the DU can be configured to implement the functions of the protocol layers below the PDCP layer (such as the Radio Link Control (RLC) layer, the Media Access Control (MAC) layer, and / or the Physical (PHY) layer). For specific descriptions of the above protocol layers, please refer to the relevant 3GPP technical specifications or the technical specifications of other applicable communication protocols.
[0115] The above division of the processing functions of CU and DU according to protocol layers is merely an example; other division methods are also possible, and this application does not limit this. For example, in one design, CU or DU can be further divided into processing functions with protocol layers. In one design, some functions of the RLC layer and the functions of the protocol layer above the RLC layer are located in the CU, while the remaining functions of the RLC layer and the functions of the protocol layer below the RLC layer are located in the DU.
[0116] In another possible design, the DU and RU collaborate to implement the PHY layer functionality, or, more specifically, a portion of the PHY layer functionality of the DU can be moved to the RU. A DU can be connected to one or more RUs. The functions of the DU and RU can be configured in various ways depending on the design. For example, the DU may be configured to implement baseband functions, and the RU may be configured to implement mid-RF functions. Alternatively, the DU may be configured to implement higher-level functions in the PHY layer, and the RU may be configured to implement lower-level functions in the PHY layer, or both lower-level and RF functions. Higher-level functions in the physical layer may include a portion of the physical layer's functionality closer to the MAC layer, and lower-level functions may include another portion of the physical layer's functionality closer to the mid-RF side. This application does not limit the specific functions of the DU and RU. The interface between the DU and RU can be called a fronthaul interface. In one design, the CU may not have a PDCP layer; for example, the CU may only include an RRC layer. The CU-CP may not have PDCP-C. The CU-UP may not have PDCP-U, or may not have a CU-UP. In one design, the DU may not have an RLC layer; for example, the DU may only have a MAC and a higher PHY layer.
[0117] When the RAN is O-RAN, it can also have artificial intelligence (AI) capabilities. For example, O-RAN includes an intelligent controller. The intelligent controller can be a non-real-time RAN intelligent controller (RIC / non-RT RIC / NRTRIC) or a near-real-time RAN intelligent controller (RIC / nRT RIC / nRT RIC). A non-real-time RIC can be used to implement non-real-time intelligent management of RAN functions, enabling workflows including model training and updates, and guiding applications / functions in the nRT RIC based on policies. A near-real-time RIC can be used to implement near-real-time intelligent management of the RAN. Through data collection and related operations on the E2 interface, near-real-time control and optimization of O-RAN modules and resources are achieved.
[0118] (4) Carrier Network
[0119] An operator's network also includes multiple core network components, or, in other words, the part of an operator's network other than the (wireless) access network component can be referred to as the core network component.
[0120] The core network comprises multiple core network elements, such as Network Exposure Function (NEF) elements, Network Function Repository Function (NRF) elements, Policy Control Function (PCF) elements, Unified Data Management (UDM) elements, Application Function (AF) elements, Network Slice Selection Function (NSSF) elements, Authentication Server Function (AUSF) elements, AMF elements, SMF elements, User Plane Function (UPF) elements, Authentication Server Function (AUSF) elements, Network Slice Selection Function (NSSF) elements, and (R)AN (Radio Access Network). For ease of explanation, (R)AN will be referred to as RAN in the following description. It should be noted that the network elements included in the above-mentioned operator network lock are only examples. Operator networks may also include more network elements, such as network data analytics function (NWDAF) network elements.
[0121] The AMF (Active Mobile Function) element is responsible for UE mobility management, including mobility state management, assigning temporary UE identities, and authenticating and authorizing UEs. The SMF (Supply, Service, and Facilitation) element is responsible for UPF (Uniform and Persistent Function) element selection and reselection, IP address allocation, bearer establishment, modification, and release, and Quality of Service (QoS) control. The UPF element supports all or some of the following functions: interconnecting Protocol Data Unit (PDU) sessions with the data network; packet routing and forwarding (e.g., supporting uplink classification of traffic before forwarding to the data network); and packet inspection. The UDM (Uniform DM) element is responsible for managing subscription data and notifying the relevant network elements when subscription data is modified.
[0122] Figure 1Nnef, Nudsf, Nnrf, Npcf, Nudm, Naf, Namf, Nnvaf, Nsmf, Nnwdaf, N1, N2, N3, N4, and N6 are interface sequence numbers. The meanings of these interface sequence numbers can be found in the definitions in the 3GPP standard protocols, and are not limited here.
[0123] It should be noted that, Figure 1 The communication system shown does not constitute a limitation on the communication systems applicable to the embodiments of this application. Furthermore, the communication system provided in this application can be used in terrestrial networks (TN) and / or non-terrestrial networks (NTN), without limitation. Additionally, it should be noted that the embodiments of this application do not limit the names of the network elements in the communication system. For example, in different communication systems, each network element may have other names; or, for example, when multiple network elements are integrated into the same physical device, that physical device may also have other names.
[0124] In this embodiment of the application, the core network element can also be called an NF network element, or simply NF (hereinafter, this will be used as an example). Figure 1 In the architecture shown, the UE and AMF maintain a NAS connection via (R)AN, and (R)AN forwards NAS messages between the UE and AMF. For example, (R)AN forwards mobility management (MM) NAS messages or service request (SR) NAS messages between the UE and AMF. After receiving a NAS message, the AMF parses the corresponding request and then sends the request to the corresponding NF. In a service-oriented architecture, NF can also be called NS (Network Service).
[0125] Currently, the UE uses the AMF as the anchor point during the connection establishment process between the UE and the core network elements. For example, please refer to [link to relevant documentation]. Figure 2 This is a schematic diagram illustrating a process for establishing a connection between the UE and core network elements.
[0126] like Figure 2As shown, when the UE is in RRC idle state, it can establish a connection with the AMF network element through the initial NAS message. For example, the UE can send an SR message to the AMF network element to establish a connection between the UE and the AMF network element. The AMF network element sends an SR accept message back to the UE. After receiving the SR accept message, the UE can send a message to a certain NF. When the UE needs to send a message to a certain NF, the UE can send the message to the AMF, and the AMF will forward the message to that NF. Taking the NF as an example, if the UE initiates a session service, the UE will send the session request as an SM container in a non-initial NAS message to the AMF. The AMF parses the NAS message, selects the SMF, and then initiates a session request to that SMF.
[0127] based on Figure 2 The process is as follows: when the UE is in RRC idle state, the UE can only establish a connection between the UE and the AMF by initiating an SR message to the AMF. If the terminal device needs to communicate with other core network elements (such as the SMF) besides the AMF, the terminal device first needs to establish a connection with the AMF, and then forward the data between the terminal device and the SMF through the AMF.
[0128] Future support will include RAN-based services. Please see [link / reference]. Figure 3 This is the RAN-based service architecture provided in the embodiments of this application. Figure 3 Only some NFs are listed, such as Short Message Service Function (SMSF), PCF, SMF, AMF, UPF, etc. Figure 3 The dashed line indicates that the connection is not yet complete.
[0129] from Figure 3 It can be seen that in a RAN-based service-oriented architecture, the UE can communicate directly with the NF through the RAN, without needing the AMF as an anchor point. This reduces AMF congestion. Furthermore, since the AMF doesn't need to be an anchor point, data from the UE to other NFs doesn't need to pass through the AMF, achieving data isolation and simplifying the process. For the RAN, the N2 interface can also be based on a service-oriented interface protocol, without needing the AMF as an anchor point, thus requiring only one set of protocols to be maintained from the RAN to each NF. Compared to using the AMF as an anchor point, where operators need to maintain one set of protocols between the access network equipment and the AMF, and another set between the AMF and other NFs, operators only need to maintain one set of protocols between the access network equipment and the NFs, resulting in fewer protocols and lower complexity. And, based on... Figure 3 The architecture shown requires further investigation into how to establish a connection between the UE and the NF.
[0130] Furthermore, during the process of establishing an AMF connection by sending messages (e.g., SR) from the terminal device, the security of the access stratum (AS) can be activated to ensure connection security. Additionally, RRC connections and N2 interface connections can be established, ensuring reliable message transmission after the connection is established. In a RAN-based service architecture, messages between the UE and NF do not need to be relayed through the AMF, which may prevent the activation of the AS. How to ensure secure transmission between the UE and NF requires further research.
[0131] Therefore, the embodiments of this application are aimed at Figure 3 The architecture shown provides a method for the UE to establish a connection with the NF, reducing AMF congestion, isolating data between different NFs, and reducing data processing complexity. Furthermore, during the initial UE registration process, the AMF can initiate a security activation procedure to activate the security context between at least one NF and the UE. The UE and NF activate the security between them based on the NF's information (e.g., NF type). Therefore, when the UE sends information to a specific NF, the information can be encrypted and its integrity protected according to the security context between the UE and that NF, improving information security during transmission. Alternatively, during the initial UE registration process, the AMF can activate the security context between the AMF and the terminal device. Other NFs can then obtain a basic key from the AMF. Based on this basic key and the NF's information (e.g., NF type), an encryption key can be deduced to activate the security context between that NF and the terminal device. Thus, when the UE needs to communicate with a specific NF, it can request activation of that NF, thereby encrypting and protecting the information based on the activated security context between the UE and the NF, improving information security during transmission.
[0132] In the embodiments of this application, security includes encryption processing and / or integrity protection processing. "Integrity protection" can also be called integrity verification, or simply integrity verification / integrity guarantee / integrity guarantee. "Encryption" and "integrity protection" can be independent algorithms. Alternatively, "encryption" may also include "integrity protection." That is, "encryption" includes both encryption and integrity protection.
[0133] Encryption refers to the process by which the sending end uses an algorithm to convert plaintext data into ciphertext based on input parameters such as a key. Decryption refers to the process by which the receiving end uses an algorithm to convert the ciphertext back into plaintext based on input parameters such as a key. When the input parameters used by the sending end and the receiving end are the same, it is possible for information encrypted at the sending end to be successfully decrypted at the receiving end.
