Reporting session s-nssai to DN-AAA server
By reporting S-NSSAI to the DN-AAA server via SMF, the solution addresses the lack of network slice information in existing systems, enabling accurate authentication and accounting for PDU sessions.
Patent Information
- Application Number
- JP2025133169
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2020-12-31
- Filing Date
- 2025-08-08
- Publication Date
- 2025-11-18
AI Technical Summary
Existing solutions fail to provide network slice-specific authentication and authorization for PDU sessions, as the NSS-AAA server cannot separate the N6 network based on S-NSSAI, and 3GPP Stage 3 specifications do not specify the 'slice' attribute in Radius authentication and accounting messages, leading to the DN-AAA server lacking network slice information for authentication and accounting statistics.
The Session Management Function (SMF) reports S-NSSAI associated with PDU sessions to the DN-AAA server through access and accounting request messages, using vendor-specific attributes like 3GPP-Session-S-NSSAI and 3GPP-Session-Id, enabling the DN-AAA server to obtain network slice information for authentication and statistics.
The solution allows the DN-AAA server to accurately authenticate and perform network slice-related statistics by receiving S-NSSAI information, ensuring correct network slice-related accounting and authentication processes.
Smart Images

Figure 2025170285000001_ABST
Abstract
Description
[Technical Field]
[0001] Embodiments herein relate generally to the field of communications, and more particularly, embodiments herein relate to reporting Single Network Slice Selection Assistance Information (S-NSSAI) associated with a Protocol Data Unit (PDU) session to a Data Network Authentication, Authorization, and Accounting (DN-AAA) server. [Background technology]
[0002] Although the network slice-specific authentication and authorization (NSS-AAA) server may obtain S-NSSAI information during a network slice access authentication request, this solution requires the user equipment (UE), authentication management function (AMF), network slice-specific authentication and authorization function (NSSAAF), and NSS-AAA server all to support the network slice-specific authentication and authorization (NSSAA) feature, and also requires optional UE subscription data with one or more S-NSSAIs according to the network slice-specific authentication specified in the 3GPP Stage 2 specifications. Meanwhile, since the NSSAA feature is not applicable to the PDU session and accounting functions in Stage 2, Stage 3 TS29.561 specifies that PDU session and accounting request / response messages are not applicable to interacting with the NSS-AAA server. That is, while the NSSAA feature solution notifies the Remote Authentication Dial-In User Service (RADIUS) server which slice is allocated for each session, it cannot separate the N6 network based on the S-NSSAI.
[0003] References: 1. 3GPP TS29.561 V17.0.0 2. 3GPP TS23.501 V16.7.0 Summary of the Invention
[0004] In view of the above deficiencies in the prior art, embodiments herein propose a solution for a Session Management Function (SMF) to report S-NSSAIs related to PDU sessions for Radius or Diameter authentication and accounting requests to a DN-AAA server.
[0005] In one embodiment, a first method is proposed, which is implemented by a first network function implementing a DN-AAA server. In one embodiment, the method may include receiving a request message from a second network function, the request message including network slice-related information for a PDU session. Further, the request message may be an access request message for authentication based on at least the network slice-related information, or an accounting request message indicating that the PDU session has started.
[0006] In another embodiment, a first network function implementing a DN-AAA server is proposed, which may comprise at least one processor and a non-transitory computer-readable medium coupled to the at least one processor. In one embodiment, the non-transitory computer-readable medium may include instructions executable by the at least one processor, whereby the at least one processor is configured to perform a first method.
[0007] In yet another embodiment, a second method is proposed, which is implemented by a second network function implementing SMF or a combined SMF+PGW-C. In one embodiment, the method may include sending a request message including network slice-related information for the PDU session to a first network function implementing a DN-AAA server. Further, the request message may be an access request message for authentication based on at least the network slice-related information, or an accounting request message indicating that the PDU session has started.
[0008] In yet another embodiment, a second network function implementing the SMF or combined SMF+PGW-C is proposed, which may comprise at least one processor and a non-transitory computer-readable medium coupled to the at least one processor. In one embodiment, the non-transitory computer-readable medium may include instructions executable by the at least one processor, whereby the at least one processor is configured to perform the second method.
[0009] In yet another embodiment, a computer readable medium is proposed which may comprise computer readable code which, when run on a device, causes the device to perform any of the above methods.
[0010] In yet another embodiment, a computer program product is proposed which may comprise computer readable code which, when run on a device, causes the device to perform any of the methods described above.
[0011] In an embodiment herein, the DN-AAA server can know network slice information related to a session for authentication and statistics based on the received session S-NSSAI information.
[0012] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate various embodiments of the present disclosure and, together with the description, serve to further explain the principles of the disclosure and to enable those skilled in the art to make and use the embodiments disclosed herein. In the drawings, like reference numbers indicate equivalent or functionally similar elements. [Brief explanation of the drawings]
[0013] [Figure 1] 1 is a schematic block diagram illustrating an exemplary communication system in which embodiments herein may be implemented. [Figure 2] 10 is a schematic signaling chart showing messages during reporting of session S-NSSAI. [Figure 3]1 is a schematic flow chart illustrating an exemplary method in a first network function (such as a DN-AAA server), according to embodiments herein. [Figure 4] 10 is a schematic flowchart illustrating an exemplary method in a second network function (such as an SMF or a combined SMF+PGW-C), according to embodiments herein. [Figure 5] 1 is a schematic block diagram illustrating an example network function that may be configured as a first network function or a second network function, according to embodiments herein. [Figure 6] FIG. 1 is a schematic block diagram illustrating an exemplary computer-implemented device, according to embodiments herein. DETAILED DESCRIPTION OF THE INVENTION
[0014] Embodiments of the present specification are described in detail below with reference to the accompanying drawings, in which the embodiments are shown. However, these embodiments of the present specification may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Elements of the drawings are not necessarily to scale relative to each other.
[0015] A reference to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described with respect to that embodiment is included in at least one embodiment. Thus, the appearances of the phrase "in one embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment.
[0016] The term "A, B, or C" as used herein means "A" or "B" or "C", the term "A, B, and C" as used herein means "A" and "B" and "C", and the term "A, B, and / or C" as used herein means "A", "B", "C", "A and B", "A and C", "B and C" or "A, B, and C".
[0017] The prior art solution in which the NSS-AAF reports the S-NSSAI to the NSS-AAA while informing the Radius server which slice is allocated for each of the sessions cannot meet the requirement to separate the N6 network based on the S-NSSAI.
[0018] On the other hand, 3GPP TS29.561 does not specify the "slice" attribute in the Radius authentication and accounting (start, intermediate, stop) messages that interact with the DN-AAA server. Therefore, the DN-AAA server, which handles both authentication, authorization, and accounting, does not know the network slice information associated with the PDU session for authentication and accounting statistics.
[0019] In view of the above problems and deficiencies in the prior art, the embodiments herein propose that the SMF sends an S-NSSAI associated with a PDU session to the DN-AAA server.
[0020] FIG. 1 is a schematic block diagram illustrating an exemplary communication system 100 in which embodiments herein may be implemented.
[0021] In one embodiment, an application scenario of the embodiments herein may occur in a 5G system, as shown in Figure 1. The communication system 100 may include, but is not limited to, a first network function 101 and a second network function 102. In one embodiment, the first network function 101 may be configured as a DN-AAA server. In one embodiment, the second network function 102 may be configured as an SMF.
[0022] It should be noted that if the DN-AAA server 101 located in the 5G Core (5GC) or in an external packet data network (PDN) is directly reachable, the SMF 102 may communicate with the DN-AAA server 101 directly without involving the User Plane Function (UPF) 104, which is applicable to all message flows over the N6 interface in the following embodiments.
[0023] It should be understood that a network function may be implemented either as a network element on dedicated hardware, as a software instance running on dedicated hardware, or as a virtualized function instantiated on a suitable platform, for example, on a cloud infrastructure.
[0024] It should be understood that application scenarios of the embodiments herein may also occur in other current communication systems, such as 4G systems or EPC or future communication systems, where the network functions may have the same or similar functions as the above network functions in 5GS. For example, in a 4G system, the second network function 102 may also be configured as a combined SMF+PGW-C.
[0025] For simplicity, the embodiments herein are based on the 5G architecture, but are also applicable to the 4G (EPC) architecture.
[0026] FIG. 2 is a schematic signaling chart showing messages during reporting of session S-NSSAI.