[0134] Integrity protection processing refers to the sending end calculating integrity protection parameters (e.g., parameter A) using an algorithm based on input parameters such as data packets and keys. Integrity verification refers to the receiving end calculating parameter B using an algorithm based on input parameters such as data packets and keys. If parameters A and B match, integrity verification succeeds; otherwise, it fails. When the input parameters used by the sending end and the receiving end are the same, information that has undergone integrity protection at the sending end can be successfully verified for integrity by the receiving end.
[0135] In this embodiment, requesting the RAN to establish a connection to at least one NF can also be replaced by requesting the RAN to create a context with at least one NF. Alternatively, in this embodiment, the meaning of the RAN establishing a connection to an NF includes the RAN creating a context with the NF.
[0136] The technical solutions provided in the embodiments of this application can be applied to various communication systems, such as LTE communication systems, 5G mobile communication systems / NR communication systems, or future mobile communication systems, or other similar communication systems, as long as the communication system supports RAN-based services. Other similar communication systems may include wireless fidelity (WIFI), vehicle-to-everything (V2X), and Internet of Things (IoT) systems, etc.
[0137] For ease of description, the embodiments of this application are applied to Figure 1 and Figure 3 Taking a combined network architecture as an example. The system described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems. It should be noted that the above... Figure 1 and Figure 3 The network elements, functions, or services mentioned can be network components in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network elements, functions, or services can be implemented by a single device, multiple devices working together, or a functional module within a single device; this application does not specifically limit this. Furthermore, some English abbreviations used in this document to describe embodiments of this application using the current 5G network as an example may change as the network evolves; specific evolution can be found in the descriptions in the relevant standards.
[0138] In the embodiments of this application, "transmission" includes "sending" and / or "receiving." "Sending" and "receiving" indicate the direction of signal transmission. For example, "sending information to XX" can be understood as the destination of the information being XX, which can include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receiving information from YY" can be understood as the source of the information being YY, which can include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Sending" can also be understood as the "output" of a chip interface, and "receiving" can also be understood as the "input" of a chip interface. In other words, sending and receiving can occur between devices, such as between access network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.
[0139] In this application embodiment, the number of nouns, unless otherwise specified, refers to "singular nouns or plural nouns," that is, "one or more." "At least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A / B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. For example, A / B means: A or B. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and / or c means the following combinations: a exists alone, b exists alone, c exists alone, a and b exist simultaneously, a and c exist simultaneously, b and c exist simultaneously, or a, b, and c exist simultaneously, where a, b, and c can be single or multiple.
[0140] In the embodiments of this application, "when," "if," and "if" all refer to the device taking corresponding actions under certain objective circumstances, and are not time-limited, nor do they require the device to perform a judgment action, nor do they imply any other limitations. Unless otherwise specified, "if" and "if" can be substituted, and "when" and "in the case of" can be substituted. "When" and "if" / "if" can be substituted.
[0141] In this application, the ordinal numbers such as "first" and "second" are used to distinguish multiple objects, and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. For example, "first identifier" and "second identifier" refer to two different identifiers, and do not indicate a difference in priority or importance between the two identifiers.
[0142] In the embodiments of this application, the solutions in each embodiment can be used in a reasonable combination, and the explanations or descriptions of various terms, similar operations, or steps appearing in the embodiments can be referenced or explained to each other in the embodiments, without limitation.
[0143] The solutions provided in the embodiments of this application are described below with reference to the accompanying drawings.
[0144] This application's embodiments involve a first network element, a first NF, an access network device, and a terminal device. The first network element can be a core network element, for example, an AMF or other network elements capable of similar functions. The steps executed by the first network element can be performed by the first network element itself or by components within the first network element (such as processors, chips, or logic function modules). The first NF can be a core network element, for example, an SMF, PCF, UPF, SMSF, etc. The steps executed by the first NF can be performed by the first NF itself or by components within the first NF (such as processors, chips, or logic function modules). The access network device can be a RAN device, for example, an access network element is a station. The steps executed by the access network device can be performed by the access network device itself, or by components (such as CU, DU, or RU) that perform some or all of the functions of the access network device. The steps executed by the terminal device can be performed by the terminal device itself, or by components within the terminal device (such as baseband chips, or other processing units or processor modules).
[0145] It should be noted that there are no restrictions on the specific names of each NF. For example, network elements can have other names in different communication systems. For instance, in 5G communication systems, the Access and Mobility Management Function is called AMF, and in future communication systems, the Access and Mobility Management Function may also have other names.
[0146] For ease of description, in the various embodiments below, the first network element is taken as an AMF, and RAN refers to RAN equipment. In the embodiments of this application, the information of the first NF may include (or be) the identification information of the first NF. The information of the first NF may also include (or be) the type information of the first NF.
[0147] Please see Figure 4 This is a flowchart illustrating the communication method 400 provided in an embodiment of this application. Figure 4 This method is described from the perspective of interaction between AMF, UE, RAN, and the first NF. The processing performed by a single execution entity can also be divided into processing by multiple execution entities, which can be logically and / or physically separated. For example, the processing performed by the access network device can be divided into processing by at least one of CU, DU, RU, etc.
[0148] like Figure 4 As shown, the communication method 400 includes the following steps.
[0149] S401, RAN sends a first message to AMF, which includes a NAS message.
[0150] Accordingly, the AMF receives a first message from the RAN. This first message can be used to trigger the AMF to request the RAN to establish a connection with at least one NF. Alternatively, the first message can be used to trigger the AMF to request the RAN to establish a connection with at least one NF, or it can be used to trigger the AMF to request the RAN to create a context with at least one NF. The specific name of the first message is not limited in this embodiment.
[0151] S401 can occur during the UE registration process. For example, when a UE requests registration, it sends a registration request to the RAN; the RAN receives the registration request and sends a first message to the AMF. The UE can place the registration request in a NAS message and send it to the RAN. The RAN receives the NAS message and, by default, forwards it to the AMF. For example, the first message includes a NAS message containing the registration request. Optionally, the first message can also include the UE's identifier (ID) and a unique identifier assigned to the UE by the RAN. For ease of description, the unique identifier assigned to the UE by the RAN is referred to as the first identifier, which can be denoted as RAN UE ID.
[0152] S401 can also occur during UE service provision. For example, when a UE has a service request, it sends a service request message to the RAN; the RAN receives the service request message and sends a first message to the AMF. The UE can send the service request message in a NAS message to the RAN, and the RAN, upon receiving the NAS message, will forward it to the AMF by default. For example, the first message includes a NAS message, which in turn includes the service request message. The NAS message includes information about the NF (Network Function) used to request the establishment of a connection between the UE and the NF. This NF information includes the NF's type or identification information, allowing the AMF to clearly identify the NF that the UE needs to establish a connection with. Furthermore, the AMF requests the access network device to establish a connection with this NF, ensuring that the NF established by the access network device is the same NF that the terminal device needs to establish a connection with, thus satisfying the terminal device's connection requirements.
[0153] Optionally, the first message may also include the UE ID and the RAN UE ID. The RAN informs the AMF of the UE ID, allowing the AMF to clearly identify the UE requiring a connection. The access network device informs the AMF of the RAN UE ID, enabling the AMF to maintain the connection with the access network device based on the RAN UE ID. For example, the first network element can determine the already connected terminal device based on the first identifier without triggering network paging.
[0154] Optionally, the first message may also include UE capability information, which may indicate the UE's capabilities. For example, the capability information may be included in a registration request; the first message sent by the RAN to the AMF may include a NAS message, and the NAS message may include the UE's capability information in the registration request. Alternatively, the capability information may be included in a service request message; the first message sent by the RAN to the AMF may include a NAS message, and the NAS message may include the UE's capability information in the service request message.
[0155] Optionally, the first message may also include UE capability information that is not included in the NAS message.
[0156] S402, AMF sends a second message to RAN, which requests RAN to establish a connection to at least one NF.
[0157] The AMF receives a first message and, based on the NAS message included in the first message, determines that the UE needs to establish a connection with the CN. Therefore, the AMF receives the first message and sends a second message to the RAN. This second message can be used to request the RAN to establish a connection to at least one NF. It should be noted that if the first message is used to trigger the AMF to request the RAN to establish a connection to at least one NF, then the second message is used by the RAN to establish a connection to at least one NF. If the first message can be used to trigger the AMF to request the RAN to create a context with at least one NF, then the second message is used to create a context from the RAN to at least one NF. The specific name of the second message is not limited in this embodiment.
[0158] The second message includes information about at least one Functional Element (NF). This NF information can be either NF identification information (e.g., NFID) or NF type information. That is, the second message may include identification information for at least one NF, or it may include type information for at least one NF. Optionally, the second message also includes a first identifier and a unique identifier assigned to the UE by the AMF. For ease of description, the unique identifier assigned to the UE by the AMF is referred to as the third identifier, for example, it can be denoted as AMFUE ID. By carrying the AMF UE ID and RAN UE ID in the second message, the RAN can explicitly establish a connection with the AMF or create a context with the AMF.
[0159] Optionally, if the first message includes UE capability information, the AMF can also select at least one NF based on the UE capability information, wherein the at least one NF matches the UE's capabilities. Additionally, for at least one NF, the AMF can also generate a context for that at least one NF.
[0160] S403, RAN sends a first request message to the first NF, which can be used to request the establishment of a connection with the first NF.
[0161] The RAN receives a second message from the AMF, which can be used to establish a connection with at least one NF indicated by the second message, or to create a RAN-to-at least one NF context. For example, the RAN receives the second message and sends a first request message to a first NF, which can be used to request the establishment of a connection with the first NF. Alternatively, the first request message can be used by the RAN to request the creation of a RAN-to-at least one NF context.
[0162] The first request message includes the UE ID and the RAN UE ID, enabling the first NF to clearly identify which UE the connection requested by the RAN is serving. The specific name of the first request message is not limited in this embodiment. For example, the first request message may be called a connection establishment request message or a context creation request message.
[0163] It should be noted that S403 uses the first NF as an example. In reality, the RAN will send a first request message for each NF in at least one NF. For example, if at least one NF includes a first NF and a second NF, the RAN will send a first request message to the first NF and also send a first request message to the second NF.
[0164] S404. The first NF sends a first response message to the RAN, which indicates that the connection between the first NF and the RAN has been established.
[0165] The first response message is a response or reply message to the first request message. The first response message indicates that the connection between the first NF and the RAN has been established. Alternatively, it can be used to indicate that the context creation of the first NF has been completed. It should be understood that the first request message can be used to request the establishment of a connection with the first NF, and the first response message indicates that the connection between the first NF and the RAN has been established. The first request message can be used by the RAN to request the creation of a context from the RAN to at least one NF, and the first response message can be used to indicate that the context creation of the first NF has been completed.
[0166] The first response message may include the RAN UE ID and a unique identifier assigned to the UE by the first NF. For ease of description, the unique identifier assigned to the UE by the first NF is referred to as the second identifier, which can be denoted as NF UE ID. For example, if the first NF is SMF, the second identifier can be SMF UE ID. The AMF feeds back the RAN UE ID and SMF UE ID to the RAN. By maintaining the correspondence between the SMF UE ID and the RAN UE ID, the RAN can maintain the correspondence between the terminal device and the SMF.
[0167] S405, the AMF sends a fourth message to the UE, and the UE receives the fourth message from the AMF accordingly.
[0168] For a given NF, if the AMF determines that the RAN has already established a connection with that NF, the AMF can send a fourth message to the UE to indicate that a connection has been established between the NF and the UE, or to indicate that a context has been created between the NF and the UE. The specific name of the fourth message is not limited in this application embodiment. For example, if the first message includes a registration request, the fourth message could be called a registration acceptance message. Or, for example, if the first message includes a service request message, the fourth message could be called a service acceptance message. Figure 4 Taking the establishment of a connection between the first NF and the UE as an example, the fourth message can indicate that the first NF and the UE have established a connection.
[0169] As an example, the fourth message may include NF type information to indicate that the NF corresponding to that type information has established a connection with the UE / connection establishment is complete, or to indicate that a context has been created between the NF corresponding to that type information and the UE. Alternatively, the fourth message may include NF identification information to indicate that the NF has established a connection with the UE / connection establishment is complete, or to indicate that a context has been created between the NF and the UE. Another example is that the fourth message may include NF type information and NF identification information to indicate that a connection has been established with an NF of that type / connection establishment is complete, or to indicate that a context has been created between an NF of that type and the UE.
[0170] Optionally, during the registration request process, the fourth message includes the type information of the NF and / or the identification information of the NF.
[0171] As another example, the fourth message may not include information about the NF; for example, the fourth message may not include the identification information of the NF. In this case, the UE may assume that a connection or context has been established with all the NFs that need to communicate, or the UE may assume that a connection or context has been established with the requested NF.
[0172] Optionally, during the business request process, the fourth message may not include the type information and / or identification information of the NF.
[0173] In a possible implementation, the fourth message includes NF type information and / or NF identification information, which can be used to inform the UE to send a third message to the RAN. Based on the NF type information and / or NF identification information included in the fourth message, the UE can determine the NFs that have been established with the UE, and thus decide which NF to send information to, or what kind of information to send to the corresponding NF.
[0174] S406, the UE sends a third message to the RAN, which is used to indicate the identifier of the first NF or the type of the first NF.
[0175] Accordingly, the RAN receives a third message from the UE. Based on S401-S405, the RAN establishes a connection with at least one NF, or the RAN creates a context to at least one NF. For the UE, when there is a service request, it can forward the corresponding message to a certain NF through the RAN. For example, taking the case where the UE needs to send a message to the first NF, assuming that the UE needs to handle protocol data unit (PDU) (session management, SM) related requirements, the first NF can be an SMF.
[0176] When a UE needs to send a message (e.g., a third message) to the first NF, the UE can send the third message to the RAN. To ensure that the access network device clearly identifies the first NF, the third message also indicates the first NF to avoid forwarding errors by the access network device. For example, the third message may also indicate the identifier or type of the first NF. The third message includes the identifier information or type information of the first NF.
[0177] S407, RAN sends the third message to the first NF.
[0178] When the RAN receives a third message, it can forward the third message to the first NF. Accordingly, the first NF receives the third message from the RAN.
[0179] If the third message includes the identifier of the first NF, the RAN can identify the first NF based on the third message and forward the third message to the first NF. If the third message includes the type of the first NF, the RAN can select the NF matching that type as the first NF based on the third message and forward the third message to the first NF. For example, the RAN determines the NFUE ID based on the UE ID and the type of the first NF, and then determines the first NF based on the NF UE ID.
[0180] In communication method 400, the AMF can determine based on the first message that the UE needs to establish a connection with the NF, and thus request the RAN to establish a connection with at least one NF or create a context for at least one NF. Subsequently, the UE can forward information to the NF through the RAN without using the AMF as an anchor point, which can reduce AMF congestion and also achieve data isolation between the UE and each NF.
[0181] Understandably, in the current 5G network architecture, the AMF (Active Network Frame) serves as the anchor point for communication between the UE and other NFs (Network Components) besides the AMF. During the registration request process from the UE to the AMF, authentication is performed. After successful UE authentication, the AMF initiates a secure mode procedure, activates the security context, and completes the creation of security contexts on both the AMF and UE sides, thereby activating encryption and integrity protection between the UE and the AMF.
[0182] In this embodiment, under the RAN-based service architecture, NFs other than the AMF do not yet have keys, and therefore cannot create security contexts, thus failing to achieve encryption and integrity protection with the UE. To improve the security between the UE and at least one NF, this embodiment also proposes two schemes for activating the security context between the UE and the NF. For example, the AMF can activate the security context between at least one NF and the UE. When the UE sends information to an NF, the information can be encrypted and protected for integrity based on the security context between the UE and that NF. Another example is that if the AMF can activate the security context between the AMF and the UE, other NFs can obtain a basic key from the AMF. Based on this basic key and the NF's information (e.g., NF type), an encryption key can be deduced to activate the security context between that NF and the UE. Thus, when the UE needs to communicate with an NF, it can request the activation of that NF, which can then activate the security context with the UE, thereby using the security context to encrypt and protect the information for integrity.
[0183] Either of the two schemes for activating the security context between the UE and NF mentioned above can be combined with communication method 400. For ease of understanding, the communication method 400 will be further described below with specific examples.
[0184] Example 1: The AMF activates a security context between at least one NF and the UE, and the first message includes a registration request.
[0185] Please see Figure 5 The following is a flowchart illustrating the communication method 400A provided in this application embodiment. Figure 5 This method is introduced from the perspective of AMF, UE, RAN, and first NF interaction. For example... Figure 5 As shown, the process of the communication method 400A includes the following steps.
[0186] S501, the UE sends a registration request to the RAN, and the RAN receives the registration request from the UE accordingly.
[0187] This registration request is used to register with the network so that the UE can establish a connection with the RAN or CN. The registration request may include the UE's capability information, registration type, etc.
[0188] S502, RAN sends a first message to AMF, which includes a NAS message.
[0189] Regarding the similarities between S502 and S401, please refer to the relevant content of S401 mentioned above, which will not be repeated here.
[0190] S503, AMF, and UE complete authentication.
[0191] Upon receiving the first message, the AMF determines that the UE needs to access the network. The AMF can send an authentication request to the UE via the RAN, requesting the UE to provide its identity information. This authentication request may include a random number. The UE receives the authentication request, obtains the random number, generates a new value based on its stored key and the random number, and sends this data back to the AMF in the authentication response. The AMF receives the authentication response and determines the UE's identity based on the value in the response. If the UE's identity is trusted, the AMF continues processing the first message; if the UE's identity is untrusted, the AMF may refuse to process the first message to prevent unauthorized access.
[0192] S504, AMF selects at least one NF based on the UE's capability information.
[0193] If the first message includes UE capability information, the AMF can select at least one NF based on that capability information, and that at least one NF matches the UE's capabilities. Additionally, the AMF can generate the context for at least one NF.
[0194] At least one NF and the UE's security context are activated between S505, AMF, and UE.
[0195] After selecting at least one NF, the AMF can initiate a Security Mode Control (SMC) procedure to activate the security context between the at least one NF and the UE. For example, the AMF can send a Security Mode Command message to the UE, which includes a key identifier and information about at least one NF. Optionally, the Security Mode Command message also includes information about the security algorithms between the UE and each NF. Upon receiving the Security Mode Command, the UE can perform corresponding operations. For example, the UE can deduce a new encryption key based on the key indicated by the key identifier and the NF information (e.g., NF type) and perform corresponding security configurations, such as updating the encryption key. The encryption key deduced by the UE differs for different NFs. After completing the security configuration, the UE can send a Security Mode Completion message to the AMF to indicate that the Security Mode Control procedure is complete. In other words, the Security Mode Completion message indicates that the security mode operation has been successfully implemented.
[0196] S506, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0197] For details regarding S506, please refer to the aforementioned content of S402; it will not be repeated here.
[0198] S507, RAN sends a first request message to the first NF, and correspondingly, the first NF receives the first request message from RAN.
[0199] For information on S507, please refer to the relevant content of S403 mentioned above; it will not be repeated here.
[0200] S508, the first NF sends a first response message to the RAN, and correspondingly, the RAN receives the first response message from the first NF.