[0027] In one embodiment, when the SMF 102 obtains the S-NSSAI from the AMF 103, the SMF 102 may report this S-NSSAI to the DN-AAA server 101 (i.e., the authentication, authorization, and accounting server). In one embodiment, as shown in Figure 2, the reporting procedure may involve the following steps:
[0028] Step 1: The UE 105 may initiate a PDU session establishment procedure by including authentication / authorization information.
[0029] Step 2: The AMF 103 may send an Nsmf_PDUSession_CreateSMContext request message including authentication / authorization information to the SMF 102, and the SMF 102 may respond with a service operation.
[0030] In one embodiment, the AMF 103 may send an Nsmf_PDUSession_CreateSMContext request message with the S-NSSAI.
[0031] Step 3: The SMF 102 may send the access-request message to the DN-AAA server 101. For example, the message may be forwarded from the SMF 102 to the DN-AAA server 101 by the UPF 104 in an N4 user plane message. Note that the SMF 102 may send the access-request message directly to the DN-AAA server 101 without the UPF 104. Note that network name (DNN) information may also be included in the access-request message.
[0032] In one embodiment, the SMF 102 may send the 3GPP-Session-S-NSSAI and / or a separate PDU session ID (e.g., 3GPP-Session-Id) in an Access Request message to the DN-AAA Server 101. For example, the SMF 102 may send the S-NSSAI associated with the PDU session in a 3GPP-Session-S-NSSAI Vendor-Specific-Attribute (VSA) to the DN-AAA Server 101.
[0033] In one embodiment, the access request message is a Radius access request message. In one embodiment, the S-NSSAI may be indicated by a 3GPP session S-NSSAI.
[0034] For example, an example of the VSA "3GPP-Session-S-NSSAI" and / or "3GPP-Session-Id" in the Radius Access Request message is shown in Table 1. TIFF2025170285000002.tif17170
[0035] For example, example sub-attributes of the VSA "3GPP-Session-S-NSSAI" and / or "3GPP-Session-Id" in a Radius Access Request message are shown in Table 2. TIFF2025170285000003.tif76170
[0036] For example, an example of an attribute-value pair (AVP) for the VSA “3GPP-Session-S-NSSAI” and / or “3GPP-Session-Id” in a Radius Access Request message reused from the N6 interface is shown in Table 3. TIFF2025170285000004.tif70170
[0037] For example, exemplary contents of the VSA "3GPP-Session-S-NSSAI" and / or "3GPP-Session-Id" in a Radius Access Request message are shown in Table 4-1 and Table 4-2. TIFF2025170285000005.tif54170TIFF2025170285000006.tif48170TIFF2025170285000007.tif37170
[0038] Length: 4 or 7
[0039] PduSessionId: 1-octet integer, an unsigned integer in the range 0 to 255, identifying the PDU session, as specified in subclause 5.4.2 of 3GPP TS 29.571
[46] .
[0040] SST: Slice / service type with value range 0 to 255.
[0041] SD: A 3-octet string representing the slice differentiator. The encoding follows the SD attribute specified in subclause 5.4.4.2 of 3GPP TS29.571
[46] . Its presence depends on the length field.
[0042] The SD may be sent from the SMF 102 to the DN-AAA server 101 to indicate the S-NSSAI associated with the PDU session.
[0043] As shown in Table 4-1 above, in one embodiment, the Session-S-NSSAI (such as 3GPP-Session-S-NSSAI) may further include information indicating at least one of a PDU Session ID, a Slice / Service Type (SST), and a slice differentiator of the network slice. In one embodiment, the PDU Session ID and SST shall be presented in the specified 3GPP-Session-S-NSSAI, and the slice differentiator is optional.
[0044] As shown in Table 4-2 above, in one embodiment, the PDU Session ID may be sent via a separate 3GPP-Session-Id.
[0045] Note that in another embodiment, the S-NSSAI may be indicated by another VSA that contains the S-NSSAI.
[0046] In one embodiment, the S-NSSAI may be indicated by another VSA that contains the S-NSSAI, for example, the VSA "200 - 3GPP-S-NSSAI" may be reused to indicate the S-NSSAI.
[0047] For example, exemplary contents of the VSA "3GPP-S-NSSAI" in the Radius Access Request message are shown in Table 5. TIFF2025170285000008.tif43170
[0048] Length: 3 or 6
[0049] SST: Slice / service type with value range 0 to 255.