[0201] For information on S508, please refer to the relevant content of S404 mentioned above; it will not be repeated here.
[0202] S509, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0203] This reply message is a response to the second message and is used to indicate that the RAN and the first NF have established a connection.
[0204] Optionally, upon receiving the reply message, the AMF may assume that the RAN has established a connection with at least one NF indicated by the second message. In this case, the second message may not carry NF information. Alternatively, for any NF, the RAN establishes a connection with that NF and sends a reply message to the AMF. This reply message may include information about the NF to indicate that the RAN has established a connection with that NF. In other words, the RAN may send multiple reply messages to the AMF, with each reply message targeting a specific NF.
[0205] S510, AMF sends a fourth message to UE, and correspondingly, UE receives the fourth message from AMF.
[0206] For information on S510, please refer to the relevant content of S405 mentioned above; it will not be repeated here.
[0207] S511, the UE sends a third message to the RAN, and the RAN receives the third message from the UE accordingly.
[0208] For details regarding S511, please refer to the aforementioned content of S406; it will not be repeated here.
[0209] S512, RAN sends a third message to the first NF, and the first NF receives the third message accordingly.
[0210] For information on S512, please refer to the relevant content of S407 mentioned above; it will not be repeated here.
[0211] It should be noted that, in possible implementations, S501 to S505 can be executed separately (or only S501 to S505 can be executed), without executing S506 to S512.
[0212] Using communication method 400A, the UE can forward information to the NF via the RAN without using the AMF as an anchor point, reducing AMF congestion and enabling data isolation between the UE and each NF. Furthermore, after the AMF identifies at least one NF, it can activate a security context between at least one NF and the UE. When the terminal device sends information to an NF, the information can be encrypted and its integrity protected according to the security context between the terminal device and that NF, improving the security of information exchange between the UE and that NF.
[0213] Example 2: The first message includes a business request message.
[0214] The difference between Example 2 and Example 1 is that the UE triggers the RAN to send the first message to the AMF based on service requirements. In this case, the UE has already registered with the network and established a security context with the AMF. Therefore, the procedure in Example 2 does not include the authentication process between the UE and the AMF, nor does it include the SMC procedure, compared to the procedure in Example 1.
[0215] Please see Figure 6 The following is a flowchart illustrating the communication method 400B provided in this application embodiment. Figure 6 This method is introduced from the perspective of AMF, UE, RAN, and first NF interaction. For example... Figure 6 As shown, the process of the communication method 400B includes the following steps.
[0216] S601, the UE sends a service request message to the RAN, and the RAN receives the service request message from the UE accordingly.
[0217] This service request message can be used to request the RAN to provide the UE with the corresponding service. The service request message may include the requested service type, service requirements, etc.
[0218] S602, RAN sends a first message to AMF, which includes a NAS message.
[0219] Regarding the similarities between S602 and S401, please refer to the aforementioned content on S401 for details, which will not be repeated here.
[0220] S603, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0221] For details regarding S603, please refer to the aforementioned content on S402; it will not be repeated here.
[0222] S604, RAN sends a first request message to the first NF, and correspondingly, the first NF receives the first request message from RAN.
[0223] For information on 604, please refer to the aforementioned content on S403; it will not be repeated here.
[0224] S605, the first NF sends a first response message to the RAN, and correspondingly, the RAN receives the first response message from the first NF.
[0225] For information on S605, please refer to the relevant content of S404 mentioned above; it will not be repeated here.
[0226] S606, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0227] For details regarding S606, please refer to the aforementioned content on S509; it will not be repeated here.
[0228] S607, the AMF sends a fourth message to the UE, and correspondingly, the UE receives the fourth message from the AMF.
[0229] For information on S607, please refer to the relevant content of S405 mentioned above; it will not be repeated here.
[0230] S608, the UE sends a third message to the RAN, which is used to indicate the identifier of the first NF or the type of the first NF.
[0231] For information on S608, please refer to the relevant content of S406 mentioned above; it will not be repeated here.
[0232] S609, RAN sends the third message to the first NF.
[0233] For information on S609, please refer to the relevant content of S407 mentioned above; it will not be repeated here.
[0234] Using communication method 400B, the UE can forward information to the NF through the RAN without using the AMF as an anchor point, which can reduce AMF congestion and also achieve data isolation between the UE and each NF.
[0235] Example 3: The AMF activates a security context between at least one NF and the UE, and the first message includes a registration request.
[0236] The difference between Example 3 and Example 1 is that the fourth message sent by the AMF to the UE does not include information about the NF. In this case, the UE can assume that it has established a connection or context with all the NFs that need to communicate, or it can assume that it has established a connection or context with the requested NF. However, if the UE has a message to send to an NF, it does not know in advance which NF to send it to. For example, if the UE wants to send a session message but does not know which SMF to send it to, the RAN can select the appropriate NF for the UE.
[0237] Please see Figure 7 The following is a flowchart illustrating the communication method 400C provided in this application embodiment. Figure 7 This method is introduced from the perspective of AMF, UE, RAN, and first NF interaction. For example... Figure 7 As shown, the communication method 400C includes the following steps.
[0238] S701, the UE sends a registration request to the RAN, and the RAN receives the registration request from the UE accordingly.
[0239] S702 and RAN send a first message to AMF, which includes a NAS message.
[0240] S703, AMF, and UE complete authentication.
[0241] S704, AMF selects at least one NF based on the UE's capability information.
[0242] At least one NF and UE security context are activated between S705, AMF and UE.
[0243] S706, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0244] S707, RAN sends a first request message to the first NF, and correspondingly, the first NF receives the first request message from RAN.
[0245] S708, the first NF sends a first response message to the RAN, and correspondingly, the RAN receives the first response message from the first NF.
[0246] S709, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0247] The S701 to S709 are the same as the aforementioned S501 to S509, and will not be repeated here.
[0248] S710 and AMF send a fourth message to the UE, and correspondingly, the UE receives the fourth message from the AMF.
[0249] The difference from S510 is that the fourth message in S710 does not include NF information. For example, the fourth message does not include NF identification information or NF type information.
[0250] S711, the UE sends a third message to the RAN, which is used to indicate the type of the first NF.
[0251] For information on S711, please refer to the relevant content of S406 mentioned above; it will not be repeated here.
[0252] S712, RAN can determine the first NF based on the type of the first NF, the UE ID, and the type of NF UE ID / NF.
[0253] For details regarding S712, please refer to the relevant description in the aforementioned S407, which will not be repeated here.
[0254] S712, RAN sends the third message to the first NF.
[0255] For information on S712, please refer to the aforementioned content on S407; it will not be repeated here.
[0256] It should be noted that, in possible implementations, S701 to S705 can be executed individually (or only S701 to S705 can be executed), without executing S706 to S713.
[0257] Using communication method 400C, the UE can forward information to the NF via the RAN without using the AMF as an anchor point, reducing AMF congestion and enabling data isolation between the UE and each NF. Furthermore, the AMF activates a security context between at least one NF and the UE, allowing the UE to encrypt and protect the information based on the security context with that NF, thus enhancing the security between the UE and that NF.
[0258] Example 4: The AMF activates a security context between at least one NF and the UE, and the first message includes a registration request.
[0259] The difference between Example 4 and Example 1 is that after authentication between the AMF and the UE, the AMF activates the security context between the AMF and the UE. In this case, when the UE needs to communicate with a certain NF, it can request the activation of that NF, thereby activating the security context between the NF and the UE. This allows the UE to encrypt the information to be sent based on the security context, improving security.
[0260] Please see Figure 8 The following is a flowchart illustrating the communication method 400D provided in this application embodiment. Figure 8 This method is introduced from the perspective of AMF, UE, RAN, and first NF interaction. For example... Figure 8 As shown, the process of the communication method 400D includes the following steps.
[0261] S801, the UE sends a registration request to the RAN, and the RAN receives the registration request from the UE accordingly.
[0262] S802 and RAN send a first message to AMF, which includes a NAS message.
[0263] S803, AMF, and UE complete authentication.
[0264] The same applies to S801 to S803 as to S501 to S503, so they will not be discussed further here.
[0265] S804, AMF and UE activate the security context between AMF and UE.
[0266] After the AMF and UE complete authentication, the SMC procedure can be initiated to activate the security context of the AMF and UE. For example, the AMF can send a NAS security mode command message to the UE, which includes a key identifier. Upon receiving the NAS security mode command, the UE can perform corresponding operations. For instance, the UE can deduce a new encryption key based on the key indicated by the key identifier and perform corresponding security configurations, such as updating the encryption key. After completing the security configuration, the UE can send a NAS security mode completion message to the AMF to indicate that the security mode control process is complete. In other words, the NAS security mode completion message indicates that the security mode operation has been successfully implemented.
[0267] S805, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0268] S806, RAN sends a first request message to the first NF, and correspondingly, the first NF receives the first request message from RAN.
[0269] S807, the first NF sends a first response message to the RAN, and correspondingly, the RAN receives the first response message from the first NF.
[0270] S808, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0271] S809, the AMF sends a fourth message to the UE, and correspondingly, the UE receives the fourth message from the AMF.
[0272] Regarding S805-S809 and S506-S510, they will not be elaborated upon here. Furthermore, S801-S809 are not mandatory steps; therefore, in Figure 8 The diagram is illustrated with dashed lines. Additionally, when executing S801–S804, S805–S816 can be omitted.
[0273] S810, the UE sends a seventh message to the first NF, which can be used to request the activation of the first NF.
[0274] The first NF activates the security context between the UE and the first NF. When the UE needs to communicate with the first NF, it can request the activation of the NF to improve security. For example, the UE sends a seventh message to the first NF, which can be used to request the activation of the NF. The first NF then sends a security mode command message to activate the security context between the UE and the first NF. The specific name of the seventh message is not limited in this embodiment. The seventh message may include the UE ID so that the first NF can clearly identify which UE and the first NF should activate the security context between them.