[0050] SD: A 3-octet string representing a slice differentiator. The encoding follows the sd attribute specified in subclause 5.4.4.2 of 3GPP TS 29.571
[46] . Its presence depends on the length field.
[0051] In one embodiment, for the diameter protocol, the access-request message in step 3 may be adapted as a Diameter Authentication and Authorization Request (AAR) message or a Diameter Extensible Authentication Protocol Request (DER) message. As can be understood, the examples in Tables 1 to 5 above for the radius protocol may also be used for the diameter protocol.
[0052] Step 4. The DN-AAA server 101 may respond with an Access-Accept message with this S-NSSAI and policy parameters for the DNN. In the case of the diameter protocol, step 4 may also be adapted as a Diameter Authentication-Allowance-Response (AA-A) message, or a Diameter Extensible Authentication Protocol-Response (DEA) message accordingly.
[0053] Step 5: The SMF 102 may request that accounting be started by sending an Accounting-Request (Start) message with 3GPP-Session-S-NSSAI and / or 3GPP-Session-Id to the DN-AAA accounting server, i.e., the accounting function within the DN-AAA server 101. The DN-AAA accounting server may use the 3GPP-Session-S-NSSAI and / or 3GPP-Session-Id for statistics about the user PDU session-related S-NSSAI. Note that the DN-AAA accounting server may use the 3GPP-Session-S-NSSAI and / or 3GPP-Session-Id for other functions in addition to statistics. As can be appreciated, the examples in Tables 1 to 5 above for the Access-Request message in step 3 may also be used for the Accounting-Request (Start) message in step 5. Note that DNN information may also be included in the Accounting-Request (Start) message.
[0054] Step 6: The DN-AAA 101 may respond with an Accounting-Response (Start) message. The SMF 102 may wait for the Accounting-Response (Start) before sending the Namf_Communication_N1N2MessageTransfer request in step 7.
[0055] Step 7. The SMF 102 may proceed with the PDU session establishment procedure and may send a PDU session establishment accept in the Namf_Communication_N1N2MessageTransfer service to set up the PDU session.
[0056] Step 8. The AMF 103 may send the Nsmf_PDUSession_UpdateSMContext message during some procedures, such as N2 handover.
[0057] Steps 9-10. The SMF 102 may send an Accounting-Request (Intermediate Update) message with the optional 3GPP-Session-S-NSSAI and / or 3GPP-Session-Id to the accounting server. As can be appreciated, the examples in Tables 1-5 above for the Access-Request message in step 3 may also be used for the Accounting-Request (Intermediate Update) message in step 9. Note that DNN information may also be included in the Accounting-Request (Intermediate Update) message.
[0058] Step 11. The AMF 103 may send an Nsmf_PDUSessionUpdateSMContext message when the PDU session is released.
[0059] Steps 12-13. The SMF 102 may send an Accounting-Request (Stop) message with the 3GPP-Session-S-NSSAI and / or 3GPP-Session-Id to the accounting server. As can be appreciated, the examples in Tables 1-5 above for the Access-Request message in step 3 may also be used for the Accounting-Request (Stop) message in step 12. Note that DNN information may also be included in the Accounting-Request (Stop) message.
[0060] As a result of the above reporting procedure, the DN-AAA server 101 can obtain the S-NSSAI information for the user and perform correct network slice related statistics for further action. Moreover, the DN-AAA server 101 can effectively authenticate with the UE PDU session related S-NSSAI received from the access request (initiation) message.
[0061] It should be noted that the same procedure is also applicable for a combined SMF+PGW-C with 4G access and support EPS interworking, where the SMF 102 may obtain, for example, S-NSSAI information from the UDM server and used for this PDN connection.
[0062] FIG. 3 is a schematic flow chart illustrating an exemplary method 300 in a first network function 101 (such as a DN-AAA server), according to embodiments herein.
[0063] Method 300 may begin in step S301, where a first network function 101 may receive a request message from a second network function 102 (such as an SMF or a combined SMF+PGW-C) including network slice-related information for a PDU session.
[0064] In one embodiment, the network slice-related information may indicate an S-NSSAI associated with a PDU session. For example, the S-NSSAI may be indicated by a 3GPP session S-NSSAI and / or a 3GPP-Session-Id or other VSA including an S-NSSAI as shown in Tables 1 to 4.