[0275] S811, The first NF determines the key identifier, which can be used to activate the security context between the UE and the first NF.
[0276] The first NF determines the key identifier, which includes the first NF acquiring the key identifier. This key identifier is associated with a set of security contexts and can be used to activate the security context between the UE and the first NF. Furthermore, after receiving the seventh message, the first NF can obtain the base key used between the UE and the first NF from the AMF based on the UE ID. The first NF then derives the encryption key used to activate the security context between the UE and the first NF based on this base key.
[0277] S812, the first NF sends a security mode command message to the UE, and the UE receives the security mode command message from the first NF accordingly.
[0278] The security mode command message may include a key identifier and information about the first NF (First Network Context) to activate the security context between the terminal device and the first NF. The key identifier may indicate the encryption key derived from the first NF. The security mode command message may also include the security algorithm from the UE to the first NF.
[0279] S813, The UE activates the security context between the UE and the first NF based on the key identifier and the information of the first NF.
[0280] The information for the first NF includes its type information. The UE can activate the security context between the UE and the first NF based on the encryption key indicated by the key identifier.
[0281] S814, the UE sends a security mode completion message to the first NF, and correspondingly, the first NF receives the security mode completion message from the UE.
[0282] The security mode completion message indicates that the security mode control process is complete. Optionally, the security mode completion message includes information about the first NF, indicating that the security context of the UE and the first NF has been activated.
[0283] S815, the UE sends a third message to the RAN, and the RAN receives the third message from the UE accordingly.
[0284] S816, RAN sends a third message to the first NF, and correspondingly, the first NF receives the third message from RAN.
[0285] S815 and S816 can be referred to S406 and S407 mentioned above, and will not be repeated here.
[0286] Using communication method 400D, the UE can forward information to the NF via the RAN without using the AMF as an anchor point, reducing AMF congestion and achieving data isolation between the UE and each NF. Furthermore, activating the context between the AMF and the UE allows the AMF and UE to obtain a base key. In this case, other NFs can obtain the key from the AMF, deduce an encryption key based on this key, and use it to activate the security context between that NF and the UE. Thus, when the UE needs to communicate with a specific NF, it can request the activation of that NF, allowing that NF to activate its security context with the UE, and then use that security context to encrypt and protect the information's integrity.
[0287] In communication method 400, the AMF requests the RAN to establish or create a connection to at least one NF based on a first message trigger. Alternatively, the AMF can also trigger the RAN to establish or create a connection to at least one NF based on a UE trigger. This will be described below with reference to the accompanying drawings.
[0288] Please see Figure 9 This is a flowchart illustrating the communication method 900 provided in an embodiment of this application. Figure 9 This method is described from the perspective of interaction between AMF, UE, RAN, and the first NF. The processing performed by a single execution entity can also be divided into processing by multiple execution entities, which can be logically and / or physically separated. For example, the processing performed by the access network device can be divided into processing by at least one of CU, DU, RU, etc.
[0289] like Figure 9 As shown, the communication method 900 includes the following steps.
[0290] S901, the AMF sends a fourth message to the UE, and the UE receives the fourth message from the AMF accordingly.
[0291] The fourth message may include information about the first NF, such as the type information and / or identification information of the first NF. Therefore, the UE can identify the NFs with which it has already established a connection based on the fourth message, so that the UE can subsequently specify which NF(s) to send the third message to.
[0292] S902, the UE sends the fifth message to the AMF, and the AMF receives the fifth message from the UE accordingly.
[0293] The fifth message can be used to request the establishment of a connection between the UE and the first NF, where there is no NAS signaling connection between the UE and the first NF. The specific name of the fifth message is not limited in this application embodiment. This fifth message may include information about the first NF, so that the AMF clearly identifies the NF to which the UE needs to establish a connection as the first NF. The information about the first NF may be its identification information or its type information. If the fourth message includes the identification information of the first NF, then the information about the first NF in the fifth message can also be the identification information of the first NF. If the fourth message includes the type information of the first NF, then the information about the first NF in the fifth message can also be the type information of the first NF.
[0294] S903, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0295] S903 can be referred to in the relevant description of S402 above. The difference between the second message in S903 and the second message in S402 is that the second message in S903 may include information about the first NF. The parts of S903 that are repeated from S402 will not be described again.
[0296] S904, RAN sends a first request message to the first NF, which can be used to request the establishment of a connection with the first NF.
[0297] S904 can be referred to in the relevant description of S403 above, and will not be repeated here.
[0298] S905, the first NF sends a first response message to the RAN, which indicates that the connection between the first NF and the RAN has been established.
[0299] S905 can be referred to in the relevant description of S404 mentioned above, and will not be repeated here.
[0300] S906, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0301] S906 can be referred to in the relevant description of S509 mentioned above, and will not be repeated here.
[0302] S907, the AMF sends a sixth message to the UE, and the UE receives the sixth message from the AMF accordingly.
[0303] The sixth message can be a reply to the fifth message, indicating that the connection to the first NF has been established. The sixth message may include information about the first NF. For example, the sixth message may include the type information or the identification information of the first NF.
[0304] S908, the UE sends a third message to the RAN, and the RAN receives the third message from the UE accordingly.
[0305] S909, RAN sends a third message to the first NF, and correspondingly, the first NF receives the third message from RAN.
[0306] S908 and S909 can be referenced from the aforementioned S406 and S407, and will not be repeated here.
[0307] Through communication method 900, the UE can forward information to the NF via the RAN without using the AMF as an anchor point, which reduces AMF congestion and enables data isolation between the UE and each NF. Furthermore, the UE can request to establish a connection with the first NF from the AMF based on actual needs, reducing unnecessary NF connections and saving signaling overhead.
[0308] Communication method 900 can be combined with either of the two schemes mentioned above for activating the security context between the UE and NF. For ease of understanding, the communication method 900 will be further described below with specific examples.
[0309] Example 5: AMF activates a security context between at least one NF and UE.
[0310] Please see Figure 10 The following is a flowchart of the communication method 900A provided in the embodiments of this application. Figure 10 This method is introduced from the perspective of AMF, UE, RAN, and first NF interaction. For example... Figure 10 As shown, the communication method 900A includes the following steps.
[0311] S1001, the UE sends a registration request to the RAN, and the RAN receives the registration request from the UE accordingly.
[0312] S1002, RAN sends a first message to AMF, which includes a NAS message.
[0313] S1003, AMF, and UE complete authentication.
[0314] S1004, AMF selects at least one NF based on the UE's capability information.
[0315] S1005, AMF and UE activate at least one NF and UE security context.
[0316] S1001~S1005 are the same as S501~S505, and will not be described again here.
[0317] S1006, AMF sends a fourth message to UE, and UE receives the fourth message from AMF accordingly.
[0318] For details regarding S1006, please refer to the relevant description in S901 above; it will not be repeated here.
[0319] S1007, the UE sends the fifth message to the AMF, and the AMF receives the fifth message from the UE accordingly.
[0320] S1007 is the same as S902, so it will not be described again here.
[0321] S1008, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0322] S1009, RAN sends a first request message to the first NF, which can be used to request to establish a connection with the first NF.
[0323] S1010, the first NF sends a first response message to the RAN, which indicates that the connection between the first NF and the RAN has been established.
[0324] S1011, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0325] S1012, AMF sends a sixth message to UE, and UE receives the sixth message from AMF accordingly.
[0326] S1013, the UE sends a third message to the RAN, and the RAN receives the third message from the UE accordingly.
[0327] S1014, RAN sends a third message to the first NF, and correspondingly, the first NF receives the third message from RAN.
[0328] S1008~S1014 are the same as S903~S909, and will not be repeated here.
[0329] It should be noted that, in possible implementations, S1001 to S1005 can be executed individually (or only S1001 to S1005 can be executed), without executing S1006 to S1014.
[0330] Example 6: AMF activates the security context between the AMF and the UE.
[0331] The difference between Example 6 and Example 5 is that after authentication between the AMF and the UE, the AMF activates the security context between the AMF and the UE. In this case, when the UE needs to communicate with a certain NF, it can request the activation of that NF. Through this NF, the security context between the UE and the UE can be activated, allowing the UE to encrypt the information to be sent based on this security context, thereby improving security.
[0332] Please see Figure 11 The following is a flowchart illustrating the communication method 900B provided in this application embodiment. Figure 11 This method is introduced from the perspective of AMF, UE, RAN, and first NF interaction. For example... Figure 11 As shown, the communication method 900B includes the following steps.
[0333] S1101, the UE sends a registration request to the RAN, and the RAN receives the registration request from the UE accordingly.
[0334] S1102, RAN sends a first message to AMF, which includes a NAS message.
[0335] S1103, AMF, and UE complete authentication.
[0336] The same applies to S1101~S1103 as S501~S503, so they will not be discussed further here.
[0337] S1104. Activate the security context between AMF and UE.
[0338] S1104 is the same as S804, so it will not be described again here.
[0339] S1105, AMF sends a fourth message to UE, and UE receives the fourth message from AMF accordingly.
[0340] For details regarding S1006, please refer to the relevant description in S901 above; it will not be repeated here.
[0341] S1106, the UE sends the fifth message to the AMF, and the AMF receives the fifth message from the UE accordingly.
[0342] S1106 is the same as S902, so it will not be described again here.
[0343] S1107, AMF sends a second message to RAN, and RAN receives the second message from AMF accordingly.
[0344] S1108, RAN sends a first request message to the first NF, which can be used to request the establishment of a connection with the first NF.
[0345] S1109. The first NF sends a first response message to the RAN, which indicates that the connection between the first NF and the RAN has been established.
[0346] S1110, RAN sends a reply message to AMF, and AMF receives the reply message from RAN accordingly.
[0347] S1111, AMF sends a sixth message to UE, and UE receives the sixth message from AMF accordingly.
[0348] S1107~S1111 are the same as S1008~S1012, and will not be described again here.
[0349] S1112, the UE sends a seventh message to the first NF, which can be used to request the activation of the first NF.
[0350] S1113. The first NF determines the key identifier, which can be used to activate the security context between the UE and the first NF.
[0351] S1114. The first NF sends a security mode command message to the UE, and the UE receives the security mode command message from the first NF.
[0352] S1115, The UE activates the security context between the UE and the first NF based on the key identifier and the information of the first NF.
[0353] S1116, the UE sends a security mode completion message to the first NF, and correspondingly, the first NF receives the security mode completion message from the UE.
[0354] S1112~S1116 are the same as S810~S814, and will not be repeated here.
[0355] S1117, the UE sends a third message to the RAN, and the RAN receives the third message from the UE accordingly.
[0356] S1118, RAN sends a third message to the first NF, and correspondingly, the first NF receives the third message from RAN.
[0357] S1117~S1118 are the same as S908~S909, and will not be repeated here.
[0358] It should be noted that steps S1101 to S1111 are not mandatory. In other words, in communication method 900B, steps S1101 to S1111 can be omitted.
[0359] This application also provides a communication method. This method enables NF-level connection relationships, which helps save resources and improve resource utilization.
[0360] Please see Figure 12 This is a flowchart illustrating the communication method 1200 provided in an embodiment of this application. Figure 12This method is described from the perspective of interaction between the UE, RAN, and the first NF. The processing performed by a single execution entity can also be divided into processing by multiple execution entities, which can be logically and / or physically separated. For example, the processing performed by the access network device can be divided into processing by at least one of the CU, DU, RU, etc.
[0361] like Figure 12 As shown, the communication method 1200 includes the following steps.
[0362] S1201, the first NF sends a release message to the RAN, and correspondingly, the RAN receives the release message from the first NF.
[0363] This release message can be used to request the release of the connection between the UE and the first NF. The release message may include information about the first NF.
[0364] S1202. If the UE is still connected to the second NF, the RAN releases the connection with the first NF.
[0365] If the UE is connected to more than just the first NF, for example, the UE is also connected to a second NF, then when the first NF requests the RAN to release the connection between the UE and the first NF, the RAN can release the connection with the first NF to release unnecessary connections and save resources. Otherwise, S1205 can be executed, meaning that if the UE is only connected to the first NF, when the first NF requests the RAN to release the connection between the UE and the first NF, the RAN can release the UE's RRC connection in addition to releasing the connection with the first NF, to release as many connections as possible and save resources.
[0366] S1203, the RAN sends the first message to the UE, and the UE receives the first message from the RAN accordingly.
[0367] The first message includes information about the first NF (Network Functions) and is used to instruct the UE to release the connection to the first NF. After the RAN releases the connection with the first NF, it can send the first message to the UE to make the UE explicitly aware that the connection with the first NF is broken, thus avoiding the UE sending information to the first NF and wasting signaling. It should be noted that S1202 and S1203 can be a single step.
[0368] S1204, UE records that the first NF is in an idle or inactive state.
[0369] When the connection between the UE and the first NF is released, the UE can record whether the first NF is in an idle state or an inactive state. Therefore, when the UE needs to communicate with the first NF, it can re-establish a connection with the first NF, avoiding the UE sending information to the first NF and thus avoiding the waste of signaling.
[0370] S1205. If the UE is only connected to the first NF, the RAN releases the connection with the first NF and releases the UE's RRC connection.
[0371] S1206, the RAN sends a second message to the UE, and the UE receives the second message from the RAN accordingly.
[0372] When the RAN releases the UE's RRC connection, it can send a second message to the UE, which can be used to instruct the UE to release the connection with the RAN. S1205 and S1206 can be a single step.
[0373] S1207, UE records that all NFs are in an idle or inactive state.
[0374] When the connection between the UE and the RAN is released, the UE can record all NFs in an idle or inactive state. This allows the UE to re-establish a connection with a specific NF when it needs to communicate with that NF, thus avoiding the waste of signaling by sending information to that NF.
[0375] It should be noted that S1202 to S1204 are executed, while S1205 to S1207 are not executed; or, S1205 to S1207 are executed, while S1202 to S1204 are not executed. Figure 12 Taking this as an example, and considering that 1205 to S1207 are not executed, the following is illustrated with dashed lines.
[0376] Optionally, NF is not allowed to initiate connection release; only RRC connection release is allowed.
[0377] Optionally, when an NF initiates a connection release, the RAN can release the connections of all associated NFs.
[0378] In the embodiments provided above, the methods provided by the embodiments of this application are described using terminal devices, access network devices, first network elements, and first NFs as examples. In this application, each embodiment can be implemented independently or in combination based on certain inherent connections; in each embodiment, different implementation methods can be implemented in combination or independently. To achieve the functions in the methods provided by the embodiments of this application above, the steps executed by each executing entity can be implemented by the executing entity itself, or by a functional entity including the executing entity, or by different functional entities constituting the executing entity. For example, the steps executed by the access network device can be implemented by the network device itself, or by different functional entities constituting the access network device, or by a functional entity including the access network device. For example, the network access network is an access network device, which can be a CU-DU-RU architecture, where the DU can generate a first message and the RU can send a first message. To achieve the functions in the methods provided by the embodiments of this application above, the terminal device and the network device can include hardware structures and / or software modules, implementing the above functions in the form of hardware structures, software modules, or hardware structures plus software modules. Whether a particular function among the above functions is executed through hardware structure, software module, or a combination of hardware structure and software module depends on the specific application and design constraints of the technical solution.
[0379] Based on the same inventive concept as the method embodiments, this application provides a communication device. The communication device used to implement the above method in the embodiments of this application is described below with reference to the accompanying drawings. The content above can be used in subsequent embodiments, and repeated content will not be repeated.
[0380] Figure 13 This is a schematic block diagram of a communication device 1300 provided in an embodiment of this application. The communication device 1300 can correspondingly implement the functions or steps implemented by the terminal device in the various method embodiments described above. For example, the communication device 1300 may be... Figure 1 The communication device 1300 can be a UE; or, the communication device 1300 can be a chip (system) in the UE; or, the communication device 1300 can be a software module of the UE. Alternatively, the communication device 1300 can correspondingly implement the functions or steps implemented by the access network device in the above-described method embodiments. For example, the communication device 1300 can be... Figure 1 The communication device 1300 can be a RAN (Radio Interconnect); or, it can be a chip (system) within the RAN; or, it can be a software module of the RAN. Alternatively, the communication device 1300 can correspondingly implement the functions or steps implemented by the first network element in the above method embodiments. For example, the communication device 1300 can be... Figure 1The communication device 1300 can be an AMF (Application Function); or, the communication device 1300 can be a chip (system) within the AMF; or, the communication device 1300 can be a software module of the AMF. Alternatively, the communication device 1300 can correspondingly implement the functions or steps implemented by the first NF in the above-described method embodiments. For example, the communication device 1300 can be... Figure 1 The communication device 1300 is either an SMF (system) within the SMF, or a software module of the SMF.
[0381] The communication device 1300 may include a processing module 1310 and a transceiver module 1320. Optionally, it may also include a storage module, which can be used to store instructions (code or program) and / or data. This storage module may be, for example, a memory. The processing module 1310 and the transceiver module 1320 may be coupled to the storage module. For example, the processing module 1310 can read instructions (code or program) and / or data from the storage module to implement a corresponding method. When the communication device 1300 is a chip in a terminal device, the storage module may be an internal storage module within the chip, such as a register or cache. For example, the storage module may also be an external storage module within the terminal device, such as a read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions, such as random access memory (RAM). The above-mentioned units may be set independently or partially or completely integrated.
[0382] Processing module 1310 may be a processor or controller, such as a general-purpose central processing unit (CPU), a general-purpose processor, a digital signal processing unit (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc. Transceiver module 1320 is a transceiver, interface circuit, bus, pin, or other possible communication interface for receiving signals from other devices. For example, when the device is implemented as a chip, transceiver module 1320 is an interface circuit for the chip to receive signals from other chips or devices, or an interface circuit for the chip to send signals to other chips or devices.
[0383] In one implementation, the communication device 1300 can correspondingly implement the behavior and functions of the RAN in the above method embodiments. The communication device 1300 can be an access network device, a component (e.g., a chip or circuit) within the access network device, a part of a chip or chipset within the access network device used to execute the relevant method functions, or a software module within the access network device capable of implementing the above communication method; no limitation is imposed. For details, please refer to the relevant content of the foregoing method embodiments, which will not be repeated here.
[0384] For example, transceiver module 1320 is used to send a first message to a first network element, receive a second message from the first network element, and send a first request message to a first NF. The first message includes a NAS message. The second message is used to request communication device 1300 to establish a connection with at least one NF. The second message includes identification information or type information of at least one NF. The first request message includes a first identifier and identification information of the terminal device, used to request to establish a connection with the first NF. The first identifier is a unique identifier assigned by communication device 1300 to the terminal device. The first NF belongs to at least one NF.
[0385] As an optional implementation, the NAS message includes information about the NF (Network Functions), and there can be multiple NFs. This NAS message is used to request the establishment of a connection between the terminal device and the NF. The NF information includes NF type information or NF identification information.
[0386] As an optional implementation, the first message also includes the terminal device's identification information and a first identifier.
[0387] As an optional implementation, the transceiver module 1320 is also configured to receive a first response message from the first NF, the first response message including a first identifier and a second identifier. The second identifier is a unique identifier assigned by the first NF to the terminal device. The first response message is used to indicate that the connection between the first NF and the communication device 1300 has been established.
[0388] As an optional implementation, the second message also includes a first identifier and a third identifier, wherein the third identifier is a unique identifier assigned by the first network element to the terminal device.