[0065] In one embodiment, as shown in Table 4-1, the Session-S-NSSAI (e.g., 3GPP-Session-S-NSSAI) may include information indicating at least one of a PDU Session ID, a Slice / Service Type (SST), and a slice differentiator (optional) of the network slice. As shown in Table 4-2 above, in one embodiment, the PDU Session ID may be sent via a separate 3GPP-Session-Id.
[0066] In one embodiment, the request message may be an access request message for authentication based on at least network slice-related information, as shown in step 3 of Figure 2. In one embodiment, the request message may further include DNN information.
[0067] In one embodiment, as described in conjunction with step 3 of FIG. 2, the access request message may be a Radius access request message, a Diameter AA-R message, or a DER message.
[0068] The method 300 may then proceed to step S302, where the first network function 101 may receive a request message from the second network function 102 including network slice-related information for the PDU session.
[0069] In one embodiment, the network slice-related information may indicate an S-NSSAI associated with a PDU session. For example, the S-NSSAI may be indicated by a 3GPP session S-NSSAI and / or a 3GPP-Session-Id or other VSA including an S-NSSAI as shown in Tables 1 to 4.
[0070] In one embodiment, as shown in Table 4-1, the Session-S-NSSAI (e.g., 3GPP-Session-S-NSSAI) may include information indicating at least one of a PDU Session ID, a Slice / Service Type (SST), and a slice differentiator (optional) of the network slice. As shown in Table 4-2 above, in one embodiment, the PDU Session ID may be sent separately via a separate 3GPP-Session-Id.
[0071] In one embodiment, the request message may be an accounting request message indicating that a PDU session has started, as shown in steps 5, 9, and 12 of Figure 2. In one embodiment, the request message may further include DNN information.
[0072] In one embodiment, the network slice-related information may further indicate a PDU session ID, as shown in Table 4 above. For example, the PDU session ID may be indicated by a 3GPP session ID or other VSA containing a PDU session ID.
[0073] In one embodiment, as described in conjunction with steps 5, 9, and 12 of FIG. 2, the accounting request message may be a Radius accounting request message or a Diameter accounting request message.
[0074] In one embodiment, as described in combination with step 5 of FIG. 2, the accounting request message may further include information indicating the start of an accounting session.
[0075] In one embodiment, as described in combination with step 5 of FIG. 2, the accounting request message may further include information indicating an intermediate update for the accounting session.
[0076] In one embodiment, as described in combination with step 5 of FIG. 2, the accounting request message may further include information indicating a stop for the accounting session.
[0077] The above steps are only examples, and the first network function 101 may perform the actions described with respect to FIG. 2 to obtain S-NSSAI information for the user and perform correct network slice related statistics for further action.
[0078] FIG. 4 is a schematic flow chart illustrating an exemplary method in a second network function 102 (such as an SMF or a combined SMF+PGW-C) according to embodiments herein.
[0079] Method 400 may begin in step S401, where the second network function 102 may send a request message to the first network function 101 (such as a DN-AAA server) including network slice-related information for the PDU session.
[0080] In one embodiment, the network slice-related information may indicate an S-NSSAI associated with a PDU session. For example, the S-NSSAI may be indicated by a 3GPP session S-NSSAI and / or a 3GPP-Session-Id or other VSA including an S-NSSAI as shown in Tables 1 to 4.
[0081] In one embodiment, as shown in Table 4-1, the Session-S-NSSAI (e.g., 3GPP-Session-S-NSSAI) may include information indicating at least one of a PDU Session ID, a Slice / Service Type (SST), and a slice differentiator (optional) of the network slice. As shown in Table 4-2 above, in one embodiment, the PDU Session ID may be sent separately via a separate 3GPP-Session-Id.
[0082] In one embodiment, the request message may be an access request message for authentication based on at least network slice-related information, as shown in step 3 of Figure 2. In one embodiment, the request message may further include DNN information.
[0083] In one embodiment, the network slice-related information may further indicate a PDU session ID, as shown in Table 4 above. For example, the PDU session ID may be indicated by a 3GPP session ID or other VSA containing a PDU session ID.