[0389] As an optional implementation, the transceiver module 1320 is also used to receive a third message from the terminal device and send the third message to the first NF, the third message being used to indicate the identifier of the first NF or the type of the first NF.
[0390] As an optional implementation, before sending the third message to the first NF, the transceiver module 1320 is also used to determine the first identifier based on the identification information of the terminal device, determine the second identifier based on the first identifier and the information of the first NF, and then determine the first NF based on the second identifier.
[0391] For example, transceiver module 1320 is used to receive a release message from a first NF, which requests the release of the connection between the terminal device and the first NF. Processing module 1310 is used to release the connection between communication device 1300 and the first NF if the terminal device is still connected to a second NF. Transceiver module 1320 is also used to send a first message to the terminal device, which includes information about the first NF, to indicate that the connection from the terminal device to the first NF is being released.
[0392] As an optional implementation, processing module 1310 is further configured to release the connection between the first NF and the wireless access network, and release the RRC connection of the terminal device, if the terminal device is only connected to the first NF. Transceiver module 1320 is further configured to send a second message to the terminal device, the second message being used to instruct the terminal device to release the connection with communication device 1300.
[0393] As an optional implementation, the information of the first NF includes the type information of the first NF or the identification information of the first NF.
[0394] In one implementation, the communication device 1300 can correspondingly implement the behavior and functions of the communication device 1300 / AMF in the above method embodiments. The communication device 1300 can be a communication device 1300, a component (e.g., a chip or circuit) within the communication device 1300, a part of a chip or chipset within the communication device 1300 used to execute the relevant method functions, or a software module within the communication device 1300 capable of implementing the above communication method; no limitation is imposed. For details, please refer to the relevant content of the foregoing method embodiments, which will not be repeated here.
[0395] For example, transceiver module 1320 is used to receive a first message and, in response to the first message, send a second message to the access network device. The first message includes a NAS message. The second message is used to request the access network device to establish a connection with at least one NF, and the second message includes identification information or type information of at least one NF.
[0396] As an optional implementation, the NAS message includes information about the NF (Network Functions). The NAS message is used to request the establishment of a connection between the terminal device and the NF. The NF information includes either the NF's type information or its identification information.
[0397] As an optional implementation, the first message also includes the terminal device's identification information and a first identifier, which is a unique identifier assigned to the terminal device by the access network device.
[0398] As an optional implementation, the second message may also include a first identifier and / or a third identifier, the third identifier being a unique identifier assigned by the communication device 1300 to the terminal device.
[0399] As an optional implementation, the transceiver module 1320 is also used to send a fourth message to the terminal device, the fourth message including NF type information, used to indicate that the NF corresponding to the type information has established a connection with the terminal device. Alternatively,
[0400] As an optional implementation, the transceiver module 1320 is also used to send a fourth message to the terminal device, the fourth message including the identification information of the NF, which is used to indicate that the NF has established a connection with the terminal device.
[0401] As an optional implementation, before sending the second message to the access network device in response to the first message, the transceiver module 1320 is further configured to send a security mode command message to the terminal device and receive a security mode completion message from the terminal device. The security mode command message includes a key identifier and information about at least one NF (Network Function), used to activate the security context of the terminal device to at least one NF. The security mode completion message indicates that the security mode control process has been completed.
[0402] As an optional implementation, the security mode completion message includes information about the first NF, indicating that the security context of the terminal device and the first NF is activated.
[0403] As an optional implementation, the security mode command message includes information about the security algorithm between the terminal device and each NF.
[0404] In one implementation, the communication device 1300 can correspondingly implement the behavior and functions of the UE in the above method embodiments. The communication device 1300 can be the UE, a component within the UE (e.g., a chip or circuit), a part of a chip or chipset within the UE used to execute the relevant method functions, or a software module within the UE capable of implementing the above communication method; there are no limitations. For details, please refer to the relevant content of the foregoing method embodiments, which will not be repeated here.
[0405] For example, transceiver module 1320 is used to send a fifth message to the first network element, which includes information about the first NF and is used to request the establishment of a connection between communication device 1300 and the first NF. Here, communication device 1300 and the first NF do not have a NAS signaling connection.
[0406] As an optional implementation, the transceiver module 1320 is also used to receive a sixth message from the first network element, which includes information about the first NF and is used to indicate that the first NF has completed the connection establishment.
[0407] As an optional implementation, the information of the first NF includes the identification information of the first NF or the type information of the first NF.
[0408] As an optional implementation, before sending the fifth message to the first network element, the transceiver module 1320 is also used to receive a fourth message from the first network element, the fourth message including information of at least one NF, and the at least one NF including the first NF.
[0409] As an optional implementation, before receiving the fourth message from the first network element, the transceiver module 1320 is also configured to receive a security mode command message from the first network element and send a security mode completion message to the first network element. The security mode command message includes a key identifier and information about at least one NF (Network Function), used to activate the security context of the communication device 1300 to at least one NF. The security mode completion message indicates that the security mode control process has been completed.
[0410] As an optional implementation, the security mode completion message includes information about the first NF, indicating that the security context of the communication device 1300 and the first NF is activated.
[0411] As an optional implementation, the security mode command message includes information about the security algorithm between the communication device 1300 and each NF.
[0412] For example, the transceiver module 1320 is used to send a seventh message to the first NF, receive a security mode command message sent by the first NF, and activate the security context between the communication device 1300 and the first NF based on the information of the first NF. The seventh message is used to request the activation of the first NF. The security mode command message includes a key identifier and information about the first NF, and is used to activate the security context between the communication device 1300 and the first NF.
[0413] As an optional implementation, the security mode command message includes a security algorithm from the communication device 1300 to the first NF.
[0414] As an optional implementation, the transceiver module 1320 is also used to send a security mode completion message to the first network element, which indicates that the security mode control process has been completed.
[0415] As an optional implementation, the security mode completion message includes information about the first NF, indicating that the security context of the communication device 1300 and the first NF is activated.
[0416] For example, transceiver module 132 is used to receive a first message from the access network device. The first message includes identification information or type information of the first NF, used to indicate that the connection from communication device 1300 to the first NF is released. Processing module 1310 is used to record, based on the first message, that the first NF is in an idle state.
[0417] For example, transceiver module 132 is used to receive a second message from the access network device, the second message indicating that the connection from communication device 1300 to the access network device is released. Processing module 1310 is used to record all NFs in an idle state according to the second message.
[0418] In one implementation, the communication device 1300 can correspondingly implement the behavior and function of the first NF in the above method embodiments. The communication device 1300 can be the first NF, a component (e.g., a chip or circuit) within the first NF, a part of a chip or chipset within the first NF used to perform the relevant method function, or a software module within the first NF capable of implementing the above communication method; there are no limitations. For details, please refer to the relevant content of the foregoing method embodiments, which will not be repeated here.
[0419] For example, transceiver module 1320 is used to receive a seventh message from the terminal device and send a security mode command message to the terminal device. The seventh message is used to request activation of communication device 1300. The security mode command message includes a key identifier and information about communication device 1300, and is used to activate the security context between the terminal device and communication device 1300.
[0420] In one implementation, the security mode command message includes a security algorithm from the terminal device to the communication device 1300.
[0421] When the communication device 1300 is a chip-based device or circuit, the transceiver module can be an input / output circuit and / or a communication interface; the processing module is an integrated processor, microprocessor, or integrated circuit.
[0422] Figure 14 This is a schematic block diagram of a communication device 1400 provided in an embodiment of this application. The communication device 1400 can be a UE, RAN device, AMF, or a first NF (e.g., SMF) as described in the above embodiments. For example, the communication device 1400 can be... Figure 1 The UE or the chip (system) within the UE. For example, the communication device 1400 could be... Figure 1 The RAN equipment or the chip (system) within the RAN equipment. For example, the communication device 1400 could be... Figure 1 The AMF or the chip (system) within the AMF. For example, the communication device 1400 could be... Figure 1 In this application embodiment, the chip system may be composed of chips or may include chips and other discrete devices. For specific functions, please refer to the description in the above method embodiments.
[0423] The communication device 1400 includes one or more processors 1401 for implementing or supporting the communication device 1400 in implementing the functions of the UE, RAN device, AMF, or first NF in the methods provided in the embodiments of this application. For details, please refer to the detailed description in the method examples, which will not be repeated here. The processor 1401 can also be called a processing unit or processing module, and can implement certain control functions. The processor 1401 can be a general-purpose processor or a dedicated processor, etc. For example, it includes: a baseband processor, a central processing unit, an application processor, a modem processor, a graphics processor, an image signal processor, a digital signal processor, a video codec processor, a controller, a memory, and / or a neural network processor, etc. The baseband processor can be used to process communication protocols and communication data. The central processing unit can be used to control the communication device 1400 (e.g., a terminal device or a network device), execute software programs, and / or process data. Different processors can be independent devices or integrated into one or more processors, for example, integrated on one or more application-specific integrated circuits.
[0424] In one design, processor 1401 may include program 1403 (sometimes also referred to as code or instructions), which can be executed on processor 1401 to cause communication device 1400 to perform the methods described in the embodiments below. In yet another possible design, communication device 1400 includes circuitry (…). Figure 14 (Not shown), the circuit is used to implement the functions of the UE, RAN device, AMF or first NF in the above embodiments.
[0425] In one design, the communication device 1400 may include one or more memories 1402 storing a program 1404 (sometimes referred to as code or instructions), which can be run on the processor 1401 to cause the communication device 1400 to perform the methods described in the above method embodiments.
[0426] In one design, the processor 1401 and / or memory 1402 may include an artificial intelligence (AI) module 1407 and an AI module 1408, which are used to implement AI-related functions. The AI modules can be implemented through software, hardware, or a combination of both. For example, the AI module may include a RAN intelligent controller (RIC) module. For example, the AI module may be a near real-time RIC or a non-real-time RIC.