[0084] In one embodiment, as described in conjunction with step 3 of FIG. 2, the access request message may be a Radius access request message, a Diameter AA-R message, or a DER message.
[0085] The method 400 may then proceed to step S402, where the second network function 102 may send a request message to the first network function 101 including network slice-related information for the PDU session.
[0086] In one embodiment, the network slice-related information may indicate an S-NSSAI associated with a PDU session. For example, the S-NSSAI may be indicated by a 3GPP session S-NSSAI and / or a 3GPP-Session-Id or other VSA including an S-NSSAI as shown in Tables 1 to 4.
[0087] In one embodiment, as shown in Table 4-1, the Session-S-NSSAI (e.g., 3GPP-Session-S-NSSAI) may include information indicating at least one of a PDU Session ID, a Slice / Service Type (SST), and a slice differentiator (optional) of the network slice. As shown in Table 4-2 above, in one embodiment, the PDU Session ID may be sent separately via a separate 3GPP-Session-Id.
[0088] In one embodiment, the request message may be an accounting request message indicating that a PDU session has started, as shown in steps 5, 9, and 12 of Figure 2. In one embodiment, the request message may further include DNN information.
[0089] In one embodiment, as described in conjunction with steps 5, 9, and 12 of FIG. 2, the accounting request message may be a Radius accounting request message or a Diameter accounting request message.
[0090] In one embodiment, as described in combination with step 5 of FIG. 2, the accounting request message may further include information indicating the start of an accounting session.
[0091] In one embodiment, as described in combination with step 5 of FIG. 2, the accounting request message may further include information indicating an intermediate update for the accounting session.
[0092] In one embodiment, as described in combination with step 5 of FIG. 2, the accounting request message may further include information indicating a stop for the accounting session.
[0093] The above steps are only examples, and the second network function 102 may perform the actions described with respect to FIG. 2 to report S-NSSAI information for the user to correct network slice related statistics for further action.
[0094] FIG. 5 is a schematic block diagram illustrating an exemplary network function 500 that may be configured as a first network function 101 or a second network function 102, according to embodiments herein.
[0095] In one embodiment, the network function 500 may include at least one processor 501 and a non-transitory computer-readable medium 502 coupled to the at least one processor 501. The non-transitory computer-readable medium 502 includes instructions executable by the at least one processor 501, whereby the at least one processor 501 is configured to perform steps in the exemplary method 300 shown in the schematic flowchart of Figure 3 (when configured as the first network function 101) or the exemplary method 400 shown in the schematic flowchart of Figure 4 (when configured as the second network function 102), details of which are omitted here.
[0096] It should be noted that network function 500 may be implemented as hardware, software, firmware, and any combination thereof. For example, network function 500 may include multiple units, circuits, modules, etc., each of which may be used to perform one or more steps of example methods 300 or 400, or one or more steps shown in FIG. 2 associated with first network function 101 or second network function 102.
[0097] 6 is a schematic block diagram illustrating an exemplary computer-implemented device 600 according to embodiments herein. In one embodiment, device 600 may be configured as a device described above, such as first network function 101 or second network function 102.
[0098] In one embodiment, apparatus 600 may include at least one processor, such as, but not limited to, a central processing unit (CPU) 601, a computer-readable medium 602, and a memory 603. Memory 603 may comprise volatile memory (e.g., random access memory, RAM) and / or non-volatile memory (e.g., a hard disk or flash memory). In one embodiment, computer-readable medium 602 may be configured to store computer programs and / or instructions that, when executed by processor 601, cause processor 601 to perform any of the methods described above.
[0099] In one embodiment, computer-readable medium 602 (such as a non-transitory computer-readable medium) may be stored in memory 603. In another embodiment, the computer program may be stored at a remote location, e.g., in computer program product 604 (which may also be embodied as a computer-readable medium), and accessible by processor 601, e.g., via carrier 605.
[0100] The computer readable medium 602 and / or the computer program product 604 may be distributed and / or stored on a removable computer readable medium, for example, a diskette, a CD (compact disc), a DVD (digital video disc), flash or similar removable memory medium (e.g., Compact Flash, SD (secure digital), memory stick, mini SD card, MMC multimedia card, smart media), HD-DVD (high definition DVD), or Blu-ray DVD, USB (universal serial bus) based removable memory medium, magnetic tape medium, optical storage medium, magneto-optical medium, bubble memory, or may be distributed as a propagated signal over a network (e.g., Ethernet, ATM, ISDN, PSTN, X.25, Internet, local area network (LAN), or similar network capable of transporting data packets to infrastructure nodes).
[0101] Exemplary embodiments have been described herein with reference to block diagrams and / or flowchart illustrations of computer-implemented methods, apparatus (systems and / or devices), and / or non-transitory computer program products. It should be understood that blocks of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, may be implemented by computer program instructions performed by one or more computer circuits. These computer program instructions may be provided to processor circuits of general-purpose computer circuits, special-purpose computer circuits, and / or other programmable data processing circuits to create machines, such that the instructions executing via the processor of the computer and / or other programmable data processing apparatus transform and control transistors, values stored in memory locations, and other hardware components within such circuits to implement the functions / acts specified in one or more blocks of the block diagrams and / or flowcharts, and thereby create means (functions) and / or structures for implementing the function / acts specified in the block diagram and / or flowchart block(s).
[0102] These computer program instructions may also be stored on a tangible computer-readable medium that may direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored on the computer-readable medium produce an article of manufacture containing instructions that implement the functions / acts specified in one or more blocks of the block diagrams and / or flowcharts. Thus, embodiments of the inventive concepts may be embodied in hardware and / or in software (including firmware, resident software, microcode, etc.) running on a processor, such as a digital signal processor, which may be collectively referred to as a "circuit," "module," or variations thereof.
[0103] It should also be noted that in some alternative implementations, the functions / acts noted in the blocks may occur out of the order noted in the flowcharts. For example, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functions / acts involved. Moreover, the functionality of a given block of the flowcharts and / or block diagrams may be separated into multiple blocks, and / or the functionality of two or more blocks of the flowcharts and / or block diagrams may be at least partially integrated. Finally, other blocks may be added / inserted between the shown blocks, and / or blocks / acts may be omitted without departing from the scope of the inventive concept. Moreover, while some of the figures include arrows on communication paths to indicate a primary direction of communication, it should be understood that communication may occur in the opposite direction to the illustrated arrows.
[0104] Numerous variations and modifications may be made to the embodiments without substantially departing from the principles of the inventive concept. All such variations and modifications are intended to be included herein within the scope of the inventive concept. Accordingly, the subject matter disclosed above should be considered illustrative and not limiting, and the accompanying examples of embodiments are intended to cover all such modifications, extensions, and other embodiments that fall within the spirit and scope of the inventive concept. Therefore, to the fullest extent permitted by law, the scope of the inventive concept should be determined by the broadest permissible interpretation of this disclosure, including subsequent examples of embodiments and their equivalents, and should not be limited or constrained by the above detailed description.
[0105] Abbreviation 3GPP 3rd Generation Partnership Project AAR Authentication Authorization Request AMF authentication management facility DER Diameter Extensible Authentication Protocol Request DN-AAA Data Network Authentication Authorization Accounting DNN Data Network Name PDU Protocol Data Unit PGW-C P-Gateway-C Radius Remote Authentication Dial-In User Service S-NSSAI Single Network Slice Selection Assistance Information SMF Session Management Facility SST Slice / Service Type NSSAAA Network Slice Specific Authentication and Authorization Accounting; NSSAAF network slice specific authentication and authorization functions; PDN Packet Data Network; UE User Equipment; UPF User Plane Function.
Claims
1. A method (300) performed by a first network function (101) implementing a Data Network Authentication, Authorization and Accounting (DN-AAA) server, comprising: receiving a request message from a second network function (102) including network slice related information for a protocol data unit (PDU) session (S301, S302); Including, The request message is an access request message for authentication based on at least the network slice-related information, or The request message is an accounting request message indicating that the PDU session has started. Method (300).
2. 2. The method (300) of claim 1, wherein the network slice-related information indicates single network slice selection assistance information (S-NSSAI) associated with the PDU session.
3. 3. The method (300) of claim 2, wherein the S-NSSAI is indicated by a 3GPP session S-NSSAI or other vendor specific attribute (VSA) containing an S-NSSAI.
4. 4. The method (300) of claim 3, wherein the session S-NSSAI further includes information indicating at least one of the following parameters: a PDU session ID of a network slice, a slice / service type (SST), and a slice differentiator.