[0427] In one possible design, the processor 1401 and / or memory 1402 may also store data. The processor and memory may be configured separately or integrated together.
[0428] In one possible design, when the communication device 1400 is a UE or RAN device, it may further include a transceiver 1405 and / or an antenna 1406. The processor 1401, sometimes referred to as a processing unit, controls the communication device 1400. The transceiver 1405, sometimes referred to as a transceiver unit, transceiver, transceiver circuit, or simply a transceiver, is used to implement the transmission and reception functions of the communication device 1400 via the antenna 1406.
[0429] In one possible design, the communication device 1400 may further include one or more of the following components: a wireless communication module, an audio module, an external memory interface, internal memory, a universal serial bus (USB) interface, a power management module, an antenna, a speaker, a microphone, an input / output module, a sensor module, a motor, a camera, or a display screen, etc. It is understood that in some embodiments, the communication device 1400 may include more or fewer components, or some components may be integrated, or some components may be separated. These components may be implemented in hardware, software, or a combination of software and hardware.
[0430] The communication device in the above embodiments can be a UE, RAN device, AMF, or first NF, or it can be a circuit, a chip applied in the UE, RAN device, AMF, or first NF, or other combined devices or components having the aforementioned UE, RAN device, AMF, or first NF. When the communication device is a UE or RAN device, the transceiver module can be a transceiver, which may include an antenna and radio frequency circuits, etc., and the processing module can be a processor, such as a CPU. When the communication device is a chip system, the communication device can be an FPGA, a dedicated ASIC, a SoC, a CPU, a network processor (NP), a DSP, a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips. The processing module can be the processor of the chip system. The transceiver module or communication interface can be the input / output interface or interface circuit of the chip system. For example, the interface circuit can be a code / data read / write interface circuit. The interface circuit can be used to receive code instructions (the code instructions are stored in memory and can be read directly from memory or through other devices) and transmit them to the processor; the processor can then execute the code instructions to perform the methods described in the above method embodiments. Alternatively, the interface circuit can also be a signal transmission interface circuit between a communication processor and a transceiver.
[0431] This application also provides a communication system, which includes at least one terminal device, at least one RAN device, a first network element, and a first NF. The terminal device, RAN device, first network element, and first NF are devices used to implement the functions related to the above-described communication method.
[0432] This application also provides a computer-readable storage medium including instructions that, when run on a computer, cause the computer to perform the method executed by the UE, RAN device, AMF, or first NF in the above-described communication method.
[0433] This application also provides a computer program product, including computer program code, which, when executed, causes a computer to perform the method executed by the UE, RAN device, AMF, or first NF in the above-described communication method.
[0434] This application provides a chip system including a processor and potentially a memory, for implementing the functions of the UE, RAN device, AMF, or first NF in the aforementioned communication method. The chip system can be composed of a chip or may include chips and other discrete components.
[0435] To achieve the above Figures 13-14 In addition to the functions of the communication device, this application also provides a chip, including a processor, for supporting the communication device in implementing the functions involved in the UE, RAN device, AMF, or first NF in the above method embodiments. In one possible design, the chip is connected to a memory or the chip includes a memory for storing computer programs or instructions and data necessary for the communication device.
[0436] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0437] Those skilled in the art will recognize that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0438] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0439] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0440] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0441] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the essential contributing part of the technical solution of this application, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, external hard drives, ROM, RAM, magnetic disks, or optical disks.
[0442] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A communication method characterized by comprising: Comprising: sending a first message to a first network element, the first message comprising a non-access stratum (NAS) message; receiving a second message from the first network element, the second message being used to request an access network device to establish a connection between the access network device and at least one network function (NF), the second message comprising identification information of the at least one NF or type information of the at least one NF; sending a first request message to a first NF, the first request message comprising a first identifier and identification information of a terminal device, the first identifier being a unique identifier allocated to the terminal device by the access network device, the first NF belonging to the at least one NF, the first request message being used to request the first NF to establish a connection with the terminal device.
2. The method of claim 1, wherein, The NAS message comprises information of an NF, the NAS message being used to request to establish a connection between a terminal device and the NF, the information of the NF comprising type information of the NF or identification information of the NF.
3. The method of claim 1 or 2, wherein, The first message further comprises identification information of the terminal device and the first identifier.
4. The method of any one of claims 1-3, wherein, The method further comprises: receiving a first response message from the first NF, the first response message comprising the first identifier and a second identifier, the second identifier being a unique identifier allocated to the terminal device by the first NF, the first response message being used to indicate that the connection between the first NF and the access network device is established.
5. The method of any one of claims 1-4, wherein, The second message further comprises the first identifier and a third identifier, the third identifier being a unique identifier allocated to the terminal device by the first network element.
6. The method of any one of claims 1-5, wherein, The method further comprises: receiving a third message from the terminal device, the third message being used to indicate the identification of the first NF or the type of the first NF; sending the third message to the first NF.
7. The method of claim 6, wherein, When the third message is used to indicate the type of the first NF, the method further comprises, before sending the third message to the first NF: determining the first identifier according to the identification information of the terminal device; determining the second identifier according to the first identifier and the information of the first NF; determining the first NF according to the second identifier.
8. A communication method characterized by comprising: Comprising: receiving a first message, the first message comprising a non-access stratum (NAS) message; sending a second message to an access network device in response to the first message, the second message being used to request the access network device to establish a connection between the access network device and at least one network function (NF), the second message comprising identification information of the at least one NF or type information of the at least one NF.
9. The method of claim 8, wherein, The NAS message comprises information of an NF, the NAS message being used to request to establish a connection between a terminal device and the NF, the information of the NF comprising type information of the NF or identification information of the NF.
10. The method of claim 8, wherein, The first message further comprises identification information of the terminal device and a first identifier, the first identifier being a unique identifier allocated to the terminal device by the access network device.
11. The method of any one of claims 8-10, wherein, The second message further comprises the first identifier and / or a third identifier, the third identifier being a unique identifier allocated to the terminal device by the first network element.
12. The method of any one of claims 9-11, wherein, The method further comprises: sending a fourth message to the terminal device, the fourth message comprising type information of the NF, the type information being used to indicate that the NF corresponding to the type information has already established a connection with the terminal device; or sending a fourth message to the terminal device, the fourth message comprising identification information of the NF, the identification information being used to indicate that the NF has already established a connection with the terminal device.
13. The method of any one of claims 9-12, wherein, Before sending the second message to the access network device in response to the first message, the method further comprises: sending a security mode command message to the terminal device, the security mode command message comprising key identification and information of the at least one NF, the information being used to activate a security context of the terminal device to the at least one NF; receiving a security mode complete message from the terminal device, the security mode complete message being used to indicate that a security mode control procedure is completed.
14. The method of claim 13, wherein, The security mode complete message comprises information of the first NF, the information being used to indicate that the security context of the terminal device to the first NF is activated.
15. The method of claim 13 or 14, wherein, The security mode command message comprises information of security algorithms between the terminal device and each NF.
16. A method of communication, comprising: Comprising: sending a fifth message to a first network element, the fifth message comprising information of a first network function (NF), the information being used to request to establish a connection between a terminal device and the first NF, the terminal device and the first NF not having a non-access stratum (NAS) signaling connection.
17. The method of claim 16, wherein, The method further comprises: receiving a sixth message from the first network element, the sixth message comprising information of the first NF, the information being used to indicate that the first NF completes the establishment of the connection.
18. The method of claim 16 or 17, wherein, The information of the first NF comprises identification information of the first NF or type information of the first NF.
19. The method of any one of claims 16-18, wherein, Before sending the fifth message to the first network element, the method further comprises: receiving a fourth message from the first network element, the fourth message comprising information of at least one NF, the at least one NF comprising the first NF.
20. The method of claim 19, wherein, Before receiving the fourth message from the first network element, the method further comprises: receiving a security mode command message from the first network element, the security mode command message comprising key identification and information of the at least one NF, the information being used to activate a security context of the terminal device to the at least one NF; sending a security mode complete message to the first network element, the security mode complete message being used to indicate that a security mode control procedure is completed.
21. The method of claim 20, wherein, The security mode complete message comprises information of the first NF, the information being used to indicate that the security context of the terminal device to the first NF is activated.
22. A method of communication, comprising: Comprising: receiving a security mode command message sent by the first network element, the security mode command message comprising key identification, the key identification being used to activate a security context between a terminal device and a first NF; activating the security context between the terminal device and the first NF based on information of the first NF.
23. The method of claim 22, wherein, The security mode command message further comprises the information of the first NF.
24. The method of claim 23, wherein, The information of the first NF comprises type information of the first NF.
25. The method of claim 23 or 24, wherein, The method further comprises: sending a security mode complete message to the first network element, the security mode complete message being used to indicate that a security mode control procedure is completed.
26. The method of any one of claims 23-25, wherein, The security mode complete message includes information of the first NF, used to indicate that the security context of the terminal device and the first NF is activated.
27. A communications device, characterized by comprising means for performing the method of any one of claims 1-7, or comprising means for performing the method of any one of claims 8-15, or comprising means for performing the method of any one of claims 16-21, or comprising means for performing the method of any one of claims 22-26.
28. A computer-readable storage medium, characterized in that, The computer readable storage medium is configured to store a computer program, which, when executed on a computer, causes the method of any one of claims 1-7 to be performed, or causes the method of any one of claims 8-15 to be performed, or causes the method of any one of claims 16-21 to be performed, or causes the method of any one of claims 22-26 to be performed.
29. A computer program product, characterised in that, The computer program product comprises a computer program, which, when executed on a computer, causes the method of any one of claims 1-7 to be performed, or causes the method of any one of claims 8-15 to be performed, or causes the method of any one of claims 16-21 to be performed, or causes the method of any one of claims 22-26 to be performed.