5. The method (300) of any one of claims 1 to 4, wherein the request message further comprises Data Network Name (DNN) information.
6. 2. The method (300) of claim 1, wherein the network slice-related information further indicates the PDU session ID.
7. 7. The method (300) of claim 6, wherein the PDU Session ID is indicated by a 3GPP Session ID or other Vendor Specific Attribute (VSA) containing the PDU Session ID.
8. 2. The method (300) of claim 1, wherein the access-request message is a Remote Authentication Dial-In User Service (Radius) access-request message, a Diameter Authentication Authorization Request (AAR) message, or a Diameter Extensible Authentication Protocol Request (DER) message.
9. 2. The method (300) of claim 1, wherein the accounting-request message is a Remote Authentication Dial-In User Service (Radius) accounting-request message or a Diameter accounting-request message.
10. 10. The method (300) of claim 9, wherein the accounting request message further includes information indicating a start, mid-update, or stop for an accounting session.
11. The method (300) of any one of claims 1 to 10, wherein the second network function is a network function implementing a Session Management Function (SMF) or a combined SMF+P-Gateway-C (PGW-C).
12. A method (400) performed by a second network function (102) implementing a Session Management Function (SMF) or a combined SMF+P-Gateway-C (PGW-C), comprising: Sending a request message (S401, S402) to a first network function (101) implementing a Data Network Authentication, Authorization and Accounting (DN-AAA) server, the request message including network slice related information for a Protocol Data Unit (PDU) session. Including, The request message is an access request message for authentication based on at least the network slice-related information, or The request message is an accounting request message indicating that the PDU session has started. Method (400).
13. 13. The method (400) of claim 12, wherein the network slice-related information indicates single network slice selection assistance information (S-NSSAI) associated with the PDU session.
14. 14. The method (400) of claim 13, wherein the S-NSSAI is indicated by a 3GPP session S-NSSAI or other vendor specific attribute (VSA) containing an S-NSSAI.
15. 15. The method (400) of claim 14, wherein the session S-NSSAI further includes information indicating at least one of the following parameters: a PDU session ID of a network slice, a slice / service type (SST), and a slice differentiator.
16. The method (400) of any one of claims 12 to 15, wherein the request message further comprises Data Network Name (DNN) information.
17. 13. The method (400) of claim 12, wherein the network slice-related information further indicates the PDU session ID.
18. 20. The method (400) of claim 17, wherein the PDU Session ID is indicated by a 3GPP Session ID or other Vendor Specific Attribute (VSA) containing the PDU Session ID.
19. 13. The method (400) of claim 12, wherein the access-request message is a Remote Authentication Dial-In User Service (Radius) access-request message, a Diameter Authentication Authorization Request (AAR) message, or a Diameter Extensible Authentication Protocol Request (DER) message.
20. 13. The method (400) of claim 12, wherein the accounting-request message is a Remote Authentication Dial-In User Service (Radius) accounting-request message or a Diameter accounting-request message.
21. 21. The method (400) of claim 19 or 20, wherein the accounting request message further comprises information indicating a start, an intermediate update or a stop for an accounting session.
22. a first network function (101, 500) implementing a Data Network Authentication, Authorization and Accounting (DN-AAA) server, At least one processor (501); a non-transitory computer-readable medium (502) coupled to the at least one processor (501); and wherein the non-transitory computer-readable medium (502) includes instructions executable by the at least one processor (501), whereby the at least one processor (501) is configured to perform the method of any one of claims 1 to 11.
23. a second network function (102, 500) implementing a Session Management Function (SMF) or a combined SMF+P-Gateway-C (PGW-C), At least one processor (501); a non-transitory computer-readable medium (502) coupled to the at least one processor (501); and wherein the non-transitory computer-readable medium (502) includes instructions executable by the at least one processor (501), whereby the at least one processor (501) is configured to perform the method of any one of claims 12 to 21.
24. A computer readable medium (502, 602) comprising computer readable code that, when run on a device (101, 102, 500, 600), causes the device (101, 102, 500, 600) to perform the method of any one of claims 1 to 21.
25. A computer program product (604) comprising computer readable code which, when run on a device (101, 102, 500, 600), causes said device (101, 102, 500, 600) to perform the method of any one of claims 1 to 21